{
  "type": "bundle",
  "id": "bundle--52a6e312-10c4-4ffb-bdcd-4062c6e49fe0",
  "objects": [
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--880920d0-83c0-4232-b4a3-8586832d9eda",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-48022",
      "pattern": "[vulnerability:name = 'CVE-2023-48022']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7d732467-9909-4ef4-b9bf-44e4c832613a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-62593",
      "pattern": "[vulnerability:name = 'CVE-2025-62593']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        },
        {
          "source_name": "CISA KEV: CVE-2025-62593 \u2014 Ray-Project Ray Code Injection Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f81d316-2097-429f-96da-6214bf2884e7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: bwqqvqfgsseplyoltois92rdukv0mm5th.oast.fun",
      "pattern": "[domain-name:value = 'bwqqvqfgsseplyoltois92rdukv0mm5th.oast.fun']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2932380d-18a2-412d-b2ec-80454bf07014",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: eu.zano.k1pool.com",
      "pattern": "[domain-name:value = 'eu.zano.k1pool.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b67f0acc-5581-4ea9-a8cf-dd159dd2c61b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: gulf.moneroocean.stream",
      "pattern": "[domain-name:value = 'gulf.moneroocean.stream']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        },
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2bbca0c2-e8cb-4d17-96c8-4f0ac82b4c0e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: pool.supportxmr.com",
      "pattern": "[domain-name:value = 'pool.supportxmr.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--43fd75e2-2d39-46da-a990-ebff2b124c36",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.127.134.124",
      "pattern": "[ipv4-addr:value = '103.127.134.124']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b85ba7aa-44c8-4423-ba01-e5c249f0b0ed",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.194.151.181",
      "pattern": "[ipv4-addr:value = '104.194.151.181']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--514fd4b2-34a6-4ef5-9fd9-d8e63aa39219",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 121.160.102.68",
      "pattern": "[ipv4-addr:value = '121.160.102.68']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c9848598-aadb-4aed-b9a1-d8e1017ab8ff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 158.160.123.117",
      "pattern": "[ipv4-addr:value = '158.160.123.117']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4bef04f5-4a9e-45e6-9281-210e6bd40507",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 162.248.53.119",
      "pattern": "[ipv4-addr:value = '162.248.53.119']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--49ca1fee-0b0d-4eea-9ab0-4d623d8808d8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 18.228.3.224",
      "pattern": "[ipv4-addr:value = '18.228.3.224']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6bbd590-571d-4801-841a-2b6bee5325db",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 18.230.118.147",
      "pattern": "[ipv4-addr:value = '18.230.118.147']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--41adec83-ff98-4e8e-83f4-f5ef6a25111c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.215.180.70",
      "pattern": "[ipv4-addr:value = '185.215.180.70']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cf280a85-5d42-48c3-a695-002020c0b0b1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.29.224.83",
      "pattern": "[ipv4-addr:value = '193.29.224.83']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e4b88962-4e23-470d-a366-f322af4868a3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.61.150.83",
      "pattern": "[ipv4-addr:value = '45.61.150.83']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7555bff5-60fb-41ee-8a0c-8f7456db186d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.95.168.100",
      "pattern": "[ipv4-addr:value = '45.95.168.100']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d40a711-a9dc-4f3c-aa69-3567e9968acb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 54.154.170.233",
      "pattern": "[ipv4-addr:value = '54.154.170.233']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2e0d94df-bdbd-407b-a35e-592ac8864e59",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 67.217.57.240",
      "pattern": "[ipv4-addr:value = '67.217.57.240']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1e03ae2e-ffa9-40bf-bc54-6463b792bf5d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 1f63fa7921c2f5fb8f8ffa430d02ac4a",
      "pattern": "[file:hashes.MD5 = '1f63fa7921c2f5fb8f8ffa430d02ac4a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7e411898-3f6d-4e63-b68e-259f13abc777",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 779a8af3b9838a33d1e199da3fc2f02a49e7c13e",
      "pattern": "[file:hashes.'SHA-1' = '779a8af3b9838a33d1e199da3fc2f02a49e7c13e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--83ef1680-26b9-4d60-8470-ec0ae1a8ab7d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1f6c69403678646a60925dcffe8509d22bb570c611324b93bec9aea72024ef6b",
      "pattern": "[file:hashes.'SHA-256' = '1f6c69403678646a60925dcffe8509d22bb570c611324b93bec9aea72024ef6b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6a0fbe5e-419b-4359-bde3-a98768034797",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6f445252494a0908ab51d526e09134cebc33a199384771acd58c4a87f1ffc063",
      "pattern": "[file:hashes.'SHA-256' = '6f445252494a0908ab51d526e09134cebc33a199384771acd58c4a87f1ffc063']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Brow",
          "url": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a7eef30-727c-4c38-b98a-91b382b9daf3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2007-3010",
      "pattern": "[vulnerability:name = 'CVE-2007-3010']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Dev",
          "url": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html"
        },
        {
          "source_name": "New Evooo1Bot Linux botnet turns routers into traffic relay ",
          "url": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/"
        },
        {
          "source_name": "CISA KEV: CVE-2007-3010 \u2014 Alcatel OmniPCX Enterprise Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "BleepingComputer",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fc45aad2-602e-49a9-a72f-695d939075a9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-6277",
      "pattern": "[vulnerability:name = 'CVE-2016-6277']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Dev",
          "url": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html"
        },
        {
          "source_name": "New Evooo1Bot Linux botnet turns routers into traffic relay ",
          "url": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/"
        },
        {
          "source_name": "CISA KEV: CVE-2016-6277 \u2014 NETGEAR Multiple Routers Remote Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "BleepingComputer",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4442e77e-925a-40ee-95bb-803f82a19836",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-14558",
      "pattern": "[vulnerability:name = 'CVE-2018-14558']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Dev",
          "url": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html"
        },
        {
          "source_name": "New Evooo1Bot Linux botnet turns routers into traffic relay ",
          "url": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/"
        },
        {
          "source_name": "CISA KEV: CVE-2018-14558 \u2014 Tenda AC7, AC9, and AC10 Routers ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "BleepingComputer",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c45f57b-fd4e-49d8-8712-1660e10a8590",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-14931",
      "pattern": "[vulnerability:name = 'CVE-2019-14931']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Dev",
          "url": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html"
        },
        {
          "source_name": "New Evooo1Bot Linux botnet turns routers into traffic relay ",
          "url": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "BleepingComputer"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ad0642f-1f37-4383-8fc6-9fd894d36966",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-10987",
      "pattern": "[vulnerability:name = 'CVE-2020-10987']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Dev",
          "url": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html"
        },
        {
          "source_name": "New Evooo1Bot Linux botnet turns routers into traffic relay ",
          "url": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/"
        },
        {
          "source_name": "CISA KEV: CVE-2020-10987 \u2014 Tenda AC1900 Router AC15 Model Re",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "BleepingComputer",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f92d5a25-092a-4127-8428-972d3e3a7696",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-36260",
      "pattern": "[vulnerability:name = 'CVE-2021-36260']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Dev",
          "url": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html"
        },
        {
          "source_name": "New Evooo1Bot Linux botnet turns routers into traffic relay ",
          "url": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/"
        },
        {
          "source_name": "CISA KEV: CVE-2020-25078 \u2014 D-Link DCS-2530L and DCS-2670L De",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "BleepingComputer",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fc76164b-4d96-47db-87a1-7f7d0b2a9b08",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-46422",
      "pattern": "[vulnerability:name = 'CVE-2021-46422']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Dev",
          "url": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html"
        },
        {
          "source_name": "New Evooo1Bot Linux botnet turns routers into traffic relay ",
          "url": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "BleepingComputer"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--556089e5-d389-4fd9-8fcf-f613006aa2cf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-20210",
      "pattern": "[vulnerability:name = 'CVE-2022-20210']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Ful",
          "url": "https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53351941-15d0-4030-8461-88b3926fac54",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-26134",
      "pattern": "[vulnerability:name = 'CVE-2022-26134']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Dev",
          "url": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html"
        },
        {
          "source_name": "New Evooo1Bot Linux botnet turns routers into traffic relay ",
          "url": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/"
        },
        {
          "source_name": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "BleepingComputer",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--328bfd78-a791-428d-b98c-d4d0f3f973c9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-29464",
      "pattern": "[vulnerability:name = 'CVE-2022-29464']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Dev",
          "url": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html"
        },
        {
          "source_name": "New Evooo1Bot Linux botnet turns routers into traffic relay ",
          "url": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/"
        },
        {
          "source_name": "CISA KEV: CVE-2022-29464 \u2014 WSO2 Multiple Products Unrestrict",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "BleepingComputer",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1a05eb5b-88b7-44c7-91a3-810f3c74db74",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-30525",
      "pattern": "[vulnerability:name = 'CVE-2022-30525']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Dev",
          "url": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html"
        },
        {
          "source_name": "New Evooo1Bot Linux botnet turns routers into traffic relay ",
          "url": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/"
        },
        {
          "source_name": "CISA KEV: CVE-2022-30525 \u2014 Zyxel Multiple Firewalls OS Comma",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "BleepingComputer",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e1465409-50c2-4ad6-ab78-168cb6e1474c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-37055",
      "pattern": "[vulnerability:name = 'CVE-2022-37055']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Dev",
          "url": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html"
        },
        {
          "source_name": "New Evooo1Bot Linux botnet turns routers into traffic relay ",
          "url": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/"
        },
        {
          "source_name": "CISA KEV: CVE-2022-37055 \u2014 D-Link Routers Buffer Overflow Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "BleepingComputer",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8e69ebcd-5f48-4757-8f0a-862f823491f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-1389",
      "pattern": "[vulnerability:name = 'CVE-2023-1389']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Dev",
          "url": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html"
        },
        {
          "source_name": "New Evooo1Bot Linux botnet turns routers into traffic relay ",
          "url": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/"
        },
        {
          "source_name": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "BleepingComputer",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--73ea8164-5bca-4d0b-827e-6baaa59000c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-34362",
      "pattern": "[vulnerability:name = 'CVE-2023-34362']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Dev",
          "url": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html"
        },
        {
          "source_name": "CISA KEV: CVE-2023-34362 \u2014 Progress MOVEit Transfer SQL Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--09e0e7f0-dbac-4a92-ae31-f6dc17a687ca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-10914",
      "pattern": "[vulnerability:name = 'CVE-2024-10914']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Dev",
          "url": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html"
        },
        {
          "source_name": "New Evooo1Bot Linux botnet turns routers into traffic relay ",
          "url": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "BleepingComputer"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--16a915cd-ddd4-4229-a885-8bd7651f77cf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-29269",
      "pattern": "[vulnerability:name = 'CVE-2024-29269']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Dev",
          "url": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html"
        },
        {
          "source_name": "New Evooo1Bot Linux botnet turns routers into traffic relay ",
          "url": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "BleepingComputer"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ddc621fa-524e-4ead-8812-b153232623d4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-4577",
      "pattern": "[vulnerability:name = 'CVE-2024-4577']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Dev",
          "url": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html"
        },
        {
          "source_name": "New Evooo1Bot Linux botnet turns routers into traffic relay ",
          "url": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/"
        },
        {
          "source_name": "CISA KEV: CVE-2024-4577 \u2014 PHP-CGI OS Command Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "BleepingComputer",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7819ffa6-1171-496b-b254-99b84549e012",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-10123",
      "pattern": "[vulnerability:name = 'CVE-2025-10123']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Dev",
          "url": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html"
        },
        {
          "source_name": "New Evooo1Bot Linux botnet turns routers into traffic relay ",
          "url": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "BleepingComputer"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--62959191-a0b2-4125-b27a-0d3733aa9fb0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-1974",
      "pattern": "[vulnerability:name = 'CVE-2025-1974']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Dev",
          "url": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html"
        },
        {
          "source_name": "New Evooo1Bot Linux botnet turns routers into traffic relay ",
          "url": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "BleepingComputer"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--72101e22-ba51-438d-9409-f88a64d067f7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-31718",
      "pattern": "[vulnerability:name = 'CVE-2025-31718']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Ful",
          "url": "https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0d1fd810-536d-47a2-bcc2-3e3e22defc91",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-55583",
      "pattern": "[vulnerability:name = 'CVE-2025-55583']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Dev",
          "url": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html"
        },
        {
          "source_name": "New Evooo1Bot Linux botnet turns routers into traffic relay ",
          "url": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "BleepingComputer"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--645e7d98-eef0-4bd8-ac22-3838b5cc2a60",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-12569",
      "pattern": "[vulnerability:name = 'CVE-2026-12569']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Philips and GE investigating Clop ransomware data theft clai",
          "url": "https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/"
        },
        {
          "source_name": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "BleepingComputer",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1ec37d91-ea86-4c7b-9f1f-8a4735d720f2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-19478",
      "pattern": "[vulnerability:name = 'CVE-2026-19478']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Critical GitLab GraphQL Flaw Could Let Unauthenticated Attac",
          "url": "https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3c91e172-b246-4513-91b2-b185506dbb49",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-19650",
      "pattern": "[vulnerability:name = 'CVE-2026-19650']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Critical GitLab GraphQL Flaw Could Let Unauthenticated Attac",
          "url": "https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c901e371-5a58-43b6-8a49-f8747dc18df4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-47686",
      "pattern": "[vulnerability:name = 'CVE-2026-47686']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-47686: VM2 has Missing Error.caus",
          "url": "https://github.com/advisories/GHSA-m283-3h24-438v"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fb8022bd-5e80-49de-8442-fb628647a0cc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-47698",
      "pattern": "[vulnerability:name = 'CVE-2026-47698']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-47698: vm2: Sandbox Breakout Usin",
          "url": "https://github.com/advisories/GHSA-cfcw-xp6x-25gj"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a1c39da1-ca35-4844-bdb6-c4512474a890",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-50656",
      "pattern": "[vulnerability:name = 'CVE-2026-50656']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft working on Defender patch for ShieldBreak zero-day",
          "url": "https://www.bleepingcomputer.com/news/security/microsoft-working-on-defender-patch-for-shieldbreak-zero-day/"
        },
        {
          "source_name": "ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Byp",
          "url": "https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "BleepingComputer",
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67b70b92-86c5-4089-b010-276028909ef7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-55158",
      "pattern": "[vulnerability:name = 'CVE-2026-55158']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-55158: conflibot vulnerable to co",
          "url": "https://github.com/advisories/GHSA-2qvg-qr73-mqxp"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eec5bfdc-f1b0-469d-b39a-300dd9af5532",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-59309",
      "pattern": "[vulnerability:name = 'CVE-2026-59309']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Suspected China-Nexus Actor Exploits VMware vCenter Flaw, De",
          "url": "https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html"
        },
        {
          "source_name": "Attackers Exploit VMware vCenter Vulnerability to Gain Persi",
          "url": "https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fb6148cb-de07-4420-bb05-f74c801ba22a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-59310",
      "pattern": "[vulnerability:name = 'CVE-2026-59310']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Suspected China-Nexus Actor Exploits VMware vCenter Flaw, De",
          "url": "https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html"
        },
        {
          "source_name": "Attackers Exploit VMware vCenter Vulnerability to Gain Persi",
          "url": "https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5ac0f66b-2b1d-4f0a-8f61-6acde4b827be",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-64849",
      "pattern": "[vulnerability:name = 'CVE-2026-64849']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-64849: MLflow: Unauthenticated fu",
          "url": "https://github.com/advisories/GHSA-7gwp-5pfp-969j"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--357e1646-699b-42c7-a1a9-d8db9064a3da",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-64859",
      "pattern": "[vulnerability:name = 'CVE-2026-64859']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-64859: New API: User List API Lea",
          "url": "https://github.com/advisories/GHSA-6x2c-phff-wx57"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4000e73c-cac3-42b9-806f-057f6aad541e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-71479",
      "pattern": "[vulnerability:name = 'CVE-2026-71479']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-71479: New API: Integer overflow ",
          "url": "https://github.com/advisories/GHSA-8r8v-xf7q-rcpr"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c631ccf8-9d80-4d45-9352-3070703f3220",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: intel.se9ly9upbhay.shop",
      "pattern": "[domain-name:value = 'intel.se9ly9upbhay.shop']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Suspected China-Nexus Actor Exploits VMware vCenter Flaw, De",
          "url": "https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--674c1382-cfe0-48a6-be74-3bcefb986cf7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: studiotikva.com",
      "pattern": "[domain-name:value = 'studiotikva.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cavern C2 Uses DNS and Google Apps Script to Blend Into Legi",
          "url": "https://thehackernews.com/2026/08/cavern-c2-uses-dns-and-google-apps.html"
        },
        {
          "source_name": "Project CAV3RN continues: Google Apps Script as C2 relay and",
          "url": "https://securelist.com/project-cav3rn-continues/120991/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--025b9344-9f47-453b-aa7b-53256cf3f16c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.243.35.63",
      "pattern": "[ipv4-addr:value = '104.243.35.63']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Philips and GE investigating Clop ransomware data theft clai",
          "url": "https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/"
        },
        {
          "source_name": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "BleepingComputer",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--991b95e8-8bcd-40e4-8e85-d4eedc87d72e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 146.59.252.178",
      "pattern": "[ipv4-addr:value = '146.59.252.178']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Suspected China-Nexus Actor Exploits VMware vCenter Flaw, De",
          "url": "https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a71e8a21-e3ad-4d9d-b3bc-0016c4e8194b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.144.28.120",
      "pattern": "[ipv4-addr:value = '185.144.28.120']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Suspected China-Nexus Actor Exploits VMware vCenter Flaw, De",
          "url": "https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cba002f8-c457-430b-8abc-731037259703",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.255.141.13",
      "pattern": "[ipv4-addr:value = '192.255.141.13']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Suspected China-Nexus Actor Exploits VMware vCenter Flaw, De",
          "url": "https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--10cf51fc-ff82-4eef-bb03-31b47ac61676",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 216.152.148.54",
      "pattern": "[ipv4-addr:value = '216.152.148.54']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Philips and GE investigating Clop ransomware data theft clai",
          "url": "https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/"
        },
        {
          "source_name": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "BleepingComputer",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--46fa8762-3905-4eb5-9dc7-3c43e24f60b3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 216.152.151.204",
      "pattern": "[ipv4-addr:value = '216.152.151.204']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Philips and GE investigating Clop ransomware data theft clai",
          "url": "https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/"
        },
        {
          "source_name": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "BleepingComputer",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--735d98d9-9018-4c33-a355-d1a02a1f9a40",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.180.41.35",
      "pattern": "[ipv4-addr:value = '5.180.41.35']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Philips and GE investigating Clop ransomware data theft clai",
          "url": "https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/"
        },
        {
          "source_name": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "BleepingComputer",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f5c2773-3e29-4a28-a664-a5a9a874d5b2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.34.176.100",
      "pattern": "[ipv4-addr:value = '5.34.176.100']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Suspected China-Nexus Actor Exploits VMware vCenter Flaw, De",
          "url": "https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8bd37b84-965d-41da-a276-bcd179d3a149",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.34.177.38",
      "pattern": "[ipv4-addr:value = '5.34.177.38']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Suspected China-Nexus Actor Exploits VMware vCenter Flaw, De",
          "url": "https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3361ce46-e3b5-475f-af44-207d00a7ade7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 91.92.40.118",
      "pattern": "[ipv4-addr:value = '91.92.40.118']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Dev",
          "url": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html"
        },
        {
          "source_name": "New Evooo1Bot Linux botnet turns routers into traffic relay ",
          "url": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "BleepingComputer"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c89dc78-79c4-4d99-a32e-ea0fd0d5b237",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4c0886349e9d348569fffe1b7a31e474d514508bf0cd6f1e5dd99c2a73525e4d",
      "pattern": "[file:hashes.'SHA-256' = '4c0886349e9d348569fffe1b7a31e474d514508bf0cd6f1e5dd99c2a73525e4d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Dev",
          "url": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html"
        },
        {
          "source_name": "New Evooo1Bot Linux botnet turns routers into traffic relay ",
          "url": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "BleepingComputer"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--261d2493-d1d6-4756-85ab-be235ffa3263",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 55a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c",
      "pattern": "[file:hashes.'SHA-256' = '55a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Philips and GE investigating Clop ransomware data theft clai",
          "url": "https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/"
        },
        {
          "source_name": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "BleepingComputer",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--88b9d453-7eca-4f1d-969d-72141491bdb9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f13cb360768363d3424e2192c7805b8c8015eb8706dbbbcdead6aed8cf390109",
      "pattern": "[file:hashes.'SHA-256' = 'f13cb360768363d3424e2192c7805b8c8015eb8706dbbbcdead6aed8cf390109']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Dev",
          "url": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html"
        },
        {
          "source_name": "New Evooo1Bot Linux botnet turns routers into traffic relay ",
          "url": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "BleepingComputer"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8de2d596-06d0-4581-902a-2beff5de4525",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-54121",
      "pattern": "[vulnerability:name = 'CVE-2026-54121']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Certighost and the Privilege Hiding in Your Certificate Auth",
          "url": "https://www.bleepingcomputer.com/news/security/certighost-and-the-privilege-hiding-in-your-certificate-authority/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "BleepingComputer"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5957594d-9a4b-41ff-a2e9-1fefa501f666",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-69414",
      "pattern": "[vulnerability:name = 'CVE-2026-69414']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft working on Defender patch for ShieldBreak zero-day",
          "url": "https://www.bleepingcomputer.com/news/security/microsoft-working-on-defender-patch-for-shieldbreak-zero-day/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "BleepingComputer"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eaabfe9f-b673-44c0-ba10-a7894da701b0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: anonfilesnew.com",
      "pattern": "[domain-name:value = 'anonfilesnew.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hacker claims 3.6 million Azure account records stolen from ",
          "url": "https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "BleepingComputer"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--92a5a8e5-6ede-4cef-8831-de7a86e3a3ee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: d8t9ldn1onp04vb3399g5krtxh14hkh3.oast.me",
      "pattern": "[domain-name:value = 'd8t9ldn1onp04vb3399g5krtxh14hkh3.oast.me']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Co",
          "url": "https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets_0330881554.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0cc1848b-0972-4eb7-854b-3091b61ab797",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: apexappliexi.dgfp.finances.gouv.fr",
      "pattern": "[domain-name:value = 'apexappliexi.dgfp.finances.gouv.fr']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "French tax authority data breach affects 678,000 individuals",
          "url": "https://www.bleepingcomputer.com/news/security/french-tax-authority-data-breach-affects-678-000-individuals/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "BleepingComputer"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cec27a84-17dd-4703-b65f-62e42972f354",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-9771",
      "pattern": "[vulnerability:name = 'CVE-2020-9771']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New AmnesiaStealer macOS malware hijacks browser sessions vi",
          "url": "https://www.bleepingcomputer.com/news/security/new-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control/"
        },
        {
          "source_name": "AmnesiaStealer Hijacks Chromium Sessions to Give Attackers L",
          "url": "https://thehackernews.com/2026/08/amnesiastealer-hijacks-chromium.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "BleepingComputer",
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--05ade2bd-d620-4123-ad33-8c9163ec743c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: debug.allllowef.space",
      "pattern": "[domain-name:value = 'debug.allllowef.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New AmnesiaStealer macOS malware hijacks browser sessions vi",
          "url": "https://www.bleepingcomputer.com/news/security/new-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control/"
        },
        {
          "source_name": "AmnesiaStealer Hijacks Chromium Sessions to Give Attackers L",
          "url": "https://thehackernews.com/2026/08/amnesiastealer-hijacks-chromium.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "BleepingComputer",
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe0c9ef6-7333-4002-b21a-2a35365618bc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: github.aoitour.com",
      "pattern": "[domain-name:value = 'github.aoitour.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New AmnesiaStealer macOS malware hijacks browser sessions vi",
          "url": "https://www.bleepingcomputer.com/news/security/new-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control/"
        },
        {
          "source_name": "AmnesiaStealer Hijacks Chromium Sessions to Give Attackers L",
          "url": "https://thehackernews.com/2026/08/amnesiastealer-hijacks-chromium.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "BleepingComputer",
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--48045336-b268-415e-9c34-24697ba4e6fd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: de5748aac4a4d4cb48cf050652679e6bc49eda33d9ffaa0d280b578122fab55a",
      "pattern": "[file:hashes.'SHA-256' = 'de5748aac4a4d4cb48cf050652679e6bc49eda33d9ffaa0d280b578122fab55a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New AmnesiaStealer macOS malware hijacks browser sessions vi",
          "url": "https://www.bleepingcomputer.com/news/security/new-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control/"
        },
        {
          "source_name": "AmnesiaStealer Hijacks Chromium Sessions to Give Attackers L",
          "url": "https://thehackernews.com/2026/08/amnesiastealer-hijacks-chromium.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "BleepingComputer",
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--51ead2e8-a89a-4881-9164-a80f9c6f93a9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e853748ca8f9a5a9168263617409a9039ab09f4ffc7d860374c1e3b0b67b31a5",
      "pattern": "[file:hashes.'SHA-256' = 'e853748ca8f9a5a9168263617409a9039ab09f4ffc7d860374c1e3b0b67b31a5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New AmnesiaStealer macOS malware hijacks browser sessions vi",
          "url": "https://www.bleepingcomputer.com/news/security/new-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control/"
        },
        {
          "source_name": "AmnesiaStealer Hijacks Chromium Sessions to Give Attackers L",
          "url": "https://thehackernews.com/2026/08/amnesiastealer-hijacks-chromium.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "BleepingComputer",
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aa564df5-466f-44df-b89a-5ec15a5fac5b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: safepal.com",
      "pattern": "[domain-name:value = 'safepal.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "SafePal data breach impacts 39,798 customers, stolen info fo",
          "url": "https://www.bleepingcomputer.com/news/security/safepal-data-breach-impacts-39-798-customers-stolen-info-for-sale/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "BleepingComputer"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e5da1f12-d2fd-4ab4-a922-55182e75f86d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-33634",
      "pattern": "[vulnerability:name = 'CVE-2026-33634']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Team PCP Stole 78,330 Secrets From 2,186 Organizations. Clou",
          "url": "https://www.stepsecurity.io/blog/teampcp-supply-chain-attack-cicd-secrets-cloudsek-disclosure"
        },
        {
          "source_name": "Malicious LiteLLM Releases Tied to Trivy Hack May Have Expos",
          "url": "https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html"
        },
        {
          "source_name": "10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Suppl",
          "url": "https://www.stepsecurity.io/blog/10-layers-deep-how-stepsecurity-stops-teampcps-trivy-supply-chain-attack-on-github-actions"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "The Hacker News",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4b7e9a3d-4697-40c7-a72c-b2ebc4e30650",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-43760",
      "pattern": "[vulnerability:name = 'CVE-2026-43760']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Apple macOS Screen Sharing Flaw Exploited on Internet-Expose",
          "url": "https://thehackernews.com/2026/08/apple-macos-screen-sharing-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de3c3f59-265e-4ec7-9929-fe983414bb98",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-43777",
      "pattern": "[vulnerability:name = 'CVE-2026-43777']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Apple macOS Screen Sharing Flaw Exploited on Internet-Expose",
          "url": "https://thehackernews.com/2026/08/apple-macos-screen-sharing-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4b53f9be-b11f-4e22-937a-e6e8e860ca8c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-43779",
      "pattern": "[vulnerability:name = 'CVE-2026-43779']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Apple macOS Screen Sharing Flaw Exploited on Internet-Expose",
          "url": "https://thehackernews.com/2026/08/apple-macos-screen-sharing-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--34641261-e0c1-45ad-b5cd-577c2da4ab28",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-58231",
      "pattern": "[vulnerability:name = 'CVE-2026-58231']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation A",
          "url": "https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html"
        },
        {
          "source_name": "SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers ",
          "url": "https://thehackernews.com/2026/08/sap-commerce-cloud-flaw-could-let.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ed564a78-94e4-4a16-8e35-1be96dfe3810",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-65400",
      "pattern": "[vulnerability:name = 'CVE-2026-65400']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Apple macOS Screen Sharing Flaw Exploited on Internet-Expose",
          "url": "https://thehackernews.com/2026/08/apple-macos-screen-sharing-flaw.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--709653a6-bf5c-40c5-8510-f184e090342e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 83.142.209.203",
      "pattern": "[ipv4-addr:value = '83.142.209.203']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Team PCP Stole 78,330 Secrets From 2,186 Organizations. Clou",
          "url": "https://www.stepsecurity.io/blog/teampcp-supply-chain-attack-cicd-secrets-cloudsek-disclosure"
        },
        {
          "source_name": "10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Suppl",
