The cybersecurity researcher TheAnalyst discovered a mail pretending to fire the victim on December 24th. The xls attachments activates the malware infection chain.
The email zip attachment contains an xls. This, if opened, contacts a url and downloads the dll, disguised as an image, which starts malware infection.