yr.c.lencr.org - URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned yr.c.lencr.org and returned a unknown verdict (score 0). 1 domain and 0 IPs were contacted. 549 malware samples communicate with this URL (Zusy, Remcos, Upatre, Phishing). This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 0) · Confidence 3%
- Scanned URL:
https://yr.c.lencr.org/ - Domain: yr.c.lencr.org
- Scan tier: fast · observed 2026-08-23 14:07:37 UTC
Malware communicating with this URL (549)
These samples were observed contacting or being served from yr.c.lencr.org. Each links to its full analysis.
- Zusy - contacted ·
3a2eb17d5f9066a56a2b6a78ace0c13e· first seen 2026-08-23 - Remcos - contacted ·
ffc48dea7fbd3a9fdb4cd6b5f4b3436f· first seen 2026-08-23 - 5bc47e42a246e43b76ba6a5be2e21a1a42a2b0206d55e2781e87caf84e8e692a - contacted ·
5bc47e42a246e43b76ba6a5be2e21a1a· first seen 2026-08-23 - Upatre - contacted ·
1148d65b47fe104f844419566028ddb8· first seen 2026-08-23 - Phishing - contacted ·
f2589dfd94c689534cb3ee73de3cdde2· first seen 2026-08-23 - 13d72132cc2b9a165a1e171e407a3b15b637e1e55a6c20fadd8833e4f5662cd2 - contacted ·
13d72132cc2b9a165a1e171e407a3b15· first seen 2026-08-23 - Phishing - contacted ·
b955e7e505e10b21fc8e22e00e9009ed· first seen 2026-08-23 - Tinba - contacted ·
306460934c99fc2ec10d3d36f5d65a62· first seen 2026-08-23 - 13f9613aff9650bb48667bb40d5d2d99bccc671c48776743e5b257a12d60d0d5.bin - contacted ·
13f9613aff9650bb48667bb40d5d2d99· first seen 2026-08-23 - Phishing - contacted ·
f7bc41346f8e74c6dcd6aec3f7b0f13e· first seen 2026-08-23 - Zusy - contacted ·
3e8de46fa8d25edc29d390bfc22d1695· first seen 2026-08-23 - Phishing - contacted ·
cd62f8e47cf49dc076da7a3ec5f3c7e8· first seen 2026-08-23 - RedLine - contacted ·
b1395c031dde2994c40bba91476bcce0· first seen 2026-08-23 - Zusy - contacted ·
3951bebe2e7282ccd136e97a0b68b3d1· first seen 2026-08-23 - Phishing - contacted ·
966ce79f43b30db9006e6ffbcaf6f622· first seen 2026-08-23
Why this verdict
- Target did not respond (DNS/connection failure or timeout); verdict from URL structure only
Observed indicators
- yr.c.lencr.org
- https://yr.c.lencr.org/
Other scans of yr.c.lencr.org (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown ·
http://yr.c.lencr.org/ - 23 Aug 2026 - unknown ·
http://yr.c.lencr.org/ - 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://yr.c.lencr.org/ - 23 Aug 2026 - unknown ·
http://yr.c.lencr.org/ - 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://yr.c.lencr.org/ - 23 Aug 2026 - unknown
- 22 Aug 2026 - unknown ·
http://yr.c.lencr.org/ - 22 Aug 2026 - unknown
Questions about yr.c.lencr.org
- Is yr.c.lencr.org safe?
- The scan of yr.c.lencr.org on 23 Aug 2026 reached no verdict either way (score 0). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with yr.c.lencr.org?
- 549 analysed samples communicate with this URL, including Zusy, Remcos, Upatre, Phishing.
- How was yr.c.lencr.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of yr.c.lencr.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan