www.fourfoods.com - malicious URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned www.fourfoods.com and returned a malicious verdict (score 58). The page resolved to 4.193.67.176 on Microsoft Corporation in SG. 9 domains and 1 IP were contacted, over 6 HTTP requests. The request followed 1 redirect before landing. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 58) · Confidence 64%
- Scanned URL:
http://fourfoods.com/images/files/23400089372.pdf - Domain: www.fourfoods.com · IP: 4.193.67.176 · AS8075 · SG
- Server: openresty/1.19.3.1
- HTTP status: 200 · text/html; charset=utf-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YE1 · valid to Nov 4 17: · subject CN=www.fourfoods.com
- HTTP requests captured: 6
- Scan tier: standard · observed 2026-08-22 11:46:26 UTC
Redirect chain
http://fourfoods.com/images/files/23400089372.pdfhttps://www.fourfoods.com/images/files/23400089372.pdf
Antivirus & YARA (4 of 48 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
- YARA: JPCERT/CC [yara]: JPCERT_LODEINFO (page content)
- YARA: SophosLabs IoCs (public) [yara]: SOPHOS_Gootloader_JS (page content)
- YARA: Stratosphere IPS [yara]: STRATO_Tor_Onion_C2 (page content)
Why this verdict
- 4 antivirus/YARA engines flagged the page content: DLV_HTML_Smuggling, JPCERT_LODEINFO, STRATO_Tor_Onion_C2, SOPHOS_Gootloader_JS
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Google Analytics
Contacted infrastructure
- 4.193.67.176 - AS8075 Microsoft Corporation (Singapore)
Observed indicators
- www.fourfoods.com
- browsehappy.com
- resource1.itopplus.com
- itp1.itopfile.com
- owlcarousel2.github.io
- www.googletagmanager.com
- www.browsehappy.com
- fonts.googleapis.com
- unpkg.com
- 4.193.67.176
- https://www.fourfoods.com/images/files/23400089372.pdf
- https://browsehappy.com/
- https://resource1.itopplus.com/Production/boypublish/Dist/distribution/js/Client/iTopPlusRouting.min.js?bust=v648
- https://resource1.itopplus.com/Production/boypublish/Dist/distribution/js/Client/itopplusComponentCommon.min.js?bust=v648
- https://resource1.itopplus.com/Production/boypublish/Dist/distribution/Dist/angular.itopplusapp.js?bust=v648
- https://resource1.itopplus.com/Production/boypublish/Dist/distribution/Dist/common.itopplusapp.js?bust=v648
- https://resource1.itopplus.com/Production/boypublish/Dist/distribution/Dist/app_advance_form.itopplusapp.js?bust=v648
- https://www.fourfoods.com/
- https://itp1.itopfile.com/ImageServer/z_itp_12042023m64g/48/48/logoz-z984583377207.png
- https://owlcarousel2.github.io/OwlCarousel2/assets/owlcarousel/assets/owl.theme.default.min.css
Other scans of www.fourfoods.com (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 12 Aug 2026 - malicious ·
https://www.fourfoods.com/images/files/tisemexupife.pdf
Questions about www.fourfoods.com
- Is www.fourfoods.com safe?
- No. MalwareAnalyzer scanned www.fourfoods.com on 22 Aug 2026 and returned a malicious verdict with a score of 58 out of 100. Treat it as hostile until it is re-checked.
- How was www.fourfoods.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.fourfoods.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan