
{
  "type": "report",
  "id": "report--00000000-0000-0000-0000-000000000000",
  "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
  "created": "2026-09-05T19:25:37.066478Z",
  "modified": "2026-09-05T19:25:37.066478Z",
  "name": "Cyber Daily Brief IOC Report - 2026-09-05 19:25 UTC",
  "description": "Indicators of Compromise extracted from daily cyber briefing.\nReport ID: IOC-20260905-192537\nClassification: OPEN - Law Enforcement / DFIR use\nSources: Article: Attackers Exploit PaperCut Flaws to Stea..., Article: Critical Citrix NetScaler auth bypass no..., Article: IDScan sued over alleged data breach aff..., Article: OpenAI admits it didn't disclose rogue A..., Article: Phishing Campaign Sends Millions of Emai..., Article: PostgreSQL Fixes 12-Year-Old Logical Dec..., Article: Thousands of OpenAI Agents Quietly Turne..., Article: Trezor Says ShipMonk Breach Exposed 67,0..., CISA KEV Catalog, OpenPhish",
  "object_marking_refs": [
    "marking-definition--00000000-0000-0000-0000-000000000002"
  ],
  "objects": {
    "identity--00000000-0000-0000-0000-000000000001": {
      "type": "identity",
      "name": "Cyber Daily Brief",
      "identity_class": "organization"
    },
    "marking-definition--00000000-0000-0000-0000-000000000002": {
      "type": "marking-definition",
      "definition_type": "statement",
      "definition": {
        "statement": "OPEN - Law Enforcement / DFIR use"
      }
    },
    "indicator--00000000-00000001-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000001-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "CVE-2026-85046",
      "description": "Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-85046']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Chromium V8 (Google)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-04",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000002-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000002-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "CVE-2026-59822",
      "description": "BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-59822']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "LiteLLM (BerriAI)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000003-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000003-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "CVE-2026-48710",
      "description": "Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-48710']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Starlette (Kludex)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000004-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000004-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "CVE-2026-49869",
      "description": "Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-49869']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Kestra OSS (Kestra)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000005-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000005-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "CVE-2026-82329",
      "description": "JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-82329']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Artifactory (JFrog)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000006-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000006-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "CVE-2026-9586",
      "description": "Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and rem",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-9586']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Switchvox (Sangoma)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000007-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000007-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "CVE-2026-83548",
      "description": "SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-83548']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "SMA1000 Appliances (SonicWall)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000008-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000008-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "CVE-2026-83549",
      "description": "SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-83549']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "SMA1000 Appliances (SonicWall)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000009-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000009-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "CVE-2026-82078",
      "description": "PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut serv",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-82078']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "NG/MF (PaperCut)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-08-31",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000010-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000010-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "CVE-2026-81578",
      "description": "PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-81578']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "NG/MF (PaperCut)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-08-31",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000011-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000011-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "policy.trezor",
      "description": "Referenced in threat context: Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Dele",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'policy.trezor']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Trezor Says ShipMonk Breach Exposed 67,0...",
        "url": "https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000012-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000012-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "metabase.however",
      "description": "Referenced in threat context: Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Dele",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'metabase.however']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Trezor Says ShipMonk Breach Exposed 67,0...",
        "url": "https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000013-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000013-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "actions.holborn",
      "description": "Referenced in threat context: Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Dele",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'actions.holborn']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Trezor Says ShipMonk Breach Exposed 67,0...",
        "url": "https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000014-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000014-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "remediation.the",
      "description": "Referenced in threat context: Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Dele",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'remediation.the']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Trezor Says ShipMonk Breach Exposed 67,0...",
        "url": "https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000015-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000015-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "restrictions.the",
      "description": "Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'restrictions.the']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: OpenAI admits it didn't disclose rogue A...",
        "url": "https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000016-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000016-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "impact.in",
      "description": "Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'impact.in']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: OpenAI admits it didn't disclose rogue A...",
        "url": "https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000017-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000017-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "succeeded.when",
      "description": "Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'succeeded.when']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: OpenAI admits it didn't disclose rogue A...",
        "url": "https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000018-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000018-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "longer.the",
      "description": "Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'longer.the']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: OpenAI admits it didn't disclose rogue A...",
        "url": "https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000019-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000019-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "addresses.openai",
      "description": "Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'addresses.openai']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: OpenAI admits it didn't disclose rogue A...",
        "url": "https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000020-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000020-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "day.openai",
      "description": "Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'day.openai']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: OpenAI admits it didn't disclose rogue A...",
        "url": "https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000021-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000021-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "incident.the",
      "description": "Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'incident.the']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: OpenAI admits it didn't disclose rogue A...",
        "url": "https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000022-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000022-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "cybersecurity.in",
      "description": "Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'cybersecurity.in']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: OpenAI admits it didn't disclose rogue A...",
        "url": "https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000023-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000023-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "sandbox.the",
      "description": "Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'sandbox.the']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Thousands of OpenAI Agents Quietly Turne...",
        "url": "https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000024-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000024-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "data.the",
      "description": "Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'data.the']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Thousands of OpenAI Agents Quietly Turne...",
        "url": "https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000025-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000025-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "behind.about",
      "description": "Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'behind.about']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Thousands of OpenAI Agents Quietly Turne...",
        "url": "https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000026-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000026-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "method.the",
      "description": "Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'method.the']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Thousands of OpenAI Agents Quietly Turne...",
        "url": "https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000027-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000027-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "blob.core",
      "description": "Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'blob.core']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Thousands of OpenAI Agents Quietly Turne...",
        "url": "https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000028-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000028-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "windows.net",
      "description": "Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'windows.net']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Thousands of OpenAI Agents Quietly Turne...",
        "url": "https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000029-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000029-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "valid.an",
      "description": "Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'valid.an']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Thousands of OpenAI Agents Quietly Turne...",
        "url": "https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000030-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000030-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "bypass.blob",
      "description": "Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bypass.blob']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Thousands of OpenAI Agents Quietly Turne...",
        "url": "https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000031-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000031-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "core.windows",
      "description": "Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'core.windows']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Thousands of OpenAI Agents Quietly Turne...",
        "url": "https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000032-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000032-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "internet.those",
      "description": "Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'internet.those']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Thousands of OpenAI Agents Quietly Turne...",
        "url": "https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000033-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000033-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "used.in",
      "description": "Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'used.in']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Thousands of OpenAI Agents Quietly Turne...",
        "url": "https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000034-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000034-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "platform.openai",
      "description": "Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'platform.openai']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Thousands of OpenAI Agents Quietly Turne...",
        "url": "https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000035-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000035-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "investigation.the",
      "description": "Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'investigation.the']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Thousands of OpenAI Agents Quietly Turne...",
        "url": "https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000036-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000036-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "on.the",
      "description": "Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'on.the']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Thousands of OpenAI Agents Quietly Turne...",
        "url": "https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000037-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000037-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "testing.openai",
      "description": "Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'testing.openai']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Thousands of OpenAI Agents Quietly Turne...",
        "url": "https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000038-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000038-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "boards.openai",
      "description": "Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'boards.openai']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Thousands of OpenAI Agents Quietly Turne...",
        "url": "https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000039-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000039-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "face.the",
      "description": "Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'face.the']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Thousands of OpenAI Agents Quietly Turne...",
        "url": "https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000040-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000040-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "said.the",
      "description": "Referenced in threat context: Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universit",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'said.the']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Attackers Exploit PaperCut Flaws to Stea...",
        "url": "https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000041-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000041-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "statement.users",
      "description": "Referenced in threat context: Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universit",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'statement.users']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Attackers Exploit PaperCut Flaws to Stea...",
        "url": "https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000042-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000042-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "cmd.exe",
      "description": "Referenced in threat context: Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universit",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'cmd.exe']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Attackers Exploit PaperCut Flaws to Stea...",
        "url": "https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000043-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000043-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "powershell.exe",
      "description": "Referenced in threat context: Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universit",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'powershell.exe']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Attackers Exploit PaperCut Flaws to Stea...",
        "url": "https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000044-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000044-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "pc-app.exe",
      "description": "Referenced in threat context: Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universit",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'pc-app.exe']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Attackers Exploit PaperCut Flaws to Stea...",
        "url": "https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000045-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000045-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "idscan.brian",
      "description": "Referenced in threat context: IDScan sued over alleged data breach affecting 153 million drivers",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'idscan.brian']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: IDScan sued over alleged data breach aff...",
        "url": "https://www.bleepingcomputer.com/news/security/idscan-sued-over-alleged-data-breach-affecting-153-million-drivers/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000046-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000046-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "cards.idscan",
      "description": "Referenced in threat context: IDScan sued over alleged data breach affecting 153 million drivers",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'cards.idscan']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: IDScan sued over alleged data breach aff...",
        "url": "https://www.bleepingcomputer.com/news/security/idscan-sued-over-alleged-data-breach-affecting-153-million-drivers/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000047-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000047-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "documents.given",
      "description": "Referenced in threat context: IDScan sued over alleged data breach affecting 153 million drivers",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'documents.given']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: IDScan sued over alleged data breach aff...",
        "url": "https://www.bleepingcomputer.com/news/security/idscan-sued-over-alleged-data-breach-affecting-153-million-drivers/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000048-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000048-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "litigation.state",
      "description": "Referenced in threat context: IDScan sued over alleged data breach affecting 153 million drivers",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'litigation.state']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: IDScan sued over alleged data breach aff...",
        "url": "https://www.bleepingcomputer.com/news/security/idscan-sued-over-alleged-data-breach-affecting-153-million-drivers/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000049-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000049-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "user.however",
      "description": "Referenced in threat context: Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filt",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'user.however']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Phishing Campaign Sends Millions of Emai...",
        "url": "https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000050-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000050-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "mondays.weekday",
      "description": "Referenced in threat context: Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filt",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mondays.weekday']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Phishing Campaign Sends Millions of Emai...",
        "url": "https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000051-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000051-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "applicants.details",
      "description": "Referenced in threat context: Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filt",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'applicants.details']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Phishing Campaign Sends Millions of Emai...",
        "url": "https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000052-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000052-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "matches.for",
      "description": "Referenced in threat context: Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filt",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'matches.for']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Phishing Campaign Sends Millions of Emai...",
        "url": "https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000053-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000053-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "basis.the",
      "description": "Referenced in threat context: Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filt",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'basis.the']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Phishing Campaign Sends Millions of Emai...",
        "url": "https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000054-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000054-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "acemlnd.com",
      "description": "Referenced in threat context: Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filt",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'acemlnd.com']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Phishing Campaign Sends Millions of Emai...",
        "url": "https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000055-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000055-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "activehosted.com",
      "description": "Referenced in threat context: Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filt",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'activehosted.com']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Phishing Campaign Sends Millions of Emai...",
        "url": "https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000056-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000056-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "networks.although",
      "description": "Referenced in threat context: Critical Citrix NetScaler auth bypass now leveraged in attacks",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'networks.although']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Critical Citrix NetScaler auth bypass no...",
        "url": "https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000057-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000057-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "attacks.the",
      "description": "Referenced in threat context: Critical Citrix NetScaler auth bypass now leveraged in attacks",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'attacks.the']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Critical Citrix NetScaler auth bypass no...",
        "url": "https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000058-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000058-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "sharply.tracked",
      "description": "Referenced in threat context: Critical Citrix NetScaler auth bypass now leveraged in attacks",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'sharply.tracked']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: Critical Citrix NetScaler auth bypass no...",
        "url": "https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000059-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000059-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "affected.exploitation",
      "description": "Referenced in threat context: PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Cod",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'affected.exploitation']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: PostgreSQL Fixes 12-Year-Old Logical Dec...",
        "url": "https://thehackernews.com/2026/09/postgresql-fixes-12-year-old-logical.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000060-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000060-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "attribute.the",
