| MD5 | b79cd7a658d8069a609bfaa20fdfd37c | 
| SHA1 | d3aad26235b800fb1c8ade422a89ef7e5b5f8f52 | 
| Filename | PaymentReceipt(3).docm | 
| Domains | [qriswell.50webs.com] | 
| IP Addresses | [162.210.101.122] | 
| Antivirus | [Heur.Macro.Downloader.d] | 
| [Macro.Trojan.Dropperd.Auto] | |
| [PP97M/Downldr] | |
| [Troj/DocDl-EKZ] | |
| [TrojanDownloader:O97M/Donoff] | |
| [VBS/Jenxcus.A] | |
| [virus.office.obfuscated.1] |