          "url": "https://www.stepsecurity.io/blog/10-layers-deep-how-stepsecurity-stops-teampcps-trivy-supply-chain-attack-on-github-actions"
        },
        {
          "source_name": "TeamPCP Plants WAV Steganography Credential Stealer in telny",
          "url": "https://www.stepsecurity.io/blog/teampcp-plants-wav-steganography-credential-stealer-in-telnyx-pypi-package"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--04b2e42c-4df7-400f-86e9-941c9f2b73a8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7321caa303fe96ded0492c747d2f353c4f7d17185656fe292ab0a59e2bd0b8d9",
      "pattern": "[file:hashes.'SHA-256' = '7321caa303fe96ded0492c747d2f353c4f7d17185656fe292ab0a59e2bd0b8d9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Team PCP Stole 78,330 Secrets From 2,186 Organizations. Clou",
          "url": "https://www.stepsecurity.io/blog/teampcp-supply-chain-attack-cicd-secrets-cloudsek-disclosure"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--78e8ecad-1a16-4252-a647-8f23c734c029",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: cd08115806662469bbedec4b03f8427b97c8a4b3bc1442dc18b72b4e19395fe3",
      "pattern": "[file:hashes.'SHA-256' = 'cd08115806662469bbedec4b03f8427b97c8a4b3bc1442dc18b72b4e19395fe3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Team PCP Stole 78,330 Secrets From 2,186 Organizations. Clou",
          "url": "https://www.stepsecurity.io/blog/teampcp-supply-chain-attack-cicd-secrets-cloudsek-disclosure"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a86e4cbf-22c3-4468-a562-16530ab47d09",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: awqhnjewqjkl.icu",
      "pattern": "[domain-name:value = 'awqhnjewqjkl.icu']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Top enterprise SCA tools in 2026",
          "url": "https://www.aikido.dev/blog/top-enterprise-sca-tools"
        },
        {
          "source_name": "ChainDrop: Inside a Self-Propagating npm Worm",
          "url": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9b2ad9bf-0f0c-4ac3-ab49-11c6090e5788",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: black-popular.com",
      "pattern": "[domain-name:value = 'black-popular.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a",
          "url": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c192600f-fa9f-488a-8fca-5b340c7db496",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: browser-update.pages.dev",
      "pattern": "[domain-name:value = 'browser-update.pages.dev']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d2576bb-cdae-49e2-acd4-0df97fbbb5c0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cloudtroe.giize.com",
      "pattern": "[domain-name:value = 'cloudtroe.giize.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a",
          "url": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3401d33b-fcfd-4fb7-9564-8059130f2fa7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: dns.wizkidblogger.com",
      "pattern": "[domain-name:value = 'dns.wizkidblogger.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7899b792-5b3d-4777-82e1-e05703a71535",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: eastus2.wac-azure.com",
      "pattern": "[domain-name:value = 'eastus2.wac-azure.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d3f970f-e75b-4e4b-b167-6c123b340fff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: employers.theworkpc.com",
      "pattern": "[domain-name:value = 'employers.theworkpc.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a",
          "url": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a6709f00-185c-4655-8ccb-71e343f858f6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: fonts.chrorne.com",
      "pattern": "[domain-name:value = 'fonts.chrorne.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--984d685d-cd3d-49b9-b26e-5e6f1192520a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: fonts.tarotfree101.top",
      "pattern": "[domain-name:value = 'fonts.tarotfree101.top']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b1bb5e64-c240-407b-bd4b-7d35347a1014",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: freeread.casacam.net",
      "pattern": "[domain-name:value = 'freeread.casacam.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a",
          "url": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f51c004c-b7f3-4154-8cce-791f7661f03e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: js-mirror.com",
      "pattern": "[domain-name:value = 'js-mirror.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Top enterprise SCA tools in 2026",
          "url": "https://www.aikido.dev/blog/top-enterprise-sca-tools"
        },
        {
          "source_name": "ChainDrop: Inside a Self-Propagating npm Worm",
          "url": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/"
        },
        {
          "source_name": "Why metaphor may dictate your security strategy",
          "url": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Unit 42 (Palo Alto)",
        "Cisco Talos",
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d18df67-606d-4700-9a5a-fff071d1bff1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: mailbycloud.com",
      "pattern": "[domain-name:value = 'mailbycloud.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2a15d91f-27d5-46bc-8949-5c34bd3c5007",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: microsoft-flash.com",
      "pattern": "[domain-name:value = 'microsoft-flash.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dfe362c7-0b60-4112-8601-d741b1529ada",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: news.dursamjbataar.org",
      "pattern": "[domain-name:value = 'news.dursamjbataar.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a",
          "url": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b6bcde1a-8d37-4fc6-aa5a-a1aec55ef502",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: npm-cache.com",
      "pattern": "[domain-name:value = 'npm-cache.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Top enterprise SCA tools in 2026",
          "url": "https://www.aikido.dev/blog/top-enterprise-sca-tools"
        },
        {
          "source_name": "ChainDrop: Inside a Self-Propagating npm Worm",
          "url": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/"
        },
        {
          "source_name": "Why metaphor may dictate your security strategy",
          "url": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Unit 42 (Palo Alto)",
        "Cisco Talos",
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--124ad0b4-ff6d-4fcb-915b-0c9095c87904",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ns1.jkskhei.com",
      "pattern": "[domain-name:value = 'ns1.jkskhei.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8a65884-c30c-4392-9c18-c658c8914dff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: peopleforce.io",
      "pattern": "[domain-name:value = 'peopleforce.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using B",
          "url": "https://thehackernews.com/2026/08/ctm360-uncovers-over-3000-recruitment.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e6f5373d-9f05-443c-9de1-4ca79b29a1f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: pypi-get.com",
      "pattern": "[domain-name:value = 'pypi-get.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Top enterprise SCA tools in 2026",
          "url": "https://www.aikido.dev/blog/top-enterprise-sca-tools"
        },
        {
          "source_name": "ChainDrop: Inside a Self-Propagating npm Worm",
          "url": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/"
        },
        {
          "source_name": "Why metaphor may dictate your security strategy",
          "url": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Unit 42 (Palo Alto)",
        "Cisco Talos",
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e3f558f7-14b2-408e-9577-3964e46460d7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: robot.avbliud.com",
      "pattern": "[domain-name:value = 'robot.avbliud.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ef85b0f-a7a0-4990-9819-24309ff5dcc1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sundanish.freeddns.org",
      "pattern": "[domain-name:value = 'sundanish.freeddns.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a",
          "url": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb81d23d-83c5-49da-aae2-694df362502c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: torinarlabs.webredirect.org",
      "pattern": "[domain-name:value = 'torinarlabs.webredirect.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a",
          "url": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b187c03-0f56-4335-8944-78328222c693",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: us.lenovoappstore.com",
      "pattern": "[domain-name:value = 'us.lenovoappstore.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a",
          "url": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3fd0b152-0ebe-4692-ac96-f1d45ca168b7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: video.dursamjbataar.org",
      "pattern": "[domain-name:value = 'video.dursamjbataar.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a",
          "url": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5248fa9c-c68d-4440-ab3f-17a0b609b132",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: whatismybestthing.com",
      "pattern": "[domain-name:value = 'whatismybestthing.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a",
          "url": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d4cfcf5f-1abd-4067-bbca-1f55755a641d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: www.f1ash.org.cn",
      "pattern": "[domain-name:value = 'www.f1ash.org.cn']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--902c926b-4e58-4002-8dd8-8c8bd3eae53a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: www.jkskhei.com",
      "pattern": "[domain-name:value = 'www.jkskhei.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c20286b0-7f01-4fa9-88b4-0770fa30eb42",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: www.wps-cn.com",
      "pattern": "[domain-name:value = 'www.wps-cn.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff9ca2e5-597b-4a1f-a467-40062a7af875",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.87.9.62",
      "pattern": "[ipv4-addr:value = '103.87.9.62']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb04d940-0e0f-4b3b-9c28-05f1d8c5d986",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 129.212.237.224",
      "pattern": "[ipv4-addr:value = '129.212.237.224']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--242079e1-07d3-44b5-81de-115750db31c8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 152.42.174.151",
      "pattern": "[ipv4-addr:value = '152.42.174.151']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0a0abb96-dda9-4b66-8c0a-86efe4e33316",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 167.71.195.255",
      "pattern": "[ipv4-addr:value = '167.71.195.255']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f700e418-13a1-4d86-9673-acfb187e8ae5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 219.76.254.184",
      "pattern": "[ipv4-addr:value = '219.76.254.184']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b68173b6-d8ec-4f6c-a7fc-f92992d59310",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.12.1.47",
      "pattern": "[ipv4-addr:value = '38.12.1.47']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e0c56d0-d334-472e-9cfb-37ac2ba396b7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 43.246.208.179",
      "pattern": "[ipv4-addr:value = '43.246.208.179']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--79787331-0553-4113-abc6-5ad93d58104d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 43.246.208.236",
      "pattern": "[ipv4-addr:value = '43.246.208.236']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--557dbbad-040c-4851-ac5a-a2918093ea3a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 47.250.208.35",
      "pattern": "[ipv4-addr:value = '47.250.208.35']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--abba8d5a-324a-4072-8e2e-4d1f1c4b0289",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 47.84.37.113",
      "pattern": "[ipv4-addr:value = '47.84.37.113']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b6d8b67f-0a85-4034-90a2-61ad9d0fe204",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 47.84.51.173",
      "pattern": "[ipv4-addr:value = '47.84.51.173']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--daff681c-6790-491d-94d8-2bdd2b893071",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 47.87.71.167",
      "pattern": "[ipv4-addr:value = '47.87.71.167']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e6e088bd-a0ef-49df-bfda-662894467b89",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 2d7c8780e97409770a9d4f31c66c9d63",
      "pattern": "[file:hashes.MD5 = '2d7c8780e97409770a9d4f31c66c9d63']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mustang Panda Adds Signed Windows Rootkit to CoolClient Back",
          "url": "https://thehackernews.com/2026/08/mustang-panda-adds-signed-windows.html"
        },
        {
          "source_name": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a",
          "url": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e25d539f-5ac1-4e33-b5c3-6b3e057660d7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 9460e150e1981d5c165043520c5c12fe",
      "pattern": "[file:hashes.MD5 = '9460e150e1981d5c165043520c5c12fe']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mustang Panda Adds Signed Windows Rootkit to CoolClient Back",
          "url": "https://thehackernews.com/2026/08/mustang-panda-adds-signed-windows.html"
        },
        {
          "source_name": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a",
          "url": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--842666ca-be1f-4baa-96f8-0d435f913dbe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 9717f005c5fb98e08d2ad983d88f94ee",
      "pattern": "[file:hashes.MD5 = '9717f005c5fb98e08d2ad983d88f94ee']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mustang Panda Adds Signed Windows Rootkit to CoolClient Back",
          "url": "https://thehackernews.com/2026/08/mustang-panda-adds-signed-windows.html"
        },
        {
          "source_name": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a",
          "url": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4b11b2ca-39ea-41c2-aa80-4a1814d3742a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: eb79558b037669792652a816e2c669de",
      "pattern": "[file:hashes.MD5 = 'eb79558b037669792652a816e2c669de']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a",
          "url": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9d8b6fe5-e813-4523-a504-1fedc473f58a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: f518d8e5fe70d9090f6280c68a95998f",
      "pattern": "[file:hashes.MD5 = 'f518d8e5fe70d9090f6280c68a95998f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mustang Panda Adds Signed Windows Rootkit to CoolClient Back",
          "url": "https://thehackernews.com/2026/08/mustang-panda-adds-signed-windows.html"
        },
        {
          "source_name": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a",
          "url": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--75795da1-bb26-495e-9e76-0658833c0a8a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a",
      "pattern": "[file:hashes.'SHA-256' = '01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e9cc416-43ec-4e9f-b858-f241a037ee8d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff",
      "pattern": "[file:hashes.'SHA-256' = '09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--783d4223-37fd-4c6a-bf22-35c44e42f7a0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd",
      "pattern": "[file:hashes.'SHA-256' = '0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb6aa50b-5b0f-45ec-8acd-515b71d43c7d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94e",
      "pattern": "[file:hashes.'SHA-256' = '153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e65381cf-510d-4c7e-9d42-4cc9a6946988",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561",
      "pattern": "[file:hashes.'SHA-256' = '297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8a46cc1f-4bd3-4d3e-b4cc-c95d1b9bf86e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 30f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61d",
      "pattern": "[file:hashes.'SHA-256' = '30f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--079753a7-c05c-4f65-aa39-24af848d74a5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55",
      "pattern": "[file:hashes.'SHA-256' = '430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--59edd410-16f9-4a83-85d8-ef07879808a9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97ef",
      "pattern": "[file:hashes.'SHA-256' = '5ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97ef']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a2f3a25a-78c6-4a45-a681-715af1c7babc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7ac",
      "pattern": "[file:hashes.'SHA-256' = '5edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7ac']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb3f9bfc-729a-4148-9397-1949767f1398",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2",
      "pattern": "[file:hashes.'SHA-256' = '6d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c3ab98bf-a784-43bc-80da-67d35cbb6ee2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 97c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aad",
      "pattern": "[file:hashes.'SHA-256' = '97c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aad']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--558b82a0-c7b2-47dd-b15a-84fbfe2e1160",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3",
      "pattern": "[file:hashes.'SHA-256' = '9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e3cbf779-4770-40cf-b5cb-9f110d619171",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc",
      "pattern": "[file:hashes.'SHA-256' = '9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Top enterprise SCA tools in 2026",
          "url": "https://www.aikido.dev/blog/top-enterprise-sca-tools"
        },
        {
          "source_name": "ChainDrop: Inside a Self-Propagating npm Worm",
          "url": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/"
        },
        {
          "source_name": "Why metaphor may dictate your security strategy",
          "url": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Unit 42 (Palo Alto)",
        "Cisco Talos",
        "Microsoft Security Blog",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--539ce7fb-439c-49e4-a79a-478043301574",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813",
      "pattern": "[file:hashes.'SHA-256' = 'ac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d863fd2c-41cd-4280-aa08-ab71caf4d0d5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e",
      "pattern": "[file:hashes.'SHA-256' = 'b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d932cccf-d994-4bc6-92f8-e45a0821230a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42cc",
      "pattern": "[file:hashes.'SHA-256' = 'c11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--233b2878-6b3e-45e5-989c-a224ddf5e1ca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530",
      "pattern": "[file:hashes.'SHA-256' = 'e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67cdbc7a-cbea-4ecb-8867-9cada7c77492",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf",
      "pattern": "[file:hashes.'SHA-256' = 'e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--332b17e4-6475-4a3d-a345-33d59718047e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0",
      "pattern": "[file:hashes.'SHA-256' = 'e782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4a0ab354-f444-461d-be6d-fd2bfb21ab0c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb",
      "pattern": "[file:hashes.'SHA-256' = 'e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--820981ef-1d09-4c4f-b8ea-426ef6491a01",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34",
      "pattern": "[file:hashes.'SHA-256' = 'e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9dadca98-ea73-459d-a004-5283f794b285",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ea893abf20b00d9bfc042a88fbf7b4bd42e68ce07c116d3e3b002e5b4a853877",
      "pattern": "[file:hashes.'SHA-256' = 'ea893abf20b00d9bfc042a88fbf7b4bd42e68ce07c116d3e3b002e5b4a853877']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3eec7ea1-ae46-42b5-bf8f-0d4c3fe236d1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ed96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869",
      "pattern": "[file:hashes.'SHA-256' = 'ed96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0e012ba2-cd34-4f93-91e0-74a690edf510",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8",
      "pattern": "[file:hashes.'SHA-256' = 'f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "China-Linked Jewelbug Uses XG-Web for Government Espionage a",
          "url": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--abf0e9cc-1382-4d5e-864d-8c79e9053871",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb",
      "pattern": "[file:hashes.'SHA-256' = 'fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Top enterprise SCA tools in 2026",
          "url": "https://www.aikido.dev/blog/top-enterprise-sca-tools"
        },
        {
          "source_name": "ChainDrop: Inside a Self-Propagating npm Worm",
          "url": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/"
        },
        {
          "source_name": "Why metaphor may dictate your security strategy",
          "url": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Unit 42 (Palo Alto)",
        "Cisco Talos",
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--771d1d64-94f0-4bcb-8343-a39f78269d72",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: 6789x.site",
      "pattern": "[domain-name:value = '6789x.site']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f386b854-d3ed-4fb6-8d15-a65b04cd3e9e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: 90phutyy.io",
      "pattern": "[domain-name:value = '90phutyy.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--edbbf0f7-fe2a-4563-9b3a-6f66dee7b628",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: animalrampage3d.io",
      "pattern": "[domain-name:value = 'animalrampage3d.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fbeb7633-45e3-43e3-8dc3-5bb8f25bf310",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: api-score.com",
      "pattern": "[domain-name:value = 'api-score.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--95a2bb0f-baa4-4fd7-9144-309ba4b281bd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: buffalomarket.com",
      "pattern": "[domain-name:value = 'buffalomarket.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c56bef72-0bd4-4a37-baf4-c8efa7847313",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cel-robox.com",
      "pattern": "[domain-name:value = 'cel-robox.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1f45fae4-86ec-425c-b7ea-5af731a9eb07",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: colascore.com",
      "pattern": "[domain-name:value = 'colascore.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--14244a22-a0e0-4c8d-80d1-5b0c56b763c9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: colatv88xb.cc",
      "pattern": "[domain-name:value = 'colatv88xb.cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f2051438-2ceb-44dc-91ec-c7fd37f9d9bd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: gene-chips.com",
      "pattern": "[domain-name:value = 'gene-chips.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--13c8413b-e475-41f3-94a7-809b4889b170",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: gvapi.cc",
      "pattern": "[domain-name:value = 'gvapi.cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3bbad936-e2fd-463d-9264-62cb64eb44f2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: healthymagination.com",
      "pattern": "[domain-name:value = 'healthymagination.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1532c00e-4881-4650-bb13-8e97b2ffce1e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: institutobancopalmas.org",
      "pattern": "[domain-name:value = 'institutobancopalmas.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4dc2f1ad-f81a-4417-8b17-ac6a43e4b089",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: jurasudfoot.com",
      "pattern": "[domain-name:value = 'jurasudfoot.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--04c03741-9bd7-4104-bf84-12ff10606d36",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: krogeralbertsons.com",
      "pattern": "[domain-name:value = 'krogeralbertsons.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--20834386-69db-4fb2-9568-6df82a6a52b7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: lfastcdn.com",
      "pattern": "[domain-name:value = 'lfastcdn.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e50b8110-b7e8-4124-9e39-8fec4c090ccf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: maxfactor-international.com",
      "pattern": "[domain-name:value = 'maxfactor-international.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da3dd67b-15cf-4274-88bb-ef9e84a071f5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: refvsb.com",
      "pattern": "[domain-name:value = 'refvsb.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0a660e8-fa6e-4656-9725-c1d4232dbab7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: rezilion.com",
      "pattern": "[domain-name:value = 'rezilion.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9f17e2c9-40fc-4602-8e02-50df01dbb64a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sadd.io",
      "pattern": "[domain-name:value = 'sadd.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b3fee3d-afc7-48c1-9ffb-25d8a60ebd60",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: samefacts.com",
      "pattern": "[domain-name:value = 'samefacts.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--28e70507-66e1-4d52-be22-be71ba12e0bf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: snsystems.com",
      "pattern": "[domain-name:value = 'snsystems.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fafb268d-0db1-43f7-b931-2488a9b2834d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: socoliveku.cc",
      "pattern": "[domain-name:value = 'socoliveku.cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a10948f4-42a7-4958-b515-f11450beb6fa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sportliveapiz.com",
      "pattern": "[domain-name:value = 'sportliveapiz.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--665be772-c45c-487b-8431-226014cc241e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: stope40.org",
      "pattern": "[domain-name:value = 'stope40.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f649ce5b-40d2-457f-b0a0-1546b61ba0ff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: trackervsb.live",
      "pattern": "[domain-name:value = 'trackervsb.live']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9d58c0f3-2d67-45f9-924e-de35f1048568",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: veinteractive.com",
      "pattern": "[domain-name:value = 'veinteractive.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--682c551f-b721-454c-ab17-47bb20d4e8bd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: vsbet276.com",
      "pattern": "[domain-name:value = 'vsbet276.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--15ab887a-33d1-4416-9a44-af5d1c3530f2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: xemlaibongda.net",
      "pattern": "[domain-name:value = 'xemlaibongda.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--36f84f4f-5e19-4717-bdfc-b90901c889ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: xoilacxys.top",
      "pattern": "[domain-name:value = 'xoilacxys.top']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7befcb3f-6de9-4517-af8e-0f15f68813f5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: xoilacz.com",
      "pattern": "[domain-name:value = 'xoilacz.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--235cda40-84c9-4b5a-8269-a7820534a510",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 0464caa1c45cb753db25a95a30ce0b6814650b6f839a07cf8c2afdc143de7216",
      "pattern": "[file:hashes.'SHA-256' = '0464caa1c45cb753db25a95a30ce0b6814650b6f839a07cf8c2afdc143de7216']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hackers Spend Nearly $7 Million on Expired Domains to Redire",
          "url": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--be93ebcb-d0ba-4bde-9d5b-bbcece28822d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 14eb4ce01dd4307759887ff819359b70d7d9ff709ecde039a5abc1aac325b128",
      "pattern": "[file:hashes.'SHA-256' = '14eb4ce01dd4307759887ff819359b70d7d9ff709ecde039a5abc1aac325b128']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Top enterprise SCA tools in 2026",
          "url": "https://www.aikido.dev/blog/top-enterprise-sca-tools"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc999d13-d76e-42da-b668-cdc1adc6e531",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 29ac906c8bd801dfe1cb39596197df49f80fff2270b3e7fbab52287c24e4f1a7",
      "pattern": "[file:hashes.'SHA-256' = '29ac906c8bd801dfe1cb39596197df49f80fff2270b3e7fbab52287c24e4f1a7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Top enterprise SCA tools in 2026",
          "url": "https://www.aikido.dev/blog/top-enterprise-sca-tools"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--038ffd10-d639-4cbe-a159-995f0e325df7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3f3f42d072bd36860ab7bd7fb5e10ac0d22c741c13c89505ccd6ec0ea572eea7",
      "pattern": "[file:hashes.'SHA-256' = '3f3f42d072bd36860ab7bd7fb5e10ac0d22c741c13c89505ccd6ec0ea572eea7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Top enterprise SCA tools in 2026",
          "url": "https://www.aikido.dev/blog/top-enterprise-sca-tools"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--01c180ab-e00b-47e5-aefc-b6be63a21e35",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 619c56acf572df75b6004a6fc013c80900316a76099b241d64312da3a44f10b4",
      "pattern": "[file:hashes.'SHA-256' = '619c56acf572df75b6004a6fc013c80900316a76099b241d64312da3a44f10b4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Top enterprise SCA tools in 2026",
          "url": "https://www.aikido.dev/blog/top-enterprise-sca-tools"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--55c1bc55-ddcf-40a9-95c6-fc6387e60457",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 927387d0cfac1118df4b383decc2ea6ba49c9d2f98b47098bcbcba1efc026e1f",
      "pattern": "[file:hashes.'SHA-256' = '927387d0cfac1118df4b383decc2ea6ba49c9d2f98b47098bcbcba1efc026e1f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Top enterprise SCA tools in 2026",
          "url": "https://www.aikido.dev/blog/top-enterprise-sca-tools"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e18af70b-ee53-4fee-951f-2b849e323cea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-6387",
      "pattern": "[vulnerability:name = 'CVE-2024-6387']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New PATCHCORD Backdoor Targets Afghan Telecom and Indian Cri",
          "url": "https://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6eb60eae-88b0-4469-add2-2c253d7269db",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-20685",
      "pattern": "[vulnerability:name = 'CVE-2026-20685']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, C",
          "url": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--97447f8d-854e-4eff-8221-45b7c212a12a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-55040",
      "pattern": "[vulnerability:name = 'CVE-2026-55040']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Attackers Exploit SharePoint Authentication Bypass After Pub",
          "url": "https://thehackernews.com/2026/08/attackers-exploit-sharepoint.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6726df2b-bade-4d76-94f5-f1fa824a66d1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: appstoore.solutions",
      "pattern": "[domain-name:value = 'appstoore.solutions']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New PATCHCORD Backdoor Targets Afghan Telecom and Indian Cri",
          "url": "https://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--025e76d4-561c-4440-b2d1-06fb82bc763d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ccleanerwind.top",
      "pattern": "[domain-name:value = 'ccleanerwind.top']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, C",
          "url": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f7a6c43f-e81b-411d-8c92-82a6ce35fc60",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: city-forum.com",
      "pattern": "[domain-name:value = 'city-forum.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, C",
          "url": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--92af1e1e-018d-4c4a-9793-22c4e61d7ecd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: nic-support.site",
      "pattern": "[domain-name:value = 'nic-support.site']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New PATCHCORD Backdoor Targets Afghan Telecom and Indian Cri",
          "url": "https://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--363d319c-2355-4949-b4ba-0f20f335cc01",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: thu-ipad-02.cfd",
      "pattern": "[domain-name:value = 'thu-ipad-02.cfd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, C",
          "url": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76721d25-0987-442c-a8cc-50da6baf914e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: thu-ipad-03.cfd",
      "pattern": "[domain-name:value = 'thu-ipad-03.cfd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, C",
          "url": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--74a6b08a-016c-433b-89be-9ba937c7e7f0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: thu-ipad-04.cfd",
      "pattern": "[domain-name:value = 'thu-ipad-04.cfd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, C",
          "url": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b88ec97d-c5f6-479c-ae5d-cbfb9aeadcdd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: thu-ipad-05.cfd",
      "pattern": "[domain-name:value = 'thu-ipad-05.cfd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, C",
          "url": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2f38975d-cf35-48a2-ace3-4b2b8e611446",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: thu-ipad-06.cfd",
      "pattern": "[domain-name:value = 'thu-ipad-06.cfd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, C",
          "url": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bdaf9915-460d-4fee-8167-5b83ea963819",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: thu-ipad-07.cfd",
      "pattern": "[domain-name:value = 'thu-ipad-07.cfd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, C",
          "url": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--35906c97-698b-4e55-9a47-b821164a5af3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: thu-ipad-08.cfd",
      "pattern": "[domain-name:value = 'thu-ipad-08.cfd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, C",
          "url": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1493c89a-77a4-4fa5-bad7-5ae47339181a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: thu-ipad-09.cfd",
      "pattern": "[domain-name:value = 'thu-ipad-09.cfd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, C",
          "url": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0ba90044-84bc-4584-bd34-b0b42dffea1d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: thu-ipad-10.cfd",
      "pattern": "[domain-name:value = 'thu-ipad-10.cfd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, C",
          "url": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b976444-446b-4938-8dbd-ae311c3b061b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: thu-ipad-11.cfd",
      "pattern": "[domain-name:value = 'thu-ipad-11.cfd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, C",
          "url": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f9fcba2d-90ff-497a-b730-4860d5e3828f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: thu-ipad-12.cfd",
      "pattern": "[domain-name:value = 'thu-ipad-12.cfd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, C",
          "url": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c1ee3b9a-93e8-4165-a3fa-8cd6413e0579",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: WIN-FG3H2SKPOTA.TESTDOMAIN2.fritz.box",
      "pattern": "[domain-name:value = 'WIN-FG3H2SKPOTA.TESTDOMAIN2.fritz.box']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Attackers Exploit SharePoint Authentication Bypass After Pub",
          "url": "https://thehackernews.com/2026/08/attackers-exploit-sharepoint.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb34608d-f9bf-4a18-8856-b1c6ad7ef56b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.250.148.58",
      "pattern": "[ipv4-addr:value = '104.250.148.58']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "North Korean Remote Workers Are Infiltrating Government and ",
          "url": "https://thehackernews.com/2026/08/north-korean-remote-workers-are.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1f8e7139-846e-42ab-98b9-746ee22bdfde",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 107.150.38.250",
      "pattern": "[ipv4-addr:value = '107.150.38.250']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "North Korean Remote Workers Are Infiltrating Government and ",
          "url": "https://thehackernews.com/2026/08/north-korean-remote-workers-are.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7fe864f0-d9d9-4e01-80d9-1d4a45f1dc63",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 158.220.87.79",
      "pattern": "[ipv4-addr:value = '158.220.87.79']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, C",
          "url": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--280c8915-b0e7-4b86-a46a-3eff3a64eadb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.100.87.116",
      "pattern": "[ipv4-addr:value = '185.100.87.116']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--654f691d-ec3b-4cfd-9d72-720eb282028f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.100.87.223",
      "pattern": "[ipv4-addr:value = '185.100.87.223']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--476ddfe6-e4a0-43fa-88e2-f7acac4ce97d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.152.67.39",
      "pattern": "[ipv4-addr:value = '185.152.67.39']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "North Korean Remote Workers Are Infiltrating Government and ",
          "url": "https://thehackernews.com/2026/08/north-korean-remote-workers-are.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--17fac0a6-a932-40f4-829b-499b415e6430",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.200.115.226",
      "pattern": "[ipv4-addr:value = '192.200.115.226']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "North Korean Remote Workers Are Infiltrating Government and ",
          "url": "https://thehackernews.com/2026/08/north-korean-remote-workers-are.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4f5f88ce-09de-4861-bd8c-159be481278a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 199.168.112.175",
      "pattern": "[ipv4-addr:value = '199.168.112.175']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "North Korean Remote Workers Are Infiltrating Government and ",
          "url": "https://thehackernews.com/2026/08/north-korean-remote-workers-are.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--55697461-75f4-456d-91b5-7597e86e9361",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 206.217.134.34",
      "pattern": "[ipv4-addr:value = '206.217.134.34']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "North Korean Remote Workers Are Infiltrating Government and ",
          "url": "https://thehackernews.com/2026/08/north-korean-remote-workers-are.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--50bda50a-a063-4509-bbf4-f7c0dec7d44d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 213.218.160.48",
      "pattern": "[ipv4-addr:value = '213.218.160.48']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--91508420-4b34-4e5c-960b-10efaec6e1ba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.77.71.42",
      "pattern": "[ipv4-addr:value = '45.77.71.42']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "North Korean Remote Workers Are Infiltrating Government and ",
