t.me - URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned t.me and returned a benign verdict (score 0). The page resolved to 149.154.167.99 on Telegram Messenger Network in NL. 3 domains and 1 IP were contacted, over 1 HTTP request. 26 malware samples communicate with this URL (Note, Smuggling, Zbot, Mirai). This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: benign (score 0) · Confidence 8%
- Scanned URL:
https://t.me/CirqueiraDev - Domain: t.me · IP: 149.154.167.99 · AS62041 · NL
- Server: nginx/1.30.1
- Page title: Telegram: Contact @CirqueiraDev
- HTTP status: 200 · text/html; charset=utf-8
- TLS issuer: C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2 · valid to Nov 22 19: · subject CN=*.t.me
- HTTP requests captured: 1
- Scan tier: fast · observed 2026-08-20 10:55:26 UTC
Malware communicating with this URL (26)
These samples were observed contacting or being served from t.me. Each links to its full analysis.
- Note - referenced ·
25e1577ccee5bc33d5273e5d4aec9442· first seen 2026-08-20 - Smuggling - referenced ·
9f61ec03b9375a51ecfd89494fe5cdda· first seen 2026-08-19 - Zbot - referenced ·
8e108830eb08f96c52549dca024c65c6· first seen 2026-08-19 - 11b89592d7d737fed81aa8079faf398af78551fc483ff1273237fb8b97611335 - referenced ·
11b89592d7d737fed81aa8079faf398a· first seen 2026-08-16 - Mirai - referenced ·
c1e61d32bd277091cf92647cabec47cf· first seen 2026-08-15 - Mirai - referenced ·
be93cf8050a0ec8bc1d142cc6d3106cb· first seen 2026-08-15 - Mirai - referenced ·
bca1a1ab6f8af45dc8b855a33d9fd8bd· first seen 2026-08-15 - Mirai - referenced ·
b5fa45952fa3bb422b1d85d52a6a2969· first seen 2026-08-15 - Mirai - referenced ·
b284282059d0cbf9f7640624ae54b570· first seen 2026-08-15 - 502a54869bfba85d39a0a26b00a352a46696f98f39f2b0c9d298309d7a908422 - referenced ·
502a54869bfba85d39a0a26b00a352a4· first seen 2026-08-15 - Mirai - referenced ·
9f11e24531de2a3e5de458d335485805· first seen 2026-08-14 - Mirai - referenced ·
6d99352ccf8ef3dec20ee396418f4963· first seen 2026-08-13 - Mirai - referenced ·
6ae2d6cbbd86fc97aaf932ed79fb683e· first seen 2026-08-13 - 80e28ed36855fbe2d4014c04b9db6df7540f644c5dc75853818e8bab77c28eb3 - referenced ·
80e28ed36855fbe2d4014c04b9db6df7· first seen 2026-08-13 - AntiDebug - referenced ·
32e2637b808f658f74e765fa3373e974· first seen 2026-08-13
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- Hosted on abuse-prone infrastructure (telegram)
Detected technologies
- Nginx
- Bootstrap
Contacted infrastructure
- 149.154.167.99 - AS62041 Telegram Messenger Network (Netherlands)
Observed indicators
- t.me
- telegram.org
- cdn1.telesco.pe
- 149.154.167.99
- https://t.me/CirqueiraDev
- https://telegram.org/img/website_icon.svg?4
- https://telegram.org/img/apple-touch-icon.png
- https://telegram.org/img/favicon-32x32.png
- https://telegram.org/img/favicon-16x16.png
- https://telegram.org/img/favicon.ico
- https://telegram.org/css/font-roboto.css?1
- https://t.me/css/myriad.css
- https://telegram.org/css/bootstrap.min.css?3
- https://telegram.org/css/telegram.css?254
- https://telegram.org/
- https://telegram.org/dl?tme=5b7c5faf8dd99c88c8_13021146523102817554
- https://cdn1.telesco.pe/file/GnNh-BVHihmP9MdQed5C4OMcuu_VmF-HgIovvnAujrc6JJ78ZPu7QO3zM7ffkOsE_Apdas0uiQnceD1SKjmnPopSReivoSIjhKk169bxb-RcjHmB7SQQ_7CkNqaMGMz1-MqwHxXpoPW5dy8zQO6AyUHXQxk9wQe0r1BvLexM9XsCtXdt2e1fckD1eqXeTwa9NSbGZlZ6GlYc0H9bt9HoNeKcfDyqRrEKO5Zd9Ez6QNY9X6XvpcbAXDlwX104v5iH7dQEVBkAm8FEqScEMhCqZQP6tubc9mRQJlrmg2axZPGuWP05SgygQwGnEqmA_ZNXEykgTYfgyLg9ZtARa8mbTg.jpg
- https://telegram.org/js/tgwallpaper.min.js?3
Other scans of t.me (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown ·
https://tessa.ru/Repository/file/15363697785.pdf - 24 Aug 2026 - unknown ·
https://tessa.ru/Repository/file/15363697785.pdf - 23 Aug 2026 - malicious ·
https://dentinale.baby/ - 23 Aug 2026 - unknown ·
https://top4top.io/ - 23 Aug 2026 - unknown ·
http://star-transform-moscow.ru/uimg/files/43205011160.pdf - 23 Aug 2026 - benign ·
https://core.telegram.org/bots - 23 Aug 2026 - unknown ·
https://c.ua/ - 23 Aug 2026 - unknown ·
https://rusfishexpo.com/ - 23 Aug 2026 - unknown ·
https://mediaget.com/userfiles/files/rapazatugetizokusuvesevo.pdf - 23 Aug 2026 - unknown ·
https://worldkelo.com/
Questions about t.me
- Is t.me safe?
- The scan of t.me on 20 Aug 2026 found no evidence of harm. That is the absence of a finding at one point in time, not a guarantee: a page can change, and a scan only sees what it was served.
- What malware is associated with t.me?
- 26 analysed samples communicate with this URL, including Note, Smuggling, Zbot, Mirai.
- How was t.me checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of t.me
Scanned on MalwareAnalyzer by Cyble · Open interactive scan