URLhaus Database

You are currently viewing the URLhaus database entry for https://y-hazel-ten.vercel.app/api which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3834592
URL: https://y-hazel-ten.vercel.app/api
URL Status:Offline
Host: y-hazel-ten.vercel.app
Date added:2026-04-29 11:38:08 UTC
Last online:2026-05-04 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Abused domain (phishing)
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: o_zehentleitner
Abuse complaint sent (?): Yes (2026-05-03 19:05:20 UTC to abuse{at}amazonaws[dot]com)
Takedown time:6 days, 5 hours, 58 minutes Bad (down since 2026-05-05 17:37:42 UTC)
Tags:BeaverTail ContagiousInterview DPRK jackpot Lazarus Novara1o1

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-02apijson fbab5f4ef97eb532a8012fd1e7f13be9f9e4db8ab5b58493acfbac011d904895n/a 
2026-05-02apijson e3927101973faf1221645ee0288231bbaae9989c5d026d449301c342f8e5a3a6n/a 
2026-05-01apijson 0c89c66114c5067cc6c8b1af166b8317e9e00501ecbb50a8c83fa757085e4c79n/a 
2026-05-01apijson c8fb4a79da10bb38b3675be0ae725f7049c5e3e5c89e62e8a0b02c591638f6d3n/a 
2026-04-30apijson 6a603eb839ea0bbd5ea67ee2f0580ada0f01c61b3fd67f861cd93c81c8a44aban/a 
2026-04-30apijson a93cce76ed70168ffb51cd3360a70093ab7fd7d3ab19e9c6db0db09ecdee6b6en/a 
2026-04-29apijson 400e633655e2931f4e0f17355cf89571f680c210837f4eb91613bd4120f14cfdn/a 
2026-04-29apijson f95fd6d5a1cc6abd061f54a57bf7074de6874dd26bf885cf4408e7e0c60f46d1n/a 
2026-04-29apijson 6dae33987603e022398a9e1d4b9d55e29767742b5dcce294da5349d360e4fca2n/a