GandCrab Ransomware Being Distributed Via Malspam Disguised as Receipts

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
A new malspam campaign is underway that is pretending to be PDF receipts, but instead installs the GandCrab ransomware on a victim's computer. This is done through a series of malicious documents that ultimately install the ransomware via a PowerShell script.

The start of the chain of events that lead to the installation of GandCrab is when a victim receives an email with a subject like "Receipt Feb-078122". These emails contain a PDF attachment with names like Feb01221812.pdf as shown below.

malspam.jpg

Malspam Pretending to be a Receipt
When a user opens this PDF, they will be shown a prompt that pretends to be a captcha asking the user to confirm they are human.

malicious-pdf-file.jpg

Fake Captcha
When a user clicks on the captcha, the PDF file downloads a malicious word document. When opened, this document will contain the standard social engineering text that tries to convince the user to enable macros by clicking on the Enable Content button.
...
.
.
......
..

Once launched, GandCrab will connect to the remote Command & Control servers and begin encrypting a victim's computer.


As you can see, this all started simply by opening a malicious PDF contained in malspam. This is why it is very important to be careful not to open any attachments unless you confirm that they were actually sent by the sender. If the sender is not someone you know, then do not open it at all to be safe.


For those who are infected with this ransomware, you can request help in our GandCrab Help & Support topic.


Be smart and stay safe!
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top