Is meetgoogle.business safe?
http://meetgoogle.business/
Fake Google Meet clone hosting malware payload, registered 4 days ago, confirmed by security researchers as active phishing and malware distribution.
This is a fake Google Meet login page registered only 4 days ago. Security researchers have confirmed it distributes malware disguised as a Google Meet installer, and our antivirus partners flag the payload as dangerous.
Read the full analysis01 · Investigation Brief
Investigation Brief
The domain meetgoogle.business is a direct clone of meet.google.com, registered just 4 days ago with a typosquat design to deceive users. The page visually replicates Google Meet's authentic pre-join interface, including the logo, color scheme, and permission prompts — a classic phishing tactic. Two independent security researchers have publicly documented this domain actively hosting and distributing Google-Meet-Update.msi, a malicious payload flagged as delivering remote-access malware. Our antivirus partners ESET and Fortinet both detect the malware component. The domain has zero legitimate business registration, zero contact information, and the hosting IP shows no abuse history only because the infrastructure is freshly deployed. The combination of clone design, typosquat naming, malware payload distribution, and public security warnings makes this a confirmed active threat.
Page Content
The page title and meta description exactly match Google Meet's official join-call interface. Body text includes authentic-looking UI elements: 'Ready to join?', camera/microphone permission prompts, Gemini note-taking upsell, and phone-join options. However, no legitimate business contact, privacy policy, or terms of service appear anywhere on the page.
Infrastructure
Domain registered 4 days ago via Host Africa (Pty.) Ltd. with privacy protection disabled. SSL certificate is valid (Let's Encrypt, 85 days to expiry), which is common for phishing sites using free certificate issuers. Hosting IP 169.239.181.242 shows zero abuse reports, consistent with newly deployed malware infrastructure. No cross-domain redirects or homoglyph tricks detected — the threat relies on visual cloning and typosquat naming alone.
Domain History
Registered only 4 days ago. The typosquat pattern (meetgoogle.business instead of meet.google.com) is designed to catch users who mistype or click malicious links. Related domains include meetgooglejoin.com and googlemeet.business, suggesting a coordinated campaign.
Web Reputation
Two security researchers independently flagged this domain on Twitter/X within days of registration, documenting the malware payload (Google-Meet-Update.msi, SHA256: b2f1fe32e1059c25561af0e69343fc454f45f8d8aed4a45d396cf35ec633d006) as delivering RMM/malware. ESET and Fortinet both detect the malware component. No positive reviews, business registration, or legitimate mentions found on any consumer-trust site or business directory.
Why the score is 21
Saved antivirus evidence is adverse but no longer fresh. Coverage remains separate so missing sources cannot be mistaken for clean results.
02 · Security Evidence
Security evidence
Antivirus Engines
Saved result
2 engines flagged this URL
Every saved adverse engine is listed below. The full provider matrix remains available for audit.
- Malicious
- 2
- Suspicious
- 0
- Total
- 92
| Engine | Finding |
|---|---|
| ESETMalicious | malware |
| FortinetMalicious | malware |
All 92 engine results
- ESET - malware - Malicious
- Fortinet - malware - Malicious
- 0xSI_f33d - unrated - Clean
- Abusix - clean - Clean
- Acronis - clean - Clean
- ADMINUSLabs - clean - Clean
- AILabs (MONITORAPP) - clean - Clean
- AlienVault - clean - Clean
- alphaMountain.ai - unrated - Clean
- AlphaSOC - unrated - Clean
- Antiy-AVL - clean - Clean
- ArcSight Threat Intelligence - unrated - Clean
- AutoShun - unrated - Clean
- Bfore.Ai PreCrime - unrated - Clean
- BitDefender - clean - Clean
- Bkav - unrated - Clean
- BlockList - clean - Clean
- Blueliv - clean - Clean
- Certego - clean - Clean
- ChainPatrol - unrated - Clean
- Chong Lua Dao - clean - Clean
- CINS Army - clean - Clean
- Cluster25 - unrated - Clean
- CRDF - clean - Clean
- Criminal IP - unrated - Clean
- CSIS Security Group - unrated - Clean
- CTX AI - clean - Clean
- Cyan - unrated - Clean
- Cyble - clean - Clean
- CyRadar - clean - Clean
- desenmascara.me - clean - Clean
- DNS8 - unrated - Clean
- Dr.Web - clean - Clean
- EmergingThreats - clean - Clean
- Emsisoft - clean - Clean
- Ermes - unrated - Clean
- ESTsecurity - clean - Clean
- Forcepoint ThreatSeeker - clean - Clean
- G-Data - clean - Clean
- GCP Abuse Intelligence - unrated - Clean
- Google Safebrowsing - clean - Clean
- GreenSnow - clean - Clean
- GreyNoise - unrated - Clean
- Gridinsoft - unrated - Clean
- Guardpot - unrated - Clean
- Heimdal Security - clean - Clean
- Hunt.io Intelligence - unrated - Clean
- IPsum - clean - Clean
- Juniper Networks - clean - Clean
- K7AntiVirus - unrated - Clean
- Kaspersky - unrated - Clean
- LevelBlue - clean - Clean
- Lionic - clean - Clean
- Lumu - unrated - Clean
- Malwared - clean - Clean
- MalwarePatrol - clean - Clean
- MalwareURL - unrated - Clean
- Mimecast - unrated - Clean
- Netcraft - unrated - Clean
- OpenPhish - clean - Clean
- PhishFort - unrated - Clean
- Phishing Database - clean - Clean
- PhishLabs - unrated - Clean
- Phishtank - clean - Clean
- PREBYTES - clean - Clean
- PrecisionSec - unrated - Clean
- Quick Heal - clean - Clean
- Quttera - clean - Clean
- Rising - clean - Clean
- SafeToOpen - unrated - Clean
- Sangfor - clean - Clean
- Sansec eComscan - unrated - Clean
- Scantitan - clean - Clean
- SCUMWARE.org - clean - Clean
- Seclookup - clean - Clean
- Snort IP sample list - unrated - Clean
- SOCRadar - unrated - Clean
- Sophos - clean - Clean
- StopForumSpam - clean - Clean
- Sucuri SiteCheck - clean - Clean
- ThreatHive - clean - Clean
- URLhaus - clean - Clean
- URLQuery - unrated - Clean
- Viettel Threat Intelligence - clean - Clean
- VIPRE - unrated - Clean
- ViriBack - clean - Clean
- VX Vault - clean - Clean
- Webroot - clean - Clean
- Xcitium Verdict Cloud - clean - Clean
- Yandex Safebrowsing - clean - Clean
- ZeroCERT - clean - Clean
- ZeroFox - unrated - Clean
Security Scans
Checked against the browser threat feeds available to this scan — no hit.
