URLhaus Database

You are currently viewing the URLhaus database entry for https://ext-checkdin.vercel.app/api/m which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3787692
URL: https://ext-checkdin.vercel.app/api/m
URL Status:flame Online (spreading malware for 18 hours, 25 minutes)
Host: ext-checkdin.vercel.app
Date added:2026-02-28 19:44:10 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (phishing)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2026-03-01 13:50:19 UTC to abuse{at}amazonaws[dot]com)
Tags:BeaverTail DPRK NorthKorea npm ua-curl

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-01msh 02327b06d4ab9453914c9beae25e2648a35ec848aede39091ce4cd8c53639a7cn/a
2026-03-01msh d37c936e77e3b9185190ce906a551416baa4273e2aafced63a900b3438ef5c06n/a
2026-03-01msh 6de34ac1b49f1f6866276063c506c5abfd134432f33baa4469a06b5b8c2c257cn/a
2026-02-28msh 0c93de2d78b508b065fcb9dd0224b02b4b21c3db0ae905e0da2c42135edf314dn/a