
{
  "type": "report",
  "id": "report--00000000-0000-0000-0000-000000000000",
  "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
  "created": "2026-10-11T12:15:47.150941Z",
  "modified": "2026-10-11T12:15:47.150941Z",
  "name": "Cyber Daily Brief IOC Report - 2026-10-11 12:15 UTC",
  "description": "Indicators of Compromise extracted from daily cyber briefing.\nReport ID: IOC-20261011-121547\nClassification: OPEN - Law Enforcement / DFIR use\nSources: CISA KEV Catalog, OpenPhish",
  "object_marking_refs": [
    "marking-definition--00000000-0000-0000-0000-000000000002"
  ],
  "objects": {
    "identity--00000000-0000-0000-0000-000000000001": {
      "type": "identity",
      "name": "Cyber Daily Brief",
      "identity_class": "organization"
    },
    "marking-definition--00000000-0000-0000-0000-000000000002": {
      "type": "marking-definition",
      "definition_type": "statement",
      "definition": {
        "statement": "OPEN - Law Enforcement / DFIR use"
      }
    },
    "indicator--00000000-00000001-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000001-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "CVE-2015-5477",
      "description": "ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2015-5477']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "BIND (ISC)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-10-08",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000002-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000002-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "CVE-2016-3081",
      "description": "Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2016-3081']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Struts (Apache)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-10-08",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000003-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000003-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "CVE-2023-22894",
      "description": "Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or en",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2023-22894']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Strapi (Strapi)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-10-08",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000004-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000004-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "CVE-2021-3199",
      "description": "ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2021-3199']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Docs (ONLYOFFICE)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-10-08",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000005-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000005-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "CVE-2015-3306",
      "description": "ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2015-3306']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "ProFTPD (ProFTPD)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-10-08",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000006-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000006-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "CVE-2026-88779",
      "description": "Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-88779']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "NetScaler (Citrix)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-10-04",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000007-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000007-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "CVE-2026-102490",
      "description": "Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-102490']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Zammad (Zammad GmbH)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-10-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000008-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000008-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "CVE-2026-102489",
      "description": "Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-102489']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Zammad (Zammad GmbH)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-10-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000009-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000009-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "CVE-2026-104286",
      "description": "Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-104286']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "FortiMail (Fortinet)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-10-01",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000010-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000010-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "CVE-2026-76504",
      "description": "Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-76504']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Catalyst SD-WAN Manager (Cisco)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-30",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000011-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000011-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "https://clickblitz22.shop/",
      "description": "Active phishing URL: https://clickblitz22.shop/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://clickblitz22.shop/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://clickblitz22.shop/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000012-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000012-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "https://www.roblox.com.mu/users/1558532921/profile",
      "description": "Active phishing URL: https://www.roblox.com.mu/users/1558532921/profile",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://www.roblox.com.mu/users/1558532921/profile']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://www.roblox.com.mu/users/1558532921/profile",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000013-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000013-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "https://mfacebook.com.vn/kfpw6ogvhx9?xNK&Qup",
      "description": "Active phishing URL: https://mfacebook.com.vn/kfpw6ogvhx9?xNK&Qup",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://mfacebook.com.vn/kfpw6ogvhx9?xNK&Qup']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://mfacebook.com.vn/kfpw6ogvhx9?xNK&Qup",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000014-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000014-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "https://rbcode.net/v/271d9243d604619fd8547fbfc3a75f03",
      "description": "Active phishing URL: https://rbcode.net/v/271d9243d604619fd8547fbfc3a75f03",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://rbcode.net/v/271d9243d604619fd8547fbfc3a75f03']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://rbcode.net/v/271d9243d604619fd8547fbfc3a75f03",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000015-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000015-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "https://ledger-live-desktop-app-asc.pages.dev/",
      "description": "Active phishing URL: https://ledger-live-desktop-app-asc.pages.dev/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://ledger-live-desktop-app-asc.pages.dev/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://ledger-live-desktop-app-asc.pages.dev/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000016-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000016-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "https://www.netflixcol.vercel.app/",
      "description": "Active phishing URL: https://www.netflixcol.vercel.app/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://www.netflixcol.vercel.app/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://www.netflixcol.vercel.app/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000017-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000017-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "https://login-metemask-io.pages.dev/",
      "description": "Active phishing URL: https://login-metemask-io.pages.dev/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://login-metemask-io.pages.dev/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://login-metemask-io.pages.dev/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000018-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000018-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "http://it-corp.netlify.app/",
      "description": "Active phishing URL: http://it-corp.netlify.app/",
      "indicator_types": [
        "PHISHING URL",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'http://it-corp.netlify.app/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://it-corp.netlify.app/",
        "date": "",
        "original_section": "PHISHING URL"
      }
    },
    "indicator--00000000-00000019-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000019-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "https://account067.help/",
      "description": "Active phishing URL: https://account067.help/",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'https://account067.help/']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "openphish"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://account067.help/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000020-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000020-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "clickblitz22.shop",
      "description": "Phishing domain: clickblitz22.shop",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'clickblitz22.shop']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://clickblitz22.shop/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000021-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000021-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "www.roblox",
      "description": "Phishing domain: www.roblox",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'www.roblox']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://www.roblox.com.mu/users/1558532921/profile",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000022-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000022-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "mfacebook.com",
      "description": "Phishing domain: mfacebook.com",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mfacebook.com']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://mfacebook.com.vn/kfpw6ogvhx9?xNK&Qup",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000023-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000023-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "rbcode.net",
      "description": "Phishing domain: rbcode.net",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'rbcode.net']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://rbcode.net/v/271d9243d604619fd8547fbfc3a75f03",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000024-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000024-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "ledger-live-desktop-app-asc.pages",
      "description": "Phishing domain: ledger-live-desktop-app-asc.pages",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ledger-live-desktop-app-asc.pages']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://ledger-live-desktop-app-asc.pages.dev/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000025-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000025-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "www.netflixcol",
      "description": "Phishing domain: www.netflixcol",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'www.netflixcol']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://www.netflixcol.vercel.app/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000026-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000026-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "login-metemask-io.pages",
      "description": "Phishing domain: login-metemask-io.pages",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'login-metemask-io.pages']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://login-metemask-io.pages.dev/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000027-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000027-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "it-corp.netlify",
      "description": "Phishing domain: it-corp.netlify",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'it-corp.netlify']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "http://it-corp.netlify.app/",
        "date": "",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000028-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000028-0000-0000-0000-000000000000",
      "created": "2026-10-11T12:15:47.150941Z",
      "modified": "2026-10-11T12:15:47.150941Z",
      "name": "account067.help",
      "description": "Phishing domain: account067.help",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'account067.help']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-10-11T12:15:47.150941Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "domain-name",
        "phishing",
        "openphish",
        "domain"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "OpenPhish",
        "url": "https://account067.help/",
        "date": "",
        "original_section": "DOMAIN"
      }
    }
  }
}