
{
  "Event": {
    "id": 0,
    "date": "2026-09-07",
    "threat_level_id": 1,
    "analysis": 0,
    "attribute_count": "46",
    "publish_distribution": 0,
    "proposal_email_lock": false,
    "info": "Cyber Daily Brief IOC Report - 2026-09-07 12:55 UTC",
    "published": false,
    "uuid": "misp-event-IOC-20260907-125508",
    "orgc_id": 0,
    "Orgc": {
      "name": "Cyber Daily Brief"
    },
    "distribution": 0,
    "tags": [
      "ioc-report::2026-09-07 12:55 UTC",
      "classification:text",
      "export:requires-approval::0"
    ],
    "sharing_group_id": 0,
    "disable_correlation": false,
    "expected_count": 46,
    "event_level": 1,
    "analysis_status": "1",
    "Attribute": [
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-85046",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Chromium V8 (Google); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-04; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple ",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-04",
        "last_seen": "2026-09-04"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-59822",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: LiteLLM (BerriAI); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an ar",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-02",
        "last_seen": "2026-09-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-48710",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Starlette (Kludex); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentica",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-02",
        "last_seen": "2026-09-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-49869",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Kestra OSS (Kestra); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-02",
        "last_seen": "2026-09-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-82329",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Artifactory (JFrog); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-02",
        "last_seen": "2026-09-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-9586",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Switchvox (Sangoma); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single craf",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-02",
        "last_seen": "2026-09-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-83548",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: SMA1000 Appliances (SonicWall); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform ",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-02",
        "last_seen": "2026-09-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-83549",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: SMA1000 Appliances (SonicWall); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote cod",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-02",
        "last_seen": "2026-09-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-82078",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: NG/MF (PaperCut); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-08-31; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpa",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-08-31",
        "last_seen": "2026-08-31"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-81578",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: NG/MF (PaperCut); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-08-31; Section: SHA256 HASH; Description: PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be ",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:SHA256 HASH",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-08-31",
        "last_seen": "2026-08-31"
      },
      {
        "category": "Other",
        "type": "sha256",
        "value": "5db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms; URL: https://cybersecuritynews.com/dprk-linked-hackers/; Section: SHA256 HASH; Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:SHA256 HASH",
          "tag:hash",
          "tag:malware"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "sha256",
        "value": "09739441ed4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms; URL: https://cybersecuritynews.com/dprk-linked-hackers/; Section: SHA256 HASH; Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:SHA256 HASH",
          "tag:hash",
          "tag:malware"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "sha256",
        "value": "fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ade6df06e61",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms; URL: https://cybersecuritynews.com/dprk-linked-hackers/; Section: SHA256 HASH; Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:SHA256 HASH",
          "tag:hash",
          "tag:malware"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "sha256",
        "value": "83f7d565b0465546027052b597af46eae3a199e7a91fcc2ab936341147349130",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms; URL: https://cybersecuritynews.com/dprk-linked-hackers/; Section: SHA256 HASH; Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:SHA256 HASH",
          "tag:hash",
          "tag:malware"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "sha256",
        "value": "7007a78d50a993cb174c685eba96eb442c9507e38fd9d8e5dffc712f613ec110",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms; URL: https://cybersecuritynews.com/dprk-linked-hackers/; Section: SHA256 HASH; Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:SHA256 HASH",
          "tag:hash",
          "tag:malware"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "sha256",
        "value": "6cf1b5e92a9c0756f597a5ddefb38eba32961c52efac7ab2a0aa52c639a8fc53",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms; URL: https://cybersecuritynews.com/dprk-linked-hackers/; Section: SHA256 HASH; Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:SHA256 HASH",
          "tag:hash",
          "tag:malware"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "sha256",
        "value": "ed72f4cd8d467b5c5d95ae6aeca4aaeea14d79565d379c1ca5871a714727be16",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms; URL: https://cybersecuritynews.com/dprk-linked-hackers/; Section: SHA256 HASH; Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:SHA256 HASH",
          "tag:hash",
          "tag:malware"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "sha256",
        "value": "feeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms; URL: https://cybersecuritynews.com/dprk-linked-hackers/; Section: SHA256 HASH; Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:SHA256 HASH",
          "tag:hash",
          "tag:malware"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "sha256",
        "value": "d53c760c23b4405eb04ad0f20ead375440344b3bdf1fb7854ed12e40d155eabe",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms; URL: https://cybersecuritynews.com/dprk-linked-hackers/; Section: SHA256 HASH; Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:SHA256 HASH",
          "tag:hash",
          "tag:malware"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "sha256",
        "value": "2f02b09d61d432134e994ad671258f523bbf289ae6091fd4eae192c60bd51b6f",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms; URL: https://cybersecuritynews.com/dprk-linked-hackers/; Section: SHA256 HASH; Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:SHA256 HASH",
          "tag:hash",
          "tag:malware"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "sha256",
