It is getting harder to recognize malicious e-mail! If it was easy, then we could automate the detection and not expose you in the first place. For this particular exercise we used a real case.
Did you recognize the sender (securefileshares.com) from the e-mail address?
What can you learn when looking up this address using a search engine like google.com?
Did you actually expect such an e-mail with a scanned document?
Did you talk to the folks you thought might have been sending it?