          "url": "https://thehackernews.com/2026/08/north-korean-remote-workers-are.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--04d3ee57-2895-4316-be9a-0b6a7d923e2c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 46.30.188.13",
      "pattern": "[ipv4-addr:value = '46.30.188.13']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New PATCHCORD Backdoor Targets Afghan Telecom and Indian Cri",
          "url": "https://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cf774ba5-bb08-48d0-9d62-37470e2a1ae7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 62.33.223.165",
      "pattern": "[ipv4-addr:value = '62.33.223.165']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "North Korean Remote Workers Are Infiltrating Government and ",
          "url": "https://thehackernews.com/2026/08/north-korean-remote-workers-are.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--16ea30fb-d10d-4db8-bfde-b6533d9a7ac4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 88.86.124.114",
      "pattern": "[ipv4-addr:value = '88.86.124.114']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9a901345-f8d1-4adf-ab70-4df7fb657255",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 89.187.185.11",
      "pattern": "[ipv4-addr:value = '89.187.185.11']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "North Korean Remote Workers Are Infiltrating Government and ",
          "url": "https://thehackernews.com/2026/08/north-korean-remote-workers-are.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--debc0d4f-73a6-4008-a887-595d4de2ed6a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 2915b3f8b703eb744fc54c81f4a9c67f",
      "pattern": "[file:hashes.MD5 = '2915b3f8b703eb744fc54c81f4a9c67f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Curiouser and Curiouser",
          "url": "https://blog.talosintelligence.com/curiouser-and-curiouser/"
        },
        {
          "source_name": "Why metaphor may dictate your security strategy",
          "url": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/"
        },
        {
          "source_name": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "url": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ca04e66f-ef9d-4d33-bec5-658aa592fa35",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 38de5b216c33833af710e88f7f64fc98",
      "pattern": "[file:hashes.MD5 = '38de5b216c33833af710e88f7f64fc98']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Curiouser and Curiouser",
          "url": "https://blog.talosintelligence.com/curiouser-and-curiouser/"
        },
        {
          "source_name": "Why metaphor may dictate your security strategy",
          "url": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/"
        },
        {
          "source_name": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "url": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--23e39e3d-0c82-4a9e-866a-74b7557c7c05",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 7bdbd180c081fa63ca94f9c22c457376",
      "pattern": "[file:hashes.MD5 = '7bdbd180c081fa63ca94f9c22c457376']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Curiouser and Curiouser",
          "url": "https://blog.talosintelligence.com/curiouser-and-curiouser/"
        },
        {
          "source_name": "Why metaphor may dictate your security strategy",
          "url": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/"
        },
        {
          "source_name": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "url": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c5f441e-b281-45ec-9942-5824937a41a6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a",
      "pattern": "[file:hashes.MD5 = 'c2efb2dcacba6d3ccc175b6ce1b7ed0a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Curiouser and Curiouser",
          "url": "https://blog.talosintelligence.com/curiouser-and-curiouser/"
        },
        {
          "source_name": "Why metaphor may dictate your security strategy",
          "url": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/"
        },
        {
          "source_name": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "url": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f457233c-1747-4b92-a093-b6b780b44e80",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 11f9fb29f2cc142e81c804f53599ae36282c95b3",
      "pattern": "[file:hashes.'SHA-1' = '11f9fb29f2cc142e81c804f53599ae36282c95b3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--85b1467f-58ec-471b-8e45-d503ca013f41",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 1371b2b2da10ed178d26a7aad191634553f865ae",
      "pattern": "[file:hashes.'SHA-1' = '1371b2b2da10ed178d26a7aad191634553f865ae']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a945b2c3-75d8-4695-a25d-942a9e9cad68",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 193078cda795dc2f12983e9b66821f7e67c6495d",
      "pattern": "[file:hashes.'SHA-1' = '193078cda795dc2f12983e9b66821f7e67c6495d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a9bc06cf-c8d5-4fb6-a840-53b995d4367a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 1eac0c636edf181eec0315ffe3b5b1e310b1a352",
      "pattern": "[file:hashes.'SHA-1' = '1eac0c636edf181eec0315ffe3b5b1e310b1a352']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e135c608-6269-4be9-aa95-c6d7ae0a7c99",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 217ab41d543278d0ecce797a71ef38a6bc1493fe",
      "pattern": "[file:hashes.'SHA-1' = '217ab41d543278d0ecce797a71ef38a6bc1493fe']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f58cc5de-eaf8-45a3-b1ba-07c4a462a84b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 22fa5c967b0775c3f3398dcf5dbb46ff80e1708b",
      "pattern": "[file:hashes.'SHA-1' = '22fa5c967b0775c3f3398dcf5dbb46ff80e1708b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cfae2680-91a3-4687-9ec2-4a05acf0f2d2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 294ecf0550308dff9df0eea86ca127c064b3bfb8",
      "pattern": "[file:hashes.'SHA-1' = '294ecf0550308dff9df0eea86ca127c064b3bfb8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--58804a26-3f11-44ee-898c-b82e9ff53171",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 38ca1bc31ccdc1c650720abd76bcc619532c0166",
      "pattern": "[file:hashes.'SHA-1' = '38ca1bc31ccdc1c650720abd76bcc619532c0166']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--68fa8a74-743a-4a1f-8d87-9a1f1f106434",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 39060c673aefa0902cb5fc787fa53364cad9ed6f",
      "pattern": "[file:hashes.'SHA-1' = '39060c673aefa0902cb5fc787fa53364cad9ed6f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e87d179e-1a99-4d44-9f8e-3575cb233da8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 48d011117eacf57128c7e473bb5d4d69e3d41ef6",
      "pattern": "[file:hashes.'SHA-1' = '48d011117eacf57128c7e473bb5d4d69e3d41ef6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e8b4a312-24db-48c1-9508-2399a78ec3bc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 50cf07b97ef999e9fc5c7efae19d0e5f39db39fa",
      "pattern": "[file:hashes.'SHA-1' = '50cf07b97ef999e9fc5c7efae19d0e5f39db39fa']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--56a1734b-0001-4990-8474-85899bd79617",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 56b819cb285dbdbc307268b4fadbddaa61319bb8",
      "pattern": "[file:hashes.'SHA-1' = '56b819cb285dbdbc307268b4fadbddaa61319bb8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5671020f-7165-4822-a384-52341b7ed81c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 65ca7e9363539282c2670dfab100b75c9bfb6253",
      "pattern": "[file:hashes.'SHA-1' = '65ca7e9363539282c2670dfab100b75c9bfb6253']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--838ad250-dd89-4cdd-ace9-72371503c8b0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 67e2a1e8ab963086bb768b28307cf58dadb0acc7",
      "pattern": "[file:hashes.'SHA-1' = '67e2a1e8ab963086bb768b28307cf58dadb0acc7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f08ff49b-549d-4187-bf0b-2cc0dcbb3a12",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 6feeba25748996d3928f11ef774122e02b4b8850",
      "pattern": "[file:hashes.'SHA-1' = '6feeba25748996d3928f11ef774122e02b4b8850']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a46ca91c-5d13-49c4-98e0-af1e6767abdd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 82a35dd0ec20791bc3161a87fdb6caa68fd3d4a6",
      "pattern": "[file:hashes.'SHA-1' = '82a35dd0ec20791bc3161a87fdb6caa68fd3d4a6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e66616aa-eae3-4732-9cd4-dc70a327a2e6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 850680506df7892d43b3382f0f89a06ef18837c7",
      "pattern": "[file:hashes.'SHA-1' = '850680506df7892d43b3382f0f89a06ef18837c7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--99656799-567f-48b8-93aa-2981df98d25a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 852322e063872a025b711d5adf08531eac36a265",
      "pattern": "[file:hashes.'SHA-1' = '852322e063872a025b711d5adf08531eac36a265']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--adbd9627-8f68-4e03-a596-90782c2a1f95",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 8e665c12b7d8e80c72d86ed4425663ecd74e453c",
      "pattern": "[file:hashes.'SHA-1' = '8e665c12b7d8e80c72d86ed4425663ecd74e453c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3ba42f1b-a639-4189-92fa-fd6012cbc72a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 91e66d640b2a570bd83b408b51ebbf21e95e7469",
      "pattern": "[file:hashes.'SHA-1' = '91e66d640b2a570bd83b408b51ebbf21e95e7469']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--74c43390-f462-488f-8ddc-a12d3279b4a1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: a1574476a616599a202cc731a6d5dbf9b3a635f0",
      "pattern": "[file:hashes.'SHA-1' = 'a1574476a616599a202cc731a6d5dbf9b3a635f0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--648eea37-f65d-475a-96de-148a81cc50a7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: a72089566a711ed0781d5a36e3c289de0de13e2d",
      "pattern": "[file:hashes.'SHA-1' = 'a72089566a711ed0781d5a36e3c289de0de13e2d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c592648e-9f89-49fc-8bdf-56c4e125ba5f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: bc2bce53d71533c2eb1ccc30fd252ea2774d0100",
      "pattern": "[file:hashes.'SHA-1' = 'bc2bce53d71533c2eb1ccc30fd252ea2774d0100']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--700ef865-51c1-4566-9f3a-8de36246e39d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: bce3d9b06a3fc2312fe5be213f3d98b9350c9b22",
      "pattern": "[file:hashes.'SHA-1' = 'bce3d9b06a3fc2312fe5be213f3d98b9350c9b22']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8944741d-a3dc-432e-beae-864a29edd551",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: dfd19ee8b550f21b99d63ce87d039d1e8e1e111b",
      "pattern": "[file:hashes.'SHA-1' = 'dfd19ee8b550f21b99d63ce87d039d1e8e1e111b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--037182b6-6e46-4171-ac4a-1ad90149e2e8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: e05575afe5a01d150daa8b4bb935213cc0e538f6",
      "pattern": "[file:hashes.'SHA-1' = 'e05575afe5a01d150daa8b4bb935213cc0e538f6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2d4ff596-d6e0-4984-97f3-2c1907800b1a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: e2e836d16a1b50d4d091f7ae507b82c0a8e05376",
      "pattern": "[file:hashes.'SHA-1' = 'e2e836d16a1b50d4d091f7ae507b82c0a8e05376']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cc0efb83-f9a2-413e-a3f7-4f29ac13b831",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: ea2be784b2c08cd6f116e14079d6583ba606c556",
      "pattern": "[file:hashes.'SHA-1' = 'ea2be784b2c08cd6f116e14079d6583ba606c556']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b6d8c9b-b300-487d-9d16-48d645323a53",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: ec730da64f9feae4259ebc88113c5cebdf2b1ad7",
      "pattern": "[file:hashes.'SHA-1' = 'ec730da64f9feae4259ebc88113c5cebdf2b1ad7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "WindRelay Android Malware Turns Victims' Phones Into NFC Rel",
          "url": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--42b159e9-f222-455a-8fbd-dd4177a83f9d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1774e15e8eb96eb89bc03cb4768fc0620e10c09c5f795297f36dcc2aa5d9dd94",
      "pattern": "[file:hashes.'SHA-256' = '1774e15e8eb96eb89bc03cb4768fc0620e10c09c5f795297f36dcc2aa5d9dd94']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New PATCHCORD Backdoor Targets Afghan Telecom and Indian Cri",
          "url": "https://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da93549d-01d7-4e08-b12d-4eb949152477",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 378484112b4e837d3850b5b0802fc509202c232bb124d6944a59fe66525ba668",
      "pattern": "[file:hashes.'SHA-256' = '378484112b4e837d3850b5b0802fc509202c232bb124d6944a59fe66525ba668']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New PATCHCORD Backdoor Targets Afghan Telecom and Indian Cri",
          "url": "https://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--174c8096-4354-4f19-9b7b-03520ccb5422",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5e17360d32e9b272bb7e1b97c8e4dca34622ec9ce08fd240fe2758cc3f67dc4a",
      "pattern": "[file:hashes.'SHA-256' = '5e17360d32e9b272bb7e1b97c8e4dca34622ec9ce08fd240fe2758cc3f67dc4a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New PATCHCORD Backdoor Targets Afghan Telecom and Indian Cri",
          "url": "https://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4b4dbd22-1c3a-4290-a4a7-1f1617fc8863",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59",
      "pattern": "[file:hashes.'SHA-256' = '90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Curiouser and Curiouser",
          "url": "https://blog.talosintelligence.com/curiouser-and-curiouser/"
        },
        {
          "source_name": "Why metaphor may dictate your security strategy",
          "url": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/"
        },
        {
          "source_name": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "url": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--68c423a0-0d13-43ed-beba-5832c06e62f5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f",
      "pattern": "[file:hashes.'SHA-256' = '9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Curiouser and Curiouser",
          "url": "https://blog.talosintelligence.com/curiouser-and-curiouser/"
        },
        {
          "source_name": "Why metaphor may dictate your security strategy",
          "url": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/"
        },
        {
          "source_name": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "url": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2cb12fc3-6dbb-47f9-8fa5-fde2e4300f20",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507",
      "pattern": "[file:hashes.'SHA-256' = '9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Curiouser and Curiouser",
          "url": "https://blog.talosintelligence.com/curiouser-and-curiouser/"
        },
        {
          "source_name": "Why metaphor may dictate your security strategy",
          "url": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/"
        },
        {
          "source_name": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "url": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4cdb1e23-7827-4c08-a667-ffc719a4b75b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91",
      "pattern": "[file:hashes.'SHA-256' = 'a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Curiouser and Curiouser",
          "url": "https://blog.talosintelligence.com/curiouser-and-curiouser/"
        },
        {
          "source_name": "Why metaphor may dictate your security strategy",
          "url": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/"
        },
        {
          "source_name": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "url": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9b886ccc-8574-4d49-9512-61c9929b11f7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: cf7184c0dfe882dc6e3016f16e4ede32b75d7648f83d6f4f87eb6a703be7b8d6",
      "pattern": "[file:hashes.'SHA-256' = 'cf7184c0dfe882dc6e3016f16e4ede32b75d7648f83d6f4f87eb6a703be7b8d6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New PATCHCORD Backdoor Targets Afghan Telecom and Indian Cri",
          "url": "https://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de73a1b7-5e80-4115-8447-741a788b9d33",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ea0934472121848b80455581d289ce4480b1e5cc05678c1b90ecfc465b5ec350",
      "pattern": "[file:hashes.'SHA-256' = 'ea0934472121848b80455581d289ce4480b1e5cc05678c1b90ecfc465b5ec350']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New PATCHCORD Backdoor Targets Afghan Telecom and Indian Cri",
          "url": "https://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b28ab07-3f80-4467-8ee3-94d3d4413b07",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: managementapiservice.com",
      "pattern": "[domain-name:value = 'managementapiservice.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Armored Likho expands its cyber-espionage toolkit",
          "url": "https://securelist.com/armored-likho-still-toolkit/121033/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--25e58599-cd56-4b39-a00d-a31cc89e58c3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: orderapiserver.info",
      "pattern": "[domain-name:value = 'orderapiserver.info']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Armored Likho expands its cyber-espionage toolkit",
          "url": "https://securelist.com/armored-likho-still-toolkit/121033/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2691977b-c793-4588-8a0e-d216e9f0b5cb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: screenserv.com",
      "pattern": "[domain-name:value = 'screenserv.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Armored Likho expands its cyber-espionage toolkit",
          "url": "https://securelist.com/armored-likho-still-toolkit/121033/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--947e90e7-0fd7-44ce-abb1-86ecd82a2028",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: service8date.com",
      "pattern": "[domain-name:value = 'service8date.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Armored Likho expands its cyber-espionage toolkit",
          "url": "https://securelist.com/armored-likho-still-toolkit/121033/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c3bd7714-c632-4dcb-bdf1-0378d0a7465f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: srwinservice.com",
      "pattern": "[domain-name:value = 'srwinservice.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Armored Likho expands its cyber-espionage toolkit",
          "url": "https://securelist.com/armored-likho-still-toolkit/121033/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d89bed60-1b5c-497e-8195-ec691f4ebe53",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: tg4service.com",
      "pattern": "[domain-name:value = 'tg4service.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Armored Likho expands its cyber-espionage toolkit",
          "url": "https://securelist.com/armored-likho-still-toolkit/121033/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c5a68344-2a09-4bce-9563-c493db69189f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: updateservs.com",
      "pattern": "[domain-name:value = 'updateservs.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Armored Likho expands its cyber-espionage toolkit",
          "url": "https://securelist.com/armored-likho-still-toolkit/121033/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ef5e469-effd-482f-b6c2-014111b4b4b1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: windowserv.net",
      "pattern": "[domain-name:value = 'windowserv.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Armored Likho expands its cyber-espionage toolkit",
          "url": "https://securelist.com/armored-likho-still-toolkit/121033/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e0b069f9-12b6-4a8e-a592-1804d654007c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 145.223.68.66",
      "pattern": "[ipv4-addr:value = '145.223.68.66']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Armored Likho expands its cyber-espionage toolkit",
          "url": "https://securelist.com/armored-likho-still-toolkit/121033/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8df081fe-3dce-4400-bd9a-d88d6f3475a0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 145.223.69.143",
      "pattern": "[ipv4-addr:value = '145.223.69.143']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Armored Likho expands its cyber-espionage toolkit",
          "url": "https://securelist.com/armored-likho-still-toolkit/121033/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b6ef88aa-c728-4a08-889c-03c06af6541a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 159.198.37.74",
      "pattern": "[ipv4-addr:value = '159.198.37.74']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Armored Likho expands its cyber-espionage toolkit",
          "url": "https://securelist.com/armored-likho-still-toolkit/121033/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4c7003c7-acf2-4862-81f0-bf41d8140127",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 187.127.153.38",
      "pattern": "[ipv4-addr:value = '187.127.153.38']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Armored Likho expands its cyber-espionage toolkit",
          "url": "https://securelist.com/armored-likho-still-toolkit/121033/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--29ef8f51-9701-47ef-ad24-8c33899535be",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 188.212.124.178",
      "pattern": "[ipv4-addr:value = '188.212.124.178']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Armored Likho expands its cyber-espionage toolkit",
          "url": "https://securelist.com/armored-likho-still-toolkit/121033/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4c2ea5dc-8938-415f-8ac2-56cc2a624ea0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 213.252.244.123",
      "pattern": "[ipv4-addr:value = '213.252.244.123']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Armored Likho expands its cyber-espionage toolkit",
          "url": "https://securelist.com/armored-likho-still-toolkit/121033/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9b3ef267-2639-4eba-be59-500fce50f7a6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.26.237.250",
      "pattern": "[ipv4-addr:value = '23.26.237.250']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Armored Likho expands its cyber-espionage toolkit",
          "url": "https://securelist.com/armored-likho-still-toolkit/121033/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--66c34ffa-ddca-42a8-a2cd-f7ac928489b5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.27.24.30",
      "pattern": "[ipv4-addr:value = '23.27.24.30']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Armored Likho expands its cyber-espionage toolkit",
          "url": "https://securelist.com/armored-likho-still-toolkit/121033/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cfa7229b-1c9f-470a-9502-cad4e5046629",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 439255736797bc88bd19f282449e0436",
      "pattern": "[file:hashes.MD5 = '439255736797bc88bd19f282449e0436']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Armored Likho expands its cyber-espionage toolkit",
          "url": "https://securelist.com/armored-likho-still-toolkit/121033/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4d9309e6-d359-471d-88a4-ebbde9b1f9ce",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 9a47c4d379998ade2f8f99e23a630c06",
      "pattern": "[file:hashes.MD5 = '9a47c4d379998ade2f8f99e23a630c06']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Curiouser and Curiouser",
          "url": "https://blog.talosintelligence.com/curiouser-and-curiouser/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d8bff1a-fd7a-4ef1-897a-04ee59ac65f1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2ca8adbab98ebe305eacf272cf48f5a03ac41b097236a7723821848ae31ef141",
      "pattern": "[file:hashes.'SHA-256' = '2ca8adbab98ebe305eacf272cf48f5a03ac41b097236a7723821848ae31ef141']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Armored Likho expands its cyber-espionage toolkit",
          "url": "https://securelist.com/armored-likho-still-toolkit/121033/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8e0691a5-acbf-44d7-b3ba-369d337aeebd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4bd7c352ae277b0e38d07beedd4dd507d4bc09fb10ea2a5dc0bcbeeda5e5afdd",
      "pattern": "[file:hashes.'SHA-256' = '4bd7c352ae277b0e38d07beedd4dd507d4bc09fb10ea2a5dc0bcbeeda5e5afdd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Armored Likho expands its cyber-espionage toolkit",
          "url": "https://securelist.com/armored-likho-still-toolkit/121033/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a3e3af79-8c94-4b3b-a80a-2f70fb1db7f8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 62801f6223e860a7cca271522e303b2d68f0365d2fa8c828d012d8859e52a773",
      "pattern": "[file:hashes.'SHA-256' = '62801f6223e860a7cca271522e303b2d68f0365d2fa8c828d012d8859e52a773']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Armored Likho expands its cyber-espionage toolkit",
          "url": "https://securelist.com/armored-likho-still-toolkit/121033/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5bbbfe27-7afd-463c-9442-771e7f048da7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c1d1ee16b92e6a138ffa048855f75d7d17674b250d8b422a50a86c9ff207186d",
      "pattern": "[file:hashes.'SHA-256' = 'c1d1ee16b92e6a138ffa048855f75d7d17674b250d8b422a50a86c9ff207186d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Armored Likho expands its cyber-espionage toolkit",
          "url": "https://securelist.com/armored-likho-still-toolkit/121033/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2c398c6a-e984-4313-b67c-b2a38fc62931",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2",
      "pattern": "[file:hashes.'SHA-256' = 'c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Curiouser and Curiouser",
          "url": "https://blog.talosintelligence.com/curiouser-and-curiouser/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--41dc69c2-806c-4f67-8e7c-90444b5a283e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-49113",
      "pattern": "[vulnerability:name = 'CVE-2025-49113']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and ",
          "url": "https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html"
        },
        {
          "source_name": "CISA KEV: CVE-2025-49113 \u2014 RoundCube Webmail Deserialization",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e3df4301-7122-4950-b443-ffb0df797ae0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-20349",
      "pattern": "[vulnerability:name = 'CVE-2026-20349']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Rem",
          "url": "https://thehackernews.com/2026/08/cisco-asa-and-ftd-flaw-exploited-in.html"
        },
        {
          "source_name": "CISA KEV: CVE-2026-20349 \u2014 Cisco Secure Firewall Adaptive Se",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--29f49841-3c27-4f54-976e-2f61adb2a978",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-27302",
      "pattern": "[vulnerability:name = 'CVE-2026-27302']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classi",
          "url": "https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b2d20e7f-f595-4861-b4bc-e2d506a7713b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-34265",
      "pattern": "[vulnerability:name = 'CVE-2026-34265']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers ",
          "url": "https://thehackernews.com/2026/08/sap-commerce-cloud-flaw-could-let.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--46481b7c-80bc-4e2b-aa10-2604f4c54565",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-44758",
      "pattern": "[vulnerability:name = 'CVE-2026-44758']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers ",
          "url": "https://thehackernews.com/2026/08/sap-commerce-cloud-flaw-could-let.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a691d85a-2a68-4101-abbd-c562a911f02c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-44772",
      "pattern": "[vulnerability:name = 'CVE-2026-44772']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers ",
          "url": "https://thehackernews.com/2026/08/sap-commerce-cloud-flaw-could-let.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cd8a6d82-3746-4e7e-96d1-9810fa4b4135",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-48273",
      "pattern": "[vulnerability:name = 'CVE-2026-48273']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classi",
          "url": "https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--412564a1-2f54-4017-a15e-1131d8cacf30",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-48362",
      "pattern": "[vulnerability:name = 'CVE-2026-48362']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classi",
          "url": "https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0305db72-ef77-43de-b960-25f0d21c0345",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-48381",
      "pattern": "[vulnerability:name = 'CVE-2026-48381']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classi",
          "url": "https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d472264-085f-4990-a4d6-d78a90073090",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-48449",
      "pattern": "[vulnerability:name = 'CVE-2026-48449']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classi",
          "url": "https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--164054f0-c9fe-496b-b43d-62a870b1d4ca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62832",
      "pattern": "[vulnerability:name = 'CVE-2026-62832']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Byp",
          "url": "https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html"
        },
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3aafd0a9-d5e1-4d85-816f-456892974300",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-68820",
      "pattern": "[vulnerability:name = 'CVE-2026-68820']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and ",
          "url": "https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html"
        },
        {
          "source_name": "ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Byp",
          "url": "https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html"
        },
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--97b51cab-db90-4675-bc03-3cb334d80e93",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-71362",
      "pattern": "[vulnerability:name = 'CVE-2026-71362']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classi",
          "url": "https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--01e19e6b-fa2a-4dff-afa4-b0ba37ce39a2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-71384",
      "pattern": "[vulnerability:name = 'CVE-2026-71384']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classi",
          "url": "https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2289c854-9e57-4126-9bbb-a58f07d3f945",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-71398",
      "pattern": "[vulnerability:name = 'CVE-2026-71398']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classi",
          "url": "https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--91bd3605-8f2d-40af-94bd-7038ba2473bf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-72971",
      "pattern": "[vulnerability:name = 'CVE-2026-72971']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Byp",
          "url": "https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--886221be-192b-4e1e-8740-8c97a1ba30af",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: audit.checkmarx.cx",
      "pattern": "[domain-name:value = 'audit.checkmarx.cx']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Control Which Package Registries Your CI Jobs and Developer ",
          "url": "https://www.stepsecurity.io/blog/control-which-package-registries-your-ci-jobs-and-developer-machines-use"
        },
        {
          "source_name": "The npm Threat Landscape: Attack Surface and Mitigations (Up",
          "url": "https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/"
        },
        {
          "source_name": "10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Suppl",
          "url": "https://www.stepsecurity.io/blog/10-layers-deep-how-stepsecurity-stops-teampcps-trivy-supply-chain-attack-on-github-actions"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Unit 42 (Palo Alto)",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b6eca050-5c3d-46ae-884b-606a8712fbbd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: checkmarx.zone",
      "pattern": "[domain-name:value = 'checkmarx.zone']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Control Which Package Registries Your CI Jobs and Developer ",
          "url": "https://www.stepsecurity.io/blog/control-which-package-registries-your-ci-jobs-and-developer-machines-use"
        },
        {
          "source_name": "10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Suppl",
          "url": "https://www.stepsecurity.io/blog/10-layers-deep-how-stepsecurity-stops-teampcps-trivy-supply-chain-attack-on-github-actions"
        },
        {
          "source_name": "You Patched LiteLLM, But Do You Know Your AI Blast Radius?",
          "url": "https://snyk.io/blog/litellm-ai-blast-radius/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0be5fad-998b-43e6-9337-56cbea3085c9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: enveil.online",
      "pattern": "[domain-name:value = 'enveil.online']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and ",
          "url": "https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c594ac4-8d11-4232-a93a-5305f0f71238",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: envell.xyz",
      "pattern": "[domain-name:value = 'envell.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and ",
          "url": "https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e348c9ee-94e6-4ffc-b30f-712dd7c30b39",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: models.litellm.cloud",
      "pattern": "[domain-name:value = 'models.litellm.cloud']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Control Which Package Registries Your CI Jobs and Developer ",
          "url": "https://www.stepsecurity.io/blog/control-which-package-registries-your-ci-jobs-and-developer-machines-use"
        },
        {
          "source_name": "Malicious LiteLLM Releases Tied to Trivy Hack May Have Expos",
          "url": "https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html"
        },
        {
          "source_name": "10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Suppl",
          "url": "https://www.stepsecurity.io/blog/10-layers-deep-how-stepsecurity-stops-teampcps-trivy-supply-chain-attack-on-github-actions"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "The Hacker News",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ee7fd173-39e4-4fe6-a51e-ce1ad5ea9244",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: uxtramine.org",
      "pattern": "[domain-name:value = 'uxtramine.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and ",
          "url": "https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e06ca23a-aecd-41b1-a00d-e863e9c913b4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 135.181.185.158",
      "pattern": "[ipv4-addr:value = '135.181.185.158']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and ",
          "url": "https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--05d02626-3f9c-4beb-b3c3-e5c337f55c94",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 135.181.67.203",
      "pattern": "[ipv4-addr:value = '135.181.67.203']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and ",
          "url": "https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1b9f0f2e-41e5-4387-b734-cea8880e7a8a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 83.142.209.11",
      "pattern": "[ipv4-addr:value = '83.142.209.11']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Control Which Package Registries Your CI Jobs and Developer ",
          "url": "https://www.stepsecurity.io/blog/control-which-package-registries-your-ci-jobs-and-developer-machines-use"
        },
        {
          "source_name": "You Patched LiteLLM, But Do You Know Your AI Blast Radius?",
          "url": "https://snyk.io/blog/litellm-ai-blast-radius/"
        },
        {
          "source_name": "How a Poisoned Security Scanner Became the Key to Backdoorin",
          "url": "https://snyk.io/blog/poisoned-security-scanner-backdooring-litellm/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--448c1e4e-411d-4431-8a33-01f3a2a19790",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 94.154.172.43",
      "pattern": "[ipv4-addr:value = '94.154.172.43']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Control Which Package Registries Your CI Jobs and Developer ",
          "url": "https://www.stepsecurity.io/blog/control-which-package-registries-your-ci-jobs-and-developer-machines-use"
        },
        {
          "source_name": "The npm Threat Landscape: Attack Surface and Mitigations (Up",
          "url": "https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/"
        },
        {
          "source_name": "10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Suppl",
          "url": "https://www.stepsecurity.io/blog/10-layers-deep-how-stepsecurity-stops-teampcps-trivy-supply-chain-attack-on-github-actions"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9e29e88e-3fca-43b3-bf1c-8683890a5058",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb",
      "pattern": "[file:hashes.'SHA-256' = '18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Control Which Package Registries Your CI Jobs and Developer ",
          "url": "https://www.stepsecurity.io/blog/control-which-package-registries-your-ci-jobs-and-developer-machines-use"
        },
        {
          "source_name": "Bitwarden CLI Hijacked on npm: Bun-Staged Credential Stealer",
          "url": "https://www.stepsecurity.io/blog/bitwarden-cli-hijacked-on-npm-bun-staged-credential-stealer-targets-developers-github-actions-and-ai-tools"
        },
        {
          "source_name": "Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Sel",
          "url": "https://www.aikido.dev/blog/shai-hulud-npm-bitwarden-cli-compromise"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c0fd0e25-7dd7-4fce-9714-2ae69626599d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8605e365edf11160aad517c7d79a3b26b62290e5072ef97b102a01ddbb343f14",
      "pattern": "[file:hashes.'SHA-256' = '8605e365edf11160aad517c7d79a3b26b62290e5072ef97b102a01ddbb343f14']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Control Which Package Registries Your CI Jobs and Developer ",
          "url": "https://www.stepsecurity.io/blog/control-which-package-registries-your-ci-jobs-and-developer-machines-use"
        },
        {
          "source_name": "Bitwarden CLI Hijacked on npm: Bun-Staged Credential Stealer",
          "url": "https://www.stepsecurity.io/blog/bitwarden-cli-hijacked-on-npm-bun-staged-credential-stealer-targets-developers-github-actions-and-ai-tools"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c57df342-0652-4fc5-80bd-388a9c16f62f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: aquasecurtiy.org",
      "pattern": "[domain-name:value = 'aquasecurtiy.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Control Which Package Registries Your CI Jobs and Developer ",
          "url": "https://www.stepsecurity.io/blog/control-which-package-registries-your-ci-jobs-and-developer-machines-use"
        },
        {
          "source_name": "You Patched LiteLLM, But Do You Know Your AI Blast Radius?",
          "url": "https://snyk.io/blog/litellm-ai-blast-radius/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d346c13-261a-4cf7-b980-1026ac5407d9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: atlasvpn.space",
      "pattern": "[domain-name:value = 'atlasvpn.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bec5cc83-0ee9-4dca-ab85-aeb66a9931ca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: bezopasnet.space",
      "pattern": "[domain-name:value = 'bezopasnet.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--598afdf8-40d7-4dc4-954d-fb159df90b04",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cipherway.space",
      "pattern": "[domain-name:value = 'cipherway.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d805cd79-790f-4a8e-9464-1b535bf4896e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cloudmask.space",
