Is ATT07094.docx safe?
No engine detected malware in this 14-byte text attachment, though its DOCX extension is misleading and no runtime observation was available.
All 75 antivirus engines were free of detections, including 17 tier-1 engines, and external intelligence produced no threat matches. The attachment is only 14 bytes and identified as text rather than a valid DOCX document, so it is more likely malformed or mislabeled than harmful.
60f622ad80178b5ac5…0fbb5026d5d05cRecommended next actions
Before opening
Open it only when its sender or download source is one you independently trust.
If you already opened it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 75 antivirus engines were free of detections, including 17 tier-1 engines, and external intelligence produced no threat matches. The attachment is only 14 bytes and identified as text rather than a valid DOCX document, so it is more likely malformed or mislabeled than harmful.
The antivirus results contain no malicious or suspicious detections among 75 engines, with all 17 participating tier-1 engines reporting no detection. The sample is only 14 bytes and identified as text, which is inconsistent with a real DOCX archive and sharply limits its capacity to contain active document content. No MalwareBazaar match, YARA rule, CIRCL record, heuristic trigger, or brand conflict adds concern. Runtime behavior was not observed, so execution behavior cannot be characterized. No complete contacted-host reputation result is available, although the lack of runtime data means there are also no recorded contacts to evaluate.
What We Detected
No malicious or suspicious detections appeared among 75 antivirus engines. All 17 tier-1 engines that participated reported no detection, and MalwareBazaar, YARAify, and CIRCL produced no matching threat intelligence.
Threat Behavior
The file is only 14 bytes and was identified as text rather than a valid DOCX container. No sandbox run completed, so runtime behavior was not observed, and no complete contacted-host reputation result is available.
What To Do Now
The attachment appears malformed or mislabeled rather than active. If it came from an unexpected message, confirm the sender and avoid relying on the filename extension; request a fresh copy if a document was expected.
Where this verdict could be wrong3 caveats
- behaviour=null, so no completed runtime execution was available to confirm how an application handles the attachment.
- contactedHosts=null, meaning no complete contacted-host reputation result is available.
- The .docx extension conflicts with file.fileType='Text' and the 14-byte size, suggesting a malformed or mislabeled attachment.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/75 engines reported a malicious or suspicious result.
- engines.tier1ReportedClean=17 and engines.tier1Malicious=0.
- externalIntel.malwareBazaar.hit=false and externalIntel.yaraify.ruleCount=0.
- triggeredHeuristics is empty.
- adversarialInputFlags.anyInjectionSuspected=false.
- The .docx filename does not match file.fileType='Text'.
- The 14-byte size is inconsistent with a normal DOCX document.
- No completed runtime observation was available.
- No complete contacted-host reputation cross-check was available.
If the attachment was expected, request a valid replacement because this 14-byte file is not a normal DOCX document. Keep endpoint protection enabled and verify unexpected attachments with the sender.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 75 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 0 / 75engines flagged
- 9sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 75 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
No completed runtime observation is available for this file.
ProvenanceDerivedSourceRuntime coverageObserved at - 03
The hash has been submitted 9 times from 9 sources.
ProvenanceDerivedSourceSaved report factsObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
0 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- ATT07094.docx
- Format
- Text
- Code signing
- Not applicable to this file type
- Size
- 14 B
- Last analyzed
- Sep 12, 2026, 4:35 PM UTC
60f622ad80178b5ac57127d0914b4a6814236becf59ee94efa0fbb5026d5d05cSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Open it only when its sender or download source is one you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is ATT07094.docx safe?
What is ATT07094.docx?
How many antivirus engines detected ATT07094.docx?
What is the SHA-256 hash of ATT07094.docx?
Is it safe to open ATT07094.docx?
How up to date is this analysis of ATT07094.docx?
Community
Member reviews and reports for this exact file hash.