goo.gl - URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned goo.gl and returned a benign verdict (score 0). The page resolved to 142.251.222.14 on Google LLC in JP. 2 domains and 1 IP were contacted. 14 malware samples communicate with this URL (Gootloader, Phishing). The request followed 1 redirect before landing. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: benign (score 0) · Confidence 12%
- Scanned URL:
http://goo.gl/YroZm" - Domain: goo.gl · IP: 142.251.222.14 · AS15169 · JP
- Server: ESF
- Page title: Invalid Dynamic Link
- HTTP status: 400 · text/html; charset=utf-8
- TLS issuer: C=US, O=Google Trust Services, CN=WR2 · valid to Oct 28 20: · subject CN=*.google.com
- Scan tier: fast · observed 2026-08-20 22:07:20 UTC
Redirect chain
http://goo.gl/YroZm"https://goo.gl/YroZm"
Malware communicating with this URL (14)
These samples were observed contacting or being served from goo.gl. Each links to its full analysis.
- 266d351d4dcae031e871deda0f3973e133cb9400a89b56dae233d2e9a315d03b - referenced ·
266d351d4dcae031e871deda0f3973e1· first seen 2026-08-20 - 6c6955908592412bb22d4e69a25928fc8975327b1d15d7e83656797ef92253a4 - referenced ·
6c6955908592412bb22d4e69a25928fc· first seen 2026-08-20 - c799acfa523e8b9d8626faeaeae566cf7b1a842a33427a0ac66944da81f3af91 - referenced ·
c799acfa523e8b9d8626faeaeae566cf· first seen 2026-08-20 - 79aa5df2543989721f9cae3d93b07f0fbca54e8b301ad1faafcebf1d687902e0 - referenced ·
79aa5df2543989721f9cae3d93b07f0f· first seen 2026-08-20 - 0f3b76075929a987ffbeae163f89a9f2fe98b6295b36071abdb52b9b84dfff00 - referenced ·
0f3b76075929a987ffbeae163f89a9f2· first seen 2026-08-20 - 990e8f45756e791de727a869962ab2b332f9924eff1faedd36d46382c25c2bb4 - referenced ·
990e8f45756e791de727a869962ab2b3· first seen 2026-08-19 - Gootloader - referenced ·
f1cbe5f24bb5373e39fa3abb363f16cf· first seen 2026-08-19 - 11b84f2268a79401d1587336aefd89dda050f4bbb8d951752febfb8ca5566319 - referenced ·
11b84f2268a79401d1587336aefd89dd· first seen 2026-08-16 - 502b3536529cd15b1bf65337ba33f662c7d19c840db619daf33784de726ceb97 - referenced ·
502b3536529cd15b1bf65337ba33f662· first seen 2026-08-15 - Phishing - referenced ·
74b278be0977e985b8c4dc358512436b· first seen 2026-08-15 - 502db9195fd38ae39613bcc3432de741f36485380094596445f5c9c54de53b6d - referenced ·
502db9195fd38ae39613bcc3432de741· first seen 2026-08-14 - 3771a3de40e2d2a7898e2d2844f68858ace866866beeed1538f69cf3641494af - referenced ·
3771a3de40e2d2a7898e2d2844f68858· first seen 2026-08-13 - normal_5f871c1487165.pdf - referenced ·
59ffee883569187f53327e412c916881· first seen 2026-08-12 - b29f8a02f9fec2e6ddd681e72924eb7d8ba79223a2df659dd072a82a4b4dafbb - referenced ·
b29f8a02f9fec2e6ddd681e72924eb7d· first seen 2026-08-11
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- Submitted via URL shortener (goo.gl) — expanded before scan
Contacted infrastructure
- 142.251.222.14 - AS15169 Google LLC (Japan)
Observed indicators
- goo.gl
- firebase.google.com
- 142.251.222.14
- https://goo.gl/YroZm"
- https://firebase.google.com/
Other scans of goo.gl (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown ·
https://www.ebenisterie-burette.com/ckfinder/userfiles/files/68149192623.pdf - 23 Aug 2026 - unknown ·
http://www.aunay-sous-auneau.fr/ckfinder/userfiles/files/48467039462.pdf - 23 Aug 2026 - unknown ·
http://www.aunay-sous-auneau.fr/ckfinder/userfiles/files/48467039462.pdf - 23 Aug 2026 - unknown ·
https://www.antasboru.com/404 - 23 Aug 2026 - unknown ·
https://jerseyshorepirates.com/userfiles/files/19072922332.pdf - 23 Aug 2026 - unknown ·
https://www.golddustdental.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614caf - 23 Aug 2026 - unknown ·
https://birotex.rs/images/files/tofijawerika.pdf - 23 Aug 2026 - unknown ·
https://www.champagne-cornevin.fr/ckfinder/userfiles/files/61632674923.pdf - 23 Aug 2026 - unknown ·
https://angelofthewinds.com/ckfinder/userfiles/files/ximeradesijufesikuji.pdf - 23 Aug 2026 - unknown ·
https://linkvertise.com/13469/AFK9IqzvctpL?o=sharing
Questions about goo.gl
- Is goo.gl safe?
- The scan of goo.gl on 20 Aug 2026 found no evidence of harm. That is the absence of a finding at one point in time, not a guarantee: a page can change, and a scan only sees what it was served.
- What malware is associated with goo.gl?
- 14 analysed samples communicate with this URL, including Gootloader, Phishing.
- How was goo.gl checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of goo.gl
Scanned on MalwareAnalyzer by Cyble · Open interactive scan