      "pattern": "[domain-name:value = 'cloudmask.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--73f6ca12-74af-4f93-8419-668975cef821",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: echosecure.space",
      "pattern": "[domain-name:value = 'echosecure.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5ba0003d-11f5-4afa-a240-22c938f2806e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: gusenvpn.online",
      "pattern": "[domain-name:value = 'gusenvpn.online']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c467a6c-44c3-4734-9ad1-83bbcd4f9401",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: horizonguard.space",
      "pattern": "[domain-name:value = 'horizonguard.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ab4f222b-3953-41e7-a3a5-ae6e2ac486cc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: internetprvpn.ru",
      "pattern": "[domain-name:value = 'internetprvpn.ru']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--df52f0a4-c37b-4219-a9a5-c0adcbc2e1e6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ironproxy.space",
      "pattern": "[domain-name:value = 'ironproxy.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b89f0793-9b21-4d58-8d75-6fa5ae26509a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: korovkavpn.space",
      "pattern": "[domain-name:value = 'korovkavpn.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--09e2a271-3b7e-48d9-b24e-548ec755b8e2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: maskirovka.space",
      "pattern": "[domain-name:value = 'maskirovka.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0411e95b-e5f9-4a68-966f-7d490785e302",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: murvpn.space",
      "pattern": "[domain-name:value = 'murvpn.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0c9a202d-10c5-4045-9a73-37f6142c83aa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: myxasafe.space",
      "pattern": "[domain-name:value = 'myxasafe.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--362f8404-1b91-4129-ab7c-c73cfa69c594",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: myxasecure.space",
      "pattern": "[domain-name:value = 'myxasecure.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e7bf413c-8801-4a3b-a272-7389dec6d2d7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: myxavpn.com",
      "pattern": "[domain-name:value = 'myxavpn.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--45f9a07f-ab07-4ed2-88c0-61fe81fa6ffa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: myxavpn.pro",
      "pattern": "[domain-name:value = 'myxavpn.pro']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a3d31775-a73d-441a-987c-d3b45ddfd707",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: myxavpn.space",
      "pattern": "[domain-name:value = 'myxavpn.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--89d4cc83-f955-4d6b-a6e0-b183558007e8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: neoncloak.space",
      "pattern": "[domain-name:value = 'neoncloak.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ffced0a0-1316-4c0c-bb80-ef307a3d5bd9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: netroutehub.space",
      "pattern": "[domain-name:value = 'netroutehub.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f32374e-04ed-4e0e-8f53-902a4236e60b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: nimbusshield.space",
      "pattern": "[domain-name:value = 'nimbusshield.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b72169e6-394f-4752-813f-3cc13e1bea37",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: osavpn.su",
      "pattern": "[domain-name:value = 'osavpn.su']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4d1b1804-ef2c-4ae5-b6d6-88efca1a346a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: primeproxy.space",
      "pattern": "[domain-name:value = 'primeproxy.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7348b232-86a0-4460-bde7-639e3d685dde",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: routekeeper.space",
      "pattern": "[domain-name:value = 'routekeeper.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--655d1e4b-fcf6-4bb8-b6f4-253e80b2de34",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: securepulse.space",
      "pattern": "[domain-name:value = 'securepulse.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8a93184e-78dc-42ae-9514-1f2dcf47c0e2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: shershvpn.space",
      "pattern": "[domain-name:value = 'shershvpn.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6eca2248-4a23-4d07-8f17-788f98e39752",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: skorostvpn.space",
      "pattern": "[domain-name:value = 'skorostvpn.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a4a9e867-7145-4d38-b6b8-166b80b98a81",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: turbotunnel.space",
      "pattern": "[domain-name:value = 'turbotunnel.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--01a20723-ff92-4b46-82ac-81a915831214",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: vpn-myxa.ru",
      "pattern": "[domain-name:value = 'vpn-myxa.ru']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a609e773-186e-41ec-9626-070657606205",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: vpnmyha.shop",
      "pattern": "[domain-name:value = 'vpnmyha.shop']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6f589a56-0508-4996-9276-6670c1f60c1f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: vpnmyxa.site",
      "pattern": "[domain-name:value = 'vpnmyxa.site']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--00a4ee60-5f41-4752-9393-453f60505547",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.35.189.225",
      "pattern": "[ipv4-addr:value = '103.35.189.225']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--660e42cf-b32b-46d1-9940-ad88546b295a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.35.191.173",
      "pattern": "[ipv4-addr:value = '103.35.191.173']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--09f0c862-73ee-4fe3-a5ad-24da75a6c657",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 130.17.1.19",
      "pattern": "[ipv4-addr:value = '130.17.1.19']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a14914cd-8e48-42f0-8572-0b16fd8ea5d4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 138.124.244.206",
      "pattern": "[ipv4-addr:value = '138.124.244.206']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c4fd18e4-7ca8-42ad-bb35-edd3b9927514",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 147.45.60.241",
      "pattern": "[ipv4-addr:value = '147.45.60.241']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fbd4bc0b-5c1c-453c-883b-ec0d59f0173b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 147.45.60.252",
      "pattern": "[ipv4-addr:value = '147.45.60.252']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0ee7f259-8df5-4694-b424-e14db751f0f0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 158.160.228.178",
      "pattern": "[ipv4-addr:value = '158.160.228.178']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--adcf1306-a92e-4571-87b0-a13352087bcd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 178.130.47.129",
      "pattern": "[ipv4-addr:value = '178.130.47.129']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2920dc5e-7428-4585-969e-426201dd84a3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 178.130.47.43",
      "pattern": "[ipv4-addr:value = '178.130.47.43']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--99e53bfc-9215-427c-bb5f-703ee1a3405a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 178.130.47.44",
      "pattern": "[ipv4-addr:value = '178.130.47.44']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a3bafe74-5a9c-4c34-ba20-f37cf20a4552",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 178.130.47.50",
      "pattern": "[ipv4-addr:value = '178.130.47.50']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--349019e9-eb89-4b08-a39f-f9e342b71130",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.252.215.97",
      "pattern": "[ipv4-addr:value = '185.252.215.97']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c9b3503d-ed59-4420-bb12-122b089914a2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.252.215.98",
      "pattern": "[ipv4-addr:value = '185.252.215.98']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c5328987-4c64-4d13-8791-3bf49b434830",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.150.220.163",
      "pattern": "[ipv4-addr:value = '194.150.220.163']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9623ba92-c917-4ab7-b65a-544db80487bf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 212.192.14.75",
      "pattern": "[ipv4-addr:value = '212.192.14.75']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d325858-c09c-4775-8a01-8ee97ab1dc7f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.89.110.227",
      "pattern": "[ipv4-addr:value = '45.89.110.227']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4758435b-0840-4caa-810a-0634034fe94d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 46.151.182.203",
      "pattern": "[ipv4-addr:value = '46.151.182.203']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Control Which Package Registries Your CI Jobs and Developer ",
          "url": "https://www.stepsecurity.io/blog/control-which-package-registries-your-ci-jobs-and-developer-machines-use"
        },
        {
          "source_name": "You Patched LiteLLM, But Do You Know Your AI Blast Radius?",
          "url": "https://snyk.io/blog/litellm-ai-blast-radius/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--85e17309-a818-4f94-a720-d340ad7e5598",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.180.30.122",
      "pattern": "[ipv4-addr:value = '5.180.30.122']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6cff2d3d-7cc9-45f0-abd0-acd3b9c4543e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.180.30.15",
      "pattern": "[ipv4-addr:value = '5.180.30.15']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87048460-4bc9-41ab-9f34-56bde5291d60",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 78.153.155.112",
      "pattern": "[ipv4-addr:value = '78.153.155.112']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--346a6df2-ca3c-42b7-879d-e5ba2bbeb159",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 80.92.204.33",
      "pattern": "[ipv4-addr:value = '80.92.204.33']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--74f97e84-5719-46b0-be70-f64a562c7f1f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 80.92.204.47",
      "pattern": "[ipv4-addr:value = '80.92.204.47']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d288ccae-050d-4e61-8f97-6a4c3d7c85ca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 80.92.206.84",
      "pattern": "[ipv4-addr:value = '80.92.206.84']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5fc9584c-5573-4270-85ab-edfbeca15b50",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 81.90.31.73",
      "pattern": "[ipv4-addr:value = '81.90.31.73']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2853a8cf-805e-41eb-be4e-23a9161bd229",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 86.104.74.110",
      "pattern": "[ipv4-addr:value = '86.104.74.110']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--81d38f13-86cc-40e2-909a-220966b660c3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 94.131.118.237",
      "pattern": "[ipv4-addr:value = '94.131.118.237']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1884f803-8a17-403d-9d71-90fc5566ceed",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 94.131.118.39",
      "pattern": "[ipv4-addr:value = '94.131.118.39']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--19d32516-99fc-4016-9c59-5eae44e8d109",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 95.163.244.138",
      "pattern": "[ipv4-addr:value = '95.163.244.138']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "737 Chrome VPN Extensions Caught Routing Traffic Through Pro",
          "url": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c9d1f3bf-875e-4f65-9b3d-2ad236fd4d60",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 167ce57ef59a32a6a0ef4137785828077879092d7f83ddbc1755d6e69116e0ad",
      "pattern": "[file:hashes.'SHA-256' = '167ce57ef59a32a6a0ef4137785828077879092d7f83ddbc1755d6e69116e0ad']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Control Which Package Registries Your CI Jobs and Developer ",
          "url": "https://www.stepsecurity.io/blog/control-which-package-registries-your-ci-jobs-and-developer-machines-use"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea8b06bd-a49e-4b76-ba73-4c5aec9a3d8d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-5195",
      "pattern": "[vulnerability:name = 'CVE-2016-5195']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        },
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-5195 \u2014 Linux Kernel Race Condition Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a5d20f16-f475-4950-9303-8989274e1ace",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-31698",
      "pattern": "[vulnerability:name = 'CVE-2021-31698']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "A Malicious SIM Card Can Run Attacker Code Inside the Modems",
          "url": "https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--969ce8aa-24f9-4fb8-9200-aa2b6fb6eae9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-48618",
      "pattern": "[vulnerability:name = 'CVE-2025-48618']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "A Malicious SIM Card Can Run Attacker Code Inside the Modems",
          "url": "https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8adc3d53-af5f-4a67-9e4c-54d45cc60b27",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-15903",
      "pattern": "[vulnerability:name = 'CVE-2026-15903']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Ex",
          "url": "https://thehackernews.com/2026/08/openai-launches-gpt-56-cyber-with.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d74c1068-dd0b-4101-9c1f-e38a052d416b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-49163",
      "pattern": "[vulnerability:name = 'CVE-2026-49163']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6b37fee1-d7e9-4321-a14f-0e2e05534953",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-50481",
      "pattern": "[vulnerability:name = 'CVE-2026-50481']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--338079b6-c4bb-406c-9474-69794fcf23bb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-50515",
      "pattern": "[vulnerability:name = 'CVE-2026-50515']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1d36decb-edc1-450e-9ceb-f986af00a7d3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-50516",
      "pattern": "[vulnerability:name = 'CVE-2026-50516']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6156201d-9aa5-47ae-8795-b9a57eccac0e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-53413",
      "pattern": "[vulnerability:name = 'CVE-2026-53413']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Zoom Annotation Flaws Could Let a Meeting Participant Hijack",
          "url": "https://thehackernews.com/2026/08/zoom-annotation-flaws-could-let-meeting.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a5b031e2-5b81-4f25-8302-a68d453e89d9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-53414",
      "pattern": "[vulnerability:name = 'CVE-2026-53414']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Zoom Annotation Flaws Could Let a Meeting Participant Hijack",
          "url": "https://thehackernews.com/2026/08/zoom-annotation-flaws-could-let-meeting.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--03e55ae6-33eb-4b7d-8515-397d6c7c0095",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-53415",
      "pattern": "[vulnerability:name = 'CVE-2026-53415']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Zoom Annotation Flaws Could Let a Meeting Participant Hijack",
          "url": "https://thehackernews.com/2026/08/zoom-annotation-flaws-could-let-meeting.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--46ad0b6b-5926-48c7-a4da-782da10f7c02",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-56161",
      "pattern": "[vulnerability:name = 'CVE-2026-56161']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--091e44b8-67fe-4b5a-b59e-68655f24f937",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-56162",
      "pattern": "[vulnerability:name = 'CVE-2026-56162']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0143f367-e742-47d5-9914-0195d07d3a10",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-57550",
      "pattern": "[vulnerability:name = 'CVE-2026-57550']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "A Malicious SIM Card Can Run Attacker Code Inside the Modems",
          "url": "https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--35590dd4-6b8b-43b7-95ca-246e5c2b5162",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-58650",
      "pattern": "[vulnerability:name = 'CVE-2026-58650']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da0ecf38-33e2-4cc6-b744-03b66d300f99",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-59115",
      "pattern": "[vulnerability:name = 'CVE-2026-59115']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--877a2380-c758-4b2e-9b57-cf3886209373",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-59118",
      "pattern": "[vulnerability:name = 'CVE-2026-59118']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d4804372-00f9-4bee-8f46-4d023b4efaf7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-59124",
      "pattern": "[vulnerability:name = 'CVE-2026-59124']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--49683995-8025-4f2c-998d-29ee84acf3cb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-59132",
      "pattern": "[vulnerability:name = 'CVE-2026-59132']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--994590fa-ff34-403b-bb7b-c57970b12ed3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-59133",
      "pattern": "[vulnerability:name = 'CVE-2026-59133']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1aac3319-bb0d-427b-8702-6218df6eb6c7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-61348",
      "pattern": "[vulnerability:name = 'CVE-2026-61348']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c7632497-f027-4dec-84dc-991411b152dd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-61358",
      "pattern": "[vulnerability:name = 'CVE-2026-61358']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--09db548b-e44b-4ff3-96ef-cc10e14b2bf2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-61925",
      "pattern": "[vulnerability:name = 'CVE-2026-61925']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a4660914-b256-4ddc-ad90-f7cdb61d0a54",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-61929",
      "pattern": "[vulnerability:name = 'CVE-2026-61929']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d7e0825f-ae61-43e0-b068-ab9c88e82c14",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-61930",
      "pattern": "[vulnerability:name = 'CVE-2026-61930']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb2d210f-b8c2-48ee-ae62-aa4d82b2fd39",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62688",
      "pattern": "[vulnerability:name = 'CVE-2026-62688']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c013f9ae-aea6-45f2-8e44-18efb153ce3c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62696",
      "pattern": "[vulnerability:name = 'CVE-2026-62696']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da6cca21-628d-4de4-bfb8-b953794d31ba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62698",
      "pattern": "[vulnerability:name = 'CVE-2026-62698']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a276992d-f038-46a2-a70e-a846f526d6cd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62712",
      "pattern": "[vulnerability:name = 'CVE-2026-62712']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f05f54ab-9bb6-4bb6-8208-089d0a2abe2d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62713",
      "pattern": "[vulnerability:name = 'CVE-2026-62713']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea0fe9a7-56fd-4e5c-b768-7b4518b3eea2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62721",
      "pattern": "[vulnerability:name = 'CVE-2026-62721']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe804d3b-72ae-4110-ad21-ca2c90d3ed56",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62735",
      "pattern": "[vulnerability:name = 'CVE-2026-62735']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2019adec-9fa5-426e-8434-0a3eedfce33a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62737",
      "pattern": "[vulnerability:name = 'CVE-2026-62737']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d197193-7935-4170-9a37-5a9b623feb2c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62741",
      "pattern": "[vulnerability:name = 'CVE-2026-62741']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b4aab3d9-d7b6-4478-8154-ad9fa6b65566",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62766",
      "pattern": "[vulnerability:name = 'CVE-2026-62766']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--10bffe7c-0e34-47e5-9cfd-c92bab2a5248",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62783",
      "pattern": "[vulnerability:name = 'CVE-2026-62783']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2e56d5ba-af93-44ef-95db-96f3810bc0e0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62788",
      "pattern": "[vulnerability:name = 'CVE-2026-62788']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ce4e0d99-3630-4795-8bc4-d5c7b8797691",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62815",
      "pattern": "[vulnerability:name = 'CVE-2026-62815']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2007078c-110d-4abe-9403-990fb214da89",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62816",
      "pattern": "[vulnerability:name = 'CVE-2026-62816']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2b553319-d355-40ec-ae73-fd4c6d8f87bd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62817",
      "pattern": "[vulnerability:name = 'CVE-2026-62817']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe6493a6-303d-480b-992c-7731b9f11800",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62818",
      "pattern": "[vulnerability:name = 'CVE-2026-62818']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c688886f-961a-45e4-ac55-2ed774d94511",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62819",
      "pattern": "[vulnerability:name = 'CVE-2026-62819']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e17bc69-e74c-4881-99b2-3089032dfd49",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62820",
      "pattern": "[vulnerability:name = 'CVE-2026-62820']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b23f6121-1a92-41b7-8057-d9305621d1c3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62822",
      "pattern": "[vulnerability:name = 'CVE-2026-62822']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--acb395c2-2278-453b-bceb-27670836c80a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62823",
      "pattern": "[vulnerability:name = 'CVE-2026-62823']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--10395ffd-7a19-4e03-adbb-002bb91eb058",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62824",
      "pattern": "[vulnerability:name = 'CVE-2026-62824']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c2d90e04-dfa2-4987-82eb-96dc8f9b05f6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62827",
      "pattern": "[vulnerability:name = 'CVE-2026-62827']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--234d19b2-bfd2-4401-8b28-30384cbdb690",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62830",
      "pattern": "[vulnerability:name = 'CVE-2026-62830']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e5f2379d-84db-47a8-8620-1ed93700f64d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62836",
      "pattern": "[vulnerability:name = 'CVE-2026-62836']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ecf2e487-646b-496d-a63b-c2ffed30b9df",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62869",
      "pattern": "[vulnerability:name = 'CVE-2026-62869']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e0d606e5-df37-451d-9ae8-4adaaf797835",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62873",
      "pattern": "[vulnerability:name = 'CVE-2026-62873']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4e329c39-162f-41fe-b812-b6e28888cef2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62878",
      "pattern": "[vulnerability:name = 'CVE-2026-62878']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d79982a-d194-4ef6-ad80-f323fed1bdda",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62888",
      "pattern": "[vulnerability:name = 'CVE-2026-62888']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--93b96ad7-0e24-42db-9959-858871ad5e19",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62889",
      "pattern": "[vulnerability:name = 'CVE-2026-62889']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2c95df3a-646a-499d-9c8f-5a9f9396daa7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62890",
      "pattern": "[vulnerability:name = 'CVE-2026-62890']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--123c6d28-a776-4baf-b89d-5831f8ce3b43",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62893",
      "pattern": "[vulnerability:name = 'CVE-2026-62893']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--234ec187-595f-4008-83cd-a064838302d6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62896",
      "pattern": "[vulnerability:name = 'CVE-2026-62896']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe1281d8-a317-441b-a298-ddc92f33849f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62911",
      "pattern": "[vulnerability:name = 'CVE-2026-62911']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--574bcc06-83fa-4ce8-9b3f-5c2aa763be24",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62918",
      "pattern": "[vulnerability:name = 'CVE-2026-62918']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d68786a7-8d4e-4dda-8e8f-21768c413d52",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-63508",
      "pattern": "[vulnerability:name = 'CVE-2026-63508']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6b4bdd03-0b16-4e31-9ce3-776fcefe06cc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-63513",
      "pattern": "[vulnerability:name = 'CVE-2026-63513']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--97d290e3-19ef-4c6e-996a-d28a64e4987f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-63515",
      "pattern": "[vulnerability:name = 'CVE-2026-63515']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3c2481f1-e04c-4131-a19e-ab02c882b099",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-63518",
      "pattern": "[vulnerability:name = 'CVE-2026-63518']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b8183713-e2e8-4737-8ca2-9d225f9255af",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-63519",
      "pattern": "[vulnerability:name = 'CVE-2026-63519']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4d4dd6f-b4d3-4ab8-9236-e66d2f73e527",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-63520",
      "pattern": "[vulnerability:name = 'CVE-2026-63520']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ca49d90e-313a-4a5f-8636-ac7461213c1f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-63522",
      "pattern": "[vulnerability:name = 'CVE-2026-63522']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ba3237df-ca2d-4269-9b86-65a9274f2919",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-63525",
      "pattern": "[vulnerability:name = 'CVE-2026-63525']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8de0be2e-805f-4cfa-8761-f8dcccd12dd2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-63526",
      "pattern": "[vulnerability:name = 'CVE-2026-63526']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1b0ba5a5-4a61-477f-b330-0de99fbd431e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-63532",
      "pattern": "[vulnerability:name = 'CVE-2026-63532']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3ee58101-e59f-43e5-adc1-248d27d9e08b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-64898",
      "pattern": "[vulnerability:name = 'CVE-2026-64898']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7aae826b-36fa-497a-8ab3-74233ff99f7d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-64903",
      "pattern": "[vulnerability:name = 'CVE-2026-64903']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--acbd9295-9999-4f82-aff6-a0a13ac28dc2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-64907",
      "pattern": "[vulnerability:name = 'CVE-2026-64907']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--35000395-a785-488b-9bbe-a6a014916c56",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-64909",
      "pattern": "[vulnerability:name = 'CVE-2026-64909']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c58aba45-d8f9-4b77-8e29-54d849577095",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-64910",
      "pattern": "[vulnerability:name = 'CVE-2026-64910']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--381f53a6-b2a3-4e8c-ada7-32b3d0c9b172",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-64911",
      "pattern": "[vulnerability:name = 'CVE-2026-64911']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7ade5617-7e8e-421c-8efb-01cb1371b46b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-64921",
      "pattern": "[vulnerability:name = 'CVE-2026-64921']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8e35f827-45b4-4c66-8200-8086a256c20d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-65657",
      "pattern": "[vulnerability:name = 'CVE-2026-65657']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--78b3ec5e-448e-4c64-ae48-6316fc8868ff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-65664",
      "pattern": "[vulnerability:name = 'CVE-2026-65664']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--46703039-b4e4-48a6-997f-311762ecf18d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-65665",
      "pattern": "[vulnerability:name = 'CVE-2026-65665']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dbc8e177-cb9a-4ba4-91f6-e52c8115d715",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-65667",
      "pattern": "[vulnerability:name = 'CVE-2026-65667']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--42077fd9-00cf-42ba-82c0-f57c1ba9bf14",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-65668",
      "pattern": "[vulnerability:name = 'CVE-2026-65668']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a9c01763-0427-4227-ad13-a99848e7a766",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-65775",
      "pattern": "[vulnerability:name = 'CVE-2026-65775']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f9b7dfd1-9db1-48d0-b4b4-969e8dac5c9e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-65788",
      "pattern": "[vulnerability:name = 'CVE-2026-65788']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--50b2afb4-2812-4e97-b6d8-131dfe76401a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-65789",
      "pattern": "[vulnerability:name = 'CVE-2026-65789']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3e93d78d-cde0-49bf-bf9a-7286faf753bf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-65791",
      "pattern": "[vulnerability:name = 'CVE-2026-65791']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9e1f6b42-64a9-441b-ae81-c39770c2a70c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-66799",
      "pattern": "[vulnerability:name = 'CVE-2026-66799']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--10fb5973-4155-4711-a06a-984987f0d34d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-66802",
      "pattern": "[vulnerability:name = 'CVE-2026-66802']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0ac19891-648d-4f92-8ef8-b072d5f3d372",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-66804",
      "pattern": "[vulnerability:name = 'CVE-2026-66804']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--24941919-09a5-40db-8419-e17df6b3f3bd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-66807",
      "pattern": "[vulnerability:name = 'CVE-2026-66807']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7178650f-0b9f-4057-b1d9-ac14e8d009d2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-68794",
      "pattern": "[vulnerability:name = 'CVE-2026-68794']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5b96ac0-6060-4075-82a4-205caee1a58f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-68804",
      "pattern": "[vulnerability:name = 'CVE-2026-68804']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e2b9dc85-e891-4713-9e5c-32090549e5c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-68816",
      "pattern": "[vulnerability:name = 'CVE-2026-68816']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fc1829c8-630a-41fd-b57f-783aa549f9d7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-68823",
      "pattern": "[vulnerability:name = 'CVE-2026-68823']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6467282-12c0-4969-b754-db1e348e1af4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-69278",
      "pattern": "[vulnerability:name = 'CVE-2026-69278']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--13d06c04-a0d9-43e1-8756-25b168b82a5b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-70130",
      "pattern": "[vulnerability:name = 'CVE-2026-70130']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5213693-85dc-4845-80e5-0e13ed3233f6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-70307",
      "pattern": "[vulnerability:name = 'CVE-2026-70307']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--29001077-44ec-4d60-8a72-dcf4c990f234",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-70332",
      "pattern": "[vulnerability:name = 'CVE-2026-70332']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--263e3fe0-41e7-48bf-97e9-df1407461859",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-70335",
      "pattern": "[vulnerability:name = 'CVE-2026-70335']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fc454b79-e602-44cf-b840-8364372d3aec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-70355",
      "pattern": "[vulnerability:name = 'CVE-2026-70355']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aad07770-891a-4d9b-a162-6b2ff5aeb97f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-71331",
      "pattern": "[vulnerability:name = 'CVE-2026-71331']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-",
          "url": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e9dcff54-8997-4dc1-b729-061b2cbbde77",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-72898",
      "pattern": "[vulnerability:name = 'CVE-2026-72898']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-72898 \u2014 Metabase SQL Injection Vulnerabil",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4715ad1c-b79d-4b0b-a167-89ea4f9a3678",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-73080",
      "pattern": "[vulnerability:name = 'CVE-2026-73080']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-73080: SeaweedFS: Unauthenticated",
          "url": "https://github.com/advisories/GHSA-87fv-vqqr-m4jr"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ef378840-46b8-4481-830b-1f2a0f0924ca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: 0xrpc.io",
      "pattern": "[domain-name:value = '0xrpc.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--546806a7-f78f-44cc-98a4-2bddb2883ea4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: avax.rpcuniverse.com",
      "pattern": "[domain-name:value = 'avax.rpcuniverse.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3624e3ba-8f33-44d2-abd6-159f6ac540b1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: bright-deals.site",
      "pattern": "[domain-name:value = 'bright-deals.site']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8e2904c-aa1e-4465-858b-f4b9b4e822b8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cosmetic-deals.store",
      "pattern": "[domain-name:value = 'cosmetic-deals.store']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e4ff51a4-dfe1-4f16-98de-855b49aa0354",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: edctgwib2n5l34t525zkxqzk5bqb6e5il2yiq5r6zu7gtlxa4uosn3qd.onion",
      "pattern": "[domain-name:value = 'edctgwib2n5l34t525zkxqzk5bqb6e5il2yiq5r6zu7gtlxa4uosn3qd.onion']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Lik",
          "url": "https://thehackernews.com/2026/08/kimwolf-v7-android-botnet-makes-http2.html"
        },
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News",
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1485a181-e8c9-408a-b605-2389925a79e3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: eth-protect.rpc.blxrbdn.com",
      "pattern": "[domain-name:value = 'eth-protect.rpc.blxrbdn.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--07f9075e-d048-4e35-82fa-065a33315dea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: eth.llamarpc.com",
      "pattern": "[domain-name:value = 'eth.llamarpc.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c5bbbfa5-162b-4d3e-87d9-2729f444fa52",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: eth.merkle.io",
      "pattern": "[domain-name:value = 'eth.merkle.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--25127747-f23e-4354-9f51-aada3c1e070b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: eth.rpcuniverse.com",
      "pattern": "[domain-name:value = 'eth.rpcuniverse.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--134d49dc-c94d-47c9-83a7-d32ad963cffc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ethereum-rpc.publicnode.com",
      "pattern": "[domain-name:value = 'ethereum-rpc.publicnode.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5539cc96-065a-44ae-b841-ed9ddc88c8e2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: flexish.shop",
      "pattern": "[domain-name:value = 'flexish.shop']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--18936623-b441-498d-9b6c-e4b28f508479",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: media-hub.today",
      "pattern": "[domain-name:value = 'media-hub.today']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2a6fbb7d-ddf0-4b49-bc0c-d91024cfa713",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: nova-stream.site",
      "pattern": "[domain-name:value = 'nova-stream.site']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d921c726-0f5c-4631-be3f-13b10d7f2d96",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: penzadogshelter.site",
      "pattern": "[domain-name:value = 'penzadogshelter.site']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1ccdfab5-c9ca-42cc-aa98-37e90539f81f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: rinomobile.ink",
      "pattern": "[domain-name:value = 'rinomobile.ink']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b92f27de-0130-4aaf-acbf-51f0f3d683fd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: rpcuniverse.com",
      "pattern": "[domain-name:value = 'rpcuniverse.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3ff006cc-fa7f-464c-9ef6-f6575be0b11d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: soprasteria-bg.com",
      "pattern": "[domain-name:value = 'soprasteria-bg.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VP",
          "url": "https://thehackernews.com/2026/08/sandworm-linked-uac-0145-uses-fake-job.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--26892901-09fd-42be-b165-66dedb5618b8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sourceforge.net",
      "pattern": "[domain-name:value = 'sourceforge.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VP",
          "url": "https://thehackernews.com/2026/08/sandworm-linked-uac-0145-uses-fake-job.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--681214c8-8fec-4f33-9100-b67cac659975",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: trendy-market.site",
      "pattern": "[domain-name:value = 'trendy-market.site']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--940fdc3e-fa8e-4213-b0b8-9608a11b49b4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: urbanpixel.store",
      "pattern": "[domain-name:value = 'urbanpixel.store']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e7b034ca-fd1a-4783-a785-891eaa08e8a5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: vks.gossopka.forum",
      "pattern": "[domain-name:value = 'vks.gossopka.forum']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--05f34efa-0327-47d9-a1a4-3e60b299346e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.87.239.71",
