Explanation
The email lures the victim to a website by pretending that there was a failure to deliver a package and that a fee has to be paid.
Clicking on the link in the email leads to a phishing page with a Post logo, where the credit card information is asked. Notice that the domain “amhglobal[.]com” has no relation to Post.lu.
After that LuxTrust credentials are asked in different steps. This includes two one-time-passwords as well as the LuxTrust login credentials. Notice that even though the LuxTrust logo is present, the domain has no relation to LuxTrust.
Example