Date: 3 February 2016 at 09:12
Subject: GS Toilet Hire - Invoice (SI-523) for £60.00, due on 28/02/2016
Thank you for your business - we're pleased to attach your invoice in PDF. Please bear in mind that if we are in the area the price is reduced to £15+vat per visit.
Full details, including payment terms, are included.
If you have any questions, please don't hesitate to contact us.
Office, GS Toilet Hire
07930 391 011
(also www.ni-na27.wc.shopserve.jp/43rf3dw/34frgegrg.exe from this related spam run)
18.104.22.168 (Hostpro Ltd, Ukraine)
I strongly recommend that you block all traffic to that IP, and possibly the 22.214.171.124/22 block in which it resides.
The same spam is being sent out with a more traditional DOC attachment, Sales_Invoice_SI-523_GS Toilet Hire.doc which comes in at least two different variants (VirusTotal  ) which according to these Malwr reports   downloads a binary from the following locations:
(also best-drum-set.com/43rf3dw/34frgegrg.exe from this later spam run)
This is a different binary from before, with a detection rate of 4/53. It still phones home to the same location.