ar-intl.net - URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned ar-intl.net and returned a unknown verdict (score 0). The page resolved to 139.162.153.109 on 139.162.0.0/16 in DE. The domain was registered 4139 days ago through GoDaddy.com, LLC. 4 domains and 1 IP were contacted, over 27 HTTP requests. 9 malware samples communicate with this URL (Phishing, Phish). The request followed 1 redirect before landing. This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 0) · Confidence 0%
- Scanned URL:
http://ar-intl.net/wp-content/plugins/super-forms/uploads/php/files/53fkgp8l72br1tp9u9uu1n0io7/67487673480.pdf - Domain: ar-intl.net · IP: 139.162.153.109 · AS63949 · DE
- Server: LiteSpeed
- Page title: Page not found – AR INTERNATIONAL
- HTTP status: 404 · text/html; charset=UTF-8
- Registrar: GoDaddy.com, LLC · domain age 4139 days · created 2015-04-23
- HTTP requests captured: 27
- Scan tier: fast · observed 2026-08-23 00:36:45 UTC
Redirect chain
http://ar-intl.net/wp-content/plugins/super-forms/uploads/php/files/53fkgp8l72br1tp9u9uu1n0io7/67487673480.pdfhttps://ar-intl.net/wp-content/plugins/super-forms/uploads/php/files/53fkgp8l72br1tp9u9uu1n0io7/67487673480.pdf
Malware communicating with this URL (9)
These samples were observed contacting or being served from ar-intl.net. Each links to its full analysis.
- Phishing - referenced ·
24ca858062febc57f4128ecbdcdfcfcc· first seen 2026-08-23 - Phishing - referenced ·
a90083b3190a5a1a0264861a836dfd09· first seen 2026-08-22 - Phishing - referenced ·
f67766ee31539d9915cd073d12285d48· first seen 2026-08-21 - Phishing - referenced ·
69cc3951dcd9519aefebe427db967940· first seen 2026-08-20 - Phishing - referenced ·
405685975d3db3e1d852f27106578adb· first seen 2026-08-19 - Phishing - referenced ·
7a5008a0c29059630efbcfb03ee8e664· first seen 2026-08-19 - Phishing - referenced ·
1ea625afefe2717f2c6b0166a0be3b99· first seen 2026-08-17 - Phishing - referenced ·
5ef5f6abdaa43dea14b3bbc58e635aa6· first seen 2026-08-16 - Phish - referenced ·
3b10e87d3ba157bf361a235ddd69bcba· first seen 2026-08-14
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Detected technologies
- LiteSpeed
- WordPress
- React
- jQuery
Contacted infrastructure
- 139.162.153.109 - AS63949 139.162.0.0/16 (Germany)
Observed indicators
- ar-intl.net
- gmpg.org
- fonts.googleapis.com
- template-kit.evonicmedia.com
- 139.162.153.109
- https://ar-intl.net/wp-content/plugins/super-forms/uploads/php/files/53fkgp8l72br1tp9u9uu1n0io7/67487673480.pdf
- https://gmpg.org/xfn/11
- https://ar-intl.net/feed/
- https://ar-intl.net/comments/feed/
- https://ar-intl.net/wp-content/plugins/elementor/assets/lib/font-awesome/css/all.min.css?ver=3.35.0
- https://ar-intl.net/wp-content/plugins/elementor/assets/lib/font-awesome/css/v4-shims.min.css?ver=3.35.0
- https://ar-intl.net/wp-content/plugins/header-footer-elementor/inc/widgets-css/frontend.css?ver=2.8.3
- https://ar-intl.net/wp-content/plugins/jeg-elementor-kit/assets/css/elements/main.css?ver=3.0.2
- https://ar-intl.net/wp-includes/css/dist/block-library/style.min.css?ver=7.1
- https://ar-intl.net/wp-content/plugins/header-footer-elementor/assets/css/header-footer-elementor.css?ver=2.8.3
- https://ar-intl.net/wp-content/plugins/elementor/assets/css/frontend.min.css?ver=3.35.0
- https://ar-intl.net/wp-content/uploads/elementor/css/post-20.css?ver=1787213261
- https://ar-intl.net/wp-content/plugins/metform/public/assets/lib/cute-alert/style.css?ver=4.1.2
- https://ar-intl.net/wp-content/plugins/metform/public/assets/css/text-editor.css?ver=4.1.2
- https://ar-intl.net/wp-content/themes/hello-elementor/assets/css/reset.css?ver=3.4.5
Questions about ar-intl.net
- Is ar-intl.net safe?
- The scan of ar-intl.net on 23 Aug 2026 reached no verdict either way (score 0). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with ar-intl.net?
- 9 analysed samples communicate with this URL, including Phishing, Phish.
- How was ar-intl.net checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of ar-intl.net
Scanned on MalwareAnalyzer by Cyble · Open interactive scan