Scan report · 11 days agoPublic

zoominvite-us09web-user08b.pages.dev

188.114.96.0AS13335 · US

page delivers the program zoominstaller.exe (https://s3-us-east-1.on…ault/zoominstaller.exe)

brand impersonation (Zoom, medium); execution instructions ("downloads folder")
Engine tags
Verdict

What happened

Step by step, from what the scanner recorded.
Load 8.7 s · 8 requests
01 · Visitor openszoominvite-us09web-user08b.pages.dev
02 · Page shown
Zoomstyled as Zoom · medium
03 · OutcomeRemote control of the machineA legitimate remote-management tool, enrolled into the attacker's tenant. The tenant is the takedown target.

Dangerous — confirmed threat

Automated

Its page title claims to be Zoom, which this address is not associated with. We found strong evidence that this site is malicious — for example a phishing page, a scam, or hostile code. Treat anything it asked for (passwords, card details, codes) as exposed.

What to do

Do not enter any information or download anything. If you already did, change those passwords now and contact your bank if payment details were involved. Block or report the link to your team.

This reflects the evidence found at the time of the scan. If you believe it is a mistake, you can escalate it for analyst review.

Findings

Strongest first
StrongPage auto-started a file download
zoominstaller.exe

The page automatically triggered a file download. Normal landing pages don't do this; malware droppers do.

Analyst noteCheck the file name/type. An auto-download of an executable or archive is a strong malware-delivery tell.

SupportingPage hands the visitor an installer from another domain
https://s3-us-east-1.onlizard.com/8_BZotHyp-282q_v8NEAQ/default/zoominstaller.exe

The page's own script names an executable installer hosted on a different domain, rather than offering it as an ordinary download link.

Analyst noteThe URL was read from an inline script, so it is what the page INTENDS to deliver — a download may not have been observed. Check who operates the instance in the URL, and treat a remote-access tool offered by an unrelated lure page as a compromise attempt.

SupportingPage delivers an executable under a document pretext
https://s3-us-east-1.onlizard.com/8_BZotHyp-282q_v8NEAQ/default/zoominstaller.exe · brand impersonation (Zoom, medium); execution instructions ("downloads folder")

The page presents itself as a document but its button downloads a program to run, not a document to read.

Analyst noteConfirm what the download actually serves. A document workflow that delivers an installer is the tell; the file itself may be signed and clean.

InfoBrand impersonation detected
Zoom · medium

The page presents itself as a known brand (brand keywords/branding detected).

Analyst noteLow/medium confidence (keyword only) — can be a news article or partner page. Corroborate before acting.

File

The file was not analysed, so the scan carries no verdict on the file itself.

Infrastructure

IP
188.114.96.0CLOUDFLARENET - Cloudflare, Inc., US · AS13335US
TLS
CN=YE2, O=Let's Encrypt, C=US · expires Dec 20, 2026
26 malicious30 suspicious

Hashes & fingerprints

Page capture

Live

Title “Zoom” · brand shown: Zoom (medium)

Engines

8 · time to verdict

Page

HTTP
200 · Completed
Title
Zoom
Load
8.73 s · 8 requests
Stack · 3CloudflareHSTSHTTP/3