URLhaus Database

You are currently viewing the URLhaus database entry for https://brownshotelgroup.com/www.brownshotelgroup.com.pt/MogC/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:427296
URL: https://brownshotelgroup.com/www.brownshotelgroup.com.pt/MogC/
URL Status:Offline
Host: brownshotelgroup.com
Date added:2020-08-07 16:50:34 UTC
Last online:2020-08-07 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-07 16:52:02 UTC to abuse{at}hetzner[dot]de)
Takedown time:6 hours, 24 minutes Good (down since 2020-08-07 23:16:27 UTC)
Tags:doc emotet link epoch3 heodo link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-07invoice-ZCJT3951-466011290.docdoc 346b0ed5db257c2bf541ae37f57e3971a19bc69310811cbe7fa037768f2136a1Virustotal results 38.33% Heodo
2020-08-07Inv_ILWN82_596943.docdoc 847871d283f7c713a149c57d41ef65f78b7c7f808ba380b9e80f09fe48a837d6Virustotal results 35.48% QuakBot
2020-08-07Inv 3297 769672.docdoc 7ce67620298aa7d0fe5e7f2bab8e052f4a4ce937c3300c92875e33d7b466acc0Virustotal results 36.07% Heodo
2020-08-07Invoice GL619 2591968.docdoc 6d9ffb2447adb083ad20788cb467c96a7f91b27d9a5a9eb35a13e2471d909b32n/a QuakBot
2020-08-07INVOICE 9 17024351.docdoc bb196956c5e57876daf8c64828c2b0cff8f83fc540f7ff492ecd7632f8a235dcVirustotal results 36.07% QuakBot
2020-08-07Inv-MHP06-992511330.docdoc 5871ec926c8f2a5e608bbcc0aadc55520fcba58d418280c7f44449f8e88a3d41Virustotal results 32.79% Heodo
2020-08-07Inv-WKBV1-86645901.docdoc 01415a0a9ffd595121b549de4447ea446137954484eaa2deda4b870f30782be5Virustotal results 33.33% Heodo
2020-08-07invoice-TYG689-12041275.docdoc f6799ce710435359bc76f35247b6def30eb09ec9ac7ab51ec4494638a56ff15eVirustotal results 26.32% QuakBot