      "pattern": "[ipv4-addr:value = '194.87.239.71']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de7f35ed-964b-4f34-a668-2b835ceb3ee2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.87.93.153",
      "pattern": "[ipv4-addr:value = '194.87.93.153']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ecdbf738-3052-44a6-b2de-baf4a7e14889",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 212.193.31.102",
      "pattern": "[ipv4-addr:value = '212.193.31.102']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3027d612-7678-4d75-b6cf-2db75c2750f9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 212.193.31.119",
      "pattern": "[ipv4-addr:value = '212.193.31.119']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c7def262-4d12-4aaf-b271-dcd24fb296e4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 212.193.31.122",
      "pattern": "[ipv4-addr:value = '212.193.31.122']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f034448-8a3e-4330-bae6-e128c0991962",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 212.193.31.158",
      "pattern": "[ipv4-addr:value = '212.193.31.158']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bd10b279-1e7e-4e80-ae7c-528122511919",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 212.193.31.92",
      "pattern": "[ipv4-addr:value = '212.193.31.92']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c804401f-7410-4369-a356-705e7d5f4f76",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.94.221.104",
      "pattern": "[ipv4-addr:value = '23.94.221.104']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--98b4907e-3a3e-4ffb-8244-91ad4fd2ca5a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 31.59.102.61",
      "pattern": "[ipv4-addr:value = '31.59.102.61']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e67002ca-10e0-410d-9413-0994b7113989",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.244.205.244",
      "pattern": "[ipv4-addr:value = '38.244.205.244']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b348076-052a-4d29-9468-9be02fa5463d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 81.177.32.12",
      "pattern": "[ipv4-addr:value = '81.177.32.12']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b5967fea-42fc-40cb-91cb-9ab20d0176fa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 036bcb62be72c4663b9564955f93b05f",
      "pattern": "[file:hashes.MD5 = '036bcb62be72c4663b9564955f93b05f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--95cc0a37-a57a-45f6-90cb-53d1f0ff6429",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 0e4541c3153ec5ed01497f19cf4f63d0",
      "pattern": "[file:hashes.MD5 = '0e4541c3153ec5ed01497f19cf4f63d0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--29fdf96a-948b-456a-ad6a-aaddf789b97b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 0e79996d9483d1e44fea32b0a48c2c19",
      "pattern": "[file:hashes.MD5 = '0e79996d9483d1e44fea32b0a48c2c19']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9433b806-0421-49ae-9963-f5ab934cd801",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 129462164a7d52e9ea8560b60f0412c5",
      "pattern": "[file:hashes.MD5 = '129462164a7d52e9ea8560b60f0412c5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--70d040b3-0db0-4cb4-80b8-7b3fb3522c54",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 12d4e8f5295f2ef7e0f9bfc0f4830939",
      "pattern": "[file:hashes.MD5 = '12d4e8f5295f2ef7e0f9bfc0f4830939']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53f1c3bb-53ff-44bf-9af7-a76a1954e2f5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 2bb75c20e778eb5c416965bd4d4259b1",
      "pattern": "[file:hashes.MD5 = '2bb75c20e778eb5c416965bd4d4259b1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1d872ada-5cfc-47a9-99b4-a63fb74a3b97",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 33faca1e0090f6b12eff703daf4606e4",
      "pattern": "[file:hashes.MD5 = '33faca1e0090f6b12eff703daf4606e4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--13064b6c-784f-4312-832b-669f5570d435",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 43f435c3c437bc879a2d7d4634f43494",
      "pattern": "[file:hashes.MD5 = '43f435c3c437bc879a2d7d4634f43494']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87419fd9-09b5-4500-bc65-d1534763003a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 489f43be558b2679284ceabed7adc4f3",
      "pattern": "[file:hashes.MD5 = '489f43be558b2679284ceabed7adc4f3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--181b3b18-9082-4fda-9c89-98e296e16bc6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 4d27b4eb1c5dbb3d8160f29b8119523e",
      "pattern": "[file:hashes.MD5 = '4d27b4eb1c5dbb3d8160f29b8119523e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67ede347-b6fb-45ff-99bf-5af0c34528e5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 748c9f8cb1065000616204935f96207f",
      "pattern": "[file:hashes.MD5 = '748c9f8cb1065000616204935f96207f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--39c0251b-e0ee-4bb9-9017-49d347b5ae19",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 76554ad09897ac723a850eaf8c525efa",
      "pattern": "[file:hashes.MD5 = '76554ad09897ac723a850eaf8c525efa']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--724ef749-7276-4057-a79a-8811eefcb926",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 7f267006cac10f341c356b62fe493527",
      "pattern": "[file:hashes.MD5 = '7f267006cac10f341c356b62fe493527']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--22717638-c2b2-4d11-b783-2d12114ada08",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 8fcc3e4ccbf1725d9989fb464abf3561",
      "pattern": "[file:hashes.MD5 = '8fcc3e4ccbf1725d9989fb464abf3561']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ba38097a-4bf3-4569-9387-6f690222d749",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: aee9642b45b099cb7f3053b9b680b425",
      "pattern": "[file:hashes.MD5 = 'aee9642b45b099cb7f3053b9b680b425']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--02a47fb0-c390-4a29-8470-48f9d0a9200a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: b348642146ea34771e5785c5857950f5",
      "pattern": "[file:hashes.MD5 = 'b348642146ea34771e5785c5857950f5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--517918eb-f10e-41d2-b8cc-738ccb3319ed",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: b3a6fee3307f1c26841fd5c603e2b013",
      "pattern": "[file:hashes.MD5 = 'b3a6fee3307f1c26841fd5c603e2b013']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9e54c806-27a4-472f-af01-d607a768de3f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: c3a2abe8756910f42582b04a44ea3514",
      "pattern": "[file:hashes.MD5 = 'c3a2abe8756910f42582b04a44ea3514']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87918583-23e3-491b-a27d-fabacf37c7b4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: c5a460e4e68a088f6e51b2c6474642ec",
      "pattern": "[file:hashes.MD5 = 'c5a460e4e68a088f6e51b2c6474642ec']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ac6b662a-c778-4c73-9199-ca4b1fd5a7a1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: c915cb6c2aeb863ee8479238e1644217",
      "pattern": "[file:hashes.MD5 = 'c915cb6c2aeb863ee8479238e1644217']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--59653c6a-a707-4a45-9f7d-ad384edd8b6e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: d759364844d78a728505fb0485c3adbc",
      "pattern": "[file:hashes.MD5 = 'd759364844d78a728505fb0485c3adbc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e3e3f597-d4c1-42fc-9819-c94874dbbf3a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: dd1fd2b459b97b7d59375cb8383cd19a",
      "pattern": "[file:hashes.MD5 = 'dd1fd2b459b97b7d59375cb8383cd19a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c4ef5f6-31da-406e-a7ea-c9a342048187",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: ec0bf4a2186a88874e9f26f07cfeb532",
      "pattern": "[file:hashes.MD5 = 'ec0bf4a2186a88874e9f26f07cfeb532']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2a3fa1e6-2db2-4848-8c26-a608e8f63eb5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: ee2861d5965e8730708cd1da8a93fa4c",
      "pattern": "[file:hashes.MD5 = 'ee2861d5965e8730708cd1da8a93fa4c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Head Mare APT is exploiting vulnerabilities in an unpatched ",
          "url": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--165f1292-ab95-45d3-9fc8-f5cc2e76272c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 14F26682D0916CDD81E37B6D61B7B526D98F0353",
      "pattern": "[file:hashes.'SHA-1' = '14F26682D0916CDD81E37B6D61B7B526D98F0353']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mozilla Revokes Firefox and Thunderbird Linux Signing Key Af",
          "url": "https://thehackernews.com/2026/08/mozilla-revokes-firefox-and-thunderbird.html"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c45cfd4-5e0e-4b0d-b009-55f04768153a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 2a1d96f1b066877812587ac94f45f82dfff5f5f9",
      "pattern": "[file:hashes.'SHA-1' = '2a1d96f1b066877812587ac94f45f82dfff5f5f9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6ac761e-1d6e-464d-aae0-95a71852bd22",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2ec2e85b0358e0c681cb5067489a9086ec97dbbf7e3c952dd9cd496b319d5af5",
      "pattern": "[file:hashes.'SHA-256' = '2ec2e85b0358e0c681cb5067489a9086ec97dbbf7e3c952dd9cd496b319d5af5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f6a7270b-fd94-48f5-b49c-4356783a5fb1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 345222bca004595977f971d76900b0c65fd9bf9d91c50cd0c5bf5a93f1ad9e49",
      "pattern": "[file:hashes.'SHA-256' = '345222bca004595977f971d76900b0c65fd9bf9d91c50cd0c5bf5a93f1ad9e49']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c3ea945-035c-47dd-8402-0cc94acaa4e0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 406647de09a0ffa279756b4ccb344b1b76a333320c5b50fd367901fa006cf0ff",
      "pattern": "[file:hashes.'SHA-256' = '406647de09a0ffa279756b4ccb344b1b76a333320c5b50fd367901fa006cf0ff']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cda190a0-ff93-4744-88cc-7915d68a6eeb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 421111a57b0a4224c052fa4108d90429d579974b5b5111ed2e58516ba09422ca",
      "pattern": "[file:hashes.'SHA-256' = '421111a57b0a4224c052fa4108d90429d579974b5b5111ed2e58516ba09422ca']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a4937541-24dd-43a3-8961-113db4c910b3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8242443dfcec66e3fe04cbfa2fbd211ad34065ee07aa93813d792a437caab212",
      "pattern": "[file:hashes.'SHA-256' = '8242443dfcec66e3fe04cbfa2fbd211ad34065ee07aa93813d792a437caab212']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4b4ca4a7-6e9e-4594-a9bf-1f73c8c92f02",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9470c68f9b6fe5f90d61891b95623afd7b4298815b0f95e25610e1c09008dc24",
      "pattern": "[file:hashes.'SHA-256' = '9470c68f9b6fe5f90d61891b95623afd7b4298815b0f95e25610e1c09008dc24']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a35f3992-b8c5-4928-9b54-6626741118b6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 951c94809aa6c7ab587125f9d4df30fa6a49ee0cbba76a4b7ceedaaa0e5dcd36",
      "pattern": "[file:hashes.'SHA-256' = '951c94809aa6c7ab587125f9d4df30fa6a49ee0cbba76a4b7ceedaaa0e5dcd36']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--37b9283e-3b29-4b8b-933d-c7cc33573141",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f07821e313c16cbbd82def45094a22c8d474164051bdbc7648d6869e012014b4",
      "pattern": "[file:hashes.'SHA-256' = 'f07821e313c16cbbd82def45094a22c8d474164051bdbc7648d6869e012014b4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bf4d2ad3-88f7-4dc7-a0ae-37ecca9aab57",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f3e8a55a2a3ea7c7b6676e90f4f49a2c55b13065b68ee50c51cc35fe2b5c3237",
      "pattern": "[file:hashes.'SHA-256' = 'f3e8a55a2a3ea7c7b6676e90f4f49a2c55b13065b68ee50c51cc35fe2b5c3237']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "url": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f1b1ae7b-62ab-40e7-bb6a-b263a52007d7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: api.studiotikva.com",
      "pattern": "[domain-name:value = 'api.studiotikva.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Project CAV3RN continues: Google Apps Script as C2 relay and",
          "url": "https://securelist.com/project-cav3rn-continues/120991/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--266dd469-1048-442e-a240-2204cb4eec5c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: m.studiotikva.com",
      "pattern": "[domain-name:value = 'm.studiotikva.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Project CAV3RN continues: Google Apps Script as C2 relay and",
          "url": "https://securelist.com/project-cav3rn-continues/120991/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ca9ced47-05d4-40ab-b91d-e55329f18086",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ns1.studiotikva.com",
      "pattern": "[domain-name:value = 'ns1.studiotikva.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Project CAV3RN continues: Google Apps Script as C2 relay and",
          "url": "https://securelist.com/project-cav3rn-continues/120991/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ebcf1282-ffbc-4456-9168-5e27428efb53",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ns2.studiotikva.com",
      "pattern": "[domain-name:value = 'ns2.studiotikva.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Project CAV3RN continues: Google Apps Script as C2 relay and",
          "url": "https://securelist.com/project-cav3rn-continues/120991/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8dfa2a37-efa8-4dfc-94eb-238f399f332d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: p.studiotikva.com",
      "pattern": "[domain-name:value = 'p.studiotikva.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Project CAV3RN continues: Google Apps Script as C2 relay and",
          "url": "https://securelist.com/project-cav3rn-continues/120991/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2804e61a-17f1-4326-9e71-4053246f1c9d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: q.studiotikva.com",
      "pattern": "[domain-name:value = 'q.studiotikva.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Project CAV3RN continues: Google Apps Script as C2 relay and",
          "url": "https://securelist.com/project-cav3rn-continues/120991/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--35e84550-1cae-4db0-8b8e-50a4893085dc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: script.googleusercontent.com",
      "pattern": "[domain-name:value = 'script.googleusercontent.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Project CAV3RN continues: Google Apps Script as C2 relay and",
          "url": "https://securelist.com/project-cav3rn-continues/120991/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--66fa8f4e-1262-4f09-ba1f-73d5f6086dce",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ycz2.41414141303030.m.studiotikva.com",
      "pattern": "[domain-name:value = 'ycz2.41414141303030.m.studiotikva.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Project CAV3RN continues: Google Apps Script as C2 relay and",
          "url": "https://securelist.com/project-cav3rn-continues/120991/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b29abc98-5517-4b8c-b329-908de11d7548",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 12.121.234.120",
      "pattern": "[ipv4-addr:value = '12.121.234.120']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Project CAV3RN continues: Google Apps Script as C2 relay and",
          "url": "https://securelist.com/project-cav3rn-continues/120991/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0cc786b-7132-4bdd-9c81-f12ab5ca8991",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 12.19.29.30",
      "pattern": "[ipv4-addr:value = '12.19.29.30']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Project CAV3RN continues: Google Apps Script as C2 relay and",
          "url": "https://securelist.com/project-cav3rn-continues/120991/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--356a8056-76f3-4c3a-bb80-625c5f52eb20",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 138.226.236.51",
      "pattern": "[ipv4-addr:value = '138.226.236.51']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DeadLock Ransomware Uses Polygon Smart Contracts to Make Ext",
          "url": "https://thehackernews.com/2026/08/deadlock-ransomware-uses-polygon-smart.html"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "The Hacker News"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--81d9eae0-3ec7-4e92-aa48-6681b8e99323",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 144.172.104.82",
      "pattern": "[ipv4-addr:value = '144.172.104.82']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Project CAV3RN continues: Google Apps Script as C2 relay and",
          "url": "https://securelist.com/project-cav3rn-continues/120991/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb1a0367-7228-472d-b228-c084e80abf24",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 144.172.115.17",
      "pattern": "[ipv4-addr:value = '144.172.115.17']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Project CAV3RN continues: Google Apps Script as C2 relay and",
          "url": "https://securelist.com/project-cav3rn-continues/120991/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c611360-abe0-474f-9519-074f45919e33",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 74.65.75.102",
      "pattern": "[ipv4-addr:value = '74.65.75.102']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Project CAV3RN continues: Google Apps Script as C2 relay and",
          "url": "https://securelist.com/project-cav3rn-continues/120991/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--db45e8bd-81f8-4e84-8f5c-f26f44e58ba5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 2dcd4a8ac166404977cd3c48418a8cd9",
      "pattern": "[file:hashes.MD5 = '2dcd4a8ac166404977cd3c48418a8cd9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Project CAV3RN continues: Google Apps Script as C2 relay and",
          "url": "https://securelist.com/project-cav3rn-continues/120991/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--14c0be9e-5209-479b-90cd-66c89b3a6ff7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 34d50eec364d920b8b5d885c9bc98607",
      "pattern": "[file:hashes.MD5 = '34d50eec364d920b8b5d885c9bc98607']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Project CAV3RN continues: Google Apps Script as C2 relay and",
          "url": "https://securelist.com/project-cav3rn-continues/120991/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d4bd171-1c56-4dd0-94de-aae776610b2f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 904784c9943d019da332bea2cd03996f",
      "pattern": "[file:hashes.MD5 = '904784c9943d019da332bea2cd03996f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Project CAV3RN continues: Google Apps Script as C2 relay and",
          "url": "https://securelist.com/project-cav3rn-continues/120991/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--df077633-c019-46db-b0a5-867002f1588e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 981c7404d31b8ce35ec88a6b290f354d",
      "pattern": "[file:hashes.MD5 = '981c7404d31b8ce35ec88a6b290f354d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Project CAV3RN continues: Google Apps Script as C2 relay and",
          "url": "https://securelist.com/project-cav3rn-continues/120991/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--73c9e69e-ae45-4d7f-a391-2c98d7850f2d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: f9156d42410c8a5429dec43329bd72e0",
      "pattern": "[file:hashes.MD5 = 'f9156d42410c8a5429dec43329bd72e0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Project CAV3RN continues: Google Apps Script as C2 relay and",
          "url": "https://securelist.com/project-cav3rn-continues/120991/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ab9044ff-ef84-406d-bf41-efd8b3285640",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-33825",
      "pattern": "[vulnerability:name = 'CVE-2026-33825']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "IT threat evolution in Q2 2026. Non-mobile statistics",
          "url": "https://securelist.com/malware-report-q2-2026-pc-iot-statistics/120960/"
        },
        {
          "source_name": "CISA KEV: CVE-2026-33825 \u2014 Microsoft Defender Insufficient G",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--120f20c1-ed75-497e-8fd9-29332d5adcb4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-50751",
      "pattern": "[vulnerability:name = 'CVE-2026-50751']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "IT threat evolution in Q2 2026. Non-mobile statistics",
          "url": "https://securelist.com/malware-report-q2-2026-pc-iot-statistics/120960/"
        },
        {
          "source_name": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Impr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1e55da48-0fd7-4db0-94e7-1c343f355aee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-50752",
      "pattern": "[vulnerability:name = 'CVE-2026-50752']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "IT threat evolution in Q2 2026. Non-mobile statistics",
          "url": "https://securelist.com/malware-report-q2-2026-pc-iot-statistics/120960/"
        },
        {
          "source_name": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Impr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--69facbb2-dfeb-41bf-b206-3ca4484abcaa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: 1rpc.io",
      "pattern": "[domain-name:value = '1rpc.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DeadLock ransomware: Breaking down a Rust-based encryptor wi",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e9fd710c-8600-4673-a767-4b12440cba79",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: api.noderpc.xyz",
      "pattern": "[domain-name:value = 'api.noderpc.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76a9537f-1ff6-4240-bf3d-cf0ecb3ca6ca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: api.zan.top",
      "pattern": "[domain-name:value = 'api.zan.top']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--796ede9e-d8c9-4340-aa9f-ce2f228d0b1e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cdnjsdelivr.beer",
      "pattern": "[domain-name:value = 'cdnjsdelivr.beer']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--97053c02-1a33-4be6-96c2-2d69a6e0d0c6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion",
      "pattern": "[domain-name:value = 'deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DeadLock ransomware: Breaking down a Rust-based encryptor wi",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c49cd6f8-4d53-40ac-8775-e18bb32715a9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: deadlock.liveblog365.com",
      "pattern": "[domain-name:value = 'deadlock.liveblog365.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DeadLock ransomware: Breaking down a Rust-based encryptor wi",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1b8d6f10-1ebf-463f-a58c-bfae7c7585fb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: deadlockblog.great-site.net",
      "pattern": "[domain-name:value = 'deadlockblog.great-site.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DeadLock ransomware: Breaking down a Rust-based encryptor wi",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--31c8f23d-c204-40d6-85db-425dabdaa2e2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: deadlockblog.medianewsonline.com",
      "pattern": "[domain-name:value = 'deadlockblog.medianewsonline.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DeadLock ransomware: Breaking down a Rust-based encryptor wi",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--79dc7f69-4844-4b27-9eff-75a6c01f14b5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: dlock.liveblog365.com",
      "pattern": "[domain-name:value = 'dlock.liveblog365.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DeadLock ransomware: Breaking down a Rust-based encryptor wi",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c514508a-ce33-4df9-8d47-5b34d3d36456",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: download.sftp-api-group-wechat.com",
      "pattern": "[domain-name:value = 'download.sftp-api-group-wechat.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d4d7cb26-6c63-4761-bfbd-fca35cefe462",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: endpoints.omniatech.io",
      "pattern": "[domain-name:value = 'endpoints.omniatech.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--af02d9ed-00e9-4308-8b24-f4221d3ab582",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: gateway.tenderly.co",
      "pattern": "[domain-name:value = 'gateway.tenderly.co']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--db6b1522-04e6-4fc5-9682-bdc7405ea6fe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: polygon-amoy.gateway.tenderly.co",
      "pattern": "[domain-name:value = 'polygon-amoy.gateway.tenderly.co']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--29469da2-fb9a-4725-946a-7f755240ad2d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: polygon-amoy.therpc.io",
      "pattern": "[domain-name:value = 'polygon-amoy.therpc.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c8bc3233-91c5-4259-b147-46e64cd7792b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: polygon-bor-rpc.publicnode.com",
      "pattern": "[domain-name:value = 'polygon-bor-rpc.publicnode.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DeadLock ransomware: Breaking down a Rust-based encryptor wi",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cfa511bd-5910-427a-81a4-b3ad0c4f43c8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: polygon-mainnet.g.alchemy.com",
      "pattern": "[domain-name:value = 'polygon-mainnet.g.alchemy.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c65844ac-8035-4b47-a870-8a9fafe2d700",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: polygon-mumbai-bor-rpc.publicnode.com",
      "pattern": "[domain-name:value = 'polygon-mumbai-bor-rpc.publicnode.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0189c33c-c163-4cbd-92c0-4c013a6380e2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: polygon-mumbai.g.alchemy.com",
      "pattern": "[domain-name:value = 'polygon-mumbai.g.alchemy.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc96444e-f96d-4c43-a660-6ba8293863fe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: polygon-mumbai.gateway.tenderly.co",
      "pattern": "[domain-name:value = 'polygon-mumbai.gateway.tenderly.co']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a685801a-eebc-46d7-b7c7-ffcd24efacd5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: polygon-pokt.nodies.app",
      "pattern": "[domain-name:value = 'polygon-pokt.nodies.app']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        },
        {
          "source_name": "DeadLock ransomware: Breaking down a Rust-based encryptor wi",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)",
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--21c2e235-25f1-4bb3-bd63-a1315d1ab0d9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: polygon-rpc.com",
      "pattern": "[domain-name:value = 'polygon-rpc.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DeadLock ransomware: Breaking down a Rust-based encryptor wi",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/"
        },
        {
          "source_name": "Begun, the Patch Wars have",
          "url": "https://blog.talosintelligence.com/begun-the-patch-wars-have/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog",
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1db132fe-6980-497b-b74e-b745d707f8bd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: polygon-zkevm-mainnet.public.blastapi.io",
      "pattern": "[domain-name:value = 'polygon-zkevm-mainnet.public.blastapi.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b08636de-05e5-4120-9afd-e60e9282da50",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: polygon-zkevm.drpc.org",
      "pattern": "[domain-name:value = 'polygon-zkevm.drpc.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d9fb7c17-18c5-4fb5-82df-f3230607022e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: polygon.drpc.org",
      "pattern": "[domain-name:value = 'polygon.drpc.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DeadLock ransomware: Breaking down a Rust-based encryptor wi",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c2f1874f-b0ac-4b6d-ae28-423ebc182d6b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: polygon.meowrpc.com",
      "pattern": "[domain-name:value = 'polygon.meowrpc.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DeadLock ransomware: Breaking down a Rust-based encryptor wi",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c41f220e-5ac7-448b-93a3-6c493d777003",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: polygon.rpc.hypersync.xyz",
      "pattern": "[domain-name:value = 'polygon.rpc.hypersync.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d53007ce-ff78-4d5a-a826-468bc19e6b71",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: polygontestapi.terminet.io",
      "pattern": "[domain-name:value = 'polygontestapi.terminet.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd92f6f4-cc6d-4707-801d-83dfc3469678",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: public.stackup.sh",
      "pattern": "[domain-name:value = 'public.stackup.sh']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--49e1311e-28bb-40c2-96e5-5186a4209eb3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: rpc.polygon-zkevm.gateway.fm",
      "pattern": "[domain-name:value = 'rpc.polygon-zkevm.gateway.fm']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d4965cf5-d4f4-4eef-9643-ed823fc7b610",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: rpc.polygonsupernet.public.arianee.net",
      "pattern": "[domain-name:value = 'rpc.polygonsupernet.public.arianee.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5628ca1e-6395-48a7-8bf0-9f84e1ddd786",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: rpc.poolz.finance",
      "pattern": "[domain-name:value = 'rpc.poolz.finance']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--537e65f3-b7ed-4ea5-ac3b-5c7a8a7e55ea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sekirolegion.duckdns.org",
      "pattern": "[domain-name:value = 'sekirolegion.duckdns.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--899e8583-d2df-4175-b47e-6e26b926039a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: test-steve.cyou",
      "pattern": "[domain-name:value = 'test-steve.cyou']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f7fca4f9-e2ac-4c56-85c5-df06e9df3031",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: update-launcher.xyz",
      "pattern": "[domain-name:value = 'update-launcher.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c650a22c-d146-4288-90da-809b1fcb010e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: update.constant-path.xyz",
      "pattern": "[domain-name:value = 'update.constant-path.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1149f33f-0ebc-46a7-bfb2-17b8bff4f396",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.221.200.219",
      "pattern": "[ipv4-addr:value = '193.221.200.219']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3cc8b50b-9d2d-47e5-b174-3775f780b1f2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1505eda3da68e2ff9919b55a31018bd30a991236f041aee835f3bc4e430ce505",
      "pattern": "[file:hashes.'SHA-256' = '1505eda3da68e2ff9919b55a31018bd30a991236f041aee835f3bc4e430ce505']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f2e9a4e6-a964-4ec7-a010-962b05a6c482",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4e24bbd0fabac6c3efcec943046afbfd332b2c0108a13becfda23a0e26f9ff5f",
      "pattern": "[file:hashes.'SHA-256' = '4e24bbd0fabac6c3efcec943046afbfd332b2c0108a13becfda23a0e26f9ff5f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--44e6ccf9-cfef-4814-99ab-b079d0a7c151",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5bfb25b8255b61e5ffdf6804451534bcfa9f1dfd225e6c8cdcefb5f50d846898",
      "pattern": "[file:hashes.'SHA-256' = '5bfb25b8255b61e5ffdf6804451534bcfa9f1dfd225e6c8cdcefb5f50d846898']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4be686c4-59be-4b9e-9255-b8ecbfe61601",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 81bb80d9c5a97dc41b65f6248c131963c91346eb4fb672836b3d53ae67564d9f",
      "pattern": "[file:hashes.'SHA-256' = '81bb80d9c5a97dc41b65f6248c131963c91346eb4fb672836b3d53ae67564d9f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5deeb160-5fc5-45a7-aa84-37697133c774",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a1fdf65020ce4a0f0940c793c6425baf8a0b994ec48b9baaf72788661a9d29f4",
      "pattern": "[file:hashes.'SHA-256' = 'a1fdf65020ce4a0f0940c793c6425baf8a0b994ec48b9baaf72788661a9d29f4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DeadLock ransomware: Breaking down a Rust-based encryptor wi",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87a7e9e1-9ac8-46eb-81a3-eb8f99010f4f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ea1b6ff3a0c1a749b9f09d66789973321d63d8896b48f7345193bdad512950a2",
      "pattern": "[file:hashes.'SHA-256' = 'ea1b6ff3a0c1a749b9f09d66789973321d63d8896b48f7345193bdad512950a2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4493b504-257d-463a-9e0a-d9177e47afd2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f2a326cff405299e4ebdfaac955c52fc7e496544eaa0921ecad4816cb3ae3a27",
      "pattern": "[file:hashes.'SHA-256' = 'f2a326cff405299e4ebdfaac955c52fc7e496544eaa0921ecad4816cb3ae3a27']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based ",
          "url": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b5a795a6-e2f6-4ed1-8414-6171f821a6d0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-63221",
      "pattern": "[vulnerability:name = 'CVE-2026-63221']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-63221: CodeIgniter: SQL injection",
          "url": "https://github.com/advisories/GHSA-c9w5-rwh3-7pm9"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff1dc43e-bd6b-4c79-8bfe-7dc6c88018b7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-63223",
      "pattern": "[vulnerability:name = 'CVE-2026-63223']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-63223: CodeIgniter: Uploaded file",
          "url": "https://github.com/advisories/GHSA-mmj4-63m4-r6h5"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--596a4b29-77bc-4d42-85b6-622e68a94348",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-71851",
      "pattern": "[vulnerability:name = 'CVE-2026-71851']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-71851: crypto-js: Insufficient En",
          "url": "https://github.com/advisories/GHSA-rg76-677x-56q9"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--931d5a32-1653-4257-b85e-d309136da0ce",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-8037",
      "pattern": "[vulnerability:name = 'CVE-2026-8037']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8037 \u2014 Progress LoadMaster Command Inject",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--977ac042-019b-420e-b9a2-6a900e160942",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: ff1f0032ff58aedfcc44eb6aa7b2c78207a98009",
      "pattern": "[file:hashes.'SHA-1' = 'ff1f0032ff58aedfcc44eb6aa7b2c78207a98009']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-71851: crypto-js: Insufficient En",
          "url": "https://github.com/advisories/GHSA-rg76-677x-56q9"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--db746d8d-9767-4d45-9942-a8c76d2180ac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-48020",
      "pattern": "[vulnerability:name = 'CVE-2026-48020']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-65600: Traefik: Authentication By",
          "url": "https://github.com/advisories/GHSA-cxjq-mrr5-89rv"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f64704b3-9f10-47ce-8136-59baf4258a56",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-65600",
      "pattern": "[vulnerability:name = 'CVE-2026-65600']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-65600: Traefik: Authentication By",
          "url": "https://github.com/advisories/GHSA-cxjq-mrr5-89rv"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6bbd2c10-2710-4a97-8754-8f17c2bb04c5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: gh-token-monitor.sh",
      "pattern": "[domain-name:value = 'gh-token-monitor.sh']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ChainDrop: Inside a Self-Propagating npm Worm",
          "url": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f90dd663-dfb6-44eb-a6d2-41b694274e58",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.21.91.101",
      "pattern": "[ipv4-addr:value = '104.21.91.101']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ChainDrop: Inside a Self-Propagating npm Worm",
          "url": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bae976e3-4b64-411a-a25c-179f8c6a2cbd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.67.215.154",
      "pattern": "[ipv4-addr:value = '172.67.215.154']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ChainDrop: Inside a Self-Propagating npm Worm",
          "url": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--55fe8b1d-e4eb-40d5-bb93-80d9a2f6e2e3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668",
      "pattern": "[file:hashes.'SHA-256' = '54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ChainDrop: Inside a Self-Propagating npm Worm",
          "url": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/"
        },
        {
          "source_name": "Why metaphor may dictate your security strategy",
          "url": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/"
        },
        {
          "source_name": "ChainDrop supply chain compromise: Anatomy of a self-propaga",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)",
        "Cisco Talos",
        "Microsoft Security Blog",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f89f87c-7dc5-4ba7-9354-f2e1f5e53534",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b27b82afa5f15512f3856e549fb83d873fd0049759a4b62ce64c8d7d4dc2c678",
      "pattern": "[file:hashes.'SHA-256' = 'b27b82afa5f15512f3856e549fb83d873fd0049759a4b62ce64c8d7d4dc2c678']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ChainDrop: Inside a Self-Propagating npm Worm",
          "url": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c3e6961-0cb2-4b9e-8159-4e8c096ada64",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d30b4ea6f68456672f5abb35e9dcf7d54226372b66e9d60a7ee26b7a52568e74",
      "pattern": "[file:hashes.'SHA-256' = 'd30b4ea6f68456672f5abb35e9dcf7d54226372b66e9d60a7ee26b7a52568e74']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ChainDrop: Inside a Self-Propagating npm Worm",
          "url": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a5a03f64-f75c-4553-bce9-0115ad0ecaa5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 116.105.166.148",
      "pattern": "[ipv4-addr:value = '116.105.166.148']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Token Jacking: Cybercriminals Could Be Stealing Your AI Reso",
          "url": "https://unit42.paloaltonetworks.com/ai-token-jacking/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6be21c5-0b4b-470e-88d7-8cff55f37495",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.96.142.186",
      "pattern": "[ipv4-addr:value = '172.96.142.186']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Token Jacking: Cybercriminals Could Be Stealing Your AI Reso",
          "url": "https://unit42.paloaltonetworks.com/ai-token-jacking/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--14a734ca-71f1-43df-9a2a-fdaf4ca94435",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 3.235.109.125",
      "pattern": "[ipv4-addr:value = '3.235.109.125']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Token Jacking: Cybercriminals Could Be Stealing Your AI Reso",
          "url": "https://unit42.paloaltonetworks.com/ai-token-jacking/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b4e303c9-59ed-4a63-be1e-be0d3e6e443a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.46.219.166",
      "pattern": "[ipv4-addr:value = '38.46.219.166']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Token Jacking: Cybercriminals Could Be Stealing Your AI Reso",
          "url": "https://unit42.paloaltonetworks.com/ai-token-jacking/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5afb5b5-276b-49e7-a7f2-c799a9c1a01b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-63077",
