r.cc - URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned r.cc and returned a unknown verdict (score 8). The page resolved to 161.248.15.51 on Netforge Solution Sdn. Bhd. in HK. 2 domains and 1 IP were contacted. 4 malware samples communicate with this URL (Finfish). This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 8) · Confidence 11%
- Scanned URL:
https://r.cc/ - Domain: r.cc · IP: 161.248.15.51 · AS4907 · HK
- Server: nginx
- Page title: 安全检测Www.aliyun.Com
- HTTP status: 200 · text/html; charset=utf-8
- TLS issuer: C=US, O=Leocert LLC, CN=Leocert TLS Issuing RSA CA 1 · valid to Jul 20 15: · subject CN=r.cc
- Scan tier: fast · observed 2026-08-20 13:12:32 UTC
Malware communicating with this URL (4)
These samples were observed contacting or being served from r.cc. Each links to its full analysis.
- Finfish - referenced ·
8903aec30042e9538dbabe16431c98ea· first seen 2026-08-20 - f.txt - referenced ·
5c4ece1f1a97a6ff05e1622f544e1b58· first seen 2026-08-19 - 3903731066-lbx__pt_br.js - referenced ·
f7e2bc3ee0d4f9ae4d1267999a73f2e2· first seen 2026-08-12 - vubebuzi-safavenotivuf.pdf - referenced ·
f5aaccca1d19c01d92609720d7fddc04· first seen 2026-08-13
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Untrusted certificate (CERT_HAS_EXPIRED)
Detected technologies
- Nginx
Contacted infrastructure
- 161.248.15.51 - AS4907 Netforge Solution Sdn. Bhd. (Hong Kong)
Observed indicators
- r.cc
- cz1css4ydt9m.yc000051.cc
- 161.248.15.51
- https://r.cc/
- https://cz1css4ydt9m.yc000051.cc:8443/index.html?agentName=ZYM
Questions about r.cc
- Is r.cc safe?
- The scan of r.cc on 20 Aug 2026 reached no verdict either way (score 8). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with r.cc?
- 4 analysed samples communicate with this URL, including Finfish.
- How was r.cc checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of r.cc
Scanned on MalwareAnalyzer by Cyble · Open interactive scan