From NoReply-Duration Windows [email@example.com]
Date Mon, 01 Feb 2016 04:21:03 -0500
Subject Order Processed.
Please find details for your order attached as a PDF to this e-mail.
This email has been scanned by FilterCloud Email Security.
For more information please visit http://filtercloud.co.uk
I have only seen a single sample of this spam with an attachment V9568HW.doc which has a detection rate of 5/54.
Analysis of the attachment is pending, however this is likely to be the Dridex banking trojan.
The Malwr analysis shows that the document downloads a malicious executable from:
This has a VirusTotal detection rate of 4/54 and those reports plus this Hybrid Analysis show it phoning home to:
18.104.22.168 (System Projects LLC, Russia)
I strongly recommend that you block traffic to that IP.