Scan report · about 1 month agoPublic

us05webosportalzoomworkspacemeeting-live-invitation-m90x76.pages.dev

188.114.96.1AS13335 · US

page delivers an executable (https://www.dropbox.com…p;st=s0kbfq85&dl=1)

brand impersonation (Zoom, medium)
Engine tags
Verdict

What happened

Step by step, from what the scanner recorded.
Load 8.7 s · 3 requests
01 · Visitor opensus05webosportalzoomworkspacemeeting-live-invitation-m90x76.pages.dev
02 · Page shown
Zoom Client Update - Zoom Meetingsstyled as Zoom · medium
03 · OutcomeA program on the machineAn executable or installer was handed to the visitor under a pretext.

Be careful — warning signs found

Automated

Its page title claims to be Zoom, which this address is not associated with. This site shows signs commonly seen in scams or impersonation, but we could not confirm it for certain. It may be a real threat, or it may be a legitimate site that simply looks unusual to our automated checks.

What to do

Avoid entering passwords or payment details until you are sure it is genuine. Open the company directly from its known website or app instead of this link. Check the evidence below and escalate to your analyst if unsure.

"Suspicious" is a caution, not a confirmation — it can be a false alarm. The evidence below explains why it was flagged.

Findings

Strongest first
SupportingPage delivers an executable under a document pretext
https://www.dropbox.com/scl/fi/q6g8zi3z7cxz4u0zdl3il/ZoomApp-Update6.3.10.ClientSetup.exe?rlkey=5xeq2npi06vrxnddybx9crxyt&st=s0kbfq85&dl=1 · brand impersonation (Zoom, medium)

The page presents itself as a document but its button downloads a program to run, not a document to read.

Analyst noteConfirm what the download actually serves. A document workflow that delivers an installer is the tell; the file itself may be signed and clean.

SupportingDecoded-then-executed payload

Script on the page base64-decoded a blob and immediately ran it (decode → eval) — a classic way to hide an obfuscated payload from static inspection.

Analyst noteAlmost always obfuscation. Check the suspicious-script evidence panel for the decoded snippet.

InfoBrand impersonation detected
Zoom · medium

The page presents itself as a known brand (brand keywords/branding detected).

Analyst noteLow/medium confidence (keyword only) — can be a news article or partner page. Corroborate before acting.

File

The file was not analysed, so the scan carries no verdict on the file itself.

Infrastructure

IP
188.114.96.1CLOUDFLARENET - Cloudflare, Inc., US · AS13335US
TLS
CN=WE1, O=Google Trust Services, C=US · expires Nov 7, 2026
Redirects
0 hops · / → /
41 malicious26 suspicious

Hashes & fingerprints

Page capture

Live

Title “Zoom Client Update - Zoom Meetings” · brand shown: Zoom (medium)

Engines

8 · time to verdict

Page

HTTP
200 · Completed
Title
Zoom Client Update - Zoom Meetings
Load
8.74 s · 3 requests
Stack · 3CloudflareHSTSHTTP/3