
{
  "type": "report",
  "id": "report--00000000-0000-0000-0000-000000000000",
  "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
  "created": "2026-09-11T12:15:09.896798Z",
  "modified": "2026-09-11T12:15:09.896798Z",
  "name": "Cyber Daily Brief IOC Report - 2026-09-11 12:15 UTC",
  "description": "Indicators of Compromise extracted from daily cyber briefing.\nReport ID: IOC-20260911-121509\nClassification: OPEN - Law Enforcement / DFIR use\nSources: CISA KEV Catalog, OpenPhish",
  "object_marking_refs": [
    "marking-definition--00000000-0000-0000-0000-000000000002"
  ],
  "objects": {
    "identity--00000000-0000-0000-0000-000000000001": {
      "type": "identity",
      "name": "Cyber Daily Brief",
      "identity_class": "organization"
    },
    "marking-definition--00000000-0000-0000-0000-000000000002": {
      "type": "marking-definition",
      "definition_type": "statement",
      "definition": {
        "statement": "OPEN - Law Enforcement / DFIR use"
      }
    },
    "indicator--00000000-00000001-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000001-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "CVE-2026-86060",
      "description": "MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-86060']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "RouterOS (MikroTik)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-10",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000002-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000002-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "CVE-2026-67277",
      "description": "MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-67277']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "RouterOS (MikroTik)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-10",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000003-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000003-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "CVE-2026-19490",
      "description": "Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Pr",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-19490']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "NetScaler (Citrix)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-09",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000004-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000004-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "CVE-2025-25249",
      "description": "Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2025-25249']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Multiple Products (Fortinet)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-09",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000005-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000005-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "CVE-2026-87491",
      "description": "Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, includin",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-87491']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Chromium V8 (Google)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-09",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000006-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000006-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "CVE-2026-20079",
      "description": "Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker t",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-20079']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management (Cisco)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-09",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000007-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000007-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "CVE-2026-75650",
      "description": "Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-75650']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Commerce and Magento (Adobe)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-08",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000008-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000008-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "CVE-2026-81963",
      "description": "Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-81963']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Windows (Microsoft)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-08",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000009-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000009-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "CVE-2026-86218",
      "description": "N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-86218']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "N-central (N-able)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-08",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000010-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000010-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "CVE-2026-85880",
      "description": "Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-85880']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Windows (Microsoft)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-08",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000011-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000011-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "https://suport-coinsquare.zapier.app/portal",
      "description": "Active phishing URL: https://suport-coinsquare.zapier.app/portal",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://suport-coinsquare.zapier.app/portal']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://suport-coinsquare.zapier.app/portal",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000012-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000012-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "https://view-coisquared.zapier.app/started",
      "description": "Active phishing URL: https://view-coisquared.zapier.app/started",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://view-coisquared.zapier.app/started']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://view-coisquared.zapier.app/started",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000013-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000013-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "http://protecpackonlinedocument-ymafg.ondigitalocean.app/",
      "description": "Active phishing URL: http://protecpackonlinedocument-ymafg.ondigitalocean.app/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'http://protecpackonlinedocument-ymafg.ondigitalocean.app/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://protecpackonlinedocument-ymafg.ondigitalocean.app/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000014-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000014-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "https://view-coisquared.zapier.app/",
      "description": "Active phishing URL: https://view-coisquared.zapier.app/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://view-coisquared.zapier.app/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://view-coisquared.zapier.app/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000015-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000015-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "https://tavzavo-kxt-qelmora-r9t1hk63.pages.dev/home.html",
      "description": "Active phishing URL: https://tavzavo-kxt-qelmora-r9t1hk63.pages.dev/home.html",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://tavzavo-kxt-qelmora-r9t1hk63.pages.dev/home.html']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://tavzavo-kxt-qelmora-r9t1hk63.pages.dev/home.html",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000016-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000016-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "https://df0-3.gitbook.io/vf/",
      "description": "Active phishing URL: https://df0-3.gitbook.io/vf/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://df0-3.gitbook.io/vf/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://df0-3.gitbook.io/vf/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000017-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000017-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "https://kucoins-signin.com/",
      "description": "Active phishing URL: https://kucoins-signin.com/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://kucoins-signin.com/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://kucoins-signin.com/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000018-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000018-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "https://sessionhttps-counter-offer-a273728932h-sso-singlesso.fallbacksso.help/",
      "description": "Active phishing URL: https://sessionhttps-counter-offer-a273728932h-sso-singlesso.fallbacksso.help/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://sessionhttps-counter-offer-a273728932h-sso-singlesso.fallbacksso.help/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://sessionhttps-counter-offer-a273728932h-sso-singlesso.fallbacksso.help/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000019-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000019-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "https://bringjp37.icu/JeremyTemple",
      "description": "Active phishing URL: https://bringjp37.icu/JeremyTemple",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://bringjp37.icu/JeremyTemple']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://bringjp37.icu/JeremyTemple",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000020-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000020-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "suport-coinsquare.zapier",
      "description": "Phishing domain: suport-coinsquare.zapier",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'suport-coinsquare.zapier']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://suport-coinsquare.zapier.app/portal",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000021-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000021-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "view-coisquared.zapier",
      "description": "Phishing domain: view-coisquared.zapier",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'view-coisquared.zapier']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://view-coisquared.zapier.app/started",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000022-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000022-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "protecpackonlinedocument-ymafg.ondigitalocean",
      "description": "Phishing domain: protecpackonlinedocument-ymafg.ondigitalocean",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'protecpackonlinedocument-ymafg.ondigitalocean']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://protecpackonlinedocument-ymafg.ondigitalocean.app/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000023-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000023-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "tavzavo-kxt-qelmora-r9t1hk63.pages",
      "description": "Phishing domain: tavzavo-kxt-qelmora-r9t1hk63.pages",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'tavzavo-kxt-qelmora-r9t1hk63.pages']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://tavzavo-kxt-qelmora-r9t1hk63.pages.dev/home.html",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000024-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000024-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "df0-3.gitbook",
      "description": "Phishing domain: df0-3.gitbook",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'df0-3.gitbook']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://df0-3.gitbook.io/vf/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000025-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000025-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "kucoins-signin.com",
      "description": "Phishing domain: kucoins-signin.com",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'kucoins-signin.com']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://kucoins-signin.com/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000026-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000026-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "sessionhttps-counter-offer-a273728932h-sso-singlesso.fallbacksso",
      "description": "Phishing domain: sessionhttps-counter-offer-a273728932h-sso-singlesso.fallbacksso",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'sessionhttps-counter-offer-a273728932h-sso-singlesso.fallbacksso']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://sessionhttps-counter-offer-a273728932h-sso-singlesso.fallbacksso.help/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000027-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000027-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "bringjp37.icu",
      "description": "Phishing domain: bringjp37.icu",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bringjp37.icu']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://bringjp37.icu/JeremyTemple",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000028-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000028-0000-0000-0000-000000000000",
      "created": "2026-09-11T12:15:09.896798Z",
      "modified": "2026-09-11T12:15:09.896798Z",
      "name": "sp26ct-teski-biz-pelun-varka.pages",
      "description": "Phishing domain: sp26ct-teski-biz-pelun-varka.pages",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'sp26ct-teski-biz-pelun-varka.pages']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-11T12:15:09.896798Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://sp26ct-teski-biz-pelun-varka.pages.dev/",
        "date": "",
        "original_section": "DOMAIN"
      }
    }
  }
}