e.top - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned e.top and returned a suspicious verdict (score 20). The page resolved to 121.40.180.105 on Aliyun Computing Co., LTD in CN. 2 domains and 1 IP were contacted, over 2 HTTP requests. 61 malware samples communicate with this URL (Office365, Smuggling). The request followed 1 redirect before landing. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 20) · Confidence 26%
- Scanned URL:
https://e.top/ - Domain: e.top · IP: 121.40.180.105 · AS37963 · CN
- Server: nginx
- Page title: 赛诸葛-成功企业的标配
- HTTP status: 404 · text/html
- TLS issuer: C=CN, O=TrustAsia Technologies, Inc., CN=LiteSSL RSA CA 2025 · valid to Oct 6 09: · subject CN=xcx.168chayou.com
- HTTP requests captured: 2
- Scan tier: fast · observed 2026-08-21 19:11:50 UTC
Redirect chain
https://e.top/https://e.top/login
Malware communicating with this URL (61)
These samples were observed contacting or being served from e.top. Each links to its full analysis.
- 157221c4a25018a0ca66a4620b88c37f39e5e3dc8959234cafb4473071391124 - referenced ·
157221c4a25018a0ca66a4620b88c37f· first seen 2026-08-21 - index.js - referenced ·
0a4c6daf63c7457ac0d9e330202611a3· first seen 2026-08-21 - Office365 - referenced ·
32355d18c0964d6a36a4c52477d51217· first seen 2026-08-21 - ba17d8c78a3a4efb7f54f00403d1d81b80569d3573b14242bd0b55ecb33c3ede - referenced ·
ba17d8c78a3a4efb7f54f00403d1d81b· first seen 2026-08-21 - a1be19891b68ad0da52007a4aeca67dc004dc1332706c5718628a1a62ea1d833 - referenced ·
a1be19891b68ad0da52007a4aeca67dc· first seen 2026-08-21 - 89ebdda5f0fde21dff7e4309a83f1211c6f4f852b8518fa40f6635a98f7b8f03 - referenced ·
89ebdda5f0fde21dff7e4309a83f1211· first seen 2026-08-21 - 5d2b889a01f761b084546c4ac5fc4c05da23ae6bcb027f68c5719bff4d0f76ee - referenced ·
5d2b889a01f761b084546c4ac5fc4c05· first seen 2026-08-21 - 5e9d8d758a6195b29c57ca50480475e708ff3474ad797abd3738128ede0bb2f1 - referenced ·
5e9d8d758a6195b29c57ca50480475e7· first seen 2026-08-20 - bd2e66c8b696636770aa6712fade35ba2d368a0810dcd21f0206ce9de9a1dc87 - referenced ·
bd2e66c8b696636770aa6712fade35ba· first seen 2026-08-20 - 75dddabf09140ec98f00ece2c32cd9ca0bafd88d70824a7a605af725add5f0cb - referenced ·
75dddabf09140ec98f00ece2c32cd9ca· first seen 2026-08-20 - 6be73b408ce5f3d42d61d94d2c4e38b27e4569090698ac3c75d2cd092f468217 - referenced ·
6be73b408ce5f3d42d61d94d2c4e38b2· first seen 2026-08-20 - Smuggling - referenced ·
0a671d84672e367bebf78293820b8f9a· first seen 2026-08-20 - 78b6852b6ffb3d7dfbe84564a8f262608f798a9c722f43ea6b220bc832b0edf3 - referenced ·
78b6852b6ffb3d7dfbe84564a8f26260· first seen 2026-08-20 - 497c3d3bc4061e06ea844a22b9055f08858688c3e119121be7c571599aea8743 - referenced ·
497c3d3bc4061e06ea844a22b9055f08· first seen 2026-08-20 - f5c1380a5ebbe9ebc15216e4d3d5a90d14baad352dc1dd32052861a2e31142e2 - referenced ·
f5c1380a5ebbe9ebc15216e4d3d5a90d· first seen 2026-08-20
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Abuse-heavy TLD .top
- Untrusted certificate (ERR_TLS_CERT_ALTNAME_INVALID)
Detected technologies
- Nginx
- jQuery
Contacted infrastructure
- 121.40.180.105 - AS37963 Aliyun Computing Co., LTD (China)
Observed indicators
- e.top
- oss.tiantianhuoke.com
- 121.40.180.105
- https://e.top/login
- https://e.top/favicon.ico
- https://e.top/static/plugins/font-awesome/css/font-awesome.min.css?v=2023082201
- https://e.top/static/assets/css/error-page.css?v={:config(
- https://e.top/static/assets/css/error-page-responsive.css?v={:config(
- https://oss.tiantianhuoke.com/static/admin/images/error-noAccess.png
- https://e.top/static/assets/js/jquery-3.5.1.min.js
- https://e.top/static/assets/js/script.js?v={:config(
Other scans of e.top (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - suspicious
- 23 Aug 2026 - suspicious
- 23 Aug 2026 - suspicious
- 22 Aug 2026 - suspicious
- 22 Aug 2026 - suspicious
- 20 Aug 2026 - suspicious
- 20 Aug 2026 - suspicious
- 19 Aug 2026 - suspicious
- 19 Aug 2026 - suspicious
- 17 Aug 2026 - unknown ·
https://e.top/
Questions about e.top
- Is e.top safe?
- No. MalwareAnalyzer scanned e.top on 21 Aug 2026 and returned a suspicious verdict with a score of 20 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with e.top?
- 61 analysed samples communicate with this URL, including Office365, Smuggling.
- How was e.top checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of e.top
Scanned on MalwareAnalyzer by Cyble · Open interactive scan