From: Run Do Not Reply [mailto:firstname.lastname@example.org]The malicious payload is on [donotclick]editdvsyourself.net/detects/beeweek_status-check.php, hosted on the familiar IP address of 18.104.22.168 (Vodafone, Fiji).
Sent: 09 October 2012 15:10
Subject: Your Biweekly payroll is accepted
Your Biweekly payroll for check date 10/09/2012 is ready to go. Your payroll will be issued at least Two days prior to your check date to ensure timely tax deposits and delivery. If you offer direct deposit to your employees, this would also support pay down their money right at the necessary date.
Client ID: XXXXXXX1
Other details: Click here to Review
Important: Please be advised that calls to and from your payroll service team may be monitored or recorded.
Please don't reply to this message. automative notification system not configured to accept incoming email.
The following malicious domains are also associated with this IP: