Scan report · about 16 hours agoPublic

gooqlemeet-live.com

104.21.55.90AS13335 · US

the page matches the catalogued phishing kit "Google Meet lobby -> Google sign-in panel kit (handleRequest continueWith / resubmit_email + checkStatus)"

its markup matches that kit
Engine tags
Brand clone
Verdict

What happened

Step by step, from what the scanner recorded.
Load 8.8 s · 7 requests
01 · Visitor opensgooqlemeet-live.com
02 · Page shown
Google Meet - Join Meetingstyled as Google · medium
03 · OutcomeCredential phishingA login page wearing a brand it does not own.

Dangerous — confirmed threat

Automated

Its page title claims to be Google, which this address is not associated with. Its page code matches a known phishing kit (brand-clone). We found strong evidence that this site is malicious — for example a phishing page, a scam, or hostile code. Treat anything it asked for (passwords, card details, codes) as exposed.

What to do

Do not enter any information or download anything. If you already did, change those passwords now and contact your bank if payment details were involved. Block or report the link to your team.

This reflects the evidence found at the time of the scan. If you believe it is a mistake, you can escalate it for analyst review.

Findings

Strongest first
StrongKnown phishing-kit signature matched
Google Meet lobby -> Google sign-in panel kit (handleRequest continueWith / resubmit_email + checkStatus) · brand-clone · high

The page's structure/assets match a catalogued phishing kit — pre-built attacker software for cloning a brand's login.

Analyst noteKit rated high and flagged for auto-escalation — treat as malicious.

SupportingIts only destination is its own sign-in screen
https://gooqlemeet-live.com/login.php?id= · 1 identity input(s), no password yet · Google

This page offers the visitor nothing to fill in and nowhere else to go: every link on it stays on this host, and its own script sends the visitor to its own sign-in screen. We opened that screen once and it asks for the account it claims to sign in to, under the same costume. Nothing was typed and nothing was pressed.

Analyst noteJudge the page we opened, not this one — it is where the credentials would go. The entry page is deliberately empty so that a scanner reading only the first URL finds no form at all.

InfoBrand impersonation detected
Google · medium

The page presents itself as a known brand (brand keywords/branding detected).

Analyst noteLow/medium confidence (keyword only) — can be a news article or partner page. Corroborate before acting.

Infrastructure

IP
104.21.55.90CLOUDFLARENET - Cloudflare, Inc., US · AS13335US
TLS
CN=WE1, O=Google Trust Services, C=US · expires Nov 17, 2026

WHOIS

Registrar
DreamHost, LLC
Created
Oct 27, 2025
Expires
Oct 27, 2026
Nameservers
dakota.ns.cloudflare.compearl.ns.cloudflare.com
53 malicious10 suspicious

Hashes & fingerprints

Page capture

Live

Title “Google Meet - Join Meeting” · brand shown: Google (medium)

Engines

7 · time to verdict

Page

HTTP
200 · Completed
Title
Google Meet - Join Meeting
Load
8.77 s · 7 requests
Stack · 5cdnjsCloudflareHTTP/3jQueryjQuery CDN