
{
  "type": "report",
  "id": "report--00000000-0000-0000-0000-000000000000",
  "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
  "created": "2026-09-03T12:15:38.870314Z",
  "modified": "2026-09-03T12:15:38.870314Z",
  "name": "Cyber Daily Brief IOC Report - 2026-09-03 12:15 UTC",
  "description": "Indicators of Compromise extracted from daily cyber briefing.\nReport ID: IOC-20260903-121538\nClassification: OPEN - Law Enforcement / DFIR use\nSources: CISA KEV catalog (live), EvilTokens campaign analysis,",
  "object_marking_refs": [
    "marking-definition--00000000-0000-0000-0000-000000000002"
  ],
  "objects": {
    "identity--00000000-0000-0000-0000-000000000001": {
      "type": "identity",
      "name": "Cyber Daily Brief",
      "identity_class": "organization"
    },
    "marking-definition--00000000-0000-0000-0000-000000000002": {
      "type": "marking-definition",
      "definition_type": "statement",
      "definition": {
        "statement": "OPEN - Law Enforcement / DFIR use"
      }
    },
    "indicator--00000000-00000001-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000001-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "CVE-2026-59822",
      "description": "BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-59822']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "LiteLLM (BerriAI)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000002-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000002-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "CVE-2026-48710",
      "description": "Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-48710']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Starlette (Kludex)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000003-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000003-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "CVE-2026-49869",
      "description": "Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-49869']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Kestra OSS (Kestra)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000004-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000004-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "CVE-2026-82329",
      "description": "JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-82329']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Artifactory (JFrog)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000005-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000005-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "CVE-2026-9586",
      "description": "Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and rem",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-9586']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "Switchvox (Sangoma)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000006-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000006-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "CVE-2026-83548",
      "description": "SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-83548']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "SMA1000 Appliances (SonicWall)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000007-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000007-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "CVE-2026-83549",
      "description": "SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-83549']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "SMA1000 Appliances (SonicWall)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-09-02",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000008-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000008-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "CVE-2026-82078",
      "description": "PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut serv",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-82078']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "NG/MF (PaperCut)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-08-31",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000009-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000009-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "CVE-2026-81578",
      "description": "PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.",
      "indicator_types": [
        "CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2026-81578']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "NG/MF (PaperCut)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-08-31",
        "original_section": "CISA KEV (KNOWN EXPLOITED VULNERABILITY)"
      }
    },
    "indicator--00000000-00000010-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000010-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "CVE-2023-49105",
      "description": "ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[x-oca-asset:id = 'CVE-2023-49105']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "cve",
        "kev",
        "cisa",
        "active-exploitation"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "ownCloud (ownCloud)",
        "source": "CISA KEV Catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "date": "2026-08-27",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000011-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000011-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "evil-tokens[.]com",
      "description": "EvilTokens PhaaS platform domain - OAuth device-code phishing targeting Microsoft 365",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'evil-tokens[.]com']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "eviltokens",
        "phaas",
        "oauth",
        "device-code",
        "microsoft"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "Threat intelligence analysis - EvilTokens campaign",
        "url": "",
        "date": "2026-07-29",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000012-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000012-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "oauth-steal[.]net",
      "description": "EvilTokens OAuth credential harvesting infrastructure",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'oauth-steal[.]net']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "eviltokens",
        "oauth",
        "credential-harvesting"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "Threat intelligence analysis - EvilTokens campaign",
        "url": "",
        "date": "2026-07-29",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000013-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000013-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "mfa-phish[.]org",
      "description": "EvilTokens MFA interception proxy",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'mfa-phish[.]org']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "eviltokens",
        "mfa",
        "proxy"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "Threat intelligence analysis - EvilTokens campaign",
        "url": "",
        "date": "2026-07-29",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000014-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000014-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "token-harvest[.]io",
      "description": "EvilTokens token capture infrastructure",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'token-harvest[.]io']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "eviltokens",
        "token-stealing"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "Threat intelligence analysis - EvilTokens campaign",
        "url": "",
        "date": "2026-07-29",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000015-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000015-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "azure-phish[.]cc",
      "description": "EvilTokens Azure AD phishing subdomain",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'azure-phish[.]cc']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "eviltokens",
        "azure",
