
{
  "type": "report",
  "id": "report--00000000-0000-0000-0000-000000000000",
  "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
  "created": "2026-09-28T12:15:46.123372Z",
  "modified": "2026-09-28T12:15:46.123372Z",
  "name": "Cyber Daily Brief IOC Report - 2026-09-28 12:15 UTC",
  "description": "Indicators of Compromise extracted from daily cyber briefing.\nReport ID: IOC-20260928-121546\nClassification: OPEN - Law Enforcement / DFIR use\nSources: CISA KEV Catalog, OpenPhish",
  "object_marking_refs": [
    "marking-definition--00000000-0000-0000-0000-000000000002"
  ],
  "objects": {
    "identity--00000000-0000-0000-0000-000000000001": {
      "type": "identity",
      "name": "Cyber Daily Brief",
      "identity_class": "organization"
    },
    "marking-definition--00000000-0000-0000-0000-000000000002": {
      "type": "marking-definition",
      "definition_type": "statement",
      "definition": {
        "statement": "OPEN - Law Enforcement / DFIR use"
      }
    },
    "indicator--00000000-00000001-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000001-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "CVE-2026-88772",
      "description": "Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-88772']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "NetScaler (Citrix)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-27",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000002-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000002-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "CVE-2026-88771",
      "description": "Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-88771']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "NetScaler (Citrix)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-27",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000003-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000003-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "CVE-2026-67279",
      "description": "Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploi",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-67279']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "RouterOS (MikroTik)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-25",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000004-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000004-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "CVE-2026-65660",
      "description": "Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-65660']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "SharePoint (Microsoft)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-25",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000005-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000005-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "CVE-2026-87902",
      "description": "WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code exec",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-87902']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Core (WordPress)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-25",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000006-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000006-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "CVE-2026-5430",
      "description": "WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-5430']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Multiple Products (WSO2)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-24",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000007-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000007-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "CVE-2026-71362",
      "description": "Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-71362']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Commerce and Magento  (Adobe)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-24",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000008-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000008-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "CVE-2026-93952",
      "description": "Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confident",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-93952']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "VeloCloud Orchestrator (Arista)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-22",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000009-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000009-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "CVE-2026-94127",
      "description": "F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-94127']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "BIG-IP APM (F5)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-22",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000010-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000010-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "CVE-2026-93616",
      "description": "Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary script",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-93616']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Multiple Products (Check Point)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-22",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000011-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000011-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "http://ledger-com-strts.pages.dev/",
      "description": "Active phishing URL: http://ledger-com-strts.pages.dev/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'http://ledger-com-strts.pages.dev/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://ledger-com-strts.pages.dev/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000012-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000012-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "https://filmistanstudios.com/fonts/purchase.html?e=valos@2c5a11bb81b5b1c04d53c01f56c510b84c79.net",
      "description": "Active phishing URL: https://filmistanstudios.com/fonts/purchase.html?e=valos@2c5a11bb81b5b1c04d53c01f56c510b84c79.net",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[email-addr:value = 'https://filmistanstudios.com/fonts/purchase.html?e=valos@2c5a11bb81b5b1c04d53c01f56c510b84c79.net']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "email-addr",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://filmistanstudios.com/fonts/purchase.html?e=valos@2c5a11bb81b5b1c04d53c01f56c510b84c79.net",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000013-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000013-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "http://square-nddax-en-us.square.site/",
      "description": "Active phishing URL: http://square-nddax-en-us.square.site/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'http://square-nddax-en-us.square.site/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://square-nddax-en-us.square.site/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000014-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000014-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "http://bet-facebook.blogspot.com/?m=1",
      "description": "Active phishing URL: http://bet-facebook.blogspot.com/?m=1",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'http://bet-facebook.blogspot.com/?m=1']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://bet-facebook.blogspot.com/?m=1",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000015-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000015-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "http://www.bet-facebook.blogspot.com/?m=1",
      "description": "Active phishing URL: http://www.bet-facebook.blogspot.com/?m=1",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'http://www.bet-facebook.blogspot.com/?m=1']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://www.bet-facebook.blogspot.com/?m=1",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000016-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000016-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "http://rmaconsultoria.net/",
      "description": "Active phishing URL: http://rmaconsultoria.net/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'http://rmaconsultoria.net/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://rmaconsultoria.net/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000017-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000017-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "http://auth-bitbuys-webb.webflow.io/",
      "description": "Active phishing URL: http://auth-bitbuys-webb.webflow.io/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'http://auth-bitbuys-webb.webflow.io/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://auth-bitbuys-webb.webflow.io/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000018-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000018-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "http://g00gle-mobile-verif.com/",
      "description": "Active phishing URL: http://g00gle-mobile-verif.com/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'http://g00gle-mobile-verif.com/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://g00gle-mobile-verif.com/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000019-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000019-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "http://aapsuite.pages.dev/",
      "description": "Active phishing URL: http://aapsuite.pages.dev/",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'http://aapsuite.pages.dev/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://aapsuite.pages.dev/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000020-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000020-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "ledger-com-strts.pages",
      "description": "Phishing domain: ledger-com-strts.pages",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ledger-com-strts.pages']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://ledger-com-strts.pages.dev/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000021-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000021-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "filmistanstudios.com",
      "description": "Phishing domain: filmistanstudios.com",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'filmistanstudios.com']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://filmistanstudios.com/fonts/purchase.html?e=valos@2c5a11bb81b5b1c04d53c01f56c510b84c79.net",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000022-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000022-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "square-nddax-en-us.square",
      "description": "Phishing domain: square-nddax-en-us.square",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'square-nddax-en-us.square']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://square-nddax-en-us.square.site/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000023-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000023-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "bet-facebook.blogspot",
      "description": "Phishing domain: bet-facebook.blogspot",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bet-facebook.blogspot']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://bet-facebook.blogspot.com/?m=1",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000024-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000024-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "www.bet",
      "description": "Phishing domain: www.bet",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'www.bet']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://www.bet-facebook.blogspot.com/?m=1",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000025-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000025-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "rmaconsultoria.net",
      "description": "Phishing domain: rmaconsultoria.net",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'rmaconsultoria.net']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://rmaconsultoria.net/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000026-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000026-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "auth-bitbuys-webb.webflow",
      "description": "Phishing domain: auth-bitbuys-webb.webflow",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'auth-bitbuys-webb.webflow']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://auth-bitbuys-webb.webflow.io/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000027-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000027-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "mobile-verif.com",
      "description": "Phishing domain: mobile-verif.com",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mobile-verif.com']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://g00gle-mobile-verif.com/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000028-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000028-0000-0000-0000-000000000000",
      "created": "2026-09-28T12:15:46.123372Z",
      "modified": "2026-09-28T12:15:46.123372Z",
      "name": "aapsuite.pages",
      "description": "Phishing domain: aapsuite.pages",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'aapsuite.pages']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-28T12:15:46.123372Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://aapsuite.pages.dev/",
        "date": "",
        "original_section": "DOMAIN"
      }
    }
  }
}