yr.c.lencr.org - URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned yr.c.lencr.org and returned a unknown verdict (score 0). 1 domain and 0 IPs were contacted. 193 malware samples communicate with this URL (Obfus, Phishing, Zusy, Fromcharcode). This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 0) · Confidence 3%
- Scanned URL:
https://yr.c.lencr.org/ - Domain: yr.c.lencr.org
- Scan tier: fast · observed 2026-08-22 07:26:55 UTC
Malware communicating with this URL (193)
These samples were observed contacting or being served from yr.c.lencr.org. Each links to its full analysis.
- 5a32552292040fdc6472ddd169f9f63c1059c2ec6f4df37fe523ae596a11ef03 - contacted ·
5a32552292040fdc6472ddd169f9f63c· first seen 2026-08-22 - Obfus - contacted ·
d3271d526831d4629b35d968049c4827· first seen 2026-08-22 - d3242974285610810d3644452360034d0028950c373840f3c0c63a9240bc397c - contacted ·
d3242974285610810d3644452360034d· first seen 2026-08-22 - d328deec6d47df2726c91a6d667b559e35befa9772d7a6296f9e2b515d0bb629 - contacted ·
d328deec6d47df2726c91a6d667b559e· first seen 2026-08-22 - Phishing - contacted ·
6fccbb73a4071a67229a694973cf5247· first seen 2026-08-22 - Zusy - contacted ·
f31a1573a6cc9ec309866ad65b7963a9· first seen 2026-08-22 - Zusy - contacted ·
53fd5d53cbaaea05057a2f0d954eb39c· first seen 2026-08-22 - Phishing - contacted ·
0aa550056a4cf6de1b63118efc9f2967· first seen 2026-08-22 - Fromcharcode - contacted ·
6b14086f600694063708cba202b5b489· first seen 2026-08-22 - Phishing - contacted ·
90bc6ec8b1f3d33c1d42571ed8cdbe35· first seen 2026-08-22 - Urelas - contacted ·
407436519b513e3fc16c7685bba2ebee· first seen 2026-08-22 - Phishing - contacted ·
66b358f27b15c1398a30bf65536fb890· first seen 2026-08-22 - 26e2f3e04d972ea87d286c7f2f64ba58ff2b06e9feb0368cec906b1ef8476782 - contacted ·
26e2f3e04d972ea87d286c7f2f64ba58· first seen 2026-08-22 - AntiDebug - contacted ·
5c5e550350ec4651f04203623c890d5c· first seen 2026-08-22 - 545b5aefb0a2b57c625edb99e7a71d7f81aafc6b2163b001417c3df881b38300 - contacted ·
545b5aefb0a2b57c625edb99e7a71d7f· first seen 2026-08-22
Why this verdict
- Target did not respond (DNS/connection failure or timeout); verdict from URL structure only
Observed indicators
- yr.c.lencr.org
- https://yr.c.lencr.org/
Other scans of yr.c.lencr.org (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://yr.c.lencr.org/ - 23 Aug 2026 - unknown ·
http://yr.c.lencr.org/ - 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://yr.c.lencr.org/ - 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://yr.c.lencr.org/ - 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://yr.c.lencr.org/ - 23 Aug 2026 - unknown
Questions about yr.c.lencr.org
- Is yr.c.lencr.org safe?
- The scan of yr.c.lencr.org on 22 Aug 2026 reached no verdict either way (score 0). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with yr.c.lencr.org?
- 193 analysed samples communicate with this URL, including Obfus, Phishing, Zusy, Fromcharcode.
- How was yr.c.lencr.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of yr.c.lencr.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan