The name of the sender varies, as does the fake invoice number. Attached is a .DOCM file with a filename matching that invoice number. Typical detection rates for the DOCM file are 13/56.
From: AUTUMN RHINES
Date: 12 December 2016 at 10:40
Subject: Invoice number: 947781
Please find attached a copy of your invoice.
Tel: 0800 170 7234
Fax: 0161 850 0404
For all your stationery needs please visit Stationerybase.
Automated analysis of a couple of these files     show the macro downloading a component from miel-maroc.com/874ghv3 (there are probably many more locations). A DLL is dropped with a current detection rate of 11/57.
All those analyses indicate that this is Locky ransomware (Osiris variant), phoning home to:
18.104.22.168/checkupdate (Rinet LLC, Ukraine)
22.214.171.124/checkupdate (Overoptic Systems, UK / Russia)
126.96.36.199/checkupdate (FLP Kochenov Aleksej Vladislavovich aka uadomen.com, Ukraine)