api-content.dropbox.com - URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned api-content.dropbox.com and returned a benign verdict (score 0). The page resolved to 162.125.83.14 on Dropbox, Inc. in AU. The domain was registered 11378 days ago through MarkMonitor Inc.. 4 domains and 1 IP were contacted. 3 malware samples communicate with this URL (HUILoader, STRATO). This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: benign (score 0) · Confidence 15%
- Scanned URL:
https://api-content.dropbox.com/1/files_put/auto - Domain: api-content.dropbox.com · IP: 162.125.83.14 · AS19679 · AU
- Server: envoy
- Page title: Dropbox - 404
- HTTP status: 404 · text/html
- Registrar: MarkMonitor Inc. · domain age 11378 days · created 1995-06-28
- TLS issuer: C=US, O=DigiCert Inc, CN=DigiCert Global G3 TLS ECC SHA384 2020 CA1 · valid to Mar 12 23: · subject C=US, ST=California, L=San Francisco, O=Dropbox, Inc, CN=api-content-au.dropbox.com
- Evidenced operator: Dropbox, Inc
- Scan tier: fast · observed 2026-08-22 20:47:58 UTC
Malware communicating with this URL (3)
These samples were observed contacting or being served from api-content.dropbox.com. Each links to its full analysis.
- HUILoader - referenced ·
8eddc615fbb7ebbd0e6237376a0b6c1f· first seen 2026-08-22 - STRATO - referenced ·
c4b779c2bc43fa427750797fa27ccd94· first seen 2026-08-12 - HUILoader - referenced ·
7f4205d52f12b6fc75b751647cf1d080· first seen 2026-08-12
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
Contacted infrastructure
- 162.125.83.14 - AS19679 Dropbox, Inc. (Australia)
Observed indicators
- api-content.dropbox.com
- cfl.dropboxstatic.com
- assets.dropbox.com
- www.dropbox.com
- 162.125.83.14
- https://api-content.dropbox.com/1/files_put/auto
- https://cfl.dropboxstatic.com/static/metaserver/static/css/error.css
- https://cfl.dropboxstatic.com/static/images/favicon.ico
- https://assets.dropbox.com/www/en-us/illustrations/spot/look-magnifying-glass.svg
- https://www.dropbox.com/home?_tk=fof
- https://www.dropbox.com/help?_tk=fof
- https://www.dropbox.com/login?_tk=fof
- https://www.dropbox.com/register?_tk=fof
- https://www.dropbox.com/plus?_tk=fof
- https://www.dropbox.com/business?_tk=fof
Other scans of api-content.dropbox.com (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 12 Aug 2026 - benign
- 12 Aug 2026 - benign ·
https://api-content.dropbox.com/1/files/auto
Questions about api-content.dropbox.com
- Is api-content.dropbox.com safe?
- The scan of api-content.dropbox.com on 22 Aug 2026 found no evidence of harm. That is the absence of a finding at one point in time, not a guarantee: a page can change, and a scan only sees what it was served.
- What malware is associated with api-content.dropbox.com?
- 3 analysed samples communicate with this URL, including HUILoader, STRATO.
- How was api-content.dropbox.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of api-content.dropbox.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan