I have received hundreds of these today , currently ~850 ( luckily ClamAv on the mail server has recognised them and quarantined them. The email looks like: From: no-reply@-.co.uk. Date: Wed 19/04/2017 12:29. Subject: – ( 123-230044839 ).
An email with the subject of – ( 123-230044839 ) [random numbers] pretending to come from no-reply@-.co.uk with a malicious pdf attachment that contains an embedded word doc delivers Dridex banking Trojan.
– ( 123-015309323 ) pretending to come from no-reply@-.co.uk with a malicious word doc or Excel XLS spreadsheet attachment is another one from the current bot runs which try to download various Trojans and password stealers especially banking credential…