URLhaus Database

You are currently viewing the URLhaus database entry for https://huadongrubbercable.com/johnson/r.txt which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3548071
URL: https://huadongrubbercable.com/johnson/r.txt
URL Status:Offline
Host: huadongrubbercable.com
Date added:2025-05-20 11:53:15 UTC
Last online:2025-07-09 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-05-20 11:54:08 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 month, 19 days, 23 hours, 51 minutes Bad (down since 2025-07-09 11:45:08 UTC)
Tags:ascii base64-loader DBatLoader link Encoded opendir RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-06r.txttxt e819a2e0ba6cc1c69025a16d24eeacfeabfba90da853c260bbf40e73f746775en/a 
2025-06-04r.txttxt 165cc355a837f6c7095fdd444d48f3d8037a9e249eaf43eda15156b8f7aa6a31n/a RemcosRAT
2025-06-03r.txttxt 53c30784787fd1db2252aa1e4fb01e24315a7afa4ce20bcf4cdc74d92d8ce4f8n/a 
2025-05-30r.txttxt d0ace3af2ea5552b64c806b8aaf6b672bbdadac07894d0311c7f8755ee45a5bcn/a 
2025-05-20r.txttxt 4e02f5b9c5201ae53302c834bb0c1779cc91124716cf0d6f37c73ecb81437915n/a DBatLoader