livemeetcall[.]xyz
“Google”
livemeetcall.xyz — Контент недоступен. Олицетворение бренда: Google; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 19/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25); URLQuery 2 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Регистратор: Namecheap.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain livemeetcall.xyz has been flagged for brand impersonation, specifically targeting Google. This threat was identified as high risk due to its potential to deceive users by imitating a well-known brand. Although there is no specific mention of a crypto drainer or fake login mechanism, the presence of a page titled 'Google' indicates an attempt to impersonate Google services. This malicious activity poses a significant threat by leveraging one of the most trusted brands to mislead users.
In terms of technical indicators, livemeetcall.xyz was detected by 19 out of 95 security vendors on VirusTotal. The domain was registered through Namecheap and resolves to the IP address 199.36.158.100. It was created on April 18, 2026, suggesting a relatively recent attempt at deploying this impersonation tactic. The domain appears on 4 security blocklists, including those maintained by MetaMask, PhishDestroy, SEAL, and Maltrail. Additionally, AlienVault OTX has recognized this domain in a threat intelligence pulse, and it holds a Gridinsoft trust score of 0 out of 100, indicating a complete lack of trustworthiness.
Currently, the domain has been taken offline, effectively mitigating immediate risks to users. However, the fact that it was able to operate long enough to be detected by multiple security vendors highlights the need for ongoing vigilance. Security teams should ensure that their systems are updated with the latest blocklists and encourage users to be cautious when interacting with domains mimicking known brands. Continuous monitoring for similar threats remains crucial to prevent future occurrences and protect user data integrity.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | maps.googleapis.com/maps-api-v3/api/js/64/9c/common.js |
audit | Hunting_JS_WebAssembly |
| Hagezi Threat Feed | livemeetcall.xyz |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
PD-20260418-322F71 Recipient: abuse@namecheap.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание