Security Scan Report: app.dropboxer.net

Redirected to:
https://dropbox.okta.com/oauth2/v1/authorize?client_id=0oab3gdwm3DUBIR...
Submitted: Dec 24, 2025, 6:24:22 PMCompleted: Dec 24, 2025, 6:43:36 PMpubliccompleted
Loading additional data...

Summary

This website contacted 10 IPs in 1 country across 5 domains to perform 33 HTTP transactions. The main domain is dropbox.okta.com and was registered NaN years ago.

Submitted URL: https://app.dropboxer.net

Effective URL: https://dropbox.okta.com/oauth2/v1/authorize?client_id=0oab3gdwm3DUBIR0e4x7&redirect_uri=https%3A%2F%2Fapp.dropboxer.net%2Fauth%2Foktaauthcallback&scope=openid+email+profile&state=%7B%22secret%22%3A+%22fsMRN80Ir4ZTcHJSVvRRiY9zZg1DFKvxYdor9cTeITdKD_BhtYZq5K_rFPpEQEw3vvwNxZAAxl7u5daNpV_zrQ%22%2C+%22next%22%3A+%22%2F%22%7D&code_challenge=Komm-fpVrXksxL8Ytp4E7LA9Xz-q3tN-2OH8gyCQGFk&code_challenge_method=S256&response_type=code&response_mode=queryRedirected

The Cisco Umbrella rank of the primary domain is #863,496 of the top 1 million websites

AI Security Verdict

Low Risk

Confidence: 92%

2
Risk Score

The site impersonates Dropbox, collects user credentials, and uses obfuscated scripts – high‑confidence phishing scam.

Risk Factors
Brand impersonation / typosquatting
Low domain reputation for a well‑known brand
Credential‑harvesting form (email field) without clear legitimate purpose
Multiple redirects to external authentication service
Highly obfuscated JavaScript
Safety Factors
Page served from an identity-provider sign-in endpoint (dropbox.okta.com); a relying-party brand and login form here are normal SSO, not impersonation — risk clamped from 9 to 2
Domain age information unavailable

Details

Page Title

Dropbox Okta - Sign In

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(82%)

Domain Information

The domain name 'app.dropboxer.net' uses the network infrastructure generic top-level domain (.net); it also runs on subdomain 'app'. The second-level label 'dropboxer' is 9 characters long with 3 vowels and six consonants. Tokenizing the label suggests 2 words: drop, boxer. Median word length is 4.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://app.dropboxer.net

Page Load Overview

29.30s
Total Load Time
33
HTTP Requests
5
Domains
2.1 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:423 chars
Detector Agreement:75%

Website Classification

Primary Category

technology software82% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
82%
documentation technical
69%
download file sharing
40%
government public service
36%
adult content
35%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6127.0.0.1United States
AS16509AMAZON-02
375.2.58.245United States
AS16509AMAZON-02
33.164.68.85United States
AS16509AMAZON-02
354.215.244.8San Jose, California, United States
AS16509AMAZON-02
33.164.68.16United States
AS16509AMAZON-02
354.193.177.85San Jose, California, United States
AS16509AMAZON-02
33.174.113.86United States
AS16509AMAZON-02
399.83.188.67United States
AS16509AMAZON-02
33.164.68.117United States
AS16509AMAZON-02
33.164.68.33United States
AS16509AMAZON-02
3310--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C3E2D6D20959DDEE16819C88A67B8616714287C3C7A1DEC477FCCEC9AF98C0B752E24C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:I8tZD/XqhwkVhSDWR3lHAFSDWR3lHAj/t0Es5:dtZLXqbVpmI/t0Ei

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:33401:CEQEIAl4qhFYaTY7EASYgCIADHQGASJAAYKIBIkYByAUFKk5EISRQFWoOOShIiiI4o6QoCVCDAiCiWAK8BADsNEIJiAIEIEU

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:7f7fffffffffffff
Perceptual Hash:800001030fffffff
Difference Hash:8080000000000000
Wavelet Hash:30303030f0f0f0f0
Color Hash:#c187c5

Other Hashes

Crop Resistant:8080000000000000

Scan History

Scan history not available

Unable to load historical scan data