      "description": "Referenced in threat context: PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Cod",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'attribute.the']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "domain-name",
        "domain",
        "extracted"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: PostgreSQL Fixes 12-Year-Old Logical Dec...",
        "url": "https://thehackernews.com/2026/09/postgresql-fixes-12-year-old-logical.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000061-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000061-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "roblox.com",
      "description": "Phishing domain: roblox.com",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'roblox.com']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://roblox.com.mu/communities/7901998248/LeightXyn",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000062-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000062-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "revenuewise.sbs",
      "description": "Phishing domain: revenuewise.sbs",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'revenuewise.sbs']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://revenuewise.sbs/how-to-file/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000063-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000063-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "undian-shopee1772.blogspot",
      "description": "Phishing domain: undian-shopee1772.blogspot",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'undian-shopee1772.blogspot']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://undian-shopee1772.blogspot.com/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000064-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000064-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "hadiahshopee3232.blogspot",
      "description": "Phishing domain: hadiahshopee3232.blogspot",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'hadiahshopee3232.blogspot']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://hadiahshopee3232.blogspot.com/?m=1",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000065-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000065-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "www.newcomc",
      "description": "Phishing domain: www.newcomc",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'www.newcomc']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://www.newcomc.weebly.com/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000066-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000066-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "pesta-undian-shopee2023.blogspot",
      "description": "Phishing domain: pesta-undian-shopee2023.blogspot",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'pesta-undian-shopee2023.blogspot']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://pesta-undian-shopee2023.blogspot.com/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000067-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000067-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "surajyadav-07.github",
      "description": "Phishing domain: surajyadav-07.github",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'surajyadav-07.github']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://surajyadav-07.github.io/ecommerce-website",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000068-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000068-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "lbr-icloud.com",
      "description": "Phishing domain: lbr-icloud.com",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'lbr-icloud.com']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://lbr-icloud.com/help?JpN",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000069-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000069-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "first-agency-743956.framer",
      "description": "Phishing domain: first-agency-743956.framer",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'first-agency-743956.framer']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://first-agency-743956.framer.app/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000070-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000070-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "http://roblox.com.mu/communities/7901998248/LeightXyn",
      "description": "Active phishing URL: http://roblox.com.mu/communities/7901998248/LeightXyn",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'http://roblox.com.mu/communities/7901998248/LeightXyn']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://roblox.com.mu/communities/7901998248/LeightXyn",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000071-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000071-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "https://revenuewise.sbs/how-to-file/",
      "description": "Active phishing URL: https://revenuewise.sbs/how-to-file/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://revenuewise.sbs/how-to-file/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://revenuewise.sbs/how-to-file/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000072-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000072-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "https://revenuewise.sbs/get-transcript/",
      "description": "Active phishing URL: https://revenuewise.sbs/get-transcript/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://revenuewise.sbs/get-transcript/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://revenuewise.sbs/get-transcript/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000073-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000073-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "https://revenuewise.sbs/businesses-1/",
      "description": "Active phishing URL: https://revenuewise.sbs/businesses-1/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://revenuewise.sbs/businesses-1/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://revenuewise.sbs/businesses-1/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000074-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000074-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "https://revenuewise.sbs/get-your-refund-faster-tell-irs-to-direct-deposit-your-refund-to-one-two-or-three-accounts/",
      "description": "Active phishing URL: https://revenuewise.sbs/get-your-refund-faster-tell-irs-to-direct-deposit-your-refund-to-one-two-or-three-accounts/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://revenuewise.sbs/get-your-refund-faster-tell-irs-to-direct-deposit-your-refund-to-one-two-or-three-accounts/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://revenuewise.sbs/get-your-refund-faster-tell-irs-to-direct-deposit-your-refund-to-one-two-or-three-accounts/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000075-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000075-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "https://revenuewise.sbs/credits-and-deductions-for-individuals/",
      "description": "Active phishing URL: https://revenuewise.sbs/credits-and-deductions-for-individuals/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://revenuewise.sbs/credits-and-deductions-for-individuals/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://revenuewise.sbs/credits-and-deductions-for-individuals/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000076-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000076-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "https://revenuewise.sbs/clean-vehicle-and-energy-credits/",
      "description": "Active phishing URL: https://revenuewise.sbs/clean-vehicle-and-energy-credits/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://revenuewise.sbs/clean-vehicle-and-energy-credits/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://revenuewise.sbs/clean-vehicle-and-energy-credits/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000077-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000077-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "https://revenuewise.sbs/about-refunds/",
      "description": "Active phishing URL: https://revenuewise.sbs/about-refunds/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://revenuewise.sbs/about-refunds/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://revenuewise.sbs/about-refunds/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000078-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000078-0000-0000-0000-000000000000",
      "created": "2026-09-05T19:25:37.066478Z",
      "modified": "2026-09-05T19:25:37.066478Z",
      "name": "https://undian-shopee1772.blogspot.com/",
      "description": "Active phishing URL: https://undian-shopee1772.blogspot.com/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://undian-shopee1772.blogspot.com/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-05T19:25:37.066478Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://undian-shopee1772.blogspot.com/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    }
  }
}