A zip attachment contains a img with an exe: the malware. The other, a pdf downloading a zip with an exe: the same malware. The data is exfiltrated via SMTP.
Cybercrime, Request for Quotation from India bait for AgentTesla campaign

A Request for Quotation from India is the bait of an AgentTesla campaign. The email zip attachment contains an exe file: the malware itself. The stolen data is then exfiltrated via FTP
A Request for Quotation from India conveys a new AgentTesla campaign.
The email zip attachment contains an exe file: the malware itself. The stolen data is then exfiltrated via FTP.
AgentTesla, through the keylogger function, is able to acquire everything the user types. Furthermore, it can steal browser emails and credentials and take screenshots. Finally, it has the ability to remotely issue commands on the infected PC, such as downloading additional payloads or updating existing ones.