cdn-cms.f-static.net - malicious URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned cdn-cms.f-static.net and returned a malicious verdict (score 100). The page resolved to 103.180.114.1 on BUNNYWAY, informacijske storitve d.o.o in AU. The domain was registered 6138 days ago through GoDaddy.com, LLC. 1 domain and 1 IP were contacted. 29264 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 100) · Confidence 80%
- Scanned URL:
https://cdn-cms.f-static.net/uploads/4366341/normal_5f8724db36d9d.pdf - Domain: cdn-cms.f-static.net · IP: 103.180.114.1 · AS200325 · AU
- Server: BunnyCDN-SYD1-1151
- HTTP status: 200 · application/pdf
- Registrar: GoDaddy.com, LLC · domain age 6138 days · created 2009-10-29
- Scan tier: fast · observed 2026-08-19 12:23:40 UTC
Malware communicating with this URL (29264)
These samples were observed contacting or being served from cdn-cms.f-static.net, and at least one was hosted here. Each links to its full analysis.
- normal_5f88690f5e005.pdf - referenced ·
43fb706aab3df1ff4d93374e6009572d· first seen 2026-08-19 - Phishing - referenced ·
e35fd3299f0482cb063711cb397080ce· first seen 2026-08-19 - 48735913560.pdf - referenced (hosted here) ·
201ab10fc61c572baae5c81c1ea32e12· first seen 2026-08-19 - normal_5fa3a944bf11b.pdf - referenced ·
01de4fce15b881e3f9cf44708e44d8da· first seen 2026-08-19 - 72391805394.pdf - referenced ·
83009141c249dea170993465a03d84ab· first seen 2026-08-19 - Phishing - referenced ·
165fc8a42c5c69249461c2754f8fd61d· first seen 2026-08-19 - normal_5f870d80ba632.pdf - referenced ·
dfddb4d168ae90a8551fcea499206fd3· first seen 2026-08-19 - normal_5f89773ed98ce.pdf - referenced ·
f2df57497c4e4eddf3128063dd349325· first seen 2026-08-19 - normal_5f8897b2407f5.pdf - referenced ·
89c79e384c6e9bb9d074129566d3a63a· first seen 2026-08-19 - 69051893524.pdf - referenced ·
a445b5bbbea02092af32eea6fb5d413c· first seen 2026-08-19 - Phishing - referenced ·
a418caf69ffeb8084dca365dcaa3f877· first seen 2026-08-19 - Phishing - referenced ·
bc30422d161753f21ef80be45e2b8ab2· first seen 2026-08-19 - normal_5f8ee9be86f52.pdf - referenced ·
5774c97d327c367eb362eea51d836937· first seen 2026-08-19 - normal_5f8bab4e80a4f.pdf - referenced ·
3cb91342487c2147bd5a15162b5ee82d· first seen 2026-08-19 - normal_5f882984a5e92.pdf - referenced ·
ea0b36a88fed31a4018c558fe906ae04· first seen 2026-08-19
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Hosts payload/config for 4 malware samples
- Grabbed file (normal_5f8724db36d9d.pdf) is known malicious in the corpus
- File download routed to the malware sandbox (normal_5f8724db36d9d.pdf)
Contacted infrastructure
- 103.180.114.1 - AS200325 BUNNYWAY, informacijske storitve d.o.o (Australia)
Files served by this page
- normal_5f8724db36d9d.pdf ·
7d63188e35d840a5c73fe695cea426e1
Observed indicators
- cdn-cms.f-static.net
- 103.180.114.1
- https://cdn-cms.f-static.net/uploads/4366341/normal_5f8724db36d9d.pdf
Other scans of cdn-cms.f-static.net (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - suspicious ·
https://cdn-cms.f-static.net/uploads/4494877/normal_6065dec4d2f4d.pdf - 24 Aug 2026 - suspicious ·
https://cdn-cms.f-static.net/uploads/4370268/normal_602ac8cfea60f.pdf - 24 Aug 2026 - suspicious ·
https://cdn-cms.f-static.net/uploads/4393485/normal_601bdf83e5b96.pdf - 24 Aug 2026 - suspicious ·
https://cdn-cms.f-static.net/uploads/4406806/normal_5fd621db0b154.pdf - 24 Aug 2026 - suspicious ·
https://cdn-cms.f-static.net/uploads/4387417/normal_6012fc71daeaf.pdf - 24 Aug 2026 - unknown ·
https://cdn-cms.f-static.net/uploads/4374696/normal_5f9a5a6f34867.pdf - 24 Aug 2026 - unknown ·
https://cdn-cms.f-static.net/uploads/4380536/normal_5f9b9d3c6862d.pdf - 24 Aug 2026 - unknown ·
https://cdn-cms.f-static.net/uploads/4401515/normal_5f9788db73e11.pdf - 24 Aug 2026 - suspicious ·
https://cdn-cms.f-static.net/uploads/4420230/normal_605652a894a26.pdf - 24 Aug 2026 - suspicious ·
https://cdn-cms.f-static.net/uploads/4386849/normal_6024264fc3de9.pdf
Questions about cdn-cms.f-static.net
- Is cdn-cms.f-static.net safe?
- No. MalwareAnalyzer scanned cdn-cms.f-static.net on 19 Aug 2026 and returned a malicious verdict with a score of 100 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with cdn-cms.f-static.net?
- 29264 analysed samples communicate with this URL, including Phishing. At least one was served directly from this host.
- How was cdn-cms.f-static.net checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of cdn-cms.f-static.net
Scanned on MalwareAnalyzer by Cyble · Open interactive scan