Date: Fri, 10 Aug 2012 13:43:57 +0200
From: "New order" [8A4EDCFB@williamsvilla.com]
Subject: Verify your order
please verify your order #809910 at http://simplythebestevents.com/wp-content/plugins/mm-forms-community/upload/temp/tracking17948.php?user_id=[redacted]&order_id=8D17821C359
We hope to see you again soon!
The malicious payload is at [donotclick]yrikdhxzwo.org/main.php?page=3f19233d6515cd5d (the payload is defying analysis at the moment), hosted on 18.104.22.168 (Amazon, US). The domain btgjoulrys.info is also on the same server and can be safely assumed to be malicious.