        "value": "8f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66c",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms; URL: https://cybersecuritynews.com/dprk-linked-hackers/; Section: SHA256 HASH; Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:SHA256 HASH",
          "tag:hash",
          "tag:malware"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "sha256",
        "value": "a1d8af3a6acb731f07f72040eccb3450c1c83d40e29f736c2a63d35388660be4",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms; URL: https://cybersecuritynews.com/dprk-linked-hackers/; Section: SHA256 HASH; Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:SHA256 HASH",
          "tag:hash",
          "tag:malware"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "sha256",
        "value": "12810854c8b2c391b23e2e18b013e873d0369b0637aa3cf993136c07188ba3b8",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms; URL: https://cybersecuritynews.com/dprk-linked-hackers/; Section: SHA256 HASH; Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:SHA256 HASH",
          "tag:hash",
          "tag:malware"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "sha256",
        "value": "009a1e2d7a582a24e50cf2ffc2a005482c8e38f22bf5ed416053855f8d054e1e",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms; URL: https://cybersecuritynews.com/dprk-linked-hackers/; Section: SHA256 HASH; Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:SHA256 HASH",
          "tag:hash",
          "tag:malware"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "sha256",
        "value": "4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms; URL: https://cybersecuritynews.com/dprk-linked-hackers/; Section: SHA256 HASH; Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:SHA256 HASH",
          "tag:hash",
          "tag:malware"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "sha256",
        "value": "94630b96f628c96a6bff7904b40ffc9ad67c86f8a4ff6080c3b524831c93f402",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms; URL: https://cybersecuritynews.com/dprk-linked-hackers/; Section: SHA256 HASH; Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:SHA256 HASH",
          "tag:hash",
          "tag:malware"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "sha256",
        "value": "72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms; URL: https://cybersecuritynews.com/dprk-linked-hackers/; Section: SHA256 HASH; Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:SHA256 HASH",
          "tag:hash",
          "tag:malware"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "sha256",
        "value": "a8bfab4de81a1acb04aacdf757346946b0f5e30f0c9f402004016d0e425119c7",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms; URL: https://cybersecuritynews.com/dprk-linked-hackers/; Section: PHISHING URL; Description: Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:hash",
          "tag:malware"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://loyaltyprogram.ink/aQzXm",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://loyaltyprogram.ink/aQzXm; Section: PHISHING URL; Description: Active phishing URL: https://loyaltyprogram.ink/aQzXm",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://hs393765aff890a3eac6911d6f8eb9dd9b.nexusqalinka2.quest/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://hs393765aff890a3eac6911d6f8eb9dd9b.nexusqalinka2.quest/; Section: PHISHING URL; Description: Active phishing URL: http://hs393765aff890a3eac6911d6f8eb9dd9b.nexusqalinka2.quest/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://www.hs393765aff890a3eac6911d6f8eb9dd9b.nexusqalinka2.quest/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://www.hs393765aff890a3eac6911d6f8eb9dd9b.nexusqalinka2.quest/; Section: PHISHING URL; Description: Active phishing URL: http://www.hs393765aff890a3eac6911d6f8eb9dd9b.nexusqalinka2.quest/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://ledgerw.vercel.app/login",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://ledgerw.vercel.app/login; Section: PHISHING URL; Description: Active phishing URL: https://ledgerw.vercel.app/login",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://zwjf76j-h07j.vercel.app/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://zwjf76j-h07j.vercel.app/; Section: PHISHING URL; Description: Active phishing URL: https://zwjf76j-h07j.vercel.app/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://cjrb11r-h07r.vercel.app/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://cjrb11r-h07r.vercel.app/; Section: PHISHING URL; Description: Active phishing URL: https://cjrb11r-h07r.vercel.app/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://boaa.privatbanks.org/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://boaa.privatbanks.org/; Section: PHISHING URL; Description: Active phishing URL: http://boaa.privatbanks.org/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://wteamcommunity.com/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://wteamcommunity.com/; Section: PHISHING URL; Description: Active phishing URL: http://wteamcommunity.com/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://zavravo-kxt-felquro-p9t2dp56.pages.dev/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://zavravo-kxt-felquro-p9t2dp56.pages.dev/; Section: DOMAIN; Description: Active phishing URL: http://zavravo-kxt-felquro-p9t2dp56.pages.dev/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "loyaltyprogram.ink",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://loyaltyprogram.ink/aQzXm; Section: DOMAIN; Description: Phishing domain: loyaltyprogram.ink",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "nexusqalinka2.quest",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://hs393765aff890a3eac6911d6f8eb9dd9b.nexusqalinka2.quest/; Section: DOMAIN; Description: Phishing domain: nexusqalinka2.quest",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "ledgerw.vercel",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://ledgerw.vercel.app/login; Section: DOMAIN; Description: Phishing domain: ledgerw.vercel",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "zwjf76j-h07j.vercel",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://zwjf76j-h07j.vercel.app/; Section: DOMAIN; Description: Phishing domain: zwjf76j-h07j.vercel",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "cjrb11r-h07r.vercel",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://cjrb11r-h07r.vercel.app/; Section: DOMAIN; Description: Phishing domain: cjrb11r-h07r.vercel",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "boaa.privatbanks",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://boaa.privatbanks.org/; Section: DOMAIN; Description: Phishing domain: boaa.privatbanks",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "wteamcommunity.com",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://wteamcommunity.com/; Section: DOMAIN; Description: Phishing domain: wteamcommunity.com",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "zavravo-kxt-felquro-p9t2dp56.pages",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://zavravo-kxt-felquro-p9t2dp56.pages.dev/; Section: DOMAIN; Description: Phishing domain: zavravo-kxt-felquro-p9t2dp56.pages",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "amplifyapp.com",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://staging.d8yffvk7rzff1.amplifyapp.com/; Section: DOMAIN; Description: Phishing domain: amplifyapp.com",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      }
    ]
  }
}