cdn-cms.f-static.net - malicious URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned cdn-cms.f-static.net and returned a malicious verdict (score 74). The page resolved to 103.180.114.1 on BUNNYWAY, informacijske storitve d.o.o in AU. 1 domain and 1 IP were contacted. 30040 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 74) · Confidence 80%
- Scanned URL:
https://cdn-cms.f-static.net/uploads/4367905/normal_5f8764a4f3eaf.pdf - Domain: cdn-cms.f-static.net · IP: 103.180.114.1 · AS200325 · AU
- Server: BunnyCDN-SYD1-1151
- HTTP status: 200 · application/pdf
- Scan tier: fast · observed 2026-08-19 17:59:21 UTC
Malware communicating with this URL (30040)
These samples were observed contacting or being served from cdn-cms.f-static.net. Each links to its full analysis.
- normal_5f99c3c97747b.pdf - referenced ·
3f113d9f1999588196e64946560faf40· first seen 2026-08-19 - normal_5f95145ec64bd.pdf - referenced ·
3af9de94508a6dd9211fa30135457ae2· first seen 2026-08-19 - normal_5fa195c306503.pdf - referenced ·
5412f2633591a44f2749232470dc5ea3· first seen 2026-08-19 - normal_5f881e11dbf8e.pdf - referenced ·
9b1ab1a1eb755f366f70663470f29f6a· first seen 2026-08-19 - normal_5f8748a93c2d6.pdf - referenced ·
326248acce61d836314b0ba10169cd0f· first seen 2026-08-19 - normal_5f8a3fb75577e.pdf - referenced ·
6e07f0a33e0ed6a423fa88be2959fcde· first seen 2026-08-19 - normal_5f87b8905237f.pdf - referenced ·
5724cdcf4f4a605b7d5c42420f1cee6b· first seen 2026-08-19 - normal_5f871605a76ee.pdf - referenced ·
dceb8716db43454c88ee54c7d06d4b60· first seen 2026-08-19 - Phishing - referenced ·
1777c237fad328988c9550c44504a21a· first seen 2026-08-19 - normal_5f873bf7a2cfa.pdf - referenced ·
b2453caf4acdf31aa01bb2e1298d3852· first seen 2026-08-19 - Phishing - referenced ·
7343881c691355a2d405779a2d4b42c0· first seen 2026-08-19 - Phishing - referenced ·
288c6ad58c30927b1e4be4ad6c2200ad· first seen 2026-08-19 - Phishing - referenced ·
58c63f29d61976b4b45010db946d5a20· first seen 2026-08-19 - Phishing - referenced ·
755419e84187682b9909e8d1db03b27d· first seen 2026-08-19 - Phishing - referenced ·
d3b88784d2f74f15bf9bfa00b0091794· first seen 2026-08-19
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Grabbed file (normal_5f8764a4f3eaf.pdf) is known malicious in the corpus
- File download routed to the malware sandbox (normal_5f8764a4f3eaf.pdf)
Contacted infrastructure
- 103.180.114.1 - AS200325 BUNNYWAY, informacijske storitve d.o.o (Australia)
Files served by this page
- normal_5f8764a4f3eaf.pdf ·
577843fb624f759a835db822aebf47e5
Observed indicators
- cdn-cms.f-static.net
- 103.180.114.1
- https://cdn-cms.f-static.net/uploads/4367905/normal_5f8764a4f3eaf.pdf
Other scans of cdn-cms.f-static.net (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - suspicious ·
https://cdn-cms.f-static.net/uploads/4420230/normal_605652a894a26.pdf - 24 Aug 2026 - suspicious ·
https://cdn-cms.f-static.net/uploads/4386849/normal_6024264fc3de9.pdf - 24 Aug 2026 - suspicious ·
https://cdn-cms.f-static.net/uploads/4367922/normal_5fd39fc352bdf.pdf - 24 Aug 2026 - suspicious ·
https://cdn-cms.f-static.net/uploads/4474450/normal_6055be4b8ef01.pdf - 23 Aug 2026 - suspicious ·
https://cdn-cms.f-static.net/uploads/4445743/normal_60632f8fab910.pdf - 23 Aug 2026 - suspicious ·
https://cdn-cms.f-static.net/uploads/4404953/normal_605223288f425.pdf - 23 Aug 2026 - suspicious ·
https://cdn-cms.f-static.net/uploads/4382408/normal_602d2eb286de9.pdf - 23 Aug 2026 - suspicious ·
https://cdn-cms.f-static.net/uploads/4385633/normal_601d7cb3184c0.pdf - 23 Aug 2026 - suspicious ·
https://cdn-cms.f-static.net/uploads/4451035/normal_5fdc69d837006.pdf - 23 Aug 2026 - suspicious ·
https://cdn-cms.f-static.net/uploads/4369330/normal_6063643fc967e.pdf
Questions about cdn-cms.f-static.net
- Is cdn-cms.f-static.net safe?
- No. MalwareAnalyzer scanned cdn-cms.f-static.net on 19 Aug 2026 and returned a malicious verdict with a score of 74 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with cdn-cms.f-static.net?
- 30040 analysed samples communicate with this URL, including Phishing.
- How was cdn-cms.f-static.net checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of cdn-cms.f-static.net
Scanned on MalwareAnalyzer by Cyble · Open interactive scan