Threat research notebook

Gridinsoft Security Lab

Fresh malware notes, phishing samples, scam redirects, ransomware observations, and field reports from Gridinsoft research. No gallery, no filler: date, case, finding, next read.

291 lab records

Latest note ·

VirTool:Win32/DefenderTamperingRestore

VirTool:Win32/DefenderTamperingRestore is the name of the Microsoft Defender detection of a malicious element present in the system. Usually, it marks a thing that can weaken the system's security and make the device vulnerable to...

Research log

01

PC Accelerate

Record ·

PC Accelerate is a questionable software that is presented as a useful utility designed to optimize your computer's performance. In reality though, this software...

03

Walliant App

Record ·

The Walliant application is a Potentially Unwanted Application (PUA). It is promoted as an app that automatically changes desktop wallpapers. Though it in fact...

04

SMApps Virus

Record ·

SMApps is a malicious program that aims at spreading illegal promotions. It mainly attacks browsers by changing settings and redirecting search queries from Google...

05

Hunt Ransomware ([email protected])

Record ·

Hunt ransomware is a new sample of the Dharma/CrySis ransomware family that appeared on April 5, 2024. This malware aims at encrypting the files...

06

GoFetch Vulnerability in Apple Silicon Uncovered

Record ·

Researchers uncovered a vulnerability in Apple Silicon processors, dubbed GoFetch. It allows attackers to extract secret keys from Mac computers while performing widespread cryptographic...

07

Dragon Angel Malicious Browser Extension

Record ·

Dragon Angel is a browser extension that functions as a hijacker malware. It redirects users to promoted search engines or websites. These redirects ruin...

08

Taskbarify Unwanted Application

Record ·

Taskbarify is unwanted software (like a Movidown)that claims it is a tiny little Windows tweaker. However, it also turns the device into a proxy...

09

PUABundler:Win32/uTorrent_BundleInstaller

Record ·

PUABundler:Win32/uTorrent_BundleInstaller is a Microsoft Defender detection for a potentially unwanted bundled installer connected to uTorrent or BitTorrent-style setup packages. The issue is usually the...

11

PUABundler:Win32/FusionCore

Record ·

PUABundler:Win32/FusionCore is a designation that Microsoft Defender Antivirus uses to detect and remove potentially unwanted programs (PUP) that are spread by bundling technology. FusionCore...

AI Assistant

Hello! 👋 How can I help you today?