The xls attachment contacts a single link and downloads the dll, which activates the malware infection. Provided that the IP is Italian and not on the blacklist.
The xlsm attachment contacts a single url from which it downloads the dll, starting the malware infection. But only from Italian IPs and if they’re not blacklisted.
The xlsm attachment contacts single url from which it downloads the dll, starting malware infection. But only from Italian IPs and if they are not blacklisted.