Analysis as of July 31, 2026 indicates that the domain telos.run is actively used for generic phishing campaigns. The domain was registered through GoDaddy.com, LLC on February 19, 2022 and is currently hosted on the IP address 177.8.248.45. DNS resolution is served by the authoritative nameservers ns1.isuper.com.br and ns2.isuper.com.br, suggesting that the hosting infrastructure resides in a Brazilian name‑server network.
VirusTotal reports that one out of ninety‑one scanned security vendors flagged the domain, confirming that at least one detection engine has identified malicious activity associated with telos.run. The domain appears on a single public blocklist and is explicitly blocked by the PhishDestroy service, reinforcing the assessment of high risk. No additional public indicators such as SSL certificate details, HTTP response codes, or Safe Browsing verdicts are available in the current intelligence set, leaving the exact payload and lure mechanisms unverified.
Defenders should therefore treat telos.run as a high‑confidence phishing indicator: network perimeter controls should deny outbound connections to the resolved IP, DNS filtering should block resolution of the domain, and endpoint security policies should include the domain in blocklists. Continuous monitoring for new detections on additional threat‑intel platforms is recommended, as further analysis may reveal the specific brand or credential‑harvesting pages used. Until more detailed forensic evidence is obtained, the precautionary posture is to prevent any user interaction with telos.run and to consider the domain compromised for internal threat‑hunting activities.