Security Scan Report: dropboxusercontent.co

Redirected to:
https://ww547.dropboxusercontent.co/?tkn=19vnMT3S
Submitted: Sep 22, 2026, 8:42:26 PMCompleted: Sep 22, 2026, 8:43:16 PMpubliccompleted

This website contacted 3 IPs in 1 country across 2 domains to perform 4 HTTP transactions. The main domain is ww547.dropboxusercontent.co and was registered 11 months ago.

Submitted URL: https://dropboxusercontent.co

Effective URL:

https://ww547.dropboxusercontent.co/?tkn=19vnMT3S
Redirected

AI Security Verdict

High Risk

Confidence: 75%

7
Risk Score

Typosquat of Dropbox's dropboxusercontent.com using a token-parameterized subdomain and Dropbox-branded cloud-storage text on an unranked domain — brand impersonation infrastructure, do not enter credentials.

Risk Factors (4)
Typosquatted domain impersonating Dropbox's content-serving domain
Token-parameterized random subdomain indicative of phishing-kit hosting
Unranked domain (absent from Cisco Umbrella top 1M) displaying a major brand's identity
Currently returns 502 Bad Gateway — consistent with a kit/lure that is inactive or being rotated
Domain age information unavailable

Details

Page Title

Dropboxusercontentsecondary capture

Scan Type

public

Domain Name Analysis

The domain 'dropboxusercontent.co' uses the Colombian country-code top-level domain (.co) with no subdomain. The core label 'dropboxusercontent' covers 18 characters holding six vowels versus twelve consonants. Breaking it apart gives 4 words: drop, box, user, content. Expect 4 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://dropboxusercontent.co

Page Load Overview

0.76s
Total Load Time
1 KB
Total Size

Language Analysis

Primary Language

🏳️UNKNOWN
Code: unknown
Confidence:0%

Detection Details

Text Length:10 chars
Detector Agreement:0%

Website Classification

Primary Category

technology software29% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

technology software
29%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
234.160.121.137Google · CDNKansas City, Missouri, United States
AS396982Google LLC
1173.234.157.130Edison, New Jersey, United States
AS396362Leaseweb USA, Inc.
134.149.1.127Google · CDNKansas City, Missouri, United States
AS396982Google LLC
43--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T117E218A959F3615124A3E06D6B9BA2447229E043F41AEC1CB99C930C8FD9D95C9F3BCC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:mdbFI45M6ZamGzejrGh29GVGYuF9lAUICy1Y/dSRr:ZOMPze2h3sYuLlrdy15

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:33114:IdUwIABQQgAIACQMosHCnB2SCwOcDgQiAjoMAYwDMAFJETR9PgBWIIQFfxDwODqCcaUlGEAIiESuQFAA4IAAkAEQmASDhStS

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3038383818000000
Perceptual Hash:cccc6666ce233333
Difference Hash:2020202020080010
Wavelet Hash:3c3c3c3c3c0c0018
Color Hash:#784f3a

Other Hashes

Crop Resistant:2020202020080010

Scan History

Scan history not available

Unable to load historical scan data