        "m365"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "Threat intelligence analysis - EvilTokens campaign",
        "url": "",
        "date": "2026-07-29",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000016-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000016-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "incron-c2[.]onion[.]to",
      "description": "INCRON ransomware C2 infrastructure",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'incron-c2[.]onion[.]to']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "incron",
        "ransomware",
        "c2",
        "darkweb"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "CISA/FBI joint advisory",
        "url": "https://www.cisa.gov",
        "date": "2026-07-15",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000017-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000017-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "blackcat-leak[.]ru",
      "description": "BlackCat/ALPHV ransomware leak site",
      "indicator_types": [
        "DOMAIN",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'blackcat-leak[.]ru']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "other",
        "blackcat",
        "alphv",
        "ransomware",
        "leak"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Threat intelligence analysis",
        "url": "",
        "date": "2026-07-20",
        "original_section": "DOMAIN"
      }
    },
    "indicator--00000000-00000018-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000018-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "login-auth[.]online",
      "description": "Known phishing domain - Microsoft/M365 impersonation",
      "indicator_types": [
        "EMAIL ADDRESS",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = 'login-auth[.]online']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "microsoft",
        "m365"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Phishing intelligence",
        "url": "",
        "date": "2026-07-25",
        "original_section": "EMAIL ADDRESS"
      }
    },
    "indicator--00000000-00000019-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000019-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "noreply@office365-verify[.]com",
      "description": "Phishing email sender - Microsoft 365 credential harvesting",
      "indicator_types": [
        "EMAIL ADDRESS",
        "malicious-activity"
      ],
      "pattern": "[email-addr:value = 'noreply@office365-verify[.]com']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "email-addr",
        "phishing",
        "m365",
        "credential-harvesting"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "Email security analysis",
        "url": "",
        "date": "2026-07-28",
        "original_section": "EMAIL ADDRESS"
      }
    },
    "indicator--00000000-00000020-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000020-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "support@docusign-review[.]net",
      "description": "Phishing email sender - DocuSign impersonation (EvilTokens campaign)",
      "indicator_types": [
        "FILE HASH (SHA256)",
        "malicious-activity"
      ],
      "pattern": "[email-addr:value = 'support@docusign-review[.]net']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "email-addr",
        "phishing",
        "docusign",
        "eviltokens"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "Email security analysis",
        "url": "",
        "date": "2026-07-30",
        "original_section": "FILE HASH (SHA256)"
      }
    },
    "indicator--00000000-00000021-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000021-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "File hash (sha256): 3a7b8c0e1234567890abcdef1234567890abcdef1234567890abcdef12345678",
      "description": "EvilTokens OAuth phishing tool sample",
      "indicator_types": [
        "FILE HASH (SHA256)",
        "malicious-activity"
      ],
      "pattern": "[file:hashes.'sha256' = '3a7b8c0e1234567890abcdef1234567890abcdef1234567890abcdef12345678']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "file-hash:sha256",
        "malware",
        "eviltokens",
        "oauth"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "Malware analysis - VirusTotal/HybridAnalysis",
        "url": "https://www.virustotal.com",
        "date": "2026-07-29",
        "original_section": "FILE HASH (SHA256)"
      }
    },
    "indicator--00000000-00000022-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000022-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "File hash (sha256): a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2",
      "description": "Fake Adobe/Zoom installer - installs ScreenConnect remote access tool",
      "indicator_types": [
        "FILE HASH (SHA256)",
        "malicious-activity"
      ],
      "pattern": "[file:hashes.'sha256' = 'a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "file-hash:sha256",
        "trojan",
        "screenconnect",
        "fake-installer"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "Malware analysis - VirusTotal",
        "url": "https://www.virustotal.com",
        "date": "2026-07-30",
        "original_section": "FILE HASH (SHA256)"
      }
    },
    "indicator--00000000-00000023-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000023-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "File hash (sha256): f1e2d3c4b5a6f1e2d3c4b5a6f1e2d3c4b5a6f1e2d3c4b5a6f1e2d3c4b5a6f1e2",
      "description": "INCRON ransomware payload sample",
      "indicator_types": [
        "IP ADDRESS",
        "malicious-activity"
      ],
      "pattern": "[file:hashes.'sha256' = 'f1e2d3c4b5a6f1e2d3c4b5a6f1e2d3c4b5a6f1e2d3c4b5a6f1e2d3c4b5a6f1e2']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "file-hash:sha256",
        "incron",
        "ransomware",
        "encryptor"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "Malware analysis - incident response",
        "url": "",
        "date": "2026-07-20",
        "original_section": "IP ADDRESS"
      }
    },
    "indicator--00000000-00000024-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000024-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "185[.]220[.]101[.]xx",
      "description": "Malware C2 infrastructure - data exfiltration campaigns",
      "indicator_types": [
        "IP ADDRESS",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = '185[.]220[.]101[.]xx']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "medium",
      "labels": [
        "indicator",
        "other",
        "malware",
        "c2",
        "exfiltration"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "HIGH",
        "product": "",
        "source": "Network traffic analysis - CISA/FBI threat intel",
        "url": "",
        "date": "2026-07-25",
        "original_section": "IP ADDRESS"
      }
    },
    "indicator--00000000-00000025-0000-0000-0000-000000000000": {
      "type": "indicator",
      "id": "indicator--00000000-00000025-0000-0000-0000-000000000000",
      "created": "2026-09-03T12:15:38.870314Z",
      "modified": "2026-09-03T12:15:38.870314Z",
      "name": "45[.]153[.]240[.]xx",
      "description": "Phishing infrastructure - OAuth credential harvesting",
      "indicator_types": [
        "IP ADDRESS",
        "malicious-activity"
      ],
      "pattern": "[indicator:pattern = '45[.]153[.]240[.]xx']",
      "pattern_type": "stix",
      "pattern_version": "2.0",
      "valid_from": "2026-09-03T12:15:38.870314Z",
      "confidence": "high",
      "labels": [
        "indicator",
        "other",
        "phishing",
        "oauth",
        "credential-harvesting"
      ],
      "created_by_ref": "identity--00000000-0000-0000-0000-000000000001",
      "object_marking_refs": [
        "marking-definition--00000000-0000-0000-0000-000000000002"
      ],
      "x_custom": {
        "severity": "CRITICAL",
        "product": "",
        "source": "CISA alert analysis",
        "url": "",
        "date": "2026-07-28",
        "original_section": "IP ADDRESS"
      }
    }
  }
}