x2.c.lencr.org - URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned x2.c.lencr.org and returned a unknown verdict (score -12). The page resolved to 23.221.133.54 on Akamai Technologies, Inc. in AU. The domain was registered 2244 days ago through Cloudflare, Inc.. 1 domain and 1 IP were contacted. 238 malware samples communicate with this URL (Phishing, Urelas, Remcos, RedLine). This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -12) · Confidence 15%
- Scanned URL:
https://x2.c.lencr.org/ - Domain: x2.c.lencr.org · IP: 23.221.133.54 · AS16625 · AU
- Server: nginx
- HTTP status: 200 · application/pkix-crl
- Registrar: Cloudflare, Inc. · domain age 2244 days · created 2020-06-29
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Nov 12 10: · subject CN=crl.root-x1.letsencrypt.org
- Scan tier: fast · observed 2026-08-22 10:16:21 UTC
Malware communicating with this URL (238)
These samples were observed contacting or being served from x2.c.lencr.org. Each links to its full analysis.
- Phishing - contacted ·
55ddac8c94830eebd9487bf230ec8643· first seen 2026-08-22 - 4867ff07554acbb69487e2240835c55b417a694c24e22015e3671bc6fff392db - contacted ·
4867ff07554acbb69487e2240835c55b· first seen 2026-08-22 - 6399a76d6a1ef060a616b0921b9d952abf78655ee7e36ab2d60284a78451f63a - contacted ·
6399a76d6a1ef060a616b0921b9d952a· first seen 2026-08-22 - Urelas - contacted ·
3aee4c02c0d3a11f2b3001888b8b1768· first seen 2026-08-22 - Phishing - contacted ·
8acfb68851b54af42972323808f7bfc9· first seen 2026-08-22 - Remcos - contacted ·
80524e38d83418165e3b94d048ce7aac· first seen 2026-08-22 - RedLine - contacted ·
4624f1a8ecaea13280ff0ba32e869e85· first seen 2026-08-22 - Zusy - contacted ·
cacf223f93a227249c59952bbec6efd2· first seen 2026-08-22 - Phishing - contacted ·
aa5796aa0aa69a0b1839679b044632fa· first seen 2026-08-22 - 02d31864a5ffe65f109f0a6f2a3f893c2c5ea293778bcd996a61d980aa84a706 - contacted ·
02d31864a5ffe65f109f0a6f2a3f893c· first seen 2026-08-22 - 820a34f6abdaab0656bcea25fd3525d49eb647e2d7b04702a828c1384a857aaf - contacted ·
820a34f6abdaab0656bcea25fd3525d4· first seen 2026-08-22 - Zusy - contacted ·
b47570488755d173fb9ff9f6f89ba0e8· first seen 2026-08-22 - a4da5d5aab8fb033efce237b865cce76dbdc308d1009746a560d2d761d1d4548 - contacted ·
a4da5d5aab8fb033efce237b865cce76· first seen 2026-08-22 - Juko - contacted ·
bc44a99936f46e9a77f38166456913cc· first seen 2026-08-22 - fec27e686d75cc615ef15ad86ac19e925c4a269a308124b133261523b0e9b4a7 - contacted ·
fec27e686d75cc615ef15ad86ac19e92· first seen 2026-08-22
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Nginx
Contacted infrastructure
- 23.221.133.54 - AS16625 Akamai Technologies, Inc. (Australia)
Observed indicators
- x2.c.lencr.org
- 23.221.133.54
- https://x2.c.lencr.org/
Other scans of x2.c.lencr.org (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown
- 24 Aug 2026 - unknown ·
http://x2.c.lencr.org/ - 24 Aug 2026 - unknown ·
http://x2.c.lencr.org/ - 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://x2.c.lencr.org/ - 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://x2.c.lencr.org/ - 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://x2.c.lencr.org/ - 23 Aug 2026 - unknown
Questions about x2.c.lencr.org
- Is x2.c.lencr.org safe?
- The scan of x2.c.lencr.org on 22 Aug 2026 reached no verdict either way (score -12). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with x2.c.lencr.org?
- 238 analysed samples communicate with this URL, including Phishing, Urelas, Remcos, RedLine.
- How was x2.c.lencr.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of x2.c.lencr.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan