Scan report · 7 days agoPublic

lenlu.me

104.21.43.87AS13335 · US

page delivers an executable (http://yourserver.com/payload.ps1)

delivers a script, not an installer ("payload.ps1"); document pretext ("invoice") on a full website
Engine tags
Verdict

What happened

Step by step, from what the scanner recorded.
Load 1.1 s · 18 requests
01 · Visitor openslenlu.me
02 · Page shown
LENLU SC ∥ CYBERNETIC FORGE v4.0styled as Anthropic · low
03 · OutcomeRemote control of the machineA legitimate remote-management tool, enrolled into the attacker's tenant. The tenant is the takedown target.

Be careful — warning signs found

Automated

Its page title claims to be Anthropic, which this address is not associated with. It asks for a password in a sign-in box that stays hidden in the page until you click — so the request only appears once you interact with it. This site shows signs commonly seen in scams or impersonation, but we could not confirm it for certain. It may be a real threat, or it may be a legitimate site that simply looks unusual to our automated checks.

What to do

Avoid entering passwords or payment details until you are sure it is genuine. Open the company directly from its known website or app instead of this link. Check the evidence below and escalate to your analyst if unsure.

"Suspicious" is a caution, not a confirmation — it can be a false alarm. The evidence below explains why it was flagged.

Findings

Strongest first
Suspicious fileSuspicious content in the downloaded file
387a6c4d-cb87-4b43-8fa8-14742868d574.html

Our Content Inspection engine downloaded the file this URL serves and analyzed it. The payload shows traits commonly seen in malware. Treat it as unsafe until verified.

Success

SHA-256 51c91ed8addfb6d1ab8e52699169d043aefd3cd6baf7bd680a278b521f4d582f

SupportingPage hands the visitor an installer from another domain
http://yourserver.com/payload.exe

The page's own script names an executable installer hosted on a different domain, rather than offering it as an ordinary download link.

Analyst noteThe URL was read from an inline script, so it is what the page INTENDS to deliver — a download may not have been observed. Check who operates the instance in the URL, and treat a remote-access tool offered by an unrelated lure page as a compromise attempt.

SupportingPage delivers an executable under a document pretext
http://yourserver.com/payload.ps1 · delivers a script, not an installer ("payload.ps1"); document pretext ("invoice") on a full website

The page presents itself as a document but its button downloads a program to run, not a document to read.

Analyst noteConfirm what the download actually serves. A document workflow that delivers an installer is the tell; the file itself may be signed and clean.

InfoBrand impersonation detected
Anthropic · low

The page presents itself as a known brand (brand keywords/branding detected).

Analyst noteLow/medium confidence (keyword only) — can be a news article or partner page. Corroborate before acting.

Infrastructure

IP
104.21.43.87CLOUDFLARENET - Cloudflare, Inc., US · AS13335US
TLS
CN=WE1, O=Google Trust Services, C=US · expires Dec 6, 2026
Redirects
0 hops · / → /
52 malicious3 suspicious

Hashes & fingerprints

Page capture

Live

Title “LENLU SC ∥ CYBERNETIC FORGE v4.0” · brand shown: Anthropic (low)

Engines

7 · time to verdict

Page

HTTP
200 · Completed
Title
LENLU SC ∥ CYBERNETIC FORGE v4.0
Load
1.07 s · 18 requests
Stack · 5cdnjsCloudflareHTTP/3JSZipThree.js