alrabbancapital.com - URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned alrabbancapital.com and returned a unknown verdict (score 6). The page resolved to 50.87.253.26 on Unified Layer in US. 4 domains and 1 IP were contacted, over 13 HTTP requests. 4 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 6) · Confidence 9%
- Scanned URL:
http://alrabbancapital.com/file/files/16371943191.pdf - Domain: alrabbancapital.com · IP: 50.87.253.26 · AS46606 · US
- Server: Apache
- Page title: --> <!--
- HTTP status: 404 · text/html; charset=UTF-8
- HTTP requests captured: 13
- Scan tier: fast · observed 2026-08-19 18:03:09 UTC
Malware communicating with this URL (4)
These samples were observed contacting or being served from alrabbancapital.com. Each links to its full analysis.
- Phishing - referenced ·
9fed31a8d62b762001597c2aa692c836· first seen 2026-08-19 - Phishing - referenced ·
494f2737cfc7c66b7efa5bb393be13ad· first seen 2026-08-16 - Phishing - referenced ·
cbe226f125da1bb039ad3227333ba623· first seen 2026-08-16 - Phishing - referenced ·
3aafb169f6689066cdff2297e0e152e9· first seen 2026-08-15
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Served over plaintext HTTP
Detected technologies
- Apache
- WordPress
- jQuery
Contacted infrastructure
- 50.87.253.26 - AS46606 Unified Layer (United States)
Observed indicators
- alrabbancapital.com
- fonts.googleapis.com
- orangeqatar.com
- www.google.com
- 50.87.253.26
- http://alrabbancapital.com/file/files/16371943191.pdf
- http://fonts.googleapis.com/
- http://alrabbancapital.com/wp-content/cache/wpo-minify/1776944973/assets/wpo-minify-header-contact-form-7.min.css
- http://alrabbancapital.com/wp-content/cache/wpo-minify/1776944973/assets/wpo-minify-header-rabban-manrope-font.min.css
- http://alrabbancapital.com/wp-content/cache/wpo-minify/1776944973/assets/wpo-minify-header-rabban-style1772521202.min.css
- http://alrabbancapital.com/wp-content/cache/wpo-minify/1776944973/assets/wpo-minify-header-rabban-owl1725910322.min.css
- http://alrabbancapital.com/wp-content/cache/wpo-minify/1776944973/assets/wpo-minify-header-rabban-aos1770196454.min.css
- http://alrabbancapital.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- http://alrabbancapital.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://alrabbancapital.com/wp-json/
- https://alrabbancapital.com/xmlrpc.php?rsd
- http://alrabbancapital.com/wp-content/themes/al-rabban/img/fav.png
- https://alrabbancapital.com/wp-content/uploads/2026/01/cropped-fav-32x32.png
- https://alrabbancapital.com/wp-content/uploads/2026/01/cropped-fav-192x192.png
- https://alrabbancapital.com/wp-content/uploads/2026/01/cropped-fav-180x180.png
Other scans of alrabbancapital.com (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown ·
http://alrabbancapital.com/file/files/33899477107.pdf - 19 Aug 2026 - unknown
Questions about alrabbancapital.com
- Is alrabbancapital.com safe?
- The scan of alrabbancapital.com on 19 Aug 2026 reached no verdict either way (score 6). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with alrabbancapital.com?
- 4 analysed samples communicate with this URL, including Phishing.
- How was alrabbancapital.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of alrabbancapital.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan