yr.c.lencr.org - URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned yr.c.lencr.org and returned a unknown verdict (score 0). 1 domain and 0 IPs were contacted. 65 malware samples communicate with this URL (Phishing, HUILoader, Juko, Zusy). This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 0) · Confidence 3%
- Scanned URL:
https://yr.c.lencr.org/ - Domain: yr.c.lencr.org
- Scan tier: fast · observed 2026-08-22 01:10:44 UTC
Malware communicating with this URL (65)
These samples were observed contacting or being served from yr.c.lencr.org. Each links to its full analysis.
- 7bff53b1bb5e9ea099ec71d411aff56e329348d3439e859e58b8674c92be5657 - contacted ·
7bff53b1bb5e9ea099ec71d411aff56e· first seen 2026-08-22 - 3f70ac3b4bdb4fd8b75c5e8c6361f6e63360bf2473703e004ed43a450a42ce91 - contacted ·
3f70ac3b4bdb4fd8b75c5e8c6361f6e6· first seen 2026-08-22 - Phishing - contacted ·
e7b85371e9f99c4d5706b7fdccb58796· first seen 2026-08-22 - HUILoader - contacted ·
b2aadda6a9a011c583f5fd468f695cc9· first seen 2026-08-22 - Juko - contacted ·
cd0082d170b89ca0d575e49dee4b5f59· first seen 2026-08-22 - 178f58c015c9e29282f6bebc4b55dc5560345ef6659eb79c18609703fbd13a7e - contacted ·
178f58c015c9e29282f6bebc4b55dc55· first seen 2026-08-22 - Zusy - contacted ·
b41dbb76e6b7df55199a9c4930f35a6b· first seen 2026-08-22 - 70bf9c7f2d60addf4ef4fbceb6d17bcb215ad45662ec91a284620ff7d2364604 - contacted ·
70bf9c7f2d60addf4ef4fbceb6d17bcb· first seen 2026-08-22 - Phishing - contacted ·
0a8eec0b42ccebb1ea0137c2169efdde· first seen 2026-08-22 - 1887d81364a608663d411e3f827abf816614f63b3560bfb44fdae853a54e4c50 - contacted ·
1887d81364a608663d411e3f827abf81· first seen 2026-08-22 - 3f7bc46ba042e45b6040a19cbd123f8e8994a9885fae7c7b84c5cf767ce0c542 - contacted ·
3f7bc46ba042e45b6040a19cbd123f8e· first seen 2026-08-22 - Phishing - contacted ·
de48efb7954b1384fe472528f94a19d6· first seen 2026-08-22 - Zusy - contacted ·
95bc42e6fe130d3fc162d22febc8b4b6· first seen 2026-08-22 - Zusy - contacted ·
f404e972f3d3923d1b19544cf9e64136· first seen 2026-08-22 - Lmir - contacted ·
448879649f6e11e857d3f172b29b604f· first seen 2026-08-22
Why this verdict
- Target did not respond (DNS/connection failure or timeout); verdict from URL structure only
Observed indicators
- yr.c.lencr.org
- https://yr.c.lencr.org/
Other scans of yr.c.lencr.org (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown ·
http://yr.c.lencr.org/ - 23 Aug 2026 - unknown ·
http://yr.c.lencr.org/ - 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://yr.c.lencr.org/ - 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://yr.c.lencr.org/ - 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://yr.c.lencr.org/ - 23 Aug 2026 - unknown
- 22 Aug 2026 - unknown ·
http://yr.c.lencr.org/
Questions about yr.c.lencr.org
- Is yr.c.lencr.org safe?
- The scan of yr.c.lencr.org on 22 Aug 2026 reached no verdict either way (score 0). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with yr.c.lencr.org?
- 65 analysed samples communicate with this URL, including Phishing, HUILoader, Juko, Zusy.
- How was yr.c.lencr.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of yr.c.lencr.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan