
{
  "Event": {
    "id": 0,
    "date": "2026-09-08",
    "threat_level_id": 1,
    "analysis": 0,
    "attribute_count": "43",
    "publish_distribution": 0,
    "proposal_email_lock": false,
    "info": "Cyber Daily Brief IOC Report - 2026-09-08 12:41 UTC",
    "published": false,
    "uuid": "misp-event-IOC-20260908-124108",
    "orgc_id": 0,
    "Orgc": {
      "name": "Cyber Daily Brief"
    },
    "distribution": 0,
    "tags": [
      "ioc-report::2026-09-08 12:41 UTC",
      "classification:text",
      "export:requires-approval::0"
    ],
    "sharing_group_id": 0,
    "disable_correlation": false,
    "expected_count": 43,
    "event_level": 1,
    "analysis_status": "1",
    "Attribute": [
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-85046",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Chromium V8 (Google); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-04; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple ",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-04",
        "last_seen": "2026-09-04"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-59822",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: LiteLLM (BerriAI); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an ar",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-02",
        "last_seen": "2026-09-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-48710",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Starlette (Kludex); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentica",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-02",
        "last_seen": "2026-09-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-49869",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Kestra OSS (Kestra); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-02",
        "last_seen": "2026-09-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-82329",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Artifactory (JFrog); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-02",
        "last_seen": "2026-09-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-9586",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Switchvox (Sangoma); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single craf",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-02",
        "last_seen": "2026-09-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-83548",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: SMA1000 Appliances (SonicWall); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform ",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-02",
        "last_seen": "2026-09-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-83549",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: SMA1000 Appliances (SonicWall); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote cod",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-02",
        "last_seen": "2026-09-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-82078",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: NG/MF (PaperCut); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-08-31; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpa",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-08-31",
        "last_seen": "2026-08-31"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-81578",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: NG/MF (PaperCut); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-08-31; Section: IP ADDRESS; Description: PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be ",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:IP ADDRESS",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-08-31",
        "last_seen": "2026-08-31"
      },
      {
        "category": "IP address",
        "type": "ip-dst",
        "value": "23.234.64.0",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: N-able Patches Critical Zero-Day in N-central; URL: https://www.securityweek.com/n-able-patches-critical-zero-day-in-n-central/; Section: IP ADDRESS; Description: C2/infrastructure in threat context: N-able Patches Critical Zero-Day in N-central",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:IP ADDRESS",
          "tag:ip",
          "tag:infrastructure"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "IP address",
        "type": "ip-dst",
        "value": "23.234.64.0",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: N-able Patches Critical Zero-Day in N-central; URL: https://www.securityweek.com/n-able-patches-critical-zero-day-in-n-central/; Section: IP ADDRESS; Description: C2/infrastructure in threat context: N-able Patches Critical Zero-Day in N-central",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:IP ADDRESS",
          "tag:ip",
          "tag:infrastructure"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "IP address",
        "type": "ip-dst",
        "value": "23.234.64.0",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: N-able Patches Critical Zero-Day in N-central; URL: https://www.securityweek.com/n-able-patches-critical-zero-day-in-n-central/; Section: IP ADDRESS; Description: C2/infrastructure in threat context: N-able Patches Critical Zero-Day in N-central",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:IP ADDRESS",
          "tag:ip",
          "tag:infrastructure"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "IP address",
        "type": "ip-dst",
        "value": "23.234.64.0",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: N-able Patches Critical Zero-Day in N-central; URL: https://www.securityweek.com/n-able-patches-critical-zero-day-in-n-central/; Section: IP ADDRESS; Description: C2/infrastructure in threat context: N-able Patches Critical Zero-Day in N-central",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:IP ADDRESS",
          "tag:ip",
          "tag:infrastructure"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "IP address",
        "type": "ip-dst",
        "value": "23.234.64.0",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: N-able Patches Critical Zero-Day in N-central; URL: https://www.securityweek.com/n-able-patches-critical-zero-day-in-n-central/; Section: IP ADDRESS; Description: C2/infrastructure in threat context: N-able Patches Critical Zero-Day in N-central",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:IP ADDRESS",
          "tag:ip",
          "tag:infrastructure"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "IP address",
        "type": "ip-dst",
        "value": "82.192.72.4",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: \u26a1 Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More; URL: https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html; Section: IP ADDRESS; Description: C2/infrastructure in threat context: \u26a1 Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:IP ADDRESS",
          "tag:ip",
          "tag:infrastructure"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "IP address",
        "type": "ip-dst",
        "value": "103.102.31.18",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: \u26a1 Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More; URL: https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html; Section: IP ADDRESS; Description: C2/infrastructure in threat context: \u26a1 Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:IP ADDRESS",
          "tag:ip",
          "tag:infrastructure"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "IP address",
        "type": "ip-dst",
        "value": "82.192.72.4",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: MikroTik Patches Critical Flaws Chained to Hack Routers; URL: https://www.securityweek.com/mikrotik-patches-critical-flaws-chained-to-hack-routers/; Section: IP ADDRESS; Description: C2/infrastructure in threat context: MikroTik Patches Critical Flaws Chained to Hack Routers",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:IP ADDRESS",
          "tag:ip",
          "tag:infrastructure"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "IP address",
        "type": "ip-dst",
        "value": "103.102.31.18",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: MikroTik Patches Critical Flaws Chained to Hack Routers; URL: https://www.securityweek.com/mikrotik-patches-critical-flaws-chained-to-hack-routers/; Section: IP ADDRESS; Description: C2/infrastructure in threat context: MikroTik Patches Critical Flaws Chained to Hack Routers",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:IP ADDRESS",
          "tag:ip",
          "tag:infrastructure"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "IP address",
        "type": "ip-dst",
        "value": "82.192.72.4",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: MikroTik Patches Critical Flaws Chained to Hack Routers; URL: https://www.securityweek.com/mikrotik-patches-critical-flaws-chained-to-hack-routers/; Section: IP ADDRESS; Description: C2/infrastructure in threat context: MikroTik Patches Critical Flaws Chained to Hack Routers",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:IP ADDRESS",
          "tag:ip",
          "tag:infrastructure"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "IP address",
        "type": "ip-dst",
        "value": "103.102.31.18",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: MikroTik Patches Critical Flaws Chained to Hack Routers; URL: https://www.securityweek.com/mikrotik-patches-critical-flaws-chained-to-hack-routers/; Section: IP ADDRESS; Description: C2/infrastructure in threat context: MikroTik Patches Critical Flaws Chained to Hack Routers",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:IP ADDRESS",
          "tag:ip",
          "tag:infrastructure"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "IP address",
        "type": "ip-dst",
        "value": "82.192.72.4",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: MikroTik Patches Critical Flaws Chained to Hack Routers; URL: https://www.securityweek.com/mikrotik-patches-critical-flaws-chained-to-hack-routers/; Section: IP ADDRESS; Description: C2/infrastructure in threat context: MikroTik Patches Critical Flaws Chained to Hack Routers",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:IP ADDRESS",
          "tag:ip",
          "tag:infrastructure"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "IP address",
        "type": "ip-dst",
        "value": "103.102.31.18",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: MikroTik Patches Critical Flaws Chained to Hack Routers; URL: https://www.securityweek.com/mikrotik-patches-critical-flaws-chained-to-hack-routers/; Section: IP ADDRESS; Description: C2/infrastructure in threat context: MikroTik Patches Critical Flaws Chained to Hack Routers",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:IP ADDRESS",
          "tag:ip",
          "tag:infrastructure"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "IP address",
        "type": "ip-dst",
        "value": "82.192.72.4",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: MikroTik Patches Critical Flaws Chained to Hack Routers; URL: https://www.securityweek.com/mikrotik-patches-critical-flaws-chained-to-hack-routers/; Section: IP ADDRESS; Description: C2/infrastructure in threat context: MikroTik Patches Critical Flaws Chained to Hack Routers",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:IP ADDRESS",
          "tag:ip",
          "tag:infrastructure"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "IP address",
        "type": "ip-dst",
        "value": "103.102.31.18",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: MikroTik Patches Critical Flaws Chained to Hack Routers; URL: https://www.securityweek.com/mikrotik-patches-critical-flaws-chained-to-hack-routers/; Section: PHISHING URL; Description: C2/infrastructure in threat context: MikroTik Patches Critical Flaws Chained to Hack Routers",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:PHISHING URL",
          "tag:ip",
          "tag:infrastructure"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://gurl.pro/roblox-users-8715356-profile",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://gurl.pro/roblox-users-8715356-profile; Section: PHISHING URL; Description: Active phishing URL: https://gurl.pro/roblox-users-8715356-profile",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://shorten.tv/l65iO",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://shorten.tv/l65iO; Section: PHISHING URL; Description: Active phishing URL: https://shorten.tv/l65iO",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://www.shorten.tv/jRftj/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://www.shorten.tv/jRftj/; Section: PHISHING URL; Description: Active phishing URL: http://www.shorten.tv/jRftj/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://itstrafflc.us/edoc/indextgpart.html",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://itstrafflc.us/edoc/indextgpart.html; Section: PHISHING URL; Description: Active phishing URL: https://itstrafflc.us/edoc/indextgpart.html",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://www.estudiocils.com.ar/home/nkl-log.php",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://www.estudiocils.com.ar/home/nkl-log.php; Section: PHISHING URL; Description: Active phishing URL: https://www.estudiocils.com.ar/home/nkl-log.php",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://www.estudiocils.com.ar/home",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://www.estudiocils.com.ar/home; Section: PHISHING URL; Description: Active phishing URL: http://www.estudiocils.com.ar/home",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://metamask-docs-git-dependabot-npmandya-95394d-consensys-ddffed67.vercel.app/embedded-wallets/sdk/unity",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://metamask-docs-git-dependabot-npmandya-95394d-consensys-ddffed67.vercel.app/embedded-wallets/sdk/unity; Section: PHISHING URL; Description: Active phishing URL: https://metamask-docs-git-dependabot-npmandya-95394d-consensys-ddffed67.vercel.app/embedded-wallets/sdk/unity",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://metamask-docs-git-dependabot-npmandya-95394d-consensys-ddffed67.vercel.app/embedded-wallets/sdk/react-native",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://metamask-docs-git-dependabot-npmandya-95394d-consensys-ddffed67.vercel.app/embedded-wallets/sdk/react-native; Section: PHISHING URL; Description: Active phishing URL: https://metamask-docs-git-dependabot-npmandya-95394d-consensys-ddffed67.vercel.app/embedded-wallets/sdk/react-native",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://amazon-landing-page-umber.vercel.app/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://amazon-landing-page-umber.vercel.app/; Section: DOMAIN; Description: Active phishing URL: https://amazon-landing-page-umber.vercel.app/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "gurl.pro",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://gurl.pro/roblox-users-8715356-profile; Section: DOMAIN; Description: Phishing domain: gurl.pro",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "shorten.tv",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://shorten.tv/l65iO; Section: DOMAIN; Description: Phishing domain: shorten.tv",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "www.shorten",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://www.shorten.tv/jRftj/; Section: DOMAIN; Description: Phishing domain: www.shorten",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "itstrafflc.us",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://itstrafflc.us/edoc/indextgpart.html; Section: DOMAIN; Description: Phishing domain: itstrafflc.us",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "www.estudiocils",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://www.estudiocils.com.ar/home/nkl-log.php; Section: DOMAIN; Description: Phishing domain: www.estudiocils",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "metamask-docs-git-dependabot-npmandya-95394d-consensys-ddffed67.vercel",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://metamask-docs-git-dependabot-npmandya-95394d-consensys-ddffed67.vercel.app/embedded-wallets/sdk/unity; Section: DOMAIN; Description: Phishing domain: metamask-docs-git-dependabot-npmandya-95394d-consensys-ddffed67.vercel",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "amazon-landing-page-umber.vercel",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://amazon-landing-page-umber.vercel.app/; Section: DOMAIN; Description: Phishing domain: amazon-landing-page-umber.vercel",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "www.amazon",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://www.amazon-landing-page-umber.vercel.app/; Section: DOMAIN; Description: Phishing domain: www.amazon",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "smilling-long-pannel.edgeone",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://smilling-long-pannel.edgeone.dev/; Section: DOMAIN; Description: Phishing domain: smilling-long-pannel.edgeone",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      }
    ]
  }
}