Saw these hitting spamtraps yesterday...
...and had to laugh. There was no payload - all the links in them were to ticketmaster's website. At least, they were in the examples I saw.
These particular ones aren't too hard to keep out - after the fact. Turns out there are some trivial checks you can do based on Ticketmaster's envelope-sender address format for legitimate transactional emails. Unfortunately, though, it's the kind of thing where you don't know you need a simple new new rule until the spew starts flooding in.