A new malspam campaign is underway that is pretending to be PDF receipts, but instead installs the
GandCrab ransomware on a victim's computer. This is done through a series of malicious documents that ultimately install the ransomware via a PowerShell script.
The start of the chain of events that lead to the installation of GandCrab is when a victim receives an email with a subject like "Receipt Feb-078122". These emails contain a PDF attachment with names like Feb01221812.pdf as shown below.
Malspam Pretending to be a Receipt
When a user opens this PDF, they will be shown a prompt that pretends to be a captcha asking the user to confirm they are human.
Fake Captcha
When a user clicks on the captcha, the PDF file downloads a malicious word document. When opened, this document will contain the standard social engineering text that tries to convince the user to enable macros by clicking on the Enable Content button.
...
.
.
......
..