A zip attachment contains a img with an exe: the malware. The other, a pdf downloading a zip with an exe: the same malware. The data is exfiltrated via SMTP.
Cybercrime, new courier-themed Formbook campaign

New courier-themed Formbook campaign. The zip attachment of the fake TNT email “TNT Express Consignment Notification for 213596003” contains an exe: the malware
The fake TNT email “TNT Express Consignment Notification for 213596003” carries a new Formbook campaign.
The zip attachment contains an exe file: the malware. Formbook, through the keylogger function, is able to acquire everything that the user types. Furthermore, it can steal email and browser credentials as well as take screenshots. Finally, it has the ability to remotely issue commands to the infected PC, such as downloading additional payloads or updating existing ones.