
{
  "type": "report",
  "id": "report--00000000-0000-0000-0000-000000000000",
  "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
  "created": "2026-09-16T15:40:39.879852Z",
  "modified": "2026-09-16T15:40:39.879852Z",
  "name": "Cyber Daily Brief IOC Report - 2026-09-16 15:40 UTC",
  "description": "Indicators of Compromise extracted from daily cyber briefing.\nReport ID: IOC-20260916-154039\nClassification: OPEN - Law Enforcement / DFIR use\nSources: CISA KEV Catalog, OpenPhish",
  "object_marking_refs": [
    "marking-definition--00000000-0000-0000-0000-000000000002"
  ],
  "objects": {
    "identity--00000000-0000-0000-0000-000000000001": {
      "type": "identity",
      "name": "Cyber Daily Brief",
      "identity_class": "organization"
    },
    "marking-definition--00000000-0000-0000-0000-000000000002": {
      "type": "marking-definition",
      "definition_type": "statement",
      "definition": {
        "statement": "OPEN - Law Enforcement / DFIR use"
      }
    },
    "indicator--00000000-00000001-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000001-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "CVE-2026-58704",
      "description": "Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-58704']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Pixel (Google)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-16",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000002-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000002-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "CVE-2026-76461",
      "description": "Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-76461']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Secure Email Gateway (Cisco)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-14",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000003-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000003-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "CVE-2026-84869",
      "description": "ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-84869']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "ScreenConnect (ConnectWise)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-11",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000004-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000004-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "CVE-2026-42016",
      "description": "JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token\u2019s scope.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-42016']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Artifactory (JFrog)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-11",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000005-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000005-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "CVE-2026-42018",
      "description": "JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-42018']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Artifactory (JFrog)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-11",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000006-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000006-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "CVE-2026-85706",
      "description": "GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits A",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-85706']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Community Edition and Enterprise Edition (GitLab)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-11",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000007-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000007-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "CVE-2026-86060",
      "description": "MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacker to change the trusted RouterOS policy mask, leading to privilege escalation.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-86060']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "RouterOS (MikroTik)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-10",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000008-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000008-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "CVE-2026-67277",
      "description": "MikroTik RouterOS contains a missing authentication for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-67277']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "RouterOS (MikroTik)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-10",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000009-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000009-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "CVE-2026-19490",
      "description": "Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Pr",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-19490']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "NetScaler (Citrix)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-09",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000010-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000010-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "CVE-2025-25249",
      "description": "Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2025-25249']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Multiple Products (Fortinet)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-09",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000011-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000011-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "https://schtrekh.de/img/",
      "description": "Active phishing URL: https://schtrekh.de/img/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://schtrekh.de/img/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://schtrekh.de/img/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000012-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000012-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "https://farren.webdesignla.info/ga/click/2-115159033-1585-17249-33739-18616-2212d2c02a-1b10dc49b9",
      "description": "Active phishing URL: https://farren.webdesignla.info/ga/click/2-115159033-1585-17249-33739-18616-2212d2c02a-1b10dc49b9",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://farren.webdesignla.info/ga/click/2-115159033-1585-17249-33739-18616-2212d2c02a-1b10dc49b9']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://farren.webdesignla.info/ga/click/2-115159033-1585-17249-33739-18616-2212d2c02a-1b10dc49b9",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000013-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000013-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "https://brayden-15.pages.dev/",
      "description": "Active phishing URL: https://brayden-15.pages.dev/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://brayden-15.pages.dev/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://brayden-15.pages.dev/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000014-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000014-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "https://ch-pak-informations.bolt.host/",
      "description": "Active phishing URL: https://ch-pak-informations.bolt.host/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://ch-pak-informations.bolt.host/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://ch-pak-informations.bolt.host/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000015-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000015-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "https://jdbdkdbsosu.blogspot.com/?m=1",
      "description": "Active phishing URL: https://jdbdkdbsosu.blogspot.com/?m=1",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://jdbdkdbsosu.blogspot.com/?m=1']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://jdbdkdbsosu.blogspot.com/?m=1",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000016-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000016-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "http://www.adsbot2-eauj.vercel.app/",
      "description": "Active phishing URL: http://www.adsbot2-eauj.vercel.app/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'http://www.adsbot2-eauj.vercel.app/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://www.adsbot2-eauj.vercel.app/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000017-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000017-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "https://proxy-test-001.pages.dev/mac-mini-2023-service-program-for-no-power-issu",
      "description": "Active phishing URL: https://proxy-test-001.pages.dev/mac-mini-2023-service-program-for-no-power-issu",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://proxy-test-001.pages.dev/mac-mini-2023-service-program-for-no-power-issu']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://proxy-test-001.pages.dev/mac-mini-2023-service-program-for-no-power-issu",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000018-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000018-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "http://ei1i7-qqt-v6l4-2qu9k-08-09-2026-hh.pages.dev/",
      "description": "Active phishing URL: http://ei1i7-qqt-v6l4-2qu9k-08-09-2026-hh.pages.dev/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'http://ei1i7-qqt-v6l4-2qu9k-08-09-2026-hh.pages.dev/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://ei1i7-qqt-v6l4-2qu9k-08-09-2026-hh.pages.dev/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000019-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000019-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "http://coinbse-extesnsion.framer.website/",
      "description": "Active phishing URL: http://coinbse-extesnsion.framer.website/",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'http://coinbse-extesnsion.framer.website/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://coinbse-extesnsion.framer.website/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000020-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000020-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "schtrekh.de",
      "description": "Phishing domain: schtrekh.de",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'schtrekh.de']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://schtrekh.de/img/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000021-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000021-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "farren.webdesignla",
      "description": "Phishing domain: farren.webdesignla",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'farren.webdesignla']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://farren.webdesignla.info/ga/click/2-115159033-1585-17249-33739-18616-2212d2c02a-1b10dc49b9",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000022-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000022-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "brayden-15.pages",
      "description": "Phishing domain: brayden-15.pages",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'brayden-15.pages']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://brayden-15.pages.dev/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000023-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000023-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "ch-pak-informations.bolt",
      "description": "Phishing domain: ch-pak-informations.bolt",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ch-pak-informations.bolt']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://ch-pak-informations.bolt.host/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000024-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000024-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "jdbdkdbsosu.blogspot",
      "description": "Phishing domain: jdbdkdbsosu.blogspot",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'jdbdkdbsosu.blogspot']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://jdbdkdbsosu.blogspot.com/?m=1",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000025-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000025-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "adsbot2-eauj.vercel",
      "description": "Phishing domain: adsbot2-eauj.vercel",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'adsbot2-eauj.vercel']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://www.adsbot2-eauj.vercel.app/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000026-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000026-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "proxy-test-001.pages",
      "description": "Phishing domain: proxy-test-001.pages",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'proxy-test-001.pages']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://proxy-test-001.pages.dev/mac-mini-2023-service-program-for-no-power-issu",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000027-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000027-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "ei1i7-qqt-v6l4-2qu9k-08-09-2026-hh.pages",
      "description": "Phishing domain: ei1i7-qqt-v6l4-2qu9k-08-09-2026-hh.pages",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ei1i7-qqt-v6l4-2qu9k-08-09-2026-hh.pages']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://ei1i7-qqt-v6l4-2qu9k-08-09-2026-hh.pages.dev/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000028-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000028-0000-0000-0000-000000000000",
      "created": "2026-09-16T15:40:39.879852Z",
      "modified": "2026-09-16T15:40:39.879852Z",
      "name": "coinbse-extesnsion.framer",
      "description": "Phishing domain: coinbse-extesnsion.framer",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'coinbse-extesnsion.framer']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-16T15:40:39.879852Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://coinbse-extesnsion.framer.website/",
        "date": "",
        "original_section": "DOMAIN"
      }
    }
  }
}