e.top - suspicious URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned e.top and returned a suspicious verdict (score 20). The page resolved to 121.40.180.105 on Aliyun Computing Co., LTD in CN. 2 domains and 1 IP were contacted, over 2 HTTP requests. 85 malware samples communicate with this URL (Smuggling, Office365). The request followed 1 redirect before landing. This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 20) · Confidence 26%
- Scanned URL:
https://e.top/ - Domain: e.top · IP: 121.40.180.105 · AS37963 · CN
- Server: nginx
- Page title: 赛诸葛-成功企业的标配
- HTTP status: 404 · text/html
- TLS issuer: C=CN, O=TrustAsia Technologies, Inc., CN=LiteSSL RSA CA 2025 · valid to Oct 6 09: · subject CN=xcx.168chayou.com
- HTTP requests captured: 2
- Scan tier: fast · observed 2026-08-23 14:28:38 UTC
Redirect chain
https://e.top/https://e.top/login
Malware communicating with this URL (85)
These samples were observed contacting or being served from e.top. Each links to its full analysis.
- 380ccb397ef46829cdb5ed3e579ad063025cadd07e19d1e9a958dcb9521b001e - referenced ·
380ccb397ef46829cdb5ed3e579ad063· first seen 2026-08-23 - c3414a2c5df56b4c8349072b31c970f9a6c931411177d67323a16629d9c30dde - referenced ·
c3414a2c5df56b4c8349072b31c970f9· first seen 2026-08-23 - 1edddbb1f62b69c632c5a558b8a24a4e6531fa5c286a915c854ec865150d5c5b - referenced ·
1edddbb1f62b69c632c5a558b8a24a4e· first seen 2026-08-23 - ee3fb0677b1474b10b01b0237027687714acd1e489c703da64306d43ab296d62 - referenced ·
ee3fb0677b1474b10b01b02370276877· first seen 2026-08-23 - f3c4f637b44270269a3020bc995c4e03e29f662396f15f86f08e6ba6a4745d28 - referenced ·
f3c4f637b44270269a3020bc995c4e03· first seen 2026-08-23 - 133951a4c4e9e0f80be439cc147c98b7c31e2b9f6cdb710dbace4be19b9a4398 - referenced ·
133951a4c4e9e0f80be439cc147c98b7· first seen 2026-08-23 - c828ed8736a781c9cab0cfecae84fcdcabd89320767c19272f9e06c0166b8079 - referenced ·
c828ed8736a781c9cab0cfecae84fcdc· first seen 2026-08-22 - 57639b1873269d286ed795d51b1fd0950c409e101941dee4cf5e97e1c9e81878 - referenced ·
57639b1873269d286ed795d51b1fd095· first seen 2026-08-22 - f3bc02b1c0926908438063a3a28cf1a5ee38bdae609afea6e27834677f6132d6 - referenced ·
f3bc02b1c0926908438063a3a28cf1a5· first seen 2026-08-22 - fc565005458e8ad5a7db8ce2b88933b46a6ede7352136814923417753aca37b9 - referenced ·
fc565005458e8ad5a7db8ce2b88933b4· first seen 2026-08-22 - 9de922cf1967e4328965311ca6000b541ac336c153e06be68f948b915aea0c83 - referenced ·
9de922cf1967e4328965311ca6000b54· first seen 2026-08-22 - 1f08f9f32e11ab34fb2fc342cfdbc346a0c0e0e61c19275041e14d2fd776d4f1 - referenced ·
1f08f9f32e11ab34fb2fc342cfdbc346· first seen 2026-08-22 - Smuggling - referenced ·
0c32e55d652bb8e2994a2a58fe36dc81· first seen 2026-08-22 - Office365 - referenced ·
d3281964f0bf3283372ef3726756d028· first seen 2026-08-22 - Office365 - referenced ·
d3212cecb80244e2f66c763638b05c34· first seen 2026-08-22
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Why this verdict
- Abuse-heavy TLD .top
- Untrusted certificate (ERR_TLS_CERT_ALTNAME_INVALID)
Detected technologies
- Nginx
- jQuery
Contacted infrastructure
- 121.40.180.105 - AS37963 Aliyun Computing Co., LTD (China)
Observed indicators
- e.top
- oss.tiantianhuoke.com
- 121.40.180.105
- https://e.top/login
- https://e.top/favicon.ico
- https://e.top/static/plugins/font-awesome/css/font-awesome.min.css?v=2023082201
- https://e.top/static/assets/css/error-page.css?v={:config(
- https://e.top/static/assets/css/error-page-responsive.css?v={:config(
- https://oss.tiantianhuoke.com/static/admin/images/error-noAccess.png
- https://e.top/static/assets/js/jquery-3.5.1.min.js
- https://e.top/static/assets/js/script.js?v={:config(
Other scans of e.top (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown ·
https://e.top/ - 23 Aug 2026 - suspicious
- 23 Aug 2026 - suspicious
- 22 Aug 2026 - suspicious
- 22 Aug 2026 - suspicious
- 21 Aug 2026 - suspicious
- 20 Aug 2026 - suspicious
- 20 Aug 2026 - suspicious
- 19 Aug 2026 - suspicious
- 19 Aug 2026 - suspicious
Questions about e.top
- Is e.top safe?
- No. MalwareAnalyzer scanned e.top on 23 Aug 2026 and returned a suspicious verdict with a score of 20 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with e.top?
- 85 analysed samples communicate with this URL, including Smuggling, Office365.
- How was e.top checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of e.top
Scanned on MalwareAnalyzer by Cyble · Open interactive scan