I've received several reports of what appears to be shellshock exploit attempts via SMTP. The sources so far have all be webhosting providers, so I'm assuming these are compromised systems.
more here...........https://isc.sans.edu/diary/Shellshock+via+SMTP/18879
more here...........https://isc.sans.edu/diary/Shellshock+via+SMTP/18879