URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: pastefy.app
Spamhaus DBL :Abused domain (malware)
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2025-06-04 14:03:03 UTC
Total malware sites :19
Online malware sites :0 (0%)
Offline Malware sites :19 (100%)
A record(s) observed :5

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-04 14:57:10 138.199.231.27static.27.231.199.138.clients.your-server.deNot listedAS24940 HETZNER-AS- DEyes
2025-09-07 16:45:53 188.245.199.145static.145.199.245.188.clients.your-server.deNot listedAS24940 HETZNER-AS- DEyes
2025-06-04 14:57:10 49.13.5.8static.8.5.13.49.clients.your-server.deNot listedAS24940 HETZNER-AS- DEyes
2025-06-04 14:03:07 188.114.96.3SBL690066AS13335 CLOUDFLARENETn/ano
2025-06-04 14:03:07 188.114.97.3SBL691350AS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-02-27 17:23:11https://pastefy.app/sLC7Jpkp/rawOfflineVIPKeylogger abuse_ch
2026-02-26 05:39:07https://pastefy.app/WSBxlMpn/rawOfflineremcos ext ua-wget BlinkzSec
2025-08-30 13:33:11https://pastefy.app/6XOj6WNG/rawOfflineRemcosRAT ext rev-base64-loader JAMESWT_WT
2025-08-30 13:33:11https://pastefy.app/cOYbAOas/rawOfflineRemcosRAT ext rev-base64-loader JAMESWT_WT
2025-07-27 18:23:07https://pastefy.app/nhqGoXpJ/rawOfflineascii abuse_ch
2025-07-26 15:51:05https://pastefy.app/ZlmM4eTt/rawOfflineascii PureLogsStealer abuse_ch
2025-07-18 12:30:08https://pastefy.app/6eHFOcQE/rawOfflinerev-base64-loader JAMESWT_WT
2025-07-18 12:29:12https://pastefy.app/P0B1RAQg/rawOfflinerev-base64-loader JAMESWT_WT
2025-07-18 12:29:08https://pastefy.app/OmvfBrxC/rawOfflinerev-base64-loader JAMESWT_WT
2025-07-18 12:29:07https://pastefy.app/DY7oIDgl/rawOfflinerev-base64-loader JAMESWT_WT
2025-07-18 12:29:07https://pastefy.app/s7ta2mWl/rawOfflinerev-base64-loader JAMESWT_WT
2025-07-17 18:59:05https://pastefy.app/XsycA1Mh/rawOfflinePureLogsStealer abuse_ch
2025-07-17 18:58:05https://pastefy.app/mPZf3B7s/rawOfflineascii PureLogsStealer abuse_ch
2025-07-12 19:07:05https://pastefy.app/hg50ErkK/rawOfflineascii abuse_ch
2025-06-27 13:06:04https://pastefy.app/dRInyUdW/rawOffline JAMESWT_WT
2025-06-27 07:52:10https://pastefy.app/dC9qzL4P/rawOffline JAMESWT_WT
2025-06-14 14:08:12https://pastefy.app/eh0k3R5q/rawOfflineascii Encoded rat RemcosRAT ext abuse_ch
2025-06-05 15:44:57https://pastefy.app/NDdosUlp/rawOfflineascii Encoded Formbook ext abuse_ch
2025-06-04 14:03:07https://pastefy.app/uMak2HKy/rawOfflineascii Encoded rat RemcosRAT ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-02-26 05:39:06134be0dcfe116c98f9897bc564d464a7e688fbffa3ea7dfe8ed3b0405aaf7b44unknown  
2025-08-30 13:33:118c1f12eea0d03ca0c6de562ded826a9cd0c49f02b0656af5ee397225ade08672txt 
2025-08-30 13:33:1060558f75eb3f28fbc4ee87b8caedbbc6ddcf727675018cf58bddfa4fbcd2b438txt 
2025-08-14 17:05:51b5df6b1fd88fc6a8e036c08022bc1ae74833593e550c0e2153abdd297ae58fcdhtml  
2025-08-14 16:06:48376c4d04435f9db9229ee5e268a470e0b3c6e8b26dcc249f8a953995f634c785html  
2025-08-14 15:55:582410e09ce99b2616d57866a67377926e2b76137d89c763a8320dd77a8b9bf3aahtml  
2025-08-14 15:46:59aa0a8e87427fd41920f0a7369a42ec6421cf39fb456caf6b6e91c518be65de7atxt  
2025-08-14 15:29:148ed6f54a570cef1e252ccad3992cd96d4adcca73d532f333b47e744233f0e4a3html  
2025-07-18 12:30:0728d1fcc968ee8f087a59a219924cbac6f53bcec0c5d57acb428246f0e568ff43txt  
2025-07-18 12:29:1228d1fcc968ee8f087a59a219924cbac6f53bcec0c5d57acb428246f0e568ff43txt  
2025-07-18 12:29:084a8b101181ac1b0e69630af6acffbeb6750de22c338c2e28e704a9f7946ba500txt  
2025-07-18 12:29:07410c76cd5d9aaa9bb2b475546dbf7dbb25aca899541b998d08e77c2678a3800etxt 
2025-07-18 12:29:074a8b101181ac1b0e69630af6acffbeb6750de22c338c2e28e704a9f7946ba500txt  
2025-06-27 07:52:101d7a4d5e368ddd4b5fe6b3947cc017de136ab0bf3263d87ad990eab8bb092f51txt  
2025-06-14 14:08:12065e2ae5801ae0178b052cafee77f772ddae9f5bea27e5759ea22010919bcc42txt RemcosRAT
2025-06-05 15:44:575a413113a8ec676c3cccb03cd41135785d31a80d8deeea6a99a6053c53989289txt  
2025-06-04 14:03:075f788b49e2d518b32e185295d92cab218adc59e23baee3cf3b5e559de49a4da8txt RemcosRAT