Date: Tue, 19 Mar 2013 08:37:37 +0200The malicious payload is at [donotclick]heelicotper.ru:8080/forum/links/column.php which isn't resolving at the moment, but was earlier hosted on:
From: Facebook [updateSIXQG03I44AX@facebookmail.com]
Subject: You have notifications pending
Here's some activity you may have missed on Facebook.
TAMISHA Gore has posted statuses, photos and more on Facebook.
Go To Facebook
See All Notifications
This message was sent to [redacted]. If you don't want to receive these emails from Facebook in the future or have your email address used for friend suggestions, please click: unsubscribe.
Facebook, Inc. Attention: Department 415 P.O Box 10005 Palo Alto CA 94303
220.127.116.11 (SoftLayer, US)
18.104.22.168 (Albert-Ludwigs-Universitaet, Germany)
22.214.171.124 (OVH, France)
The payload and associated IPs are the same as in this attack.