dropbox.ixythrandkyp.info - URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned dropbox.ixythrandkyp.info and returned a unknown verdict (score 10), categorised as suspicious-infrastructure. The page resolved to 104.21.81.202 on Cloudflare, Inc. in US. The domain was registered 301 days ago through Dynadot Inc. 1 domain and 1 IP were contacted, over 1 HTTP request. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 10) · Confidence 19%
- Scanned URL:
https://dropbox.ixythrandkyp.info/ - Domain: dropbox.ixythrandkyp.info · IP: 104.21.81.202 · AS13335 · US
- Server: cloudflare
- Page title: 404 Not Found
- HTTP status: 404 · text/html
- Registrar: Dynadot Inc · domain age 301 days · created 2025-10-23
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Nov 17 22: · subject CN=dropbox.ixythrandkyp.info
- HTTP requests captured: 1 · outgoing links: 1
- Scan tier: standard · observed 2026-08-20 22:26:03 UTC
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- suspicious-infrastructure
Why this verdict
- Algorithmically-generated (DGA-like) hostname
- Valid TLS, no impersonation or off-origin credential post
- Certificate issued < 48h ago
Detected technologies
- Cloudflare
Contacted infrastructure
- 104.21.81.202 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- dropbox.ixythrandkyp.info
- 104.21.81.202
- https://dropbox.ixythrandkyp.info/
- https://dropbox.ixythrandkyp.info/cdn-cgi/content?id=jPwTCJtYCVidawa3c2jruVWRysRwU196agSsPIjTO6o-1787264763.3005695-1.2.1.1-QfLCWvMQguIyTl4m0b1cw2zlNWpenm8uk3O5bytnAo.I_7NL.soGzP6foyEEG7Td
Questions about dropbox.ixythrandkyp.info
- Is dropbox.ixythrandkyp.info safe?
- The scan of dropbox.ixythrandkyp.info on 20 Aug 2026 reached no verdict either way (score 10). Too little was captured to judge it, which is an unknown rather than a pass.
- How was dropbox.ixythrandkyp.info checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of dropbox.ixythrandkyp.info
Scanned on MalwareAnalyzer by Cyble · Open interactive scan