Date: Mon, 4 Mar 2013 08:53:20 +0300The malicious payload is at [donotclick]forumla.ru:8080/forum/links/column.php (report here) hosted on 220.127.116.11 (Chungwa Telecom, Taiwan). These other sites are also visible on the same IP:
From: LinkedIn [email@example.com]
Subject: Efax Corporate
Fax Message [Caller-ID: 646370000]
You have received a 57 pages fax at Mon, 4 Mar 2013 08:53:20 +0300, (213)-406-0113.
* The reference number for this fax is [eFAX-336705661].
View attached fax using your Internet Browser.
© 2013 j2 Global Communications, Inc. All rights reserved.
eFax ® is a registered trademark of j2 Global Communications, Inc.
This account is subject to the terms listed in the eFax ® Customer Agreement.