Date: Thu, 28 Jun 2012 00:52:04 +0200
From: "2012, LinkedIn Corporation" [firstname.lastname@example.org]
Subject: Relationship LinkedIn Mail
• From Kevin Sellers (VP Analytic Services at Glencore)
• There are a total of 9 messages awaiting your response. Visit your InBox now.
Don't want to receive email notifications? Adjust your message settings.
LinkedIn values your privacy. At no time has LinkedIn made your email address available to any other LinkedIn user without your permission. © 2012, LinkedIn Corporation.
The malicious payload is at [donotclick]18.104.22.168/getfile.php?u=71fd37ed (report here) which is part of a small netblock of 22.214.171.124/27 rented out by Limestone Networks in the US. Some attempt has been made to prevent analysis by generating a fake 403 page if you try to analyse it directly.