Step-by-Step Malware Removal Instructions

Agreement Update Email Scam
Phishing/Scam

Agreement Update Email Scam

"Agreement Update" is a phishing email. This spam letter is disguised as a notification regarding an update to terms of service. The goal of this deception is to lure recipients into visiting a phishing website that targets log-in credentials. Email passwords entered into this page can enable scam

Thenetaservices.com Ads
Notification Spam

Thenetaservices.com Ads

Thenetaservices[.]com is a rogue webpage designed to promote browser notification spam. It can also redirect visitors to different (likely dubious/malicious) sites. Our research team discovered thenetaservices[.]com while inspecting websites that use rogue advertising networks. Aside from redirec

New Investor Email Scam
Phishing/Scam

New Investor Email Scam

After reading the "New Investor" email, we determined that it is spam. This letter is presented as an investment and joint venture proposal. It must be stressed that all the information this email provides is false, and this mail is not associated with any real public figures or legitimate entiti

Yourgiardiablog.com Ads
Notification Spam

Yourgiardiablog.com Ads

We have inspected yourgiardiablog[.]com and discovered that it is an unreliable web page that uses clickbait to achieve its purpose, which is to trick visitors into agreeing to receive notifications. There are numerous examples of sites similar to yourgiardiablog[.]com, and most of them show misle

Claim RWA Scam
Phishing/Scam

Claim RWA Scam

After inspecting "Claim RWA", we determined that it is a scam. This scheme, as hosted on claimed-rugwa[.]com, supposedly allows users to obtain RWA cryptocurrency tokens. After users "connect" their wallets to this fake page, they are exposed to a crypto drainer designed to steal digital assets.

PepeFork ($PORK) Registration Scam
Phishing/Scam

PepeFork ($PORK) Registration Scam

We have inspected the PepeFork ($PORK) Registration site (porkcoin[.]support) and found that it is a scam website mimicking the original pond0x[.]com and pondcoin[.]com websites. The fraudulent site is created by scammers with the intention of stealing cryptocurrency from unsuspecting individuals.

Robaj Ransomware
Ransomware

Robaj Ransomware

While inspecting new file submissions to the VirusTotal platform, our researchers discovered the Robaj ransomware. After this malware was executed on our testing system, it encrypted files and dropped a ransom note – "readme.txt" – demanding payment for the decryption. The locked files had their

Merlin Swap Airdrop Scam
Phishing/Scam

Merlin Swap Airdrop Scam

Upon closer inspection of the site (mage-airdrop-merlinchain[.]com), we identified that it is a deceptive website promoting a fake cryptocurrency giveaway (airdrop). This scam page is presented as the number one decentralized exchange in the Bitcoin ecosystem. Scammers use this website to steal cr

Blaster Token ($BLSTR) Early Access Scam
Phishing/Scam

Blaster Token ($BLSTR) Early Access Scam

After inspecting this "Blaster Token ($BLSTR) Early Access" airdrop, we determined that it is a scam. This scheme was hosted on added-ones[.]info, and it claims to be distributing Blaster tokens (BLSTR). It operates as a cryptocurrency drainer that steals funds from compromised digital wallets. I

Tuborg Ransomware
Ransomware

Tuborg Ransomware

In the process of reviewing the malware, it became apparent that Tuborg is ransomware (not associated with the Tuborg Brewery in any way) designed to encrypt files. We discovered Tuborg ransomware while examining malware samples submitted to VirusTotal. In addition to encrypting files, Tuborg chan