dropboxenterprise[.]com
“Enterprise - Dropbox”
PhishDestroy identifies dropboxenterprise.com as an active generic phishing domain impersonating Dropbox Enterprise services. The domain leverages deceptive branding to trick users into divulging sensitive credentials or installing malware under the guise of legitimate file-sharing tools. Given the absence of antivirus detections and the domain’s unresolved status, this threat remains under active investigation by cybersecurity teams to determine the full scope of malicious infrastructure tied to the campaign seed a6099d.
This domain was flagged with zero detections out of 95 VirusTotal engines, indicating limited or delayed recognition by security vendors. It resolves to IP address 15.197.225.128 and is registered through GoDaddy.com, LLC, using a GoDaddy SSL certificate issued after domain creation on October 13, 2015. The age of the domain and use of a major registrar and CA suggest an attempt to appear legitimate while hosting a spoofed login portal targeting Dropbox Enterprise users.
Mitigation for this threat involves avoiding any interaction with dropboxenterprise.com, including clicking links or entering credentials. Enterprises using Dropbox should verify all file-sharing domains via official channels and implement browser-based warnings or DNS filtering using threat intelligence feeds. Users who suspect exposure should reset account passwords via Dropbox.com, enable two-factor authentication, and scan devices for malware. Report the domain to Dropbox’s abuse team and PhishDestroy for further analysis to prevent broader propagation.
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 sources · synchronized Aug 9, 2026
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Forensic Intelligence
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of dropboxenterprise.com · checked Apr 4, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive