URLhaus Database

You are currently viewing the URLhaus database entry for https://ext-checkdin.vercel.app/api/l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3787694
URL: https://ext-checkdin.vercel.app/api/l
URL Status:Offline
Host: ext-checkdin.vercel.app
Date added:2026-02-28 19:44:12 UTC
Last online:2026-03-02 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2026-03-01 13:50:19 UTC to abuse{at}amazonaws[dot]com)
Takedown time:1 day, 17 hours, 50 minutes Poor (down since 2026-03-02 13:35:21 UTC)
Tags:BeaverTail DPRK NorthKorea npm ua-curl

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-02lsh efde52b4e7854277a4511c3ae348aa80a602a2814e18452da3e46c1b12171dfbn/a
2026-03-02lsh 6d46b70196cf60bbee569dc6558e9277ccc7cf06cd774a911495b1ad79aed0f9n/a
2026-03-01lsh e2931cd3783674b767fd7b1702ff61f9e44658b35b22b1605e426947e9fe5e92n/a
2026-03-01lsh ec4dc86bc4ed8cd3da3c83327a7bf1ef5421a4e6911cb549d39dbe312e70f770n/a
2026-03-01lsh 9998950401be061d45be70be00b5b37823cc2c194d4d464f7eec5d8ed475b3d4n/a
2026-03-01lsh 25b6d8bbe40affff5dba4cf204ec6875867486d8cdef1f23c5f4dc70ebd62042n/a
2026-02-28lsh 37b9cf8e5db0c70ea36c63f6ca3bc0eaa5a15365153c30e4707759026d38ccb6n/a