The gz attachment of the “Payment Advice - Ref: [HSBC1057029141] /RFQ Priority Payment / Customer Ref: [PI10771QT90]” email contains an exe file: the malware.
Cybercrime, “Customer’s acknowledgments Copy” Formbook campaign

“Customer’s acknowledgments Copy” Formbook campaign. The “customer’s Scan-Copy.ace” compressed attachment contains the “out.ace” file with an exe inside: the malware
“Customer’s acknowledgments Copy” is the subject of an email that conveys a Formbook campaign.
The “customer’s Scan-Copy.ace” compressed attachment contains the “out.ace” file with an exe inside: the malware. Formbook, through the keylogger function, is able to acquire everything that the user types. Furthermore, it can steal email and browser credentials as well as take screenshots. Finally, it has the ability to remotely issue commands to the infected PC, such as downloading additional payloads or updating existing ones.