What we observed
Visual warning signs were identified
The page visually matches Google Meet's genuine pre-join interface with no detectable design anomalies; however, the absence of a visible URL bar prevents confirmation that the domain is legitimate, and the push-notification modal is a tactic frequently abused on phishing clones of this service.
What the captured page showed
4 observations- 01
Push-notification permission modal overlay present, prompting user to 'Allow notifications' from Meet — a common social-engineering vector on clone pages
- 02
No URL bar visible in the screenshot, making it impossible to confirm whether the domain matches google.com or a spoofed host
- 03
Page layout and branding match Google Meet's authentic UI (logo, color scheme, 'Ready to join?' panel, Gemini upsell widget)
- 04
Microphone and camera permission prompts visible at bottom, consistent with legitimate Meet pre-join flow but also replicable on phishing clones
03 · Investigation Story
Investigation story
- 1
What the site claims
Google Meet
- 2
What we observed
The page content was captured and checked alongside 92 antivirus results.
- 3
What independent research found
No complete independent-research result was available in this saved report.
- 4
What remains unverified
5 of the five core capabilities did not complete, so those gaps remain visible in the coverage ledger.
Risk pattern correlation
Scam-Type Likelihood
2 of 21 categories showed signals
Each card names a specific harm pattern and the concrete facts that support it. The category score is supporting context; the report verdict above remains the final severity decision.
- Domain is a typosquat of meet.google.com.
- The evidence pattern matches phishing / data-harvesting.
- Domain is a typosquat of meet.google.com.
- The evidence pattern matches brand / clone-site impersonation.
19Show remaining categoriesHide checked categories
Reputation Sources
How this domain rates across independent threat-intelligence and blocklist providers.
04 · Domain & Infrastructure
Domain & infrastructure
The plumbing behind the site — who registered it, how it’s encrypted, where it’s hosted, and where it links out. A valid certificate or a calm server doesn’t mean the business is honest — scam sites pass these checks too. Use this to corroborate the verdict, not to overturn it.
Infrastructure map
How the saved page connected to the wider web.
Domain Timeline
- Jun 11, 2026Domain registered
First appeared in WHOIS records — 4 days old today.
- Jun 16, 2026Saved security review — Flagged as suspicious
The completed checks from this saved scan are detailed above.
meetgoogle.business was registered very recently and is already flagged. Freshly-registered domains are disproportionately used for scams, and a young domain with active threat signals warrants extra caution.
Contact Verification
Saved contact details can help identify the operator. Their presence supports traceability; it does not prove the business is trustworthy.
- No contact email found anywhere on the page.
- No phone number listed on the page.
- No postal address visible on the page.
Domain & Encryption
Server Reputation
Referenced Domains
Outbound domains this page links to or loads resources from. Each links to its own security scan.
05 · Evidence Ledger
Evidence ledger
Source coverage and freshness
Status shows whether usable evidence was saved; finding shows what that evidence observed.
| Source | Result | Completion | Finding |
|---|---|---|---|
| Antivirus | 2 of 92 engines flagged | Completed | Adverse |
| Browser protection | No browser threat-list match | Completed | No adverse finding |
| Page content | Page fetched · HTTP 200 | Completed | No adverse finding |
| Visual evidence | 4 visible observations saved with the page capture | Limited | Adverse |
| Independent research | Independent research was not available for this report | Unavailable | Adverse |
- Page content
- Result: Page fetched · HTTP 200
- Completed
- No adverse finding
- Visual evidence
- Result: 4 visible observations saved with the page capture
- Limited
- Adverse
- Independent research
- Result: Independent research was not available for this report
- Unavailable
- Adverse
07 · Community
Community
08 · Safety FAQ
Safety FAQ
Common questions, answered directly from the scan data above — so the answers reflect the saved verdict and evidence in this report.
0 community contributions
Share what happened, what the site requested, and what others should watch for.
Community reviews never change the scanner verdict.