From: email@example.com [firstname.lastname@example.org]
Date: 27 August 2015 at 12:28
Subject: Payslip for period end date 27/08/2015
Please find attached your payslip for period end 27/08/2015
Attached is a file payroll.zip which contains a malicious executable payroll.scr - or it would have done, but in my case the email was malformed and the archive was not attached properly.
This executable has a detection rate of 3/56 and the Hybrid Analysis report indicates that it sends traffic to a server at 220.127.116.11 (Cobranet, Nigeria) which has been used in a few recent attacks and is definitely worth blocking.