ye.c.lencr.org - URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned ye.c.lencr.org and returned a unknown verdict (score 0). 1 domain and 0 IPs were contacted. 239 malware samples communicate with this URL (Zusy, Phishing, Urelas, Remcos). This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 0) · Confidence 3%
- Scanned URL:
https://ye.c.lencr.org/ - Domain: ye.c.lencr.org
- Scan tier: fast · observed 2026-08-22 10:19:34 UTC
Malware communicating with this URL (239)
These samples were observed contacting or being served from ye.c.lencr.org. Each links to its full analysis.
- a2d1c2baf6db1822ba59845994a469986085591b75d13f2dd24efcea5ec9407a - contacted ·
a2d1c2baf6db1822ba59845994a46998· first seen 2026-08-22 - Zusy - contacted ·
8fcca58517241db561e7e4ccffcf687b· first seen 2026-08-22 - Phishing - contacted ·
55ddac8c94830eebd9487bf230ec8643· first seen 2026-08-22 - 4867ff07554acbb69487e2240835c55b417a694c24e22015e3671bc6fff392db - contacted ·
4867ff07554acbb69487e2240835c55b· first seen 2026-08-22 - 6399a76d6a1ef060a616b0921b9d952abf78655ee7e36ab2d60284a78451f63a - contacted ·
6399a76d6a1ef060a616b0921b9d952a· first seen 2026-08-22 - Urelas - contacted ·
3aee4c02c0d3a11f2b3001888b8b1768· first seen 2026-08-22 - Phishing - contacted ·
8acfb68851b54af42972323808f7bfc9· first seen 2026-08-22 - Remcos - contacted ·
80524e38d83418165e3b94d048ce7aac· first seen 2026-08-22 - RedLine - contacted ·
4624f1a8ecaea13280ff0ba32e869e85· first seen 2026-08-22 - Zusy - contacted ·
cacf223f93a227249c59952bbec6efd2· first seen 2026-08-22 - Phishing - contacted ·
aa5796aa0aa69a0b1839679b044632fa· first seen 2026-08-22 - 02d31864a5ffe65f109f0a6f2a3f893c2c5ea293778bcd996a61d980aa84a706 - contacted ·
02d31864a5ffe65f109f0a6f2a3f893c· first seen 2026-08-22 - 820a34f6abdaab0656bcea25fd3525d49eb647e2d7b04702a828c1384a857aaf - contacted ·
820a34f6abdaab0656bcea25fd3525d4· first seen 2026-08-22 - Zusy - contacted ·
b47570488755d173fb9ff9f6f89ba0e8· first seen 2026-08-22 - a4da5d5aab8fb033efce237b865cce76dbdc308d1009746a560d2d761d1d4548 - contacted ·
a4da5d5aab8fb033efce237b865cce76· first seen 2026-08-22
Why this verdict
- Target did not respond (DNS/connection failure or timeout); verdict from URL structure only
Observed indicators
- ye.c.lencr.org
- https://ye.c.lencr.org/
Other scans of ye.c.lencr.org (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://ye.c.lencr.org/ - 23 Aug 2026 - unknown ·
http://ye.c.lencr.org/ - 23 Aug 2026 - unknown ·
http://ye.c.lencr.org/ - 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://ye.c.lencr.org/ - 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://ye.c.lencr.org/ - 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://ye.c.lencr.org/
Questions about ye.c.lencr.org
- Is ye.c.lencr.org safe?
- The scan of ye.c.lencr.org on 22 Aug 2026 reached no verdict either way (score 0). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with ye.c.lencr.org?
- 239 analysed samples communicate with this URL, including Zusy, Phishing, Urelas, Remcos.
- How was ye.c.lencr.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of ye.c.lencr.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan