From: John Donald [email@example.com]There is no body text, but there is an attachment Document1.doc which is not currently detected by AV vendors, in turn it contains this malicious macro [pastebin] which downloads another component from the following location:
Date: 4 March 2015 at 09:09
Note that there may be other different versions of this document with different download locations, but it should be an identical binary that is downloaded. This file is saved as %TEMP%\GHjkdjfgjkGKJ.exe and has a VirusTotal detection rate of 2/57.
Automated analysis tools   show attempted network traffic to the following IPs:
184.108.40.206 (MWTV, Latvia)
220.127.116.11 (Net3, US)
18.104.22.168 (OneGbits, Lithunia)
22.214.171.124 (Gameservers.com / Choopa LLC, Netherlands)
According to the Malwr report it also drops another version of itself with a detection rate of just 1/57 plus a DLL with a detection rate of 7/56.