From: Bankline [email@example.com]The link in the email seems to be somewhat dynamic, as I have also seen this slightly different variant of:
Date: 23 January 2015 at 12:43
Subject: You have received a new secure message from BankLine
You have received a secure message.
Read your secure message by following the link bellow:
You will be prompted to open (view) the file or save (download) it to your computer. For best results, save the file first, then open it.
If you have concerns about the validity of this message, please contact the sender directly.
For questions please contact the Bankline Bank Secure Email Help Desk at 0131 556 3513.
The landing page looks like this:
The link on that landing page goes to http://animation-1.com/js/jquery-1.41.15.js?get_message which downloads a ZIP file called Bankline_document_pdf71274.zip (or something similar) containing an executable file named something like Bankline_document_pdf24372.exe. The numbers change in each case, and indeed the executable changes slightly every time it is downloaded.
The ThreatExpert report shows that it attempt to communicate with the well-known-bad-IP of 126.96.36.199 (Excell Media Pvt Ltd, India) which is associated with the Dyre banking trojan.