e.top - suspicious URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned e.top and returned a suspicious verdict (score 20). The page resolved to 121.40.180.105 on Aliyun Computing Co., LTD in CN. 2 domains and 1 IP were contacted, over 2 HTTP requests. 37 malware samples communicate with this URL. The request followed 1 redirect before landing. This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 20) · Confidence 26%
- Scanned URL:
https://e.top/ - Domain: e.top · IP: 121.40.180.105 · AS37963 · CN
- Server: nginx
- Page title: 赛诸葛-成功企业的标配
- HTTP status: 404 · text/html
- TLS issuer: C=CN, O=TrustAsia Technologies, Inc., CN=LiteSSL RSA CA 2025 · valid to Oct 6 09: · subject CN=xcx.168chayou.com
- HTTP requests captured: 2
- Scan tier: fast · observed 2026-08-19 12:25:07 UTC
Redirect chain
https://e.top/https://e.top/login
Malware communicating with this URL (37)
These samples were observed contacting or being served from e.top. Each links to its full analysis.
- b8edf1ce886f6656fd093dbb42d44af0a8fd8521655aab519b904741b0b3e743 - referenced ·
b8edf1ce886f6656fd093dbb42d44af0· first seen 2026-08-19 - f23abb4dc6d5173a4629e15cd7ab135633916210005442cc5edcc8f35f08a0f0 - referenced ·
f23abb4dc6d5173a4629e15cd7ab1356· first seen 2026-08-17 - de625233e1b6326660160ec7d5022d3d8c6732ded24791d07e2b99314f067eb5 - referenced ·
de625233e1b6326660160ec7d5022d3d· first seen 2026-08-17 - 9267ea4836b7840f54d4df3905a61c6bf197ac3ac539281977d9cb2f7b4c3431 - referenced ·
9267ea4836b7840f54d4df3905a61c6b· first seen 2026-08-17 - d73acd346c649f4b93fe4a4248f8803d664d02f2f2ca8772a3bf2377f1d138ad - referenced ·
d73acd346c649f4b93fe4a4248f8803d· first seen 2026-08-16 - 243872184-lbx__pt_br.js - referenced ·
1d643e4b93da79c302afdc8dab7b357a· first seen 2026-08-16 - 6ee6fc892de79953ab678b447151f27578fed64fb77f618c1dc6dcd611c08b11 - referenced ·
6ee6fc892de79953ab678b447151f275· first seen 2026-08-16 - 094c934d46e82b6704887bcfbfc8d1b61f6a1fa0637077b30c02d838057b66cc - referenced ·
094c934d46e82b6704887bcfbfc8d1b6· first seen 2026-08-16 - 2fdfbdc3767a5c79731d3a5a89e0b4903040d31bb71659453cd74d8241cffc4f - referenced ·
2fdfbdc3767a5c79731d3a5a89e0b490· first seen 2026-08-16 - 11ba9e6c2091a692ffc734431fc130be39b3103c60eaa07c0548bab50de11687 - referenced ·
11ba9e6c2091a692ffc734431fc130be· first seen 2026-08-16 - jquery-2.1.3.min.js - referenced ·
8af93bd675e1cfd9ecc850e862819fda· first seen 2026-08-16 - 129205357-lbx__pt_br.js - referenced ·
7957d117a68d99b69544472996d943f9· first seen 2026-08-15 - 945919205-lbx__pt_br.js - referenced ·
97d3352db3608186c89704e39cf04023· first seen 2026-08-15 - 3618766451-lbx__en_gb.js - referenced ·
88b4eee071a3e2d8836be1b02ec5b3e1· first seen 2026-08-14 - ee8e3eba9ba7250ba8c855c4aca38d4a8b6af38a9b1421d38171e6a3232ced6c - referenced ·
ee8e3eba9ba7250ba8c855c4aca38d4a· first seen 2026-08-15
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Abuse-heavy TLD .top
- Untrusted certificate (ERR_TLS_CERT_ALTNAME_INVALID)
Detected technologies
- Nginx
- jQuery
Contacted infrastructure
- 121.40.180.105 - AS37963 Aliyun Computing Co., LTD (China)
Observed indicators
- e.top
- oss.tiantianhuoke.com
- 121.40.180.105
- https://e.top/login
- https://e.top/favicon.ico
- https://e.top/static/plugins/font-awesome/css/font-awesome.min.css?v=2023082201
- https://e.top/static/assets/css/error-page.css?v={:config(
- https://e.top/static/assets/css/error-page-responsive.css?v={:config(
- https://oss.tiantianhuoke.com/static/admin/images/error-noAccess.png
- https://e.top/static/assets/js/jquery-3.5.1.min.js
- https://e.top/static/assets/js/script.js?v={:config(
Other scans of e.top (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - suspicious
- 23 Aug 2026 - suspicious
- 23 Aug 2026 - suspicious
- 22 Aug 2026 - suspicious
- 22 Aug 2026 - suspicious
- 21 Aug 2026 - suspicious
- 20 Aug 2026 - suspicious
- 20 Aug 2026 - suspicious
- 19 Aug 2026 - suspicious
- 17 Aug 2026 - unknown ·
https://e.top/
Questions about e.top
- Is e.top safe?
- No. MalwareAnalyzer scanned e.top on 19 Aug 2026 and returned a suspicious verdict with a score of 20 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with e.top?
- 37 analysed samples communicate with this URL.
- How was e.top checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of e.top
Scanned on MalwareAnalyzer by Cyble · Open interactive scan