zoominvite-us09web-user08b.pages.dev
Category: Phishing
- Don't sign in or pay here. Close it. If you typed a password, change it where you normally use it.
- Already visited? Check your device. A free scan shows whether anything was installed.
- Stop the next one. Combo Cleaner's web protection blocks phishing and scam sites before they load.
Combo Cleaner is PCrisk's own anti-malware tool, owned by RCS LT. Free to scan; removing what it finds needs a licence (7-day free trial).
Description of zoominvite-us09web-user08b.pages.dev
This domain appears to host a page styled to resemble Zoom, the well-known video conferencing platform. The page title is "Zoom," and the screenshot shows Zoom branding alongside a message stating that the visitor's Zoom client is out of date and offering a "Download Zoom Client" button. Based on the visible content, the page is presenting itself as a software update or download landing page rather than as an informational website.
The domain itself is a subdomain of pages.dev, a static hosting platform, and its naming pattern includes multiple Zoom-related terms such as "zoominvite" and "user," which may be intended to look relevant to Zoom meeting invitations or account activity. There is no clear indication in the scan data that this page is operated by Zoom Video Communications, and the use of a third-party hosting subdomain rather than an official Zoom-owned domain is notable.
Safety Assessment for zoominvite-us09web-user08b.pages.dev
The automated malware scan results were mixed at the time of this scan. On one hand, 0 out of 89 security engines flagged the URL, the malware file scan reported no flagged files, and the checked DNS-based mail-reputation lists were clean. On the other hand, a major threat database listed the site for social engineering, and the blacklist summary also shows a malicious listing from that same source. That type of listing is a stronger warning sign than a clean result from generic malware heuristics because it can indicate deceptive content rather than a traditional malware payload.
The page content also raises concern based on appearance alone. It uses Zoom branding and presents a prompt to download a Zoom client update, yet it is hosted on a pages.dev subdomain rather than an official Zoom web property. That mismatch may indicate an imitation page designed to persuade visitors to download software or interact with content under the impression that it is connected to Zoom.
Although several scan signals were clean, the social-engineering listing and the branding mismatch materially increase risk. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was served over HTTPS with a valid Let's Encrypt certificate that, at the time of this scan, was valid until 2026-12-20. It appears to be hosted behind Cloudflare infrastructure on IP address 188.114.97.2, with Cloudflare nameservers and hosting in Toronto, Canada. The domain is about six years old, which can sometimes be a stabilizing signal, although age alone does not verify legitimacy.
DNSSEC appears to be unsigned, which is not uncommon but does mean DNS responses do not benefit from that additional integrity layer. No malicious files, flagged external links, or iframe issues were reported in the provided scan data, but the main technical concern is the apparent use of a third-party hosted subdomain to present branded software-download messaging.
Share your experience with this website. Was it safe? Did you encounter any issues?