From: firstname.lastname@example.orgI have only seen a single sample of this with an attachment email@example.com_20160217_132046.docm which has a VirusTotal detection rate of 7/54. According the the Malwr analysis of the document, the payload is the Locky ransomware and is identical to the earlier attach described here.
Date: 17 February 2016 at 14:32
Subject: tracking documents
Reply to: firstname.lastname@example.org [email@example.com]
Device Name: Not Set
Device Model: MX-2640N
Location: Not Set
File Format: DOC (Medium)
Resolution: 200dpi x 200dpi
Attached file is scanned image in DOC format.