How can google.com be used to serve malicious content?
Someone briefly had a pointer to http://www.google.com/safebrowsing/diagnostic?site=code.goog..., which includes:
> Malicious software is hosted on 23 domain(s), including sms-bomber.googlecode.com/, gdata-issues.googlecode.com/, infojob.googlecode.com/.
sites.google.com wiki.google.com apps.google.com
This probably scanned Google's old Sites product; the equivalent of Geocities for the early '00's.
It might very well be that the malware scanner picked up a link to such a "redirector" which leads to malware and then took the TLD google.com for malicious.
Another reason why one should never ever host user-generated files (or links/redirects) on the primary domain. Github did this with github.io for the same reason.