Date: 8 March 2016 at 11:40
Subject: Samson Floyd agent Fedex
We attempted to deliver your item on March 07th, 2016, 11:40 AM.
The delivery attempt failed because the address was business closed or
nobody could sign for it. To pick up the parcel,please, print the receipt
that is attached to this email and visit Fedex office indicated in the
invoice. If the package is not picked up within 48 hours, it will be returned
to the shipper.
Expected Delivery Date: March 07th, 2016
Class: International Package Service
Service(s): Delivery Confirmation
Status: Notification sent
Thank you for choosing our service
Attached is a RAR archive file in this case named US45928460284.rar containing in turn a malicious script US45928460284.js which is rather curious [pastebin]. This attempts to download an executable from:
This has a VirusTotal detection rate of 4/54. The Malwr report shows a subsequent download from:
This has similar detections to the first binary. That Malwr report also indicates the binary POSTing data to:
This is hosted on:
220.127.116.11 (Kitdos, US / OVH, France)
I would suggest that the entire 18.104.22.168/29 range is questionable and should be blocked.
None of the automated tools I ran     gave any insight as to what the malware does, but it is clearly something malicious.