www.eyuyan.com - URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned www.eyuyan.com and returned a unknown verdict (score -12). The page resolved to 58.220.33.218 on CHINANET jiangsu province network in CN. 10 domains and 1 IP were contacted, over 1 HTTP request. 48 malware samples communicate with this URL (HUILoader, FlyAgent). The request followed 1 redirect before landing. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -12) · Confidence 15%
- Scanned URL:
http://www.eyuyan.com/ - Domain: www.eyuyan.com · IP: 58.220.33.218 · AS137697 · CN
- Server: nginx
- Page title: 易语言汉语编程官方站
- HTTP status: 200 · text/html
- TLS issuer: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=Encryption Everywhere DV TLS CA - G2 · valid to Oct 15 23: · subject CN=eyuyan.com
- HTTP requests captured: 1
- Scan tier: fast · observed 2026-08-21 08:47:36 UTC
Redirect chain
http://www.eyuyan.com/https://www.eyuyan.com/
Malware communicating with this URL (48)
These samples were observed contacting or being served from www.eyuyan.com. Each links to its full analysis.
- HUILoader - referenced ·
1baa2dd96e8a2c232272471e9a5f50ca· first seen 2026-08-21 - HUILoader - referenced ·
f140f2105b7b6f86a3818c61f0030d37· first seen 2026-08-21 - HUILoader - referenced ·
b1bbb200f030163a605e7ed1a353c494· first seen 2026-08-20 - HUILoader - referenced ·
c745d63d229252febd11d6392a56ebee· first seen 2026-08-20 - HUILoader - referenced ·
568b5de8d13b4e996a6685f6776bcc1f· first seen 2026-08-20 - HUILoader - referenced ·
a2fff96ca4ad27cb90865b855cbbd881· first seen 2026-08-20 - HUILoader - referenced ·
adbec4d2558666d80fad3e6a9358c0f1· first seen 2026-08-20 - HUILoader - referenced ·
1ce961db50252c86345d176f9c4b5ea5· first seen 2026-08-20 - HUILoader - referenced ·
97bd2c9057446be183a1c87e1970e82b· first seen 2026-08-20 - HUILoader - referenced ·
772d49f3d384902199e92c6600ead482· first seen 2026-08-20 - FlyAgent - referenced ·
8c85757c72aaff2ca589e0025b71f18f· first seen 2026-08-20 - HUILoader - referenced ·
70a45fd076b9b85ae58f8fb56f101031· first seen 2026-08-20 - HUILoader - referenced ·
b98ec1b2e94c06f0a3ecc983c6f850ad· first seen 2026-08-20 - HUILoader - referenced ·
38b3ce57b3ca5a435940f85447e8e1d0· first seen 2026-08-19 - HUILoader - referenced ·
3d06b29d4b5dd0751c0991e6e7323fdb· first seen 2026-08-19
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Nginx
Contacted infrastructure
- 58.220.33.218 - AS137697 CHINANET jiangsu province network (China)
Observed indicators
- www.eyuyan.com
- www.dywt.com.cn
- bbs.eyuyan.com
- dotef.eyuyan.com
- epl.eyuyan.com
- www.voldp.com
- www.beian.miit.gov.cn
- www.beian.gov.cn
- 210.83.208.156
- ln.cyberpolice.cn
- 58.220.33.218
- https://www.eyuyan.com/
- http://www.dywt.com.cn/favicon.ico
- https://www.eyuyan.com/images/e.ico
- https://www.eyuyan.com/images/css.css
- https://www.eyuyan.com/images/home.js
- https://www.eyuyan.com/images/index_19.gif
- https://www.eyuyan.com/index.htm
- https://www.eyuyan.com/newslist.htm
- https://www.eyuyan.com/prc.htm
Other scans of www.eyuyan.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown
- 22 Aug 2026 - unknown
- 22 Aug 2026 - unknown
- 22 Aug 2026 - unknown
- 21 Aug 2026 - unknown
- 21 Aug 2026 - unknown ·
https://www.dywt.com.cn/ - 21 Aug 2026 - unknown
- 21 Aug 2026 - unknown ·
https://www.dywt.com.cn/
Questions about www.eyuyan.com
- Is www.eyuyan.com safe?
- The scan of www.eyuyan.com on 21 Aug 2026 reached no verdict either way (score -12). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with www.eyuyan.com?
- 48 analysed samples communicate with this URL, including HUILoader, FlyAgent.
- How was www.eyuyan.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.eyuyan.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan