From: Louis - Buvasport [email@example.com]
Date: 19 April 2016 at 13:29
Subject: Facture : 1985 corrigée
Veuillez trouver en pièce-jointe, la facture de vos achats. SANS FRAIS DE TRANSPORT
Votre marchandise est partie et vous devriez la recevoir dans les prochains jours.
Si vous avez des questions, n'hésitez pas à nous contacter.
Attached is a file 093887283-19.04.2016.zip which contains a semi-randomly named script (e.g. 741194709-18.04.2016.PDF.js) with VirusTotal detection rates of 6/56  . According to these Malwr reports   the script downloads a file from one of the following locations:
There are probably other scripts with different download locations, the binary has a detection rate of 10/55.The Hybrid Analysis report shows that this executable attempts to download another executable from:
At the moment that location is 404ing and the main payload fails, although that could be easily fixed I guess. This is probably attempting to drop Locky ransomware.
The loader also attempts to interact with some servers belonging to BMG, possibly to generate false data for anyone doing network analysis.
To be on the safe side, it might be worth blocking:
18.104.22.168 (Telesweet, Ukraine)