From Replacement Keys [firstname.lastname@example.org]
Date Thu, 21 Jan 2016 17:15:08 +0530
Order Received!We will send you another email when it has been dispatched . If you have any questions about your order please reply to this email. Your order confirmation is below. Thank you for ordering from us.
Thank you again,
Attached is a file INVOICEPaid_100114000.xls of which I have only seen a single variant. The VirusTotal detection rate is 4/53 and the Malwr report indicates a download location from:
The binary dropped is identical to the one in this earlier spam run and it leads to the Dridex banking trojan.