google2oauth.network
Appeared in the .network zone on Saturday, September 5, 2026; by the end of that day the census found active website. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
The page body is an obfuscated PowerShell stager (base64-decoded strings, console hiding via ShowWindow, sandbox/hostname check, ProgramData marker file, embedded Telegram bot token/chat ID for C2, and a hidden 'powershell -ExecutionPolicy Bypass -File' relaunch) — i.e. a malware dropper served for curl/IEX execution, using a Google-OAuth-styled hostname on a cheap registrar to look like a legitimate Google endpoint.
The domain name google2oauth.network uses Google's brand to impersonate OAuth infrastructure, but the actual page content is malware—obfuscated PowerShell code designed to hide a console window, check for sandbox markers, and execute a payload from an attacker-controlled IP geolocation service. This is malware delivery masquerading under a brand name, not phishing for credentials.
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Saturday, September 5, 2026

Same data as JSON: /api/zone/domain/google2oauth.network. This page is not indexed by search engines and does not link to the site it describes.