ye.c.lencr.org - URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned ye.c.lencr.org and returned a unknown verdict (score 0). 1 domain and 0 IPs were contacted. 928 malware samples communicate with this URL (Phishing, Zusy, Tinba, Nupik). This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 0) · Confidence 3%
- Scanned URL:
https://ye.c.lencr.org/ - Domain: ye.c.lencr.org
- Scan tier: fast · observed 2026-08-23 23:06:10 UTC
Malware communicating with this URL (928)
These samples were observed contacting or being served from ye.c.lencr.org. Each links to its full analysis.
- Phishing - contacted ·
12904c37e720c57809b423aa83de9bea· first seen 2026-08-23 - Phishing - contacted ·
789b36d5314cde0301599f9cc1040e32· first seen 2026-08-23 - 4e2bbf3f2471596a1ff50a136a9a936350d87c0cae02e1ffbc5b36ed542e2b28 - contacted ·
4e2bbf3f2471596a1ff50a136a9a9363· first seen 2026-08-23 - Phishing - contacted ·
b8699bd5f3b90f8322b3c3c2ca80de11· first seen 2026-08-23 - Phishing - contacted ·
ed7963383df7125dc9e87b1919a96121· first seen 2026-08-23 - Zusy - contacted ·
8833232fe668da839e24dab1d5cd47c3· first seen 2026-08-23 - 4e2e69637fdd87dda5c32a47da418af37768d41b8f4ea298a79796789854a793 - contacted ·
4e2e69637fdd87dda5c32a47da418af3· first seen 2026-08-23 - fcb034024b90412b67fa9468dc25f6676f8804098a87216d9cd2b78a85a10870 - contacted ·
fcb034024b90412b67fa9468dc25f667· first seen 2026-08-23 - Phishing - contacted ·
9aaa1f13bc188172707d2690a3a86e2c· first seen 2026-08-23 - Phishing - contacted ·
e21017e3b45d15f7726f2e590b460d2c· first seen 2026-08-23 - Tinba - contacted ·
34204b003e33893326bd9bb5b25735e5· first seen 2026-08-23 - 5a49ab3c553a9f956c9db44d0685c340b87f5501050c0d665a0b770f5527eabd - contacted ·
5a49ab3c553a9f956c9db44d0685c340· first seen 2026-08-23 - 4e21ce044e526e9a247a917a5df600d5869908d4e1e99d9ff5d9da521b97fbdb - contacted ·
4e21ce044e526e9a247a917a5df600d5· first seen 2026-08-23 - Nupik - contacted ·
3ceff57bc8fd62402d907907e3924bd4· first seen 2026-08-23 - Phishing - contacted ·
b70c706bbcfac4ea57f135c7dc641f35· first seen 2026-08-23
Why this verdict
- Target did not respond (DNS/connection failure or timeout); verdict from URL structure only
Observed indicators
- ye.c.lencr.org
- https://ye.c.lencr.org/
Other scans of ye.c.lencr.org (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown ·
http://ye.c.lencr.org/ - 23 Aug 2026 - unknown ·
http://ye.c.lencr.org/ - 23 Aug 2026 - unknown ·
http://ye.c.lencr.org/ - 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://ye.c.lencr.org/ - 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://ye.c.lencr.org/ - 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://ye.c.lencr.org/ - 22 Aug 2026 - unknown
Questions about ye.c.lencr.org
- Is ye.c.lencr.org safe?
- The scan of ye.c.lencr.org on 23 Aug 2026 reached no verdict either way (score 0). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with ye.c.lencr.org?
- 928 analysed samples communicate with this URL, including Phishing, Zusy, Tinba, Nupik.
- How was ye.c.lencr.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of ye.c.lencr.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan