Security Scan Report: cignaemployeealerts.top

Submitted: Sep 21, 2026, 8:41:57 PMCompleted: Sep 21, 2026, 8:42:13 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 76%

8
Risk Score

Lookalike 'cignaemployeealerts.top' impersonating the Cigna brand on an unranked domain whose host IP is flagged for AsyncRAT malware by multiple feeds, with hostile *.top IDS alerts. Do not visit or submit any data.

Risk Factors (5)
Hostname impersonates the Cigna brand on an unrelated domain
Host IP flagged by multiple independent threat feeds for AsyncRAT malware
.top TLD under hostile DNS/HTTP IDS signatures
Domain resolves to a shared address reported for malware C2 activity
Parked/error page hosted on the flagged infrastructure (img.sedoparking.com)
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

The domain name 'cignaemployeealerts.top' uses the .top top-level domain with no subdomain. The second-level label 'cignaemployeealerts' is 19 characters long holding eight vowels versus 11 consonants. Segmentation suggests 5 words: c, ign, a, employee, alerts. Average segment length settles at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://cignaemployeealerts.top

Page Load Overview

0.25s
Total Load Time
180 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:169 chars
Detector Agreement:100%

Website Classification

Primary Category

healthcare medical76% confidence
Type: static
Method: ml+structural

All Detected Categories

healthcare medical
76%
documentation technical
48%
government public service
36%
adult content
29%
news media journalism
29%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
191.195.240.123Germany
AS47846SEDO GmbH
0205.234.175.175United States
AS30081CacheFly
12--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T161612A57E0D48844542B0258DDB25D3E6660D0BF770AC9527C4D021E8FCDE7DEEAAACE

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:BiEzwqVFa+DapI8jZrZ9ismlpx67sLMC4:BiUagapVjZrZUsmlpx67sn4

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:3314:IMAAAiBABlEAygAAIIRA0QASAAFIQABAAAAAACIgAAJgAGACAAQAwNIICgABAwBAAiAgJAIFkECKASRAgACigAQJAAAIpAIB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffcfc7f3ffffffff
Perceptual Hash:a1319bcecc6c3333
Difference Hash:00181c0600000000
Wavelet Hash:ffdfc7f300000000
Color Hash:#1f9370

Other Hashes

Crop Resistant:00181c0600000000

Scan History

Scan history not available

Unable to load historical scan data