livemeetcall[.]xyz
“Google”
The domain livemeetcall.xyz has been flagged for brand impersonation, specifically targeting Google. This threat was identified as high risk due to its potential to deceive users by imitating a well-known brand. Although there is no specific mention of a crypto drainer or fake login mechanism, the presence of a page titled 'Google' indicates an attempt to impersonate Google services. This malicious activity poses a significant threat by leveraging one of the most trusted brands to mislead users.
In terms of technical indicators, livemeetcall.xyz was detected by 19 out of 95 security vendors on VirusTotal. The domain was registered through Namecheap and resolves to the IP address 199.36.158.100. It was created on April 18, 2026, suggesting a relatively recent attempt at deploying this impersonation tactic. The domain appears on 4 security blocklists, including those maintained by MetaMask, PhishDestroy, SEAL, and Maltrail. Additionally, AlienVault OTX has recognized this domain in a threat intelligence pulse, and it holds a Gridinsoft trust score of 0 out of 100, indicating a complete lack of trustworthiness.
Currently, the domain has been taken offline, effectively mitigating immediate risks to users. However, the fact that it was able to operate long enough to be detected by multiple security vendors highlights the need for ongoing vigilance. Security teams should ensure that their systems are updated with the latest blocklists and encourage users to be cautious when interacting with domains mimicking known brands. Continuous monitoring for similar threats remains crucial to prevent future occurrences and protect user data integrity.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | maps.googleapis.com/maps-api-v3/api/js/64/9c/common.js |
audit | Hunting_JS_WebAssembly |
| Hagezi Threat Feed | livemeetcall.xyz |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
PD-20260418-322F71 Recipient: abuse@namecheap.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive