83trust / 100

Ioc

by telesint-api.onrender.com in Email & messaging

x402 APIPassing, checked 2 h ago

IOC feed from Telegram CTI channels. Filters: type(ip|domain|url|hash|cve), severity, min_confidence, since, tlp, tag, channel, limit, offset. Returns items[] with iocs[], ttps[], confidence, severity, tlp, tags[].

GET https://telesint-api.onrender.com/ioc

Last 30 days

All checks passedSome failedAll failedNot checked
Uptime
100%
Response time
271 ms typical, 271 ms slowest 5%
Last check
2 h ago
Next check
any minute now

How to call it

# See the payment challenge (nothing is charged)
curl -i -X GET "https://telesint-api.onrender.com/ioc?channel=vxunderground&limit=20&min_confidence=70&offset=0&severity=high&since=2026-05-01T00%3A00%3A00Z&tag=ransomware&tlp=WHITE&type=ip"
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client().register(
  "eip155:8453",
  new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)),
);
const pay = wrapFetchWithPayment(fetch, client);

// Not sure it's safe to pay? Preflight it first for $0.03:
// GET https://toolvet.app/api/v1/check?url=https%3A%2F%2Ftelesint-api.onrender.com%2Fioc
const res = await pay("https://telesint-api.onrender.com/ioc?channel=vxunderground&limit=20&min_confidence=70&offset=0&severity=high&since=2026-05-01T00%3A00%3A00Z&tag=ransomware&tlp=WHITE&type=ip");
console.log(await res.json());

Example input

{
  "channel": "vxunderground",
  "limit": 20,
  "min_confidence": 70,
  "offset": 0,
  "severity": "high",
  "since": "2026-05-01T00:00:00Z",
  "tag": "ransomware",
  "tlp": "WHITE",
  "type": "ip"
}

Example output

{
  "endpoint": "ioc",
  "items": [
    {
      "category": "ioc",
      "channel": "https://t[.]me/vxunderground",
      "confidence": 80,
      "id": "f8a3c1d2-4b5e-4f6a-9c8d-1e2f3a4b5c6d",
      "iocs": [
        {
          "context": "Exploit repository",
          "type": "url",
          "value": "https://github[.]com/Nightmare-Eclipse/MiniPlasma"
        },
        {
          "context": "C2 callback address",
          "type": "ip",
          "value": "185.220[.]101.47"
        },
        {
          "context": "Dropper hash",
          "type": "sha256",
          "value": "e3b0c44298fc1c149afb4c8996fb924..."
        }
      ],
      "severity": "high",
      "summary": "Windows zero-day exploit released by Nightmare Eclipse threat group targeting government networks",
      "tags": [
        "zero-day",
        "windows",
        "government",
        "exploit"
      ],
      "tlp": "WHITE",
      "ts": "2026-05-27T14:32:00Z",
      "ttps": [
        {
          "id": "T1204.002",
          "name": "User Execution: Malicious File",
          "tactic": "Execution"
        },
        {
          "id": "T1071.001",
          "name": "Application Layer Protocol: Web Protocols",
          "tactic": "Command and Control"
        }
      ]
    }
  ],
  "limit": 20,
  "offset": 0,
  "source": "TeleSint",
  "total": 42
}

Security scan

  • No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.

Recent checks

WhenResultHTTPTimePrice
2 h agoPassed402271 ms$0.01