      "pattern": "[vulnerability:name = 'CVE-2026-63077']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-63077 \u2014 JetBrains TeamCity Deserializatio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d3ab7fe-0486-4f67-8e29-ce3e264b770d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-71319",
      "pattern": "[vulnerability:name = 'CVE-2026-71319']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-71319: Unauthenticated Nuxt DevTo",
          "url": "https://github.com/advisories/GHSA-279x-mwfv-vcqv"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0c66995-e6a6-4838-8838-b36d4ed7fa2b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: applefilevault.com",
      "pattern": "[domain-name:value = 'applefilevault.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "From open lures to cloaked gates: How a macOS ClickFix campa",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e75e7ee0-7649-4726-b7a2-7e762d1e1cbd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: apricotfilepoint.com",
      "pattern": "[domain-name:value = 'apricotfilepoint.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "From open lures to cloaked gates: How a macOS ClickFix campa",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4b234051-0834-4e18-b725-c0834b4eb4fa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: bananafastfile.com",
      "pattern": "[domain-name:value = 'bananafastfile.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "From open lures to cloaked gates: How a macOS ClickFix campa",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f30a142-c33b-4820-8a4a-0decb54e9662",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cloudfilebridge.com",
      "pattern": "[domain-name:value = 'cloudfilebridge.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "From open lures to cloaked gates: How a macOS ClickFix campa",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a677499a-08d2-4884-8a45-74ad8b761cf8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cloudsendhub.com",
      "pattern": "[domain-name:value = 'cloudsendhub.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "From open lures to cloaked gates: How a macOS ClickFix campa",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a26ef76f-1bcd-408f-bcc5-c64a09c823f0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: filecedarwallet.online",
      "pattern": "[domain-name:value = 'filecedarwallet.online']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "From open lures to cloaked gates: How a macOS ClickFix campa",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1a6e80ac-fbf1-4e41-99ca-d02d34d5aa34",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: filecopperbasket.sbs",
      "pattern": "[domain-name:value = 'filecopperbasket.sbs']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "From open lures to cloaked gates: How a macOS ClickFix campa",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--70c69932-36cb-4f40-a3f6-bc9e656c8b23",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: filecrimsonsignal.online",
      "pattern": "[domain-name:value = 'filecrimsonsignal.online']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "From open lures to cloaked gates: How a macOS ClickFix campa",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--59200f24-d0d9-47e5-8862-7b2e1f470bc8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: filemarblegarden.sbs",
      "pattern": "[domain-name:value = 'filemarblegarden.sbs']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "From open lures to cloaked gates: How a macOS ClickFix campa",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--73de2dd4-0838-47ad-81b3-d2a9b38f1187",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: fileoceanhammer.sbs",
      "pattern": "[domain-name:value = 'fileoceanhammer.sbs']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "From open lures to cloaked gates: How a macOS ClickFix campa",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0d8507dd-7af3-4961-b3cb-00820145c1b7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: filerubyfolder.sbs",
      "pattern": "[domain-name:value = 'filerubyfolder.sbs']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "From open lures to cloaked gates: How a macOS ClickFix campa",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--61c2055a-b75b-42ed-a244-51877ca8b3e1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: filevelvettractor.sbs",
      "pattern": "[domain-name:value = 'filevelvettractor.sbs']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "From open lures to cloaked gates: How a macOS ClickFix campa",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5e143347-ec3c-47d3-a54b-31e597d77342",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: lemonfilewave.com",
      "pattern": "[domain-name:value = 'lemonfilewave.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "From open lures to cloaked gates: How a macOS ClickFix campa",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff7b218c-19e4-46e8-aeda-2fea81c40272",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: limefilescope.com",
      "pattern": "[domain-name:value = 'limefilescope.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "From open lures to cloaked gates: How a macOS ClickFix campa",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4ad0d698-745c-4aac-9ea1-d4c2fbaf80b9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: mangocloudfile.com",
      "pattern": "[domain-name:value = 'mangocloudfile.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "From open lures to cloaked gates: How a macOS ClickFix campa",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f5b0c17-eb78-4f53-b4c6-dc7059af682e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: orangesmartfile.com",
      "pattern": "[domain-name:value = 'orangesmartfile.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "From open lures to cloaked gates: How a macOS ClickFix campa",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c77ff0e-b110-401f-95f8-346c968c72d5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: syncdatavault.com",
      "pattern": "[domain-name:value = 'syncdatavault.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "From open lures to cloaked gates: How a macOS ClickFix campa",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--17a81c9a-7885-4385-adff-d87490a7452d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-24785",
      "pattern": "[vulnerability:name = 'CVE-2022-24785']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-69254: Flowise: RCE via NodeVM Sa",
          "url": "https://github.com/advisories/GHSA-3769-jgqc-cxm7"
        },
        {
          "source_name": "Adding Snyk security to Jira and Bitbucket Cloud",
          "url": "https://snyk.io/blog/adding-snyk-security-jira-bitbucket-cloud/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--897305e0-8fe1-4b8d-b8a6-61de50069536",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-24813",
      "pattern": "[vulnerability:name = 'CVE-2025-24813']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-34486 \u2014 Apache Tomcat Missing Encryption ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-24813 \u2014 Apache Tomcat Path Equivalence Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e02a117e-ee56-4c4e-804f-151405efa350",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-18556",
      "pattern": "[vulnerability:name = 'CVE-2026-18556']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-18556 \u2014 N-able N-central Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-18577 \u2014 N-able N-central Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b436f25c-8e8f-4c18-8d8a-60aaeeeb8e47",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-18577",
      "pattern": "[vulnerability:name = 'CVE-2026-18577']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-18556 \u2014 N-able N-central Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-18577 \u2014 N-able N-central Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c89d852-c865-4d55-939b-2498d4dfddfe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-29146",
      "pattern": "[vulnerability:name = 'CVE-2026-29146']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-34486 \u2014 Apache Tomcat Missing Encryption ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--60c5e0a3-0cb4-4130-9ef2-8a81966ed22e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-34486",
      "pattern": "[vulnerability:name = 'CVE-2026-34486']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-34486 \u2014 Apache Tomcat Missing Encryption ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "Chinese-Speaking Threat Actor Harnesses AI Models for Autono",
          "url": "https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV",
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a58145d5-548f-4fd1-86ce-7eb054db0b53",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-41264",
      "pattern": "[vulnerability:name = 'CVE-2026-41264']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-70470: Flowise: Pyodide validator",
          "url": "https://github.com/advisories/GHSA-52fh-8v99-63c2"
        },
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-69255: Flowise: CSV Agent Remote ",
          "url": "https://github.com/advisories/GHSA-vmv7-4m6c-3cg5"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc4bd50c-3941-439d-ab47-dcee74132e1d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-41265",
      "pattern": "[vulnerability:name = 'CVE-2026-41265']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-70470: Flowise: Pyodide validator",
          "url": "https://github.com/advisories/GHSA-52fh-8v99-63c2"
        },
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-69255: Flowise: CSV Agent Remote ",
          "url": "https://github.com/advisories/GHSA-vmv7-4m6c-3cg5"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f84527c7-e04d-4c4f-9061-a119c5131b95",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-46442",
      "pattern": "[vulnerability:name = 'CVE-2026-46442']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-69255: Flowise: CSV Agent Remote ",
          "url": "https://github.com/advisories/GHSA-vmv7-4m6c-3cg5"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ee5a1f3c-cc1d-4690-b3f2-37d9c974abb8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-69251",
      "pattern": "[vulnerability:name = 'CVE-2026-69251']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-69251: Flowise RCE via TypeORM Da",
          "url": "https://github.com/advisories/GHSA-g32j-mmxr-gfq5"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--245c2006-6366-4d23-a406-45442482e55a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-69254",
      "pattern": "[vulnerability:name = 'CVE-2026-69254']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-69254: Flowise: RCE via NodeVM Sa",
          "url": "https://github.com/advisories/GHSA-3769-jgqc-cxm7"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--80c6d792-09b0-4cae-8664-f0c56724c46b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-69255",
      "pattern": "[vulnerability:name = 'CVE-2026-69255']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-69255: Flowise: CSV Agent Remote ",
          "url": "https://github.com/advisories/GHSA-vmv7-4m6c-3cg5"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5012114e-274c-49d6-b99e-03f82132af63",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-69259",
      "pattern": "[vulnerability:name = 'CVE-2026-69259']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-69259: Flowise RCE via SQLite Rec",
          "url": "https://github.com/advisories/GHSA-x3hf-7cj6-3r4m"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d723c0a-191b-4b41-973b-5aa820bbf393",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-69264",
      "pattern": "[vulnerability:name = 'CVE-2026-69264']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-69264: Flowise: RCE via CSVAgent ",
          "url": "https://github.com/advisories/GHSA-4j8x-x6v7-w9rq"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7541f8fe-f386-41e2-9667-d527228e1bb0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-70470",
      "pattern": "[vulnerability:name = 'CVE-2026-70470']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-70470: Flowise: Pyodide validator",
          "url": "https://github.com/advisories/GHSA-52fh-8v99-63c2"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe58b850-484a-4d1a-9291-8e2981f8fe4b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-70477",
      "pattern": "[vulnerability:name = 'CVE-2026-70477']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-70477: Flowise: CSV Agent Prompt ",
          "url": "https://github.com/advisories/GHSA-5xvg-pmgg-3mxr"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8815badd-3342-4c5e-902b-4f2c3d3d5890",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-70478",
      "pattern": "[vulnerability:name = 'CVE-2026-70478']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-70478: Flowise: Unauthenticated O",
          "url": "https://github.com/advisories/GHSA-qgvm-j2hm-6m38"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--291ebb10-9f55-469d-bda2-c6ab89c17ee2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-9198",
      "pattern": "[vulnerability:name = 'CVE-2026-9198']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-9198 \u2014 IBM Langflow Code Injection Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--af32f8ff-61e6-4b6e-9bbc-2c22e3eb1771",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: mousears.synology.me",
      "pattern": "[domain-name:value = 'mousears.synology.me']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-18556 \u2014 N-able N-central Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-18577 \u2014 N-able N-central Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6b261a07-8907-47d9-a6ce-731d6ecf1501",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: wagoosh.direct.quickconnect.to",
      "pattern": "[domain-name:value = 'wagoosh.direct.quickconnect.to']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-18556 \u2014 N-able N-central Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-18577 \u2014 N-able N-central Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4831858b-63d4-4965-89cf-0d9f3a9d3723",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: who-ripped-one.direct.quickconnect.to",
      "pattern": "[domain-name:value = 'who-ripped-one.direct.quickconnect.to']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-18556 \u2014 N-able N-central Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-18577 \u2014 N-able N-central Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9bbfec00-03ec-43e7-9867-f9a831ceaa0d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 173.249.252.200",
      "pattern": "[ipv4-addr:value = '173.249.252.200']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-18556 \u2014 N-able N-central Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-18577 \u2014 N-able N-central Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bdc13c69-005b-491c-b93d-19eb559d6f81",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 37.153.90.88",
      "pattern": "[ipv4-addr:value = '37.153.90.88']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-18556 \u2014 N-able N-central Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-18577 \u2014 N-able N-central Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4c8ca87b-e6ac-47eb-9983-0bb914654611",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 37.19.210.32",
      "pattern": "[ipv4-addr:value = '37.19.210.32']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-18556 \u2014 N-able N-central Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-18577 \u2014 N-able N-central Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ceeb112b-0199-460d-964d-43c2d1ae4d88",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 68.235.46.214",
      "pattern": "[ipv4-addr:value = '68.235.46.214']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-18556 \u2014 N-able N-central Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-18577 \u2014 N-able N-central Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e444b7ed-4889-40a5-a11b-8609bc6c4497",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 87.249.138.34",
      "pattern": "[ipv4-addr:value = '87.249.138.34']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-18556 \u2014 N-able N-central Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-18577 \u2014 N-able N-central Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f7365e71-b1c5-47a3-9bf2-a618360eaf49",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 92.118.112.181",
      "pattern": "[ipv4-addr:value = '92.118.112.181']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-18556 \u2014 N-able N-central Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-18577 \u2014 N-able N-central Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a7dada81-5a11-48aa-b3de-8a5ed3113873",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d584f9b6af48b7ed1f93713944f033783bf149e1c25e1643eb8c0e9df5dc7782",
      "pattern": "[file:hashes.'SHA-256' = 'd584f9b6af48b7ed1f93713944f033783bf149e1c25e1643eb8c0e9df5dc7782']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "A First Look at Evo Agentic AppSec: Agentic Remediation and ",
          "url": "https://snyk.io/blog/remediation-agent-malicious-code-defense/"
        },
        {
          "source_name": "Inside the keyv npm Compromise: preinstall Malware, Trusted ",
          "url": "https://snyk.io/blog/inside-keyv-npm-compromise-preinstall-malware-trusted-provenance-ide-hooks/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b87bc481-c150-40d0-a5d7-0101c48e4a1d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-12420",
      "pattern": "[vulnerability:name = 'CVE-2025-12420']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Evo Continuous Offensive Security Is Here Pentesting Grade C",
          "url": "https://snyk.io/blog/evo-continuous-offensive-security/"
        },
        {
          "source_name": "AI Is Building Your Attack Surface. Are You Testing It?",
          "url": "https://snyk.io/blog/ai-is-building-your-attack-surface-are-you-testing-it/"
        },
        {
          "source_name": "Claude Code Security: A Welcome Evolution in the Remediation",
          "url": "https://snyk.io/blog/claude-code-remediation-loop-evolution/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f2174633-0fc4-4dc9-b780-ca4b6d8127be",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 154.92.19.71",
      "pattern": "[ipv4-addr:value = '154.92.19.71']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Almost Half of Malware Samples Communicate Direct to IP",
          "url": "https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4b18956-e3d0-4872-9b20-6851c57ddc25",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 178.16.54.109",
      "pattern": "[ipv4-addr:value = '178.16.54.109']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Almost Half of Malware Samples Communicate Direct to IP",
          "url": "https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--64fb5ed7-e490-46e9-bc87-49d97bcf866a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 18.228.188.56",
      "pattern": "[ipv4-addr:value = '18.228.188.56']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Almost Half of Malware Samples Communicate Direct to IP",
          "url": "https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--90d48cf1-91c5-40ee-8234-5beda2e1f5bf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.76.227.94",
      "pattern": "[ipv4-addr:value = '194.76.227.94']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Almost Half of Malware Samples Communicate Direct to IP",
          "url": "https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--49634c8b-9994-46ad-8d55-7677e7da0d15",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 2.26.98.67",
      "pattern": "[ipv4-addr:value = '2.26.98.67']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Almost Half of Malware Samples Communicate Direct to IP",
          "url": "https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3e74aa4d-e9ba-4d60-923e-67ecb14a0749",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 87.120.107.33",
      "pattern": "[ipv4-addr:value = '87.120.107.33']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Almost Half of Malware Samples Communicate Direct to IP",
          "url": "https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--be0f152d-2ec3-43bd-a2c9-c13865198b56",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: cc43cdbe8eb9874f55fffbe23b560b673eb9f31fb9a953926bba29464fd2dd07",
      "pattern": "[file:hashes.'SHA-256' = 'cc43cdbe8eb9874f55fffbe23b560b673eb9f31fb9a953926bba29464fd2dd07']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Almost Half of Malware Samples Communicate Direct to IP",
          "url": "https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--01005992-e152-4140-a6a7-4b6bcde0ba7c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-69240",
      "pattern": "[vulnerability:name = 'CVE-2026-69240']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-69240: Sequelize: SQL Injection (",
          "url": "https://github.com/advisories/GHSA-v8fg-2rw7-q452"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f87b7615-f5cc-49a7-8698-436810383c15",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-52855",
      "pattern": "[vulnerability:name = 'CVE-2026-52855']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-52855: Wings exposes node configu",
          "url": "https://github.com/advisories/GHSA-pfvc-3p5h-x7h6"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4e786ad-08a2-4129-b3c8-47c2d0ab28e3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-52887",
      "pattern": "[vulnerability:name = 'CVE-2026-52887']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-52887: NocoBase: SQL injection in",
          "url": "https://github.com/advisories/GHSA-p849-8hwh-84j9"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--84da9d0d-86d3-434d-9788-1b0dc2ec71d1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-53609",
      "pattern": "[vulnerability:name = 'CVE-2026-53609']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-53609: Apostrophe has Server-Side",
          "url": "https://github.com/advisories/GHSA-6h5j-32cf-4253"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--69085458-b468-45ef-a97c-5c532486c53c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-54725",
      "pattern": "[vulnerability:name = 'CVE-2026-54725']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-54725: vault-addr annotation SSRF",
          "url": "https://github.com/advisories/GHSA-r2v3-8gwf-7ghm"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b8eab19b-1758-4426-9b96-f8f5892abbd8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: crust.testinglab.ru",
      "pattern": "[domain-name:value = 'crust.testinglab.ru']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Network Anomaly Detection in KATA",
          "url": "https://securelist.com/tr/network-anomaly-detection-in-kata/120892/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d3c789c7-3543-4d39-a1a2-ebb90ff8a7e3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: enqqnvvtgrnyl.x.pipedream.net",
      "pattern": "[domain-name:value = 'enqqnvvtgrnyl.x.pipedream.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Anthropic's Fever Dream: Claude's package that stole real ke",
          "url": "https://www.aikido.dev/blog/anthropic-rogue-agents-package-stole-keys"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7ffa9099-c02a-4461-8efe-63add4dba6ab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: m365-owa.com",
      "pattern": "[domain-name:value = 'm365-owa.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CaptiveCrunch: Midnight Blizzard targets travelers worldwide",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f854bce4-077b-48ce-ab78-2f8cc3f421fd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ms365-device.com",
      "pattern": "[domain-name:value = 'ms365-device.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CaptiveCrunch: Midnight Blizzard targets travelers worldwide",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cbbc6ee1-3991-419a-bca8-e2a56f506158",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ms365-live.com",
      "pattern": "[domain-name:value = 'ms365-live.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CaptiveCrunch: Midnight Blizzard targets travelers worldwide",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e5394b30-d803-4a7f-b7c5-856a430a11bd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: owa-ms365.com",
      "pattern": "[domain-name:value = 'owa-ms365.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CaptiveCrunch: Midnight Blizzard targets travelers worldwide",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--235a0e18-b948-40a5-aa8f-763d2e2850a2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: testinglab.ru",
      "pattern": "[domain-name:value = 'testinglab.ru']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Network Anomaly Detection in KATA",
          "url": "https://securelist.com/tr/network-anomaly-detection-in-kata/120892/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7ee1b896-8a2c-4583-9bbd-b0154f1a92f8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.194.159.150",
      "pattern": "[ipv4-addr:value = '104.194.159.150']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CaptiveCrunch: Midnight Blizzard targets travelers worldwide",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1f541ac2-5823-42fa-abc4-08bd3b69a473",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 107.189.26.194",
      "pattern": "[ipv4-addr:value = '107.189.26.194']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CaptiveCrunch: Midnight Blizzard targets travelers worldwide",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--772ad05a-de5d-4c19-8f21-f5de02a9a9a8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 213.145.86.112",
      "pattern": "[ipv4-addr:value = '213.145.86.112']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CaptiveCrunch: Midnight Blizzard targets travelers worldwide",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c1944876-91d7-4aa9-868b-cf11422afbbf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 31.57.243.154",
      "pattern": "[ipv4-addr:value = '31.57.243.154']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CaptiveCrunch: Midnight Blizzard targets travelers worldwide",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc8e8a21-1ae4-4413-bd1f-2ede25b4013f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.146.28.132",
      "pattern": "[ipv4-addr:value = '38.146.28.132']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CaptiveCrunch: Midnight Blizzard targets travelers worldwide",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3a63246f-4249-488d-b25c-86fe45caac04",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.146.28.75",
      "pattern": "[ipv4-addr:value = '38.146.28.75']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CaptiveCrunch: Midnight Blizzard targets travelers worldwide",
          "url": "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Microsoft Security Blog"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ded21e4-c26d-4793-a057-9897da001c9c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 7df12487bade710459ccea2d3570cdbc",
      "pattern": "[file:hashes.MD5 = '7df12487bade710459ccea2d3570cdbc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Anthropic's Fever Dream: Claude's package that stole real ke",
          "url": "https://www.aikido.dev/blog/anthropic-rogue-agents-package-stole-keys"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--99069a56-ef54-4ecd-a822-a816869913c8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4ae13303fa1663a36cfaa70bebe77b52b12dbf17eef24db15c6c24c631d38fbf",
      "pattern": "[file:hashes.'SHA-256' = '4ae13303fa1663a36cfaa70bebe77b52b12dbf17eef24db15c6c24c631d38fbf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Anthropic's Fever Dream: Claude's package that stole real ke",
          "url": "https://www.aikido.dev/blog/anthropic-rogue-agents-package-stole-keys"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a2846642-5f52-4107-be3a-e04e524b4fd7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 584ef638a5415f4eccf6645abbcd06198e9abecf8b75cbd9328aa58962d9b38b",
      "pattern": "[file:hashes.'SHA-256' = '584ef638a5415f4eccf6645abbcd06198e9abecf8b75cbd9328aa58962d9b38b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Anthropic's Fever Dream: Claude's package that stole real ke",
          "url": "https://www.aikido.dev/blog/anthropic-rogue-agents-package-stole-keys"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fa11420e-cbc3-4a88-a276-c7e0ab49b7c7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f3e103a8a230b5fb3066fb0a9eb7f5fdf5831d4c7b71a9d83de54d8d6673eae2",
      "pattern": "[file:hashes.'SHA-256' = 'f3e103a8a230b5fb3066fb0a9eb7f5fdf5831d4c7b71a9d83de54d8d6673eae2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Anthropic's Fever Dream: Claude's package that stole real ke",
          "url": "https://www.aikido.dev/blog/anthropic-rogue-agents-package-stole-keys"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a1270fcf-6bf4-427c-98b1-8c04ef856117",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ff4126bd465ae6de09a2eaa94a4fd2d7d385a5dae2c093372668d4b7ecb81633",
      "pattern": "[file:hashes.'SHA-256' = 'ff4126bd465ae6de09a2eaa94a4fd2d7d385a5dae2c093372668d4b7ecb81633']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Anthropic's Fever Dream: Claude's package that stole real ke",
          "url": "https://www.aikido.dev/blog/anthropic-rogue-agents-package-stole-keys"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1cd5eff2-dd7b-4691-97fa-aeb58622bb09",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-4318",
      "pattern": "[vulnerability:name = 'CVE-2025-4318']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2025-4318: AWS Amplify Studio UI Compo",
          "url": "https://github.com/advisories/GHSA-hf3j-86p7-mfw8"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3623abff-036d-4f9a-99b0-4a655a9c035f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-68613",
      "pattern": "[vulnerability:name = 'CVE-2025-68613']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Chinese-Speaking Threat Actor Harnesses AI Models for Autono",
          "url": "https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/"
        },
        {
          "source_name": "CISA KEV: CVE-2025-68613 \u2014 n8n Improper Control of Dynamical",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--13e04c17-2264-4492-8b22-24225996809c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-16232",
      "pattern": "[vulnerability:name = 'CVE-2026-16232']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "url": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/"
        },
        {
          "source_name": "CISA KEV: CVE-2026-16232 \u2014 Check Point SmartConsole Improper",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3119a676-c303-4b12-b719-c80ba800c226",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-21858",
      "pattern": "[vulnerability:name = 'CVE-2026-21858']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Chinese-Speaking Threat Actor Harnesses AI Models for Autono",
          "url": "https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b8e0ebe4-f26e-4a40-8a9a-a46805e583d3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-3055",
      "pattern": "[vulnerability:name = 'CVE-2026-3055']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Chinese-Speaking Threat Actor Harnesses AI Models for Autono",
          "url": "https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/"
        },
        {
          "source_name": "CISA KEV: CVE-2026-3055 \u2014 Citrix NetScaler Out-of-Bounds Rea",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7adf7c93-ccc0-467a-bbca-38bf9e399315",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-33017",
      "pattern": "[vulnerability:name = 'CVE-2026-33017']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Chinese-Speaking Threat Actor Harnesses AI Models for Autono",
          "url": "https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/"
        },
        {
          "source_name": "CISA KEV: CVE-2026-55255 \u2014 Langflow Authorization Bypass Thr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-33017 \u2014 Langflow Code Injection Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--46b1b8f3-8a8f-4fd4-b4b8-c8e65c04e4a1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-33824",
      "pattern": "[vulnerability:name = 'CVE-2026-33824']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Chinese-Speaking Threat Actor Harnesses AI Models for Autono",
          "url": "https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e1849e0-f4e9-4497-b320-3d56c82493f0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-39987",
      "pattern": "[vulnerability:name = 'CVE-2026-39987']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Chinese-Speaking Threat Actor Harnesses AI Models for Autono",
          "url": "https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/"
        },
        {
          "source_name": "CISA KEV: CVE-2026-39987 \u2014 Marimo Remote Code Execution Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cee082ce-0fd0-4e92-bbc3-1973775596ad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-66066",
      "pattern": "[vulnerability:name = 'CVE-2026-66066']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-66066: Active Storage has possibl",
          "url": "https://github.com/advisories/GHSA-xr9x-r78c-5hrm"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cef63c7c-0d6a-490d-99ef-4b66c526fb97",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-67426",
      "pattern": "[vulnerability:name = 'CVE-2026-67426']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-67426: Flyto2 Core: Unauthenticat",
          "url": "https://github.com/advisories/GHSA-jx74-cqjv-2c67"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a74393a0-1f04-45b8-b1f6-b70d573bcb8d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-67429",
      "pattern": "[vulnerability:name = 'CVE-2026-67429']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-67429: Flyto2 Core: Arbitrary fil",
          "url": "https://github.com/advisories/GHSA-2956-977x-2w3r"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a2d54e6d-1167-499c-bfac-f35d9776882e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: about.blsouqs.com",
      "pattern": "[domain-name:value = 'about.blsouqs.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a556c6cd-52fe-4ff6-893e-ec50bc6e120f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: api.trongrid.io",
      "pattern": "[domain-name:value = 'api.trongrid.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Compromised npm Packages: @joyfill/components and @joyfill/l",
          "url": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cd065b66-b80b-47d0-be05-c99a448d80d8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: api2.annoyingremote.com",
      "pattern": "[domain-name:value = 'api2.annoyingremote.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b9689f6f-611a-4c8b-aa48-1a3b26bbbe28",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: bsc-dataseed.binance.org",
      "pattern": "[domain-name:value = 'bsc-dataseed.binance.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Compromised npm Packages: @joyfill/components and @joyfill/l",
          "url": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--716703ce-8941-4088-9511-9bfd00d1abe0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: bsc-rpc.publicnode.com",
      "pattern": "[domain-name:value = 'bsc-rpc.publicnode.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Compromised npm Packages: @joyfill/components and @joyfill/l",
          "url": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--293f3e53-db64-4402-92f9-e109285bf12d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: code.newcli.com",
      "pattern": "[domain-name:value = 'code.newcli.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Chinese-Speaking Threat Actor Harnesses AI Models for Autono",
          "url": "https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb96cf06-a9a0-424c-806b-753da175ac30",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: confbase.mdpsupport.net",
      "pattern": "[domain-name:value = 'confbase.mdpsupport.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--50a80866-c6c3-41ec-8b8e-e004e8b9ca9a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ctyuhjerf.kozow.com",
      "pattern": "[domain-name:value = 'ctyuhjerf.kozow.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3f1c431f-90a3-4d5f-9b97-cf084b5d8745",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: digital.leroymerlin.com",
      "pattern": "[domain-name:value = 'digital.leroymerlin.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0c301c2-08ef-4027-9093-6a11816185a7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: dns.multitoconference.com",
      "pattern": "[domain-name:value = 'dns.multitoconference.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7a96e387-0db6-464f-a7de-a8c800f4025f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: dns.ssentialserv.xyz",
      "pattern": "[domain-name:value = 'dns.ssentialserv.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53cb1393-187d-4c70-a31d-9ce5ac42a1a1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: fm01.clouddevicemetrics.com",
      "pattern": "[domain-name:value = 'fm01.clouddevicemetrics.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--041d95e0-1658-4063-8d6f-7f29b06066eb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: fullnode.mainnet.aptoslabs.com",
      "pattern": "[domain-name:value = 'fullnode.mainnet.aptoslabs.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Compromised npm Packages: @joyfill/components and @joyfill/l",
          "url": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--98ef3d87-9c05-4d71-9420-1353592abdf5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: gycudore.kozow.com",
      "pattern": "[domain-name:value = 'gycudore.kozow.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c46a06c-4318-4117-9b68-43e766917c2d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ip-api.com",
      "pattern": "[domain-name:value = 'ip-api.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Compromised npm Packages: @joyfill/components and @joyfill/l",
          "url": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--92ec5d9d-6236-45c4-88bc-7caf26e773bc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: is-01-ast.ols-img-12.workers.dev",
      "pattern": "[domain-name:value = 'is-01-ast.ols-img-12.workers.dev']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "url": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/"
        },
        {
          "source_name": "Don\u2019t swing at everything",
          "url": "https://blog.talosintelligence.com/dont-swing-at-everything/"
        },
        {
          "source_name": "Chaos ransomware's msaRAT: Living off the browser to build a",
          "url": "https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--538c4994-3f1c-4a84-887f-17775f2053a0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: rgnojb.casacam.net",
      "pattern": "[domain-name:value = 'rgnojb.casacam.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--51b16dc4-14ea-47a8-8bb5-84ddba0aa8c9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ssl.blsouqs.com",
      "pattern": "[domain-name:value = 'ssl.blsouqs.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e39c4308-b727-408e-ab03-3d09ea57cbc9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: tj.tajikistandip.com",
      "pattern": "[domain-name:value = 'tj.tajikistandip.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--28ee1f4b-9df7-44fd-870c-47c3eee02b4d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: tyhbgtyuj.gleeze.com",
      "pattern": "[domain-name:value = 'tyhbgtyuj.gleeze.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--afb7fa1f-9d66-47f5-a1c3-8186acad8762",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: uyhvfredc.accesscam.org",
      "pattern": "[domain-name:value = 'uyhvfredc.accesscam.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0da41d39-414c-48de-9c95-50cb49139122",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: wedfcvbn.gleeze.com",
      "pattern": "[domain-name:value = 'wedfcvbn.gleeze.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4b4aa340-eaa5-4805-8835-e7f3c448fc07",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 154.196.162.76",
      "pattern": "[ipv4-addr:value = '154.196.162.76']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7fe68eab-7667-4ebe-826c-962d0bd089da",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 154.196.187.73",
      "pattern": "[ipv4-addr:value = '154.196.187.73']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f9780625-96cb-4a51-b85c-68efcd5ae17e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 166.88.134.62",
      "pattern": "[ipv4-addr:value = '166.88.134.62']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Compromised npm Packages: @joyfill/components and @joyfill/l",
          "url": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6210bcb0-7600-4f76-bb41-0180ca217760",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.86.126.18",
      "pattern": "[ipv4-addr:value = '172.86.126.18']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "url": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/"
        },
        {
          "source_name": "Don\u2019t swing at everything",
          "url": "https://blog.talosintelligence.com/dont-swing-at-everything/"
        },
        {
          "source_name": "Chaos ransomware's msaRAT: Living off the browser to build a",
          "url": "https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--899bb941-ba25-4ced-9042-ba86eef585df",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 195.86.120.2",
      "pattern": "[ipv4-addr:value = '195.86.120.2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d8f745f-48ff-48a3-92fb-2f858f31f244",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 198.105.127.210",
      "pattern": "[ipv4-addr:value = '198.105.127.210']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Compromised npm Packages: @joyfill/components and @joyfill/l",
          "url": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f68e2ca0-0ac2-4038-914f-ad27337fa10a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 212.11.39.138",
      "pattern": "[ipv4-addr:value = '212.11.39.138']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb820831-1a14-47de-842b-df037e7b6a3d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.27.13.43",
      "pattern": "[ipv4-addr:value = '23.27.13.43']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Compromised npm Packages: @joyfill/components and @joyfill/l",
          "url": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--63a6426c-afb1-4c3c-9f56-d407bb55d47e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.27.202.27",
      "pattern": "[ipv4-addr:value = '23.27.202.27']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Compromised npm Packages: @joyfill/components and @joyfill/l",
          "url": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e0ce8656-35a1-4c10-9c69-058c666c72ca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.138.157.165",
      "pattern": "[ipv4-addr:value = '45.138.157.165']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fbbbe964-f16f-4e66-80f3-ce4b6dc01857",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.32.152.50",
      "pattern": "[ipv4-addr:value = '45.32.152.50']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53f94fb2-c6bc-4239-a9cd-bee9211be563",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.61.149.112",
      "pattern": "[ipv4-addr:value = '45.61.149.112']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f6f409e9-8b27-4cd5-b134-4299a5ef7445",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.77.136.228",
      "pattern": "[ipv4-addr:value = '45.77.136.228']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e1ab2958-a0ac-4248-9a96-75f3f216ffc9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 64.7.198.130",
      "pattern": "[ipv4-addr:value = '64.7.198.130']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6d337a5-09b4-4423-89a8-0273dbe6c718",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 95.179.141.26",
      "pattern": "[ipv4-addr:value = '95.179.141.26']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e3874c2d-46d0-4694-8d68-8125384f59ee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 95.179.210.138",
      "pattern": "[ipv4-addr:value = '95.179.210.138']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d25af09-107d-482b-b351-0e668c17ec72",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 082d49ef9f14e6811d68c7e0e82e5069",
      "pattern": "[file:hashes.MD5 = '082d49ef9f14e6811d68c7e0e82e5069']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0a89f22-79f9-403a-8001-3af0523190e4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 1415a78b75de7db4ba3d1e61d7db4501",
      "pattern": "[file:hashes.MD5 = '1415a78b75de7db4ba3d1e61d7db4501']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--33a73a17-5490-47e5-afd5-d5c36c8dd4e8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 18dc8bff47cc282508354771d0c8cf8c",
      "pattern": "[file:hashes.MD5 = '18dc8bff47cc282508354771d0c8cf8c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb9ceff0-69fb-4ad4-8b05-a9872a5997f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 2a571f6cee42a17d873f4c942649813f",
      "pattern": "[file:hashes.MD5 = '2a571f6cee42a17d873f4c942649813f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0d32e9ac-30a2-4e66-b3cf-7920042cd270",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 32a5985543433a4f60da2fafd873b927",
      "pattern": "[file:hashes.MD5 = '32a5985543433a4f60da2fafd873b927']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--77a0f261-9d4f-41c7-87cd-e05675075c69",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 37dc84e4bcad92fa28f1e7778d088283",
      "pattern": "[file:hashes.MD5 = '37dc84e4bcad92fa28f1e7778d088283']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--09fedce2-bcb9-4978-9081-6479cd00e410",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 3c9a1ba8e0c7475706adc6376e9d7b7c",
      "pattern": "[file:hashes.MD5 = '3c9a1ba8e0c7475706adc6376e9d7b7c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b26a172f-c127-4af8-98d1-992514e50c9e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 45cf5916fab4272a1313c26e67aa9220",
      "pattern": "[file:hashes.MD5 = '45cf5916fab4272a1313c26e67aa9220']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5ff0c40-daaa-42d5-ae50-fa06d0077e0c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 4e6d5c4770d5a822d7fcce6a74f7ad73",
      "pattern": "[file:hashes.MD5 = '4e6d5c4770d5a822d7fcce6a74f7ad73']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b2789bc6-df6b-4000-aa41-d39fc3ced247",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 5e26df131ff0a679a0a2699b723b46e3",
      "pattern": "[file:hashes.MD5 = '5e26df131ff0a679a0a2699b723b46e3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--df95bbd2-d271-48ef-8b6e-11f2291a3d14",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 6ecf84fb18f6747ed08d7598364d853a",
      "pattern": "[file:hashes.MD5 = '6ecf84fb18f6747ed08d7598364d853a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9ad544aa-708b-4fec-ba30-7964b3816b1c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 7c2f64461bb519c6cbf1fc687675514c",
      "pattern": "[file:hashes.MD5 = '7c2f64461bb519c6cbf1fc687675514c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--237e0a06-5d7c-4fb0-a9c5-d8811e19dd93",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 8269d6ba1b6842f9152c90cf7add9b93",
      "pattern": "[file:hashes.MD5 = '8269d6ba1b6842f9152c90cf7add9b93']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b50ba666-54f1-492c-95b8-b7be9fafa87b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 9a1dd1d96481d61934dcc2d568971d06",
      "pattern": "[file:hashes.MD5 = '9a1dd1d96481d61934dcc2d568971d06']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1efffbf0-4538-4f0a-a4de-00c4ef323be4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: a0cc7accc79abb0287aaba825d0351f0",
      "pattern": "[file:hashes.MD5 = 'a0cc7accc79abb0287aaba825d0351f0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8d9ab252-313d-4df8-8eda-e6ef42898bc7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: a4d550a3ba0cd073fe3839b99d98a7a8",
      "pattern": "[file:hashes.MD5 = 'a4d550a3ba0cd073fe3839b99d98a7a8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c757c2a-dc2a-4cf5-b065-bbd061ea790d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: a56cce62930a6bee80d679b4c495a340",
      "pattern": "[file:hashes.MD5 = 'a56cce62930a6bee80d679b4c495a340']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2a514d3f-fe83-4059-8709-e7e07c2f8484",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: b874123a80fc4f40e06872b9cb54ebc6",
      "pattern": "[file:hashes.MD5 = 'b874123a80fc4f40e06872b9cb54ebc6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--afb053c5-749f-4240-b29e-fd15f9e37515",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: cf903e4a1629aa0582fd0363b5786676",
      "pattern": "[file:hashes.MD5 = 'cf903e4a1629aa0582fd0363b5786676']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9223abf8-19b2-403b-8dc4-71c8a41e7d41",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: ded73d04bb3e3525226de64c38a332e3",
      "pattern": "[file:hashes.MD5 = 'ded73d04bb3e3525226de64c38a332e3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "url": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--63e029ee-0cd7-45de-aab3-12efded49b31",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: ef59aad625eebda8650aec5820d6ce69",
      "pattern": "[file:hashes.MD5 = 'ef59aad625eebda8650aec5820d6ce69']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d2b5830-172d-455a-a7f0-75bcc05d6529",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: f4578e869a735cfad691f927bae3e638",
      "pattern": "[file:hashes.MD5 = 'f4578e869a735cfad691f927bae3e638']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OctLurk and SilkLurk: newly identified tailored backdoors in",
          "url": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Securelist (Kaspersky)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--474f80b3-7f96-4a57-98fe-1687f153942d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 26351aed0397158d3a3b8cc8fd3047d4c015d264c9895f10f20f1521b974ed18",
      "pattern": "[file:hashes.'SHA-256' = '26351aed0397158d3a3b8cc8fd3047d4c015d264c9895f10f20f1521b974ed18']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Compromised npm Packages: @joyfill/components and @joyfill/l",
          "url": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1ad4b0b3-81e2-4233-b248-9e9891f7f948",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 36ff00b45e67baa7e3674b0c80f48e88737264c61e5c6b3b091200972de8157c",
      "pattern": "[file:hashes.'SHA-256' = '36ff00b45e67baa7e3674b0c80f48e88737264c61e5c6b3b091200972de8157c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Compromised npm Packages: @joyfill/components and @joyfill/l",
          "url": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--19071bc5-4bb4-4016-889f-d082c7f87ee3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: cb46f12d70824ea24ed1f8bcf45bf3f86680e02a9089aafc03b27f691be57be3",
      "pattern": "[file:hashes.'SHA-256' = 'cb46f12d70824ea24ed1f8bcf45bf3f86680e02a9089aafc03b27f691be57be3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Compromised npm Packages: @joyfill/components and @joyfill/l",
          "url": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c9de5c05-fd78-429b-807c-62b6ebd17ccb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: fc18d4060c6dad3057c0b5a70a2081473e066951720cafbd2aa159d3aaccf2e1",
      "pattern": "[file:hashes.'SHA-256' = 'fc18d4060c6dad3057c0b5a70a2081473e066951720cafbd2aa159d3aaccf2e1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "url": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a67123f2-8445-4b0b-9238-9b7abf6e5cff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-20316",
      "pattern": "[vulnerability:name = 'CVE-2026-20316']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-20316 \u2014 Cisco Secure Firewall Management ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c1c7d8d5-031c-490e-ab1c-8bc77c08831d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-54680",
      "pattern": "[vulnerability:name = 'CVE-2026-54680']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-54680: Logging operator has Fluen",
          "url": "https://github.com/advisories/GHSA-mjqf-28ph-426h"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--989b0710-7e3d-4df9-a3ab-c64dcdf9f16b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-54735",
      "pattern": "[vulnerability:name = 'CVE-2026-54735']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-54735: prebid-server's request fo",
          "url": "https://github.com/advisories/GHSA-4p3g-4hcj-wpvx"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--50cd115f-9153-42fd-95c5-d079886f8de5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-40884",
      "pattern": "[vulnerability:name = 'CVE-2026-40884']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-62325: goshs SFTP authentication ",
          "url": "https://github.com/advisories/GHSA-rjrw-mjq6-hpmm"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d509e579-c19c-40ed-8f10-44027dc6219b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-45321",
      "pattern": "[vulnerability:name = 'CVE-2026-45321']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "url": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet"
        },
        {
          "source_name": "CISA KEV: CVE-2026-48027 \u2014 Nx Console Embedded Malicious Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-45321 \u2014 TanStack Unspecified Vulnerabilit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "CISA KEV",
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b407e209-9d22-4fab-804a-3ac1f8555db3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-48027",
      "pattern": "[vulnerability:name = 'CVE-2026-48027']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "url": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet"
        },
        {
          "source_name": "CISA KEV: CVE-2026-48027 \u2014 Nx Console Embedded Malicious Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "The Wild West of VS Code extensions and how a poisoned exten",
          "url": "https://www.aikido.dev/blog/vs-code-extension-github-breach"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "CISA KEV",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9dc09b48-3ba8-4e52-b9b6-d4793d428fc0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-50138",
      "pattern": "[vulnerability:name = 'CVE-2026-50138']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-64863: goshs --no-delete WebDAV M",
          "url": "https://github.com/advisories/GHSA-hq33-8jgp-8qq3"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--084f5c0f-3e0d-4863-b31a-5127d83f574d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-54588",
      "pattern": "[vulnerability:name = 'CVE-2026-54588']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-54588: Poweradmin has Host Header",
          "url": "https://github.com/advisories/GHSA-3735-5339-xfwx"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9123c194-ea3f-4022-baa6-77a212fded1f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-54658",
      "pattern": "[vulnerability:name = 'CVE-2026-54658']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-54658: @hypequery/clickhouse has ",
          "url": "https://github.com/advisories/GHSA-6wcc-39rp-hh9p"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--46f15341-fe13-4d18-9703-8ec390c85777",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62325",
      "pattern": "[vulnerability:name = 'CVE-2026-62325']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-62325: goshs SFTP authentication ",
          "url": "https://github.com/advisories/GHSA-rjrw-mjq6-hpmm"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--64b6b5fa-fbf3-404a-95ee-e664b8095baf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-64863",
      "pattern": "[vulnerability:name = 'CVE-2026-64863']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-64863: goshs --no-delete WebDAV M",
          "url": "https://github.com/advisories/GHSA-hq33-8jgp-8qq3"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c37eb45-9091-42d8-893e-22088f85cb66",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: check.git-service.com",
      "pattern": "[domain-name:value = 'check.git-service.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "url": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet"
        },
        {
          "source_name": "Miasma Worm Hits Microsoft Again: Azure Functions Action and",
          "url": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents"
        },
        {
          "source_name": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "url": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5b2793a6-d592-4262-8ebb-751c56ab732a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: clear90489058903-document.workers.dev",
      "pattern": "[domain-name:value = 'clear90489058903-document.workers.dev']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "IR Trends Q2 2026: Phishing and weaponized remote management",
          "url": "https://blog.talosintelligence.com/ir-trends-q2-2026/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe6dc474-e734-4ad5-a53f-00bc40d0b884",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: dashboard-bl.pamconj.com",
      "pattern": "[domain-name:value = 'dashboard-bl.pamconj.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "IR Trends Q2 2026: Phishing and weaponized remote management",
          "url": "https://blog.talosintelligence.com/ir-trends-q2-2026/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9851acd4-fdec-4ec9-a05f-4a26cede17d5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: git-tanstack.com",
      "pattern": "[domain-name:value = 'git-tanstack.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "url": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet"
        },
        {
          "source_name": "CISA KEV: CVE-2026-45321 \u2014 TanStack Unspecified Vulnerabilit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "Why developer machines are now the number one target for sup",
          "url": "https://www.aikido.dev/blog/developer-machines-supply-chain-attacks"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "CISA KEV",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7f136aee-cc71-472d-95cf-2b76cdd1b7c7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: spx.pamconj.com",
      "pattern": "[domain-name:value = 'spx.pamconj.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "IR Trends Q2 2026: Phishing and weaponized remote management",
          "url": "https://blog.talosintelligence.com/ir-trends-q2-2026/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--13f03a9c-58ba-45f4-98e5-aa2a92ec7835",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 83.142.209.194",
      "pattern": "[ipv4-addr:value = '83.142.209.194']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "url": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet"
        },
        {
          "source_name": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer I",
          "url": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough"
        },
        {
          "source_name": "TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply C",
          "url": "https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--677a3413-9f6f-4d4e-a513-0a8b6e6bbe40",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 12f35b1081b17d21815b35feb57ab03d02482116",
      "pattern": "[file:hashes.'SHA-1' = '12f35b1081b17d21815b35feb57ab03d02482116']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "url": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet"
        },
        {
          "source_name": "TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply C",
          "url": "https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem"
        },
        {
          "source_name": "Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, in",
          "url": "https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--71dd270f-ffc9-4010-94dc-6188da4f7d07",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 820fa07a7328b6cf2b417078e103721d4d8f2e79",
      "pattern": "[file:hashes.'SHA-1' = '820fa07a7328b6cf2b417078e103721d4d8f2e79']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "url": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet"
        },
        {
          "source_name": "TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply C",
          "url": "https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem"
        },
        {
          "source_name": "Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, in",
          "url": "https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--64c66a48-8721-4250-838f-cbbd9cff766b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: e7d582b98ca80690883175470e96f703ef6dc497",
      "pattern": "[file:hashes.'SHA-1' = 'e7d582b98ca80690883175470e96f703ef6dc497']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "url": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet"
        },
        {
          "source_name": "TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply C",
          "url": "https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem"
        },
        {
          "source_name": "Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, in",
          "url": "https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--209210f0-5f70-4483-8c48-95776ab082e1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1e8538c6e0563d50da0f2e097e979ebd5294ce1defe01d0b9fe361ba3bed1898",
      "pattern": "[file:hashes.'SHA-256' = '1e8538c6e0563d50da0f2e097e979ebd5294ce1defe01d0b9fe361ba3bed1898']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "url": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet"
        },
        {
          "source_name": "TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply C",
          "url": "https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--79e6025c-3dd9-4aa7-94c6-5a01e66bf688",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2258284d65f63829bd67eaba01ef6f1ada2f593f9bbe41678b2df360bd90d3df",
      "pattern": "[file:hashes.'SHA-256' = '2258284d65f63829bd67eaba01ef6f1ada2f593f9bbe41678b2df360bd90d3df']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "url": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet"
        },
        {
          "source_name": "TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply C",
          "url": "https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem"
        },
        {
          "source_name": "Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, in",
          "url": "https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1ebb25ee-7109-4b5d-a07a-922ed0af2d4d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96",
      "pattern": "[file:hashes.'SHA-256' = '2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "url": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet"
        },
        {
          "source_name": "What MDM can't protect on developer machines (and what to do",
          "url": "https://www.aikido.dev/blog/what-mdm-cant-protect"
        },
        {
          "source_name": "CISA KEV: CVE-2026-45321 \u2014 TanStack Unspecified Vulnerabilit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b20dba8e-b13a-4ca3-94ad-146bd4cd9340",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c",
      "pattern": "[file:hashes.'SHA-256' = 'ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "url": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet"
        },
        {
          "source_name": "What MDM can't protect on developer machines (and what to do",
          "url": "https://www.aikido.dev/blog/what-mdm-cant-protect"
        },
        {
          "source_name": "CISA KEV: CVE-2026-45321 \u2014 TanStack Unspecified Vulnerabilit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c024fefc-b8e6-4a1f-b71f-2a1b19ac2673",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-42475",
      "pattern": "[vulnerability:name = 'CVE-2022-42475']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-68686 \u2014 Fortinet FortiOS Exposure of Sens",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0be5d6af-a33b-417a-8391-1cea53813328",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-27997",
      "pattern": "[vulnerability:name = 'CVE-2023-27997']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-68686 \u2014 Fortinet FortiOS Exposure of Sens",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-45727 \u2014 North Grid Proself Improper Restr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-27997 \u2014 Fortinet FortiOS and FortiProxy S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a99f21f3-c784-413f-9918-ea1627a05d90",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-21762",
      "pattern": "[vulnerability:name = 'CVE-2024-21762']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-68686 \u2014 Fortinet FortiOS Exposure of Sens",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-21762 \u2014 Fortinet FortiOS Out-of-Bound Wri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5e121f80-6c4c-4efb-85a3-dc7cc6d95c10",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-68686",
      "pattern": "[vulnerability:name = 'CVE-2025-68686']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-68686 \u2014 Fortinet FortiOS Exposure of Sens",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d562967f-9870-40d2-a349-b7bc70b58616",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-16812",
      "pattern": "[vulnerability:name = 'CVE-2026-16812']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-16812 \u2014 Arista VeloCloud Orchestrator On-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2b7c1a97-1ea1-48c8-95f5-58cdb1d31185",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: femboy.energy",
      "pattern": "[domain-name:value = 'femboy.energy']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud,",
          "url": "https://www.stepsecurity.io/blog/compromised-pypi-mrmustard-0-7-4-credential-stealer"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f1fb0d74-d937-4c59-b7ba-bd6802fd07cd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: metrics.femboy.energy",
      "pattern": "[domain-name:value = 'metrics.femboy.energy']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud,",
          "url": "https://www.stepsecurity.io/blog/compromised-pypi-mrmustard-0-7-4-credential-stealer"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--38e657d9-f583-42be-a621-a6fc39d276e7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 0404f8590fdaef95280c1d908068f31bf2321fe887faabf0c2329ba67c7203cb",
      "pattern": "[file:hashes.'SHA-256' = '0404f8590fdaef95280c1d908068f31bf2321fe887faabf0c2329ba67c7203cb']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud,",
          "url": "https://www.stepsecurity.io/blog/compromised-pypi-mrmustard-0-7-4-credential-stealer"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--93119273-1836-4723-9602-9f17bea353cc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 81f0d1291a975d012d1b892cf9967557fdbb1ad4e1ac0545702ad235ace1cac5",
      "pattern": "[file:hashes.'SHA-256' = '81f0d1291a975d012d1b892cf9967557fdbb1ad4e1ac0545702ad235ace1cac5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud,",
          "url": "https://www.stepsecurity.io/blog/compromised-pypi-mrmustard-0-7-4-credential-stealer"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd356b73-be10-41d4-ac8c-a018d181855a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-59864",
      "pattern": "[vulnerability:name = 'CVE-2026-59864']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-59864: Microsoft Kiota: Path/URL ",
          "url": "https://github.com/advisories/GHSA-4jwf-m4wg-8p66"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6a94bed-2596-43ee-bba7-486e033c01b8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-59865",
      "pattern": "[vulnerability:name = 'CVE-2026-59865']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-59865: Microsoft Kiota: Command i",
          "url": "https://github.com/advisories/GHSA-hq9q-27g5-qwpj"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4fa43607-53a8-40b0-865b-f6788d541bf4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-59940",
      "pattern": "[vulnerability:name = 'CVE-2026-59940']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-59940: seroval: `seroval.fromJSON",
          "url": "https://github.com/advisories/GHSA-mv8w-475r-vwqw"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ae9a898a-2b81-40d2-8b79-30a3825129d0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62263",
      "pattern": "[vulnerability:name = 'CVE-2026-62263']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-62263: OpenAM: WebAuthn Java dese",
          "url": "https://github.com/advisories/GHSA-gf8h-gq53-288j"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da0e3b9a-0e02-45c1-8cd4-7710d7f5c559",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-62379",
      "pattern": "[vulnerability:name = 'CVE-2026-62379']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-62379: OpenAM: Unauthenticated Re",
          "url": "https://github.com/advisories/GHSA-wg5r-wc3x-39vc"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--befc37c9-baf9-48ec-8f4c-061c789b2417",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-73300",
      "pattern": "[vulnerability:name = 'CVE-2026-73300']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-73300: Budibase: SQL Injection vi",
          "url": "https://github.com/advisories/GHSA-q6x4-v3qx-85qw"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5e76a975-20a5-4495-9aff-85a6dcfdf78b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-73302",
      "pattern": "[vulnerability:name = 'CVE-2026-73302']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-73302: Budibase: OIDC SSO account",
          "url": "https://github.com/advisories/GHSA-hp6v-6jw7-gv2f"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8fcecabc-c502-4d31-8e87-8c073c2bb099",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-73414",
      "pattern": "[vulnerability:name = 'CVE-2026-73414']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-73414: Shescape: Shell injection ",
          "url": "https://github.com/advisories/GHSA-w4hw-qcx7-56pr"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ca89c8cd-1833-4d8d-812b-8a92c2f7742e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-73567",
      "pattern": "[vulnerability:name = 'CVE-2026-73567']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-73567: sm-crypto: Predictable SM2",
          "url": "https://github.com/advisories/GHSA-vh45-f885-3848"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8316ce4-c905-4b41-9077-4e5d4a1c09aa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-73644",
      "pattern": "[vulnerability:name = 'CVE-2026-73644']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-73644: OpenDJ SASL PLAIN authzid ",
          "url": "https://github.com/advisories/GHSA-p279-2cqp-84jg"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6fdfddf8-d80a-4dd4-9197-d3f6ec6509ad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-73649",
      "pattern": "[vulnerability:name = 'CVE-2026-73649']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-73649: Velocity.js: Remote Code E",
          "url": "https://github.com/advisories/GHSA-7gfh-x38p-prh3"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd50fae6-2c8c-4f3b-9826-0fe13aa7054d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 143268fa0939b4da09eab8c9a2e027a04555b6c433fef4f54fc5edd517c0a6b1",
      "pattern": "[file:hashes.'SHA-256' = '143268fa0939b4da09eab8c9a2e027a04555b6c433fef4f54fc5edd517c0a6b1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-73567: sm-crypto: Predictable SM2",
          "url": "https://github.com/advisories/GHSA-vh45-f885-3848"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--92c93dd1-a890-4269-a06b-f2030f425e9d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6072e45733a4187791ec28ce906fef18c7d33c8529969e1a852833c4349cfc38",
      "pattern": "[file:hashes.'SHA-256' = '6072e45733a4187791ec28ce906fef18c7d33c8529969e1a852833c4349cfc38']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-73567: sm-crypto: Predictable SM2",
          "url": "https://github.com/advisories/GHSA-vh45-f885-3848"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2639ebac-eac8-4eae-8bb8-6f8c784b6c18",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-66376",
      "pattern": "[vulnerability:name = 'CVE-2025-66376']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Russian Global Webmail Espionage",
          "url": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/"
        },
        {
          "source_name": "CISA KEV: CVE-2025-66376 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4c71abac-5432-4433-b5f4-d46ead672208",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-16723",
      "pattern": "[vulnerability:name = 'CVE-2026-16723']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-16723: fastjson has a remote code",
          "url": "https://github.com/advisories/GHSA-crf3-v9rr-v7hj"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1da69d92-3aa1-4912-95ba-7735bcce5077",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-60137",
      "pattern": "[vulnerability:name = 'CVE-2026-60137']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Don\u2019t swing at everything",
          "url": "https://blog.talosintelligence.com/dont-swing-at-everything/"
        },
        {
          "source_name": "SQL injection isn't dead",
          "url": "https://www.aikido.dev/blog/sql-injection-isnt-dead"
        },
        {
          "source_name": "CISA KEV: CVE-2026-60137 \u2014 WordPress Core SQL Injection Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos",
        "Aikido",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a982cd43-073c-4812-8096-c7c9dc08781b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-63030",
      "pattern": "[vulnerability:name = 'CVE-2026-63030']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Don\u2019t swing at everything",
          "url": "https://blog.talosintelligence.com/dont-swing-at-everything/"
        },
        {
          "source_name": "SQL injection isn't dead",
          "url": "https://www.aikido.dev/blog/sql-injection-isnt-dead"
        },
        {
          "source_name": "CISA KEV: CVE-2026-60137 \u2014 WordPress Core SQL Injection Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos",
        "Aikido",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--70d90cdb-e33f-43ab-bab6-e70e05232161",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-73420",
      "pattern": "[vulnerability:name = 'CVE-2026-73420']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-73420: Auth.js: Email normalizer ",
          "url": "https://github.com/advisories/GHSA-7rqj-j65f-68wh"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--28b8ca8a-4777-4f74-b6be-619e70a1cb69",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-73421",
      "pattern": "[vulnerability:name = 'CVE-2026-73421']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-73421: Auth.js: Configuration err",
          "url": "https://github.com/advisories/GHSA-8fpg-xm3f-6cx3"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--125a701e-141f-433c-8f8d-a133302552e0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: analyticemailmeter.com",
      "pattern": "[domain-name:value = 'analyticemailmeter.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Russian Global Webmail Espionage",
          "url": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f9173d1f-fbef-43de-ae5e-95d9a06769ad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: emailanalytics.com.ua",
      "pattern": "[domain-name:value = 'emailanalytics.com.ua']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Russian Global Webmail Espionage",
          "url": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e2885454-375c-4de2-ae5c-0eaefaa968c1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: istc-cloud.com",
      "pattern": "[domain-name:value = 'istc-cloud.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Russian Global Webmail Espionage",
          "url": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1af056ca-19d2-4493-80f3-5bdb74bab585",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: mailnalysis.com",
      "pattern": "[domain-name:value = 'mailnalysis.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Russian Global Webmail Espionage",
          "url": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a943b95f-3dc6-4db4-80ed-4cbeb525290a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: synacorzimbra.nl",
      "pattern": "[domain-name:value = 'synacorzimbra.nl']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Russian Global Webmail Espionage",
          "url": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9ccb92c3-f87f-4b03-b50c-6956105b359f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: zimbra-metadata.com",
      "pattern": "[domain-name:value = 'zimbra-metadata.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Russian Global Webmail Espionage",
          "url": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ee5d5ce5-44ef-4a58-805a-f6eb7438ad1c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: zimbrasoft.com.ua",
      "pattern": "[domain-name:value = 'zimbrasoft.com.ua']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Russian Global Webmail Espionage",
          "url": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de0dbed1-5c59-4462-be86-652c19c190d4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: zimbrastat.com",
      "pattern": "[domain-name:value = 'zimbrastat.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Russian Global Webmail Espionage",
          "url": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3c691df9-7dc6-4b19-bcbe-7149de5c5c72",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: zmailanalytics.com",
      "pattern": "[domain-name:value = 'zmailanalytics.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Russian Global Webmail Espionage",
          "url": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--90c981f3-e4c9-4bd1-a061-a18a86adbcfb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.248.134.194",
      "pattern": "[ipv4-addr:value = '104.248.134.194']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Russian Global Webmail Espionage",
          "url": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe2a7acf-e308-4c44-85ec-391e1aa79111",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.86.79.95",
      "pattern": "[ipv4-addr:value = '185.86.79.95']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Russian Global Webmail Espionage",
          "url": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7cc43d92-d46c-42f3-8f9f-3cf24f9cf3e7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.238.152.66",
      "pattern": "[ipv4-addr:value = '193.238.152.66']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Russian Global Webmail Espionage",
          "url": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--edb71baf-1052-4825-a41c-f6abde3856f2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.156.103.193",
      "pattern": "[ipv4-addr:value = '194.156.103.193']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Russian Global Webmail Espionage",
          "url": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f302000d-55d0-43ce-a363-c9eea2120dad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 216.252.238.104",
      "pattern": "[ipv4-addr:value = '216.252.238.104']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Russian Global Webmail Espionage",
          "url": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3f4a9057-d28b-4162-b4dd-32cf9949a780",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 216.252.238.18",
      "pattern": "[ipv4-addr:value = '216.252.238.18']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Russian Global Webmail Espionage",
          "url": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--86d8e6cf-ef67-4ea4-b6f2-3d735b41e88c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 216.252.238.64",
      "pattern": "[ipv4-addr:value = '216.252.238.64']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Russian Global Webmail Espionage",
          "url": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f8d5b47-73b0-477d-9d93-b8a129e9b81f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 37.120.247.228",
      "pattern": "[ipv4-addr:value = '37.120.247.228']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Russian Global Webmail Espionage",
