Files packaged with Excel-DNA from which a dll containing 2 urls pointing to Discord is extracted. These download data files and encode them with XOR creating additional DLLs, which initiate the malware infection.
Technical Analysis by the Malware Hunter JAMESWT
New payment-themed Formbook campaign. The email lzh attachment contains an exe file: the malware itself
A fake payment is the lure of a new Formbook campaign.
The email lzh attachment contains an executable file: the malware itself. This, if open, activates the chain of infection. The goal of cybercrime is to steal sensitive data from victims. Formbook, in fact, through the keylogger function, is able to acquire everything that the user types. It can also steal email and browser credentials, as well as take screenshots. Finally, it has the ability to remotely issue commands on the infected PC, such as downloading additional payloads or updating those present.