ye.c.lencr.org - URL scan, 24 Aug 2026
MalwareAnalyzer by Cyble scanned ye.c.lencr.org and returned a unknown verdict (score 0). 1 domain and 0 IPs were contacted. 1192 malware samples communicate with this URL (HUILoader, Juko, Phishing, Autorun). This is a point-in-time observation from 24 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 0) · Confidence 3%
- Scanned URL:
https://ye.c.lencr.org/ - Domain: ye.c.lencr.org
- Scan tier: fast · observed 2026-08-24 05:07:14 UTC
Malware communicating with this URL (1192)
These samples were observed contacting or being served from ye.c.lencr.org. Each links to its full analysis.
- HUILoader - contacted ·
dec23eeb78f5a234bc910437e6176152· first seen 2026-08-24 - 1dd14f3c5df7202b25acc4adb0f56dcbc3a9c54fa0604309593dec8e29ea6080 - contacted ·
1dd14f3c5df7202b25acc4adb0f56dcb· first seen 2026-08-24 - Juko - contacted ·
43f2b3b2dd5e94c93f0feea61136c97d· first seen 2026-08-24 - Phishing - contacted ·
d85b0c8f63ffe7ea87aef30c9de00ad5· first seen 2026-08-24 - Autorun - contacted ·
65ab6a421fd1f425fca60ebcd0c40b3f· first seen 2026-08-24 - Zusy - contacted ·
7cefb5288ee3d224e83a9e2ee5031e27· first seen 2026-08-24 - 5eda92ef3eaa30e63ce79c646b4a8e57ded2cac06cbc87cf5df18de70cf3277a - contacted ·
5eda92ef3eaa30e63ce79c646b4a8e57· first seen 2026-08-24 - Revell - contacted ·
3a3f9620d8c14ec52e392a1f200cfafb· first seen 2026-08-24 - Phishing - contacted ·
afa05773d6eb85702dc4261bdc7f8ccd· first seen 2026-08-24 - Zusy - contacted ·
5b69dea4c6d2b8e5dad486f868d9979f· first seen 2026-08-24 - Zusy - contacted ·
a192d8848fbb4855ef97463d3dbbb621· first seen 2026-08-24 - 0e9ae7a4778e1acf7b7b6aac7fb82d94d6fcc23002e56db896cc9e7433c407d1 - contacted ·
0e9ae7a4778e1acf7b7b6aac7fb82d94· first seen 2026-08-24 - Phishing - contacted ·
acb8c946f8a69fd5a7d37a66878ac454· first seen 2026-08-24 - Zusy - contacted ·
93c486bf53861b10628ce682370241e5· first seen 2026-08-24 - 5edb6cb0d8b9be0b2697ab7cf7b10a99fccde29d4c53ef8b92452563168e41dd - contacted ·
5edb6cb0d8b9be0b2697ab7cf7b10a99· first seen 2026-08-24
Why this verdict
- Target did not respond (DNS/connection failure or timeout); verdict from URL structure only
Observed indicators
- ye.c.lencr.org
- https://ye.c.lencr.org/
Other scans of ye.c.lencr.org (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown ·
http://ye.c.lencr.org/ - 24 Aug 2026 - unknown ·
http://ye.c.lencr.org/ - 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://ye.c.lencr.org/ - 23 Aug 2026 - unknown ·
http://ye.c.lencr.org/ - 23 Aug 2026 - unknown ·
http://ye.c.lencr.org/ - 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://ye.c.lencr.org/ - 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://ye.c.lencr.org/
Questions about ye.c.lencr.org
- Is ye.c.lencr.org safe?
- The scan of ye.c.lencr.org on 24 Aug 2026 reached no verdict either way (score 0). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with ye.c.lencr.org?
- 1192 analysed samples communicate with this URL, including HUILoader, Juko, Phishing, Autorun.
- How was ye.c.lencr.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of ye.c.lencr.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan