www.sesc.com.ua - suspicious URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned www.sesc.com.ua and returned a suspicious verdict (score 54). The page resolved to 185.104.45.81 on Hosting Ukraine LTD in UA. The domain was registered 11249 days ago through .UA Domain Administration. 1 domain and 1 IP were contacted. 10 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 54) · Confidence 60%
- Scanned URL:
https://www.sesc.com.ua/wp-content/plugins/super-forms/uploads/php/files/c4sn1bjgpsrm2oejcg9ah0us06/30298950716.pdf - Domain: www.sesc.com.ua · IP: 185.104.45.81 · AS200000 · UA
- Server: nginx
- HTTP status: 200 · application/pdf
- Registrar: .UA Domain Administration · domain age 11249 days · created 1995-11-05
- Scan tier: fast · observed 2026-08-23 10:21:29 UTC
Malware communicating with this URL (10)
These samples were observed contacting or being served from www.sesc.com.ua. Each links to its full analysis.
- Phishing - referenced ·
26008d00fbf4d7b8797aae8f785f9f2b· first seen 2026-08-23 - Phishing - referenced ·
a90083b3190a5a1a0264861a836dfd09· first seen 2026-08-22 - Phishing - referenced ·
205ec84d04ab378cdedc7da82e229855· first seen 2026-08-21 - Phishing - referenced ·
8dd84b8a97ccac12b0d5bebdc9ab1771· first seen 2026-08-19 - Phishing - referenced ·
d34c7d7fdf3f0d296ce44e1a49cefeb1· first seen 2026-08-16 - Phishing - referenced ·
7e4447760da2e06ea6e58a63cc83eaa7· first seen 2026-08-16 - Phishing - referenced ·
bb45cf82b2759cb1a182a101ec5d1160· first seen 2026-08-15 - Phishing - referenced ·
f3e60027f2d4eed9647552859cd61682· first seen 2026-08-13 - Phishing - referenced ·
71d842ac3906b49cbdb58a6c4fa6db65· first seen 2026-08-12 - Phishing - referenced ·
1f42f95fcd90d36b786e8557fc3bb5a0· first seen 2026-08-11
Antivirus & YARA (1 of 48 engines)
- ClamAV (daily) [av]: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (served file)
Why this verdict
- Antivirus/YARA detection in page content: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- File download routed to the malware sandbox (30298950716.pdf)
Detected technologies
- Nginx
Contacted infrastructure
- 185.104.45.81 - AS200000 Hosting Ukraine LTD (Ukraine)
Files served by this page
- 30298950716.pdf ·
7403279d6c4bb8586b6f3ff4fdc90a3e
Observed indicators
- www.sesc.com.ua
- 185.104.45.81
- https://www.sesc.com.ua/wp-content/plugins/super-forms/uploads/php/files/c4sn1bjgpsrm2oejcg9ah0us06/30298950716.pdf
Other scans of www.sesc.com.ua (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 16 Aug 2026 - unknown ·
https://www.sesc.com.ua/wp-content/plugins/super-forms/uploads/php/files/jm0rvfoecl1sf6oal8d9ee8733/
Questions about www.sesc.com.ua
- Is www.sesc.com.ua safe?
- No. MalwareAnalyzer scanned www.sesc.com.ua on 23 Aug 2026 and returned a suspicious verdict with a score of 54 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with www.sesc.com.ua?
- 10 analysed samples communicate with this URL, including Phishing.
- How was www.sesc.com.ua checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.sesc.com.ua
Scanned on MalwareAnalyzer by Cyble · Open interactive scan