Skip to content
Latest
JWR Phishing Framework Shows Why MFA Codes Are Now Live TargetsEvooo1Bot Shows Why Exposed Linux and Edge Devices Are Still High-Value TargetsMalware Crypting Services Show Why Behavioral Detection MattersPrivate Wireless Utility Networks Are Becoming OT Attack PathsKong Mesh Vulnerabilities Show Why Service Mesh Security Needs Control-Plane DisciplineGunra Ransomware Shows Why VPN Compromise Is an Incident, Not a Patch TicketCI Fortify Shows Why OT Isolation Must Be Engineered Before the IncidentLazarus Dream Job Campaign Turns Fake Recruiting Into a Windows Zero-Day IntrusionDeno Runtime Abuse Shows Why Developer Tooling Needs Security GovernanceAeternum Shows Why Blockchain-Based C2 Is a Practical Defense ProblemDeadLock Ransomware Shows Why Recovery Infrastructure Is Part of the Attack SurfaceUNC6671 Shows Why Helpdesk Vishing Is a Cloud Data-Theft ProblemVeloCloud Orchestrator RCE Shows Why SD-WAN Controllers Need Incident ResponseMSI Router Command-Injection Cluster Shows Why Edge Devices Need Exposure Control

Indicator of Compromise

api[.]telegram[.]org

Domain Seen in 3 reports Watch this →

A domain observed in malicious infrastructure. Block or monitor it in DNS and web proxies. Shown defanged for safe viewing; use Copy live value for the functional form.

Included in the Domains feed (live, machine-readable).

Related indicators

Indicators that appear alongside this one in the same reporting, often shared infrastructure or the same campaign.

telegram[.]org0637069c7052118fd5c0f1113541bdd35e5f71cd9689f2516045da152c6fa8d9087499849115eb28c4364581d2b28d090x04E25a563f159308FC3E15fE9Ccc9D2CF623D0cc0x16dA95799CB8aB203f83e01AFC030B1217198Da40x1D50703722729dD68e89D819F69eFc5Fb206bBe70x27c7c36981c1ed5cFA2DCDb4B43C27A6BaF6bEa80x4dcE7d4b1229F3705BDB70341484cF2EEE36432e0x55b4F951d5Ac035C21B170C73C0A930a641b718C0x6da31EB2A016074ffd5519326573E78E2677E4C80x737791081A398151195a753Fb49f9c1b8bc1fCDB0x75cD25791A60ab3451E2d2feB5ec46c6f541C2B80x7D2D8A4A6E8D89cf5C151C4f68A521490D9779B00x8d2BaEc2687F59eE1EE7BFd322D33325f5E004ee0xb0874252a7359AA701F3F144A1f03A6e0DA8aE6D0xb3EF2D08Bf25a7daB9d8b98d64E564eA1f6Db9240xb8fB2bfb182A172b29C365AD6CF743449975C4180xbD6e817Cc510EC3DA5651B5a3AC595d34C0CF1af0xC37fB924cF5996C9e676BBA399bDfc5F936B35720xC41342908f98E813862EDFe47Ac3af676F8098C90xc7199C1dbCd82c4E002327Aa3EC9158F434a6aCE0xcaf2c54e400437da717cf215181b170f65187abf0xCE476E6f4d83a7a086Cbcdf0FE2E8f221e47e81C0xD69A36439FffD145ADAcacB94fDe6f8b3546a3610xf9438b4E3200AE1611eD3d03310c803FDdf676720xfbC267200f9e5749045f32dbB55BB16615f1CE5F0xFDB8b139EeacD17ea7c10c256eA77Ba6Dff18D7d0xFdfB8c4e827c2d053749C8F2f2058548dde0d0731099bf51e53bd5fb32401edb4e0be841d8486b191505eda3da68e2ff9919b55a31018bd30a991236f041aee835f3bc4e430ce505193[.]221[.]200[.]219194[.]87[.]92[.]1091bd0a200528c82c6488b4f48dd6dbc818d48782a2e25ccd22781c5718c3f62f52172dae9a5a695e00e0e4609e7db0207d8566d225f7e815fada246ae995c0f9b2377c47cfde148c2140faa7105628174f9c4d56d281b970f281dbea3c0e8cfc68b2e9939b253e5d3de52265b454d8f0f578768a228b47bdf16d7af6f8ec21218eac9145a32529043d15e9111ba284f1d8a9e4b3f58e071c6b69c8f271d4d02feacd44e663b0c658ebaa2bae80af97f390b9b2bb20a2f815eb584b2251255e84da4fa669d3b3eaea783fd6dab90f0408274bf8a9c49adbdc70c0efd70658d65b0e1684a3f

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

Double opt-in. One-click unsubscribe on every issue. We never share your address.