
{
  "type": "report",
  "id": "report--00000000-0000-0000-0000-000000000000",
  "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
  "created": "2026-09-06T14:27:43.931832Z",
  "modified": "2026-09-06T14:27:43.931832Z",
  "name": "Cyber Daily Brief IOC Report - 2026-09-06 14:27 UTC",
  "description": "Indicators of Compromise extracted from daily cyber briefing.\nReport ID: IOC-20260906-142743\nClassification: OPEN - Law Enforcement / DFIR use\nSources: Article: CISA KEV: CVE-2026-48710 - Kludex: Starl..., Article: CISA KEV: CVE-2026-85046 - Google: Chrom..., CISA KEV Catalog, OpenPhish",
  "object_marking_refs": [
    "marking-definition--00000000-0000-0000-0000-000000000002"
  ],
  "objects": {
    "identity--00000000-0000-0000-0000-000000000001": {
      "type": "identity",
      "name": "Cyber Daily Brief",
      "identity_class": "organization"
    },
    "marking-definition--00000000-0000-0000-0000-000000000002": {
      "type": "marking-definition",
      "definition_type": "statement",
      "definition": {
        "statement": "OPEN - Law Enforcement / DFIR use"
      }
    },
    "indicator--00000000-00000001-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000001-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "CVE-2026-85046",
      "description": "Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-85046']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Chromium V8 (Google)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-04",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000002-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000002-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "CVE-2026-59822",
      "description": "BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-59822']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "LiteLLM (BerriAI)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000003-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000003-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "CVE-2026-48710",
      "description": "Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-48710']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Starlette (Kludex)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000004-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000004-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "CVE-2026-49869",
      "description": "Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-49869']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Kestra OSS (Kestra)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000005-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000005-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "CVE-2026-82329",
      "description": "JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-82329']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Artifactory (JFrog)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000006-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000006-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "CVE-2026-9586",
      "description": "Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and rem",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-9586']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Switchvox (Sangoma)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000007-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000007-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "CVE-2026-83548",
      "description": "SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-83548']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "SMA1000 Appliances (SonicWall)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000008-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000008-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "CVE-2026-83549",
      "description": "SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-83549']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "SMA1000 Appliances (SonicWall)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000009-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000009-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "CVE-2026-82078",
      "description": "PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut serv",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-82078']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "NG/MF (PaperCut)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-08-31",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000010-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000010-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "CVE-2026-81578",
      "description": "PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.",
      "indicator_types": [
        "IP ADDRESS",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-81578']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "NG/MF (PaperCut)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-08-31",
        "original_section": "IP ADDRESS"
      }
    },
    "indicator--00000000-00000011-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000011-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "8.4.0.2",
      "description": "C2/infrastructure in threat context: CISA KEV: CVE-2026-85046 - Google: Chromium V8",
      "indicator_types": [
        "IP ADDRESS",
        "malicious-activity"
      ],
      "pattern": "[ipv4-addr:value = '8.4.0.2']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "ipv4-addr",
        "ip",
        "infrastructure"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: CISA KEV: CVE-2026-85046 - Google: Chrom...",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "",
        "original_section": "IP ADDRESS"
      }
    },
    "indicator--00000000-00000012-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000012-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "8.4.0.2",
      "description": "C2/infrastructure in threat context: CISA KEV: CVE-2026-48710 - Kludex: Starlette",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[ipv4-addr:value = '8.4.0.2']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "ipv4-addr",
        "ip",
        "infrastructure"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Article: CISA KEV: CVE-2026-48710 - Kludex: Starl...",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000013-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000013-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "https://www.nehsbe.cn/ww/",
      "description": "Active phishing URL: https://www.nehsbe.cn/ww/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://www.nehsbe.cn/ww/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://www.nehsbe.cn/ww/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000014-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000014-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "http://www.nehsbe.cn/",
      "description": "Active phishing URL: http://www.nehsbe.cn/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'http://www.nehsbe.cn/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://www.nehsbe.cn/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000015-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000015-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "https://fb-meta-verified-47091.vercel.app/",
      "description": "Active phishing URL: https://fb-meta-verified-47091.vercel.app/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://fb-meta-verified-47091.vercel.app/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://fb-meta-verified-47091.vercel.app/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000016-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000016-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "https://www.fb-meta-verified-47091.vercel.app/",
      "description": "Active phishing URL: https://www.fb-meta-verified-47091.vercel.app/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://www.fb-meta-verified-47091.vercel.app/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://www.fb-meta-verified-47091.vercel.app/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000017-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000017-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "https://samaoluwasegun-dev.github.io/alexhoffmannboa/",
      "description": "Active phishing URL: https://samaoluwasegun-dev.github.io/alexhoffmannboa/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://samaoluwasegun-dev.github.io/alexhoffmannboa/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://samaoluwasegun-dev.github.io/alexhoffmannboa/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000018-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000018-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "http://comcastsurvey.weebly.com/",
      "description": "Active phishing URL: http://comcastsurvey.weebly.com/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'http://comcastsurvey.weebly.com/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://comcastsurvey.weebly.com/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000019-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000019-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "https://pink-porcupine-845141.hostingersite.com/?naps",
      "description": "Active phishing URL: https://pink-porcupine-845141.hostingersite.com/?naps",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://pink-porcupine-845141.hostingersite.com/?naps']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://pink-porcupine-845141.hostingersite.com/?naps",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000020-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000020-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "https://ldgre-lives.pages.dev/",
      "description": "Active phishing URL: https://ldgre-lives.pages.dev/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://ldgre-lives.pages.dev/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://ldgre-lives.pages.dev/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000021-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000021-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "http://tiny.cc/rblxprivateserver",
      "description": "Active phishing URL: http://tiny.cc/rblxprivateserver",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'http://tiny.cc/rblxprivateserver']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://tiny.cc/rblxprivateserver",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000022-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000022-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "www.nehsbe",
      "description": "Phishing domain: www.nehsbe",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'www.nehsbe']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://www.nehsbe.cn/ww/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000023-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000023-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "fb-meta-verified-47091.vercel",
      "description": "Phishing domain: fb-meta-verified-47091.vercel",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'fb-meta-verified-47091.vercel']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://fb-meta-verified-47091.vercel.app/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000024-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000024-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "www.fb",
      "description": "Phishing domain: www.fb",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'www.fb']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://www.fb-meta-verified-47091.vercel.app/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000025-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000025-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "samaoluwasegun-dev.github",
      "description": "Phishing domain: samaoluwasegun-dev.github",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'samaoluwasegun-dev.github']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://samaoluwasegun-dev.github.io/alexhoffmannboa/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000026-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000026-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "comcastsurvey.weebly",
      "description": "Phishing domain: comcastsurvey.weebly",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'comcastsurvey.weebly']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://comcastsurvey.weebly.com/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000027-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000027-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "pink-porcupine-845141.hostingersite",
      "description": "Phishing domain: pink-porcupine-845141.hostingersite",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'pink-porcupine-845141.hostingersite']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://pink-porcupine-845141.hostingersite.com/?naps",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000028-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000028-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "ldgre-lives.pages",
      "description": "Phishing domain: ldgre-lives.pages",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ldgre-lives.pages']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://ldgre-lives.pages.dev/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000029-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000029-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "tiny.cc",
      "description": "Phishing domain: tiny.cc",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'tiny.cc']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://tiny.cc/rblxprivateserver",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000030-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000030-0000-0000-0000-000000000000",
      "created": "2026-09-06T14:27:43.931832Z",
      "modified": "2026-09-06T14:27:43.931832Z",
      "name": "https-wwwv-roblox.co",
      "description": "Phishing domain: https-wwwv-roblox.co",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'https-wwwv-roblox.co']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-06T14:27:43.931832Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://https-wwwv-roblox.co/login?returnUrl=288280197",
        "date": "",
        "original_section": "DOMAIN"
      }
    }
  }
}