Cybercrime, a fake payment order carries AgentTesla
2 chm files in as many rar attachments contact a url (each file different) and download a script, which contains the malware. Data is stolen via ftp.
Technical analysis by the Malware Hunter JAMESWT “Purchase Order No. PO-109688 " mail conveys AgentTesla. The exe in email XZ attachment downloads other components and starts the malware infection. Data is exfiltrated via FTP "Purchase Order No. PO-109688" is the…