The mail received is as follows: Reassculation_77979.pdf & info_9455.js. It tries to hide as a PDF file but is in fact JavaScript (JS) The eventual payload may be Andromeda/Gamarue, which will make your machine part of a botnet. While all that is happening in the background, a decoy PDF file gets opened as well, as to not raise suspicion. You can find the original JavaScript on Pastebin and the final obtained JavaScript here.”]
Source: https://bartblaze.blogspot.com/2015/11/a-quick-look-at-signed-spam-campaign.html

