www.dropbox.com - URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned www.dropbox.com and returned a unknown verdict (score 6). The page resolved to 162.125.83.18 on Dropbox, Inc. in AU. The domain was registered 11376 days ago through MarkMonitor Inc.. 2 domains and 1 IP were contacted, over 1 HTTP request. 8 malware samples communicate with this URL (Revell, QQpass, Container, Emotet). The request followed 1 redirect before landing. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 6) · Confidence 60%
- Scanned URL:
https://www.dropbox.com/oauth2/authorize - Domain: www.dropbox.com · IP: 162.125.83.18 · AS19679 · AU
- Server: envoy
- Page title: API Request Authorization - Dropbox
- HTTP status: 200 · text/html; charset=utf-8
- Registrar: MarkMonitor Inc. · domain age 11376 days · created 1995-06-28
- TLS issuer: C=US, O=DigiCert Inc, CN=DigiCert Global G3 TLS ECC SHA384 2020 CA1 · valid to Oct 14 23: · subject C=US, ST=California, L=San Francisco, O=Dropbox, Inc, CN=*.app.dropbox.com
- Evidenced operator: Dropbox, Inc
- HTTP requests captured: 1
- Scan tier: fast · observed 2026-08-20 17:43:29 UTC
Redirect chain
https://www.dropbox.com/oauth2/authorizehttps://www.dropbox.com/oauth2/authorize_error?error_detail=Missing+client_id.&error_name=missing_client_id
Malware communicating with this URL (8)
These samples were observed contacting or being served from www.dropbox.com. Each links to its full analysis.
- Revell - referenced ·
dd34316234bb61ae29f7b2012d83f7c3· first seen 2026-08-20 - QQpass - referenced ·
69cb6171f3bbfc5bbb6a46911a8e6bcf· first seen 2026-08-20 - Container - referenced ·
ef12300c2c5b0fb39a548aa347aeccda· first seen 2026-08-13 - Container - referenced ·
eeec3c27aa51940498e5d78aaf924962· first seen 2026-08-13 - Container - referenced ·
b8b5b35df4b07f355e205ef419d38c23· first seen 2026-08-13 - Emotet - referenced ·
f2912ad18a8a68b6f427c01b3287f1e8· first seen 2026-08-13 - Maldoc - referenced ·
3062516feeb2867ce7ed59f6208be5f4· first seen 2026-08-12 - Delf - referenced ·
3e3e347e74f84b757de8f8c63e7c9684· first seen 2026-08-12
Antivirus & YARA (2 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
- YARA: Yara-Rules community [yara]: YR_Packer_ASPack_MPRESS (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- 2 antivirus/YARA engines flagged the page content: DLV_HTML_Smuggling, YR_Packer_ASPack_MPRESS
- Valid TLS, no impersonation or off-origin credential post
- Certificate issued < 48h ago
Contacted infrastructure
- 162.125.83.18 - AS19679 Dropbox, Inc. (Australia)
Observed indicators
- www.dropbox.com
- cfl.dropboxstatic.com
- 162.125.83.18
- https://www.dropbox.com/oauth2/authorize_error?error_detail=Missing+client_id.&error_name=missing_client_id
- https://cfl.dropboxstatic.com/static/metaserver/static/images/logo_catalog/favicon_m1.ico
- https://cfl.dropboxstatic.com/static/metaserver/static/css/dig-components/index.web-vflWYwVOd.css
- https://cfl.dropboxstatic.com/static/metaserver/static/css/dig-fonts/index.metaserver-vflDxH9Tk.css
- https://cfl.dropboxstatic.com/static/metaserver/static/css/display_token_desktop-vflI77Mea.css
- https://cfl.dropboxstatic.com/static/typescript/component_libraries/dwg-components/src/index.web-vflpPwh9E.css
- https://cfl.dropboxstatic.com/static/metaserver/static/css/display_token_mobile-vflAYMuMM.css
- https://cfl.dropboxstatic.com/static/metaserver/static/css/main-vfl9mnJC3.css
- https://cfl.dropboxstatic.com/static/metaserver/static/css/signup_signin/dwg_refresh_exp-vflPp-RhR.css
- https://cfl.dropboxstatic.com/static/metaserver/static/css/connect_v3_react_desktop-vflbK6u1F.css
- https://cfl.dropboxstatic.com/static/metaserver/static/css/dig-components/tokens-vflc-b60y.css
- https://cfl.dropboxstatic.com/static/metaserver/static/css/error-vflBOVrxe.css
- https://cfl.dropboxstatic.com/static/metaserver/static/css/dig-illustrations/index.web-vflZ-kNZ1.css
- https://cfl.dropboxstatic.com/static/metaserver/static/css/connect_v3_react_mobile-vflsYcl69.css
- https://cfl.dropboxstatic.com/static/metaserver/static/css/login_or_register-vfl8PE8y2.css
- https://cfl.dropboxstatic.com/static/metaserver/static/css/dig-fonts/sharp_grotesk_23.metaserver-vflPUtg1U.css
- https://cfl.dropboxstatic.com/static/atlas/api_auth/oauth2_authorize_error_page_rspb_fallback/e_atlas__api_auth__static__oauth2_authorize_error_page-vflXv3zHv.js
Other scans of www.dropbox.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 22 Aug 2026 - benign ·
https://api-content.dropbox.com/1/files_put/auto - 21 Aug 2026 - benign ·
https://www.dropbox.com/sh/mjkdpouf1v59ocz/AACdZQ46UQm79uNblpkDoTtAa?dl=0&m=runtime - 20 Aug 2026 - benign ·
https://dl.dropboxusercontent.com/ - 17 Aug 2026 - unknown ·
https://www.ilccanada.org/images/how-to-get-free-robux-2021_GM431946152.pdf - 17 Aug 2026 - unknown ·
https://www.ilccanada.org/images/legit-free-spins-coin-master_GM406889139.pdf - 17 Aug 2026 - unknown ·
https://www.ilccanada.org/images/coin-master-extra-spins_GM406889139.pdf - 15 Aug 2026 - suspicious ·
https://www.ilccanada.org/images/earn-free-robux-today_GM431946152.pdf - 15 Aug 2026 - suspicious ·
https://www.ilccanada.org/images/how-to-get-free-spins-and-coins-in-coin-master_GM406889139.pdf - 14 Aug 2026 - suspicious ·
https://www.ideepercomputeredinternet.com/2011/05/effetto-shadowbox-per-gallerie-di-foto.html - 13 Aug 2026 - unknown ·
https://www.swx.global/wp-content/plugins/super-forms/uploads/php/files/cdfd07e6433d59f3e6054822adce
Questions about www.dropbox.com
- Is www.dropbox.com safe?
- The scan of www.dropbox.com on 20 Aug 2026 reached no verdict either way (score 6). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with www.dropbox.com?
- 8 analysed samples communicate with this URL, including Revell, QQpass, Container, Emotet.
- How was www.dropbox.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.dropbox.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan