lenlu.me
104.21.43.87AS13335 · USpage delivers an executable (http://yourserver.com/payload.ps1)
- Browser Analysissuspicious
- Content Inspectionsuspicious
- Network & Hostingclean
- Threat Intelligenceclean
- Related Infrastructureclean
- Domain Intelligenceunknown
- TLS Fingerprintunknown
What happened
Step by step, from what the scanner recorded.Be careful — warning signs found
AutomatedIts page title claims to be Anthropic, which this address is not associated with. It asks for a password in a sign-in box that stays hidden in the page until you click — so the request only appears once you interact with it. This site shows signs commonly seen in scams or impersonation, but we could not confirm it for certain. It may be a real threat, or it may be a legitimate site that simply looks unusual to our automated checks.
What to do
Avoid entering passwords or payment details until you are sure it is genuine. Open the company directly from its known website or app instead of this link. Check the evidence below and escalate to your analyst if unsure.
"Suspicious" is a caution, not a confirmation — it can be a false alarm. The evidence below explains why it was flagged.
Findings
Strongest firstOur Content Inspection engine downloaded the file this URL serves and analyzed it. The payload shows traits commonly seen in malware. Treat it as unsafe until verified.
Success
SHA-256 51c91ed8addfb6d1ab8e52699169d043aefd3cd6baf7bd680a278b521f4d582f
The page's own script names an executable installer hosted on a different domain, rather than offering it as an ordinary download link.
Analyst noteThe URL was read from an inline script, so it is what the page INTENDS to deliver — a download may not have been observed. Check who operates the instance in the URL, and treat a remote-access tool offered by an unrelated lure page as a compromise attempt.
The page presents itself as a document but its button downloads a program to run, not a document to read.
Analyst noteConfirm what the download actually serves. A document workflow that delivers an installer is the tell; the file itself may be signed and clean.
The page presents itself as a known brand (brand keywords/branding detected).
Analyst noteLow/medium confidence (keyword only) — can be a news article or partner page. Corroborate before acting.
Infrastructure
- IP
- 104.21.43.87CLOUDFLARENET - Cloudflare, Inc., US · AS13335US
- TLS
- CN=WE1, O=Google Trust Services, C=US · expires Dec 6, 2026
- Redirects
- 0 hops · / → /
Hashes & fingerprints
Page capture
LiveTitle “LENLU SC ∥ CYBERNETIC FORGE v4.0” · brand shown: Anthropic (low)
Engines
7 · time to verdictPage
- HTTP
- 200 · Completed
- Title
- LENLU SC ∥ CYBERNETIC FORGE v4.0
- Load
- 1.07 s · 18 requests