          "url": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a97d4d5c-73c8-40ec-ada9-b8a59d39f53c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 64.226.124.190",
      "pattern": "[ipv4-addr:value = '64.226.124.190']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Russian Global Webmail Espionage",
          "url": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5eabf36f-7456-40ec-8398-f43057da0991",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 770dbe473180366d7b539ff2c188e551",
      "pattern": "[file:hashes.MD5 = '770dbe473180366d7b539ff2c188e551']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Don\u2019t swing at everything",
          "url": "https://blog.talosintelligence.com/dont-swing-at-everything/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--12feeb76-4374-4735-9946-c7fbc2b88ef0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: dbd8dbecaa80795c135137d69921fdba",
      "pattern": "[file:hashes.MD5 = 'dbd8dbecaa80795c135137d69921fdba']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Don\u2019t swing at everything",
          "url": "https://blog.talosintelligence.com/dont-swing-at-everything/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--50a2b325-1be7-4dde-ab4b-0fd5b2b60acb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 633bd79d1efd3730234d907a2a0d98e3e253a5f0e222e4e4bf3badb3fd6aea0a",
      "pattern": "[file:hashes.'SHA-256' = '633bd79d1efd3730234d907a2a0d98e3e253a5f0e222e4e4bf3badb3fd6aea0a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Don\u2019t swing at everything",
          "url": "https://blog.talosintelligence.com/dont-swing-at-everything/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6927d066-7de6-4e9d-9715-b19ecd76b756",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba",
      "pattern": "[file:hashes.'SHA-256' = 'e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Don\u2019t swing at everything",
          "url": "https://blog.talosintelligence.com/dont-swing-at-everything/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f7f15897-ae16-4560-ae54-a3130837331f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: bold-dhawan.45-139-104-115.plesk.page",
      "pattern": "[domain-name:value = 'bold-dhawan.45-139-104-115.plesk.page']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secr",
          "url": "https://www.stepsecurity.io/blog/find-unused-stale-and-oidc-replaceable-github-actions-secrets-across-your-github-organization"
        },
        {
          "source_name": "GitHub Secret Scanning Public Monitoring for Enterprises: Co",
          "url": "https://www.stepsecurity.io/blog/github-secret-scanning-public-monitoring-for-enterprises-coverage-and-gaps"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4e2c807a-52b0-4fd3-ae50-41ece35a9ac4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: carte-avantage.com",
      "pattern": "[domain-name:value = 'carte-avantage.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secr",
          "url": "https://www.stepsecurity.io/blog/find-unused-stale-and-oidc-replaceable-github-actions-secrets-across-your-github-organization"
        },
        {
          "source_name": "GitHub Secret Scanning Public Monitoring for Enterprises: Co",
          "url": "https://www.stepsecurity.io/blog/github-secret-scanning-public-monitoring-for-enterprises-coverage-and-gaps"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ef07272c-d64b-4745-ae77-a8884f904eef",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: objective-hopper.45-139-104-115.plesk.page",
      "pattern": "[domain-name:value = 'objective-hopper.45-139-104-115.plesk.page']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secr",
          "url": "https://www.stepsecurity.io/blog/find-unused-stale-and-oidc-replaceable-github-actions-secrets-across-your-github-organization"
        },
        {
          "source_name": "GitHub Secret Scanning Public Monitoring for Enterprises: Co",
          "url": "https://www.stepsecurity.io/blog/github-secret-scanning-public-monitoring-for-enterprises-coverage-and-gaps"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c0e840e8-9462-4f3e-8af9-11e2a9b8a01b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 216.126.225.129",
      "pattern": "[ipv4-addr:value = '216.126.225.129']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secr",
          "url": "https://www.stepsecurity.io/blog/find-unused-stale-and-oidc-replaceable-github-actions-secrets-across-your-github-organization"
        },
        {
          "source_name": "Harden-Runner Block Mode Now Available for macOS and Windows",
          "url": "https://www.stepsecurity.io/blog/harden-runner-block-mode-now-available-for-macos-and-windows-github-hosted-runners"
        },
        {
          "source_name": "GitHub Secret Scanning Public Monitoring for Enterprises: Co",
          "url": "https://www.stepsecurity.io/blog/github-secret-scanning-public-monitoring-for-enterprises-coverage-and-gaps"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f9a9295-9be4-4a6d-8fa9-e16af155f6af",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.139.104.115",
      "pattern": "[ipv4-addr:value = '45.139.104.115']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secr",
          "url": "https://www.stepsecurity.io/blog/find-unused-stale-and-oidc-replaceable-github-actions-secrets-across-your-github-organization"
        },
        {
          "source_name": "GitHub Secret Scanning Public Monitoring for Enterprises: Co",
          "url": "https://www.stepsecurity.io/blog/github-secret-scanning-public-monitoring-for-enterprises-coverage-and-gaps"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6a8c5359-1467-4087-9dc9-db843453c1f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: acac5a9854650c4ae2883c4740bf87d34120c038",
      "pattern": "[file:hashes.'SHA-1' = 'acac5a9854650c4ae2883c4740bf87d34120c038']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secr",
          "url": "https://www.stepsecurity.io/blog/find-unused-stale-and-oidc-replaceable-github-actions-secrets-across-your-github-organization"
        },
        {
          "source_name": "Megalodon: Mass GitHub Actions Secret Exfiltration Across 5,",
          "url": "https://www.stepsecurity.io/blog/megalodon-mass-github-actions-secret-exfiltration-across-5-500-public-repositories"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f9293051-4433-406b-a64e-f6ba114154d7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-50522",
      "pattern": "[vulnerability:name = 'CVE-2026-50522']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-50522 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--063cc692-a000-4370-893f-dd7cb31b3d80",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: npmjs.help",
      "pattern": "[domain-name:value = 'npmjs.help']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The upgrade trap: when upgrading is the wrong answer to a CV",
          "url": "https://www.aikido.dev/blog/cve-upgrade-breaking-changes-open-source"
        },
        {
          "source_name": "What is a dependency firewall?",
          "url": "https://www.aikido.dev/blog/what-is-a-dependency-firewall"
        },
        {
          "source_name": "npm Supply Chain Attack via Open Source maintainer compromis",
          "url": "https://snyk.io/blog/npm-supply-chain-attack-via-open-source-maintainer-compromise/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7a2c6248-da8d-4d96-ba96-7a222167d490",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 139.28.37.250",
      "pattern": "[ipv4-addr:value = '139.28.37.250']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-16232 \u2014 Check Point SmartConsole Improper",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--974d9196-95bc-485f-bdbf-1527f64bbbc3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 151.241.99.207",
      "pattern": "[ipv4-addr:value = '151.241.99.207']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-16232 \u2014 Check Point SmartConsole Improper",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8397b9c5-c147-4b3e-9808-294af9a671bc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 151.241.99.233",
      "pattern": "[ipv4-addr:value = '151.241.99.233']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-16232 \u2014 Check Point SmartConsole Improper",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6602b2e8-caaa-4a42-bbfd-67e7070dd83b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 158.62.198.182",
      "pattern": "[ipv4-addr:value = '158.62.198.182']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-16232 \u2014 Check Point SmartConsole Improper",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--887718d1-2793-4a6a-8da7-f18f627db124",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.142.10.99",
      "pattern": "[ipv4-addr:value = '192.142.10.99']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-16232 \u2014 Check Point SmartConsole Improper",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--901caca6-0c3c-4eef-8f11-2c0968c53bdb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.213.18.137",
      "pattern": "[ipv4-addr:value = '194.213.18.137']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-16232 \u2014 Check Point SmartConsole Improper",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e66cf366-44d6-4a3a-8a77-b59548b537fa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-42005",
      "pattern": "[vulnerability:name = 'CVE-2024-42005']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "SQL injection isn't dead",
          "url": "https://www.aikido.dev/blog/sql-injection-isnt-dead"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f51e176e-aebf-4653-b431-b7c580448427",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-48937",
      "pattern": "[vulnerability:name = 'CVE-2026-48937']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The upgrade trap: when upgrading is the wrong answer to a CV",
          "url": "https://www.aikido.dev/blog/cve-upgrade-breaking-changes-open-source"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--825389e6-820e-4108-9a39-f4539985829e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: attacker.tld",
      "pattern": "[domain-name:value = 'attacker.tld']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Finding eight high-severity vulnerabilities in NodeBB in six",
          "url": "https://www.aikido.dev/blog/eight-high-severity-vulnerabilities-nodebb"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a20bf513-780c-4f3a-af7b-633b82cb957a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: rhythm-broke-heath-kernel.trycloudflare.com",
      "pattern": "[domain-name:value = 'rhythm-broke-heath-kernel.trycloudflare.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Finding eight high-severity vulnerabilities in NodeBB in six",
          "url": "https://www.aikido.dev/blog/eight-high-severity-vulnerabilities-nodebb"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aabf07bb-4d43-433a-a2bb-b8778108dc7b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 4.245.3.4",
      "pattern": "[ipv4-addr:value = '4.245.3.4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Finding eight high-severity vulnerabilities in NodeBB in six",
          "url": "https://www.aikido.dev/blog/eight-high-severity-vulnerabilities-nodebb"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7caccc05-c85f-4e9f-ab18-a645c4abde50",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 0ff6abe0252d4f37a196a1231fae5f26",
      "pattern": "[file:hashes.MD5 = '0ff6abe0252d4f37a196a1231fae5f26']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Sol Searching | Can Frontier Models Tackle Autonomous Long-H",
          "url": "https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1022668c-bf46-44d2-94da-6fb56fa5738e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 410eddfc19de44249897986ecc8ac449",
      "pattern": "[file:hashes.MD5 = '410eddfc19de44249897986ecc8ac449']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Sol Searching | Can Frontier Models Tackle Autonomous Long-H",
          "url": "https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cfd04eb9-d3c5-45a9-9dc3-152471649523",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: dbe51eabebf9d4ef9581ef99844a2944",
      "pattern": "[file:hashes.MD5 = 'dbe51eabebf9d4ef9581ef99844a2944']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Sol Searching | Can Frontier Models Tackle Autonomous Long-H",
          "url": "https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d0dad686-1648-4237-9ee9-3c00d522f030",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 675cb83cec5f25ebbe8d9f90dea3d836fcb1c234",
      "pattern": "[file:hashes.'SHA-1' = '675cb83cec5f25ebbe8d9f90dea3d836fcb1c234']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Sol Searching | Can Frontier Models Tackle Autonomous Long-H",
          "url": "https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5be6333b-e551-423b-b47e-45c2c4eb90c3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 92e9dcaf7249110047ef121b7586c81d4b8cb4e5",
      "pattern": "[file:hashes.'SHA-1' = '92e9dcaf7249110047ef121b7586c81d4b8cb4e5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Sol Searching | Can Frontier Models Tackle Autonomous Long-H",
          "url": "https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ab4f58c9-b9b0-4187-9415-f8b8933b9c8e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: de584703c78a60a56028f9834086facd1401b355",
      "pattern": "[file:hashes.'SHA-1' = 'de584703c78a60a56028f9834086facd1401b355']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Sol Searching | Can Frontier Models Tackle Autonomous Long-H",
          "url": "https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1de475dd-8d07-40e5-a071-dbbe2a7a57f1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 07c69fc33271cf5a2ce03ac1fed7a3b16357aec093c5bf9ef61fbfa4348d0529",
      "pattern": "[file:hashes.'SHA-256' = '07c69fc33271cf5a2ce03ac1fed7a3b16357aec093c5bf9ef61fbfa4348d0529']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Sol Searching | Can Frontier Models Tackle Autonomous Long-H",
          "url": "https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--81f9cbed-8f0f-43e1-baf1-d23e20816a62",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8fcb4d3d4df61719ee3da98241393779290e0efcd88a49e363e2a2dfbc04dae9",
      "pattern": "[file:hashes.'SHA-256' = '8fcb4d3d4df61719ee3da98241393779290e0efcd88a49e363e2a2dfbc04dae9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Sol Searching | Can Frontier Models Tackle Autonomous Long-H",
          "url": "https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--043e4f13-24ed-4222-816e-dc5cc01f7b96",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9a10e1faa86a5d39417cae44da5adf38824dfb9a16432e34df766aa1dc9e3525",
      "pattern": "[file:hashes.'SHA-256' = '9a10e1faa86a5d39417cae44da5adf38824dfb9a16432e34df766aa1dc9e3525']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Sol Searching | Can Frontier Models Tackle Autonomous Long-H",
          "url": "https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fc84de08-398b-4fea-8af5-bddbd3f63fa4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-27137",
      "pattern": "[vulnerability:name = 'CVE-2021-27137']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27137 \u2014 DD-WRT Stack-Based Buffer Overflo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--908be6a7-8dc9-46d6-8a99-b5dc4c80e25e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-0770",
      "pattern": "[vulnerability:name = 'CVE-2026-0770']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-0770 \u2014 Langflow Inclusion of Functionalit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0208b44-8beb-492e-a538-02300b2689f5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-20896",
      "pattern": "[vulnerability:name = 'CVE-2026-20896']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-20896: Gitea Docker image: `REVER",
          "url": "https://github.com/advisories/GHSA-f75j-4cw6-rmx4"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ca57585a-804f-4fbe-828f-4c8dc75ae29e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-22874",
      "pattern": "[vulnerability:name = 'CVE-2026-22874']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-22874: Gitea: Incomplete SSRF Pro",
          "url": "https://github.com/advisories/GHSA-2r5c-gw76-rh3w"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--899b5661-2520-4b04-a73f-7dcf4e9a91dd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-56750",
      "pattern": "[vulnerability:name = 'CVE-2026-56750']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-56750: Gitea Remember-Me Token Th",
          "url": "https://github.com/advisories/GHSA-rgv6-xp99-6mgj"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--15d3f5dc-4202-4b9f-8b01-74bc6708184c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-58426",
      "pattern": "[vulnerability:name = 'CVE-2026-58426']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-58426: Gitea Actions Artifacts V4",
          "url": "https://github.com/advisories/GHSA-hg5r-vq93-9fv6"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5cd15387-0caf-4ebd-900d-50e353f287b1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-58443",
      "pattern": "[vulnerability:name = 'CVE-2026-58443']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-58443: Gitea: Public-only reposit",
          "url": "https://github.com/advisories/GHSA-xxjv-752h-3vp2"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2d1cf512-de0b-4c8c-b9c8-395ce3ce48a5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-59891",
      "pattern": "[vulnerability:name = 'CVE-2026-59891']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-59891: Credential confusion in @s",
          "url": "https://github.com/advisories/GHSA-pf56-329r-95rw"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2853913e-8a58-482b-863c-9422ef163a0c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-64825",
      "pattern": "[vulnerability:name = 'CVE-2026-64825']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-64825: Home Assistant Core vulner",
          "url": "https://github.com/advisories/GHSA-5hxg-r395-fqxx"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5bec7df4-5780-4e7b-8288-adc106bf0129",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-73653",
      "pattern": "[vulnerability:name = 'CVE-2026-73653']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-73653: @vitest/browser: Browser M",
          "url": "https://github.com/advisories/GHSA-p63j-vcc4-9vmv"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0382413-36c5-4563-b809-d869b5a7678c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 159.26.98.241",
      "pattern": "[ipv4-addr:value = '159.26.98.241']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-20896: Gitea Docker image: `REVER",
          "url": "https://github.com/advisories/GHSA-f75j-4cw6-rmx4"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c1c5e9f-c4d1-44e5-9307-8be64dce2f79",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-59873",
      "pattern": "[vulnerability:name = 'CVE-2026-59873']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-59873: node-tar: Decompression/pa",
          "url": "https://github.com/advisories/GHSA-23hp-3jrh-7fpw"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bfb8b807-ec67-4602-8f3b-5e5fb5d54463",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-61736",
      "pattern": "[vulnerability:name = 'CVE-2026-61736']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-61736: LightRAG: CORS Wildcard + ",
          "url": "https://github.com/advisories/GHSA-6x6h-qqr7-855w"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d71e96a0-df2a-4355-b044-4d631edf4e9a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-61740",
      "pattern": "[vulnerability:name = 'CVE-2026-61740']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-61740: LightRAG is Vulnerable to ",
          "url": "https://github.com/advisories/GHSA-f4vv-55c2-5789"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--634eaea0-4a63-40ab-93bb-bc01899421c0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: git.disroot.org",
      "pattern": "[domain-name:value = 'git.disroot.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "SleeperGem: Compromised git_credential_manager, Dendreo, and",
          "url": "https://www.stepsecurity.io/blog/sleepergem-compromised-rubygems-drop-persistent-backdoor"
        },
        {
          "source_name": "SleeperGem: RubyGems supply chain attack targets dormant mai",
          "url": "https://www.aikido.dev/blog/sleepergem-rubygems-supply-chain-attack"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--85baa7d9-0e8a-4504-9471-3c27b3a21872",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-40947",
      "pattern": "[vulnerability:name = 'CVE-2025-40947']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilo",
          "url": "https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9af5b4a6-19f2-4605-84a0-4c080dcd5b84",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-40948",
      "pattern": "[vulnerability:name = 'CVE-2025-40948']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilo",
          "url": "https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--527560c7-36f9-4d2b-b854-262c30baa6ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-40949",
      "pattern": "[vulnerability:name = 'CVE-2025-40949']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilo",
          "url": "https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f8c4f471-9759-40d9-894a-29c0c3876e5e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-25089",
      "pattern": "[vulnerability:name = 'CVE-2026-25089']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-25089 \u2014 Fortinet FortiSandbox OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-39808 \u2014 Fortinet FortiSandbox OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f492d6a6-b3d8-42db-9aea-5cf47d527133",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-39808",
      "pattern": "[vulnerability:name = 'CVE-2026-39808']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-39808 \u2014 Fortinet FortiSandbox OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--332b0f96-d602-4c45-93ac-22a3fce24cb8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-39813",
      "pattern": "[vulnerability:name = 'CVE-2026-39813']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-39808 \u2014 Fortinet FortiSandbox OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c212ea6f-7404-43d0-9af5-35afc68b8bc1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-50661",
      "pattern": "[vulnerability:name = 'CVE-2026-50661']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Begun, the Patch Wars have",
          "url": "https://blog.talosintelligence.com/begun-the-patch-wars-have/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--482d5288-0763-4329-84a1-31c34f5bb697",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-53713",
      "pattern": "[vulnerability:name = 'CVE-2026-53713']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-53713: Envoy Gateway: Authenticat",
          "url": "https://github.com/advisories/GHSA-wcrf-9vrr-854f"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--84232fa3-6598-4db7-a924-4a2a5f3a0c57",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-55579",
      "pattern": "[vulnerability:name = 'CVE-2026-55579']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-55579: Pheditor: Hardcoded defaul",
          "url": "https://github.com/advisories/GHSA-p4h7-p9rj-2pq2"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a44fae55-8ac7-460d-87b3-88cdd509d94f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-56155",
      "pattern": "[vulnerability:name = 'CVE-2026-56155']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Begun, the Patch Wars have",
          "url": "https://blog.talosintelligence.com/begun-the-patch-wars-have/"
        },
        {
          "source_name": "CISA KEV: CVE-2026-56155 \u2014 Microsoft Active Directory Federa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c666a0aa-66e8-43e2-8e18-3e09acceabf3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-56164",
      "pattern": "[vulnerability:name = 'CVE-2026-56164']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Begun, the Patch Wars have",
          "url": "https://blog.talosintelligence.com/begun-the-patch-wars-have/"
        },
        {
          "source_name": "CISA KEV: CVE-2026-56164 \u2014 Microsoft SharePoint Server Missi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--74baf99a-43ed-417b-964d-1ebb03a15c74",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-58644",
      "pattern": "[vulnerability:name = 'CVE-2026-58644']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-58644 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--905aacda-dc38-415a-8621-205a1144b117",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: aipythondevs.com",
      "pattern": "[domain-name:value = 'aipythondevs.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Begun, the Patch Wars have",
          "url": "https://blog.talosintelligence.com/begun-the-patch-wars-have/"
        },
        {
          "source_name": "UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 imp",
          "url": "https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb7ba364-7f15-42bf-a8d8-e72797253796",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: dht.transmissionbt.com",
      "pattern": "[domain-name:value = 'dht.transmissionbt.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Deliver",
          "url": "https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--efff31cf-40b0-4836-82ef-5aafedc9e02d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: eorthopaedics.com",
      "pattern": "[domain-name:value = 'eorthopaedics.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Begun, the Patch Wars have",
          "url": "https://blog.talosintelligence.com/begun-the-patch-wars-have/"
        },
        {
          "source_name": "UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 imp",
          "url": "https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c956802a-e346-48c4-911e-cb816395a56e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: relay.damus.io",
      "pattern": "[domain-name:value = 'relay.damus.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Deliver",
          "url": "https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b9fa3e65-211a-4b3b-9017-6d1198a3cb55",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: relay.nostr.com",
      "pattern": "[domain-name:value = 'relay.nostr.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Deliver",
          "url": "https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--859e1972-0d2b-4078-a09a-fd02e81d41eb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: router.bittorrent.com",
      "pattern": "[domain-name:value = 'router.bittorrent.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Deliver",
          "url": "https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--48fa624b-7273-4be7-a60a-ded2cb15844d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sastoro.com",
      "pattern": "[domain-name:value = 'sastoro.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Begun, the Patch Wars have",
          "url": "https://blog.talosintelligence.com/begun-the-patch-wars-have/"
        },
        {
          "source_name": "UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 imp",
          "url": "https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b60e7da9-9ec7-4aea-a72d-ca2ac0fa9c86",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: web-devtools.com",
      "pattern": "[domain-name:value = 'web-devtools.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Begun, the Patch Wars have",
          "url": "https://blog.talosintelligence.com/begun-the-patch-wars-have/"
        },
        {
          "source_name": "UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 imp",
          "url": "https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bf289db8-ff8b-45f2-a472-2705da5507ca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: windowscreenrepairnearme.com",
      "pattern": "[domain-name:value = 'windowscreenrepairnearme.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Begun, the Patch Wars have",
          "url": "https://blog.talosintelligence.com/begun-the-patch-wars-have/"
        },
        {
          "source_name": "UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 imp",
          "url": "https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e984ac9-c163-4056-8a82-12ebdfd53f5d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: zynaris.io",
      "pattern": "[domain-name:value = 'zynaris.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Begun, the Patch Wars have",
          "url": "https://blog.talosintelligence.com/begun-the-patch-wars-have/"
        },
        {
          "source_name": "UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 imp",
          "url": "https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--22dc6054-46e2-4c14-a5ff-ae66822a89c3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 85.137.53.71",
      "pattern": "[ipv4-addr:value = '85.137.53.71']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Deliver",
          "url": "https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm"
        },
        {
          "source_name": "AsyncAPI npm packages backdoored via GitHub Actions",
          "url": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--28b756d0-3352-4b5c-a3cf-c84854252598",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 0398df5a18f71efcfeef4571a2cef577",
      "pattern": "[file:hashes.MD5 = '0398df5a18f71efcfeef4571a2cef577']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Begun, the Patch Wars have",
          "url": "https://blog.talosintelligence.com/begun-the-patch-wars-have/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--80c0d64e-7df4-4bb5-bf98-352958e843f0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 24b9ee242f21a73b55f7bb3297eafb33c60840907386b542ed79fc6b72365168",
      "pattern": "[file:hashes.'SHA-256' = '24b9ee242f21a73b55f7bb3297eafb33c60840907386b542ed79fc6b72365168']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Deliver",
          "url": "https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f545ab8-d57b-49aa-b82d-e54587167415",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6e78713b75bd34828d49896176627f7face7aa9036cd874f2e02d9f23a9a9c71",
      "pattern": "[file:hashes.'SHA-256' = '6e78713b75bd34828d49896176627f7face7aa9036cd874f2e02d9f23a9a9c71']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Deliver",
          "url": "https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb46ed14-2def-422a-98e2-bbc4cef0465c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b270bdf8e2274ea1af0a6eed74d8f10e5fe61012d6cc226a43cc7cc7fd9f6292",
      "pattern": "[file:hashes.'SHA-256' = 'b270bdf8e2274ea1af0a6eed74d8f10e5fe61012d6cc226a43cc7cc7fd9f6292']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Deliver",
          "url": "https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb941803-4c37-4207-bd97-015818b52fd1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b8be9a5e0a191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a",
      "pattern": "[file:hashes.'SHA-256' = 'b8be9a5e0a191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Begun, the Patch Wars have",
          "url": "https://blog.talosintelligence.com/begun-the-patch-wars-have/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Cisco Talos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7e155b45-3170-4b7c-8edf-b6484cecb5ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: byte-io.us",
      "pattern": "[domain-name:value = 'byte-io.us']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Runtime Security for Third-Party GitHub Actions Runners: Bit",
          "url": "https://www.stepsecurity.io/blog/runtime-security-for-third-party-github-actions-runners"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e3ac1c48-e2ce-4321-87a4-f9dc976b234e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cloud-sync.online",
      "pattern": "[domain-name:value = 'cloud-sync.online']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Runtime Security for Third-Party GitHub Actions Runners: Bit",
          "url": "https://www.stepsecurity.io/blog/runtime-security-for-third-party-github-actions-runners"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f72aa5d8-45bc-4e62-8e54-0c0172a31344",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: datahub.ink",
      "pattern": "[domain-name:value = 'datahub.ink']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Runtime Security for Third-Party GitHub Actions Runners: Bit",
          "url": "https://www.stepsecurity.io/blog/runtime-security-for-third-party-github-actions-runners"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4cd9d31-13aa-4185-bd3c-c8933ea1f529",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 208.115.220.17",
      "pattern": "[ipv4-addr:value = '208.115.220.17']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Runtime Security for Third-Party GitHub Actions Runners: Bit",
          "url": "https://www.stepsecurity.io/blog/runtime-security-for-third-party-github-actions-runners"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d46c72e9-2d19-4758-8e6b-0fc561c513ae",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 89.36.224.5",
      "pattern": "[ipv4-addr:value = '89.36.224.5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Runtime Security for Third-Party GitHub Actions Runners: Bit",
          "url": "https://www.stepsecurity.io/blog/runtime-security-for-third-party-github-actions-runners"
        },
        {
          "source_name": "Harden-Runner Block Mode Now Available for macOS and Windows",
          "url": "https://www.stepsecurity.io/blog/harden-runner-block-mode-now-available-for-macos-and-windows-github-hosted-runners"
        },
        {
          "source_name": "@velora-dex/sdk Compromised on npm: Malicious Version Drops ",
          "url": "https://www.stepsecurity.io/blog/velora-dex-sdk-compromised-on-npm-malicious-version-drops-macos-backdoor-via-launchctl-persistence"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bdbc2bc8-6035-4216-bc38-c8599869df56",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 0a8ab3d16b12d3a453ee5a3208fe04744ad54514ef8ea27bb8fe32679efad270",
      "pattern": "[file:hashes.'SHA-256' = '0a8ab3d16b12d3a453ee5a3208fe04744ad54514ef8ea27bb8fe32679efad270']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Runtime Security for Third-Party GitHub Actions Runners: Bit",
          "url": "https://www.stepsecurity.io/blog/runtime-security-for-third-party-github-actions-runners"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6855bb32-e99c-4bff-b986-52e52533eab8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 0b028b781950641818800fee2b4bf68e4ef2bcee53fe71a21755275ba108783d",
      "pattern": "[file:hashes.'SHA-256' = '0b028b781950641818800fee2b4bf68e4ef2bcee53fe71a21755275ba108783d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Runtime Security for Third-Party GitHub Actions Runners: Bit",
          "url": "https://www.stepsecurity.io/blog/runtime-security-for-third-party-github-actions-runners"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a7e34329-b19b-4e1c-bf70-8d0eb317e94c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-4346",
      "pattern": "[vulnerability:name = 'CVE-2023-4346']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-4346 \u2014 KNX Association KNX Protocol Conne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f1876d17-4da3-41e2-8245-76b576cc0727",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-46817",
      "pattern": "[vulnerability:name = 'CVE-2026-46817']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-46817 \u2014 Oracle E-Business Suite Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3f43eb83-3bc5-41fa-8b20-68a61d0a83ff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-47156",
      "pattern": "[vulnerability:name = 'CVE-2026-47156']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-47156: MantisBT: SOAP API Authent",
          "url": "https://github.com/advisories/GHSA-c2xg-qjqw-2v98"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d9b64e6b-d07d-4229-b4fb-c15afb793f12",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-52847",
      "pattern": "[vulnerability:name = 'CVE-2026-52847']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-52881: MantisBT: Reflected XSS in",
          "url": "https://github.com/advisories/GHSA-vcrw-4xvv-jh49"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8044c2d8-89db-44f4-8fc8-497a08d872fc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-52881",
      "pattern": "[vulnerability:name = 'CVE-2026-52881']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-52881: MantisBT: Reflected XSS in",
          "url": "https://github.com/advisories/GHSA-vcrw-4xvv-jh49"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ef097131-f2e2-48e1-9b0a-621ce0bafcc2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: digikalas.online",
      "pattern": "[domain-name:value = 'digikalas.online']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted ",
          "url": "https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9e955de0-52d0-499b-893d-c4fc89a0899c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: newtuxdev.sevielw.digikalas.online",
      "pattern": "[domain-name:value = 'newtuxdev.sevielw.digikalas.online']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted ",
          "url": "https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32e57bc1-4a6e-4eda-b16e-3d8c489c744b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.10.68.127",
      "pattern": "[ipv4-addr:value = '185.10.68.127']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted ",
          "url": "https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f86da9b-b60d-4d6c-9fb6-9116f1b168f1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 209.182.237.133",
      "pattern": "[ipv4-addr:value = '209.182.237.133']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted ",
          "url": "https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a5aefe37-b833-400f-ae99-1cd52e0a99b0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 71dfbb171eca4ef9d02ff630b56e5283bbef7b375d4dbe9e8c9531bef312fa8d",
      "pattern": "[file:hashes.'SHA-256' = '71dfbb171eca4ef9d02ff630b56e5283bbef7b375d4dbe9e8c9531bef312fa8d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted ",
          "url": "https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Unit 42 (Palo Alto)"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0324dd2b-1da2-466f-a4fc-c85842432c47",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-15409",
      "pattern": "[vulnerability:name = 'CVE-2026-15409']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-15409 \u2014 SonicWall SMA1000 Appliances Serv",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-15410 \u2014 SonicWall SMA1000 Appliances Code",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--16433d88-800c-44eb-90ce-8dfcad01c5b2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-15410",
      "pattern": "[vulnerability:name = 'CVE-2026-15410']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-15409 \u2014 SonicWall SMA1000 Appliances Serv",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-15410 \u2014 SonicWall SMA1000 Appliances Code",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4d36510e-f550-4004-8824-20f3ad9b99a5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-45262",
      "pattern": "[vulnerability:name = 'CVE-2026-45262']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-45262: FacturaScripts: Authentica",
          "url": "https://github.com/advisories/GHSA-5qmh-x653-g8qj"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e7abd682-3bec-480e-afa8-89a72190eafc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-50006",
      "pattern": "[vulnerability:name = 'CVE-2026-50006']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-50006: Anyquery: Arbitrary File W",
          "url": "https://github.com/advisories/GHSA-xrcf-6jh3-ggvx"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c230e17-0494-4da2-8f68-090b83973637",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-52824",
      "pattern": "[vulnerability:name = 'CVE-2026-52824']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-52824: Kimai: Default APP_SECRET ",
          "url": "https://github.com/advisories/GHSA-jr9p-4h4j-6c58"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e02ef1f6-58d1-4ebd-b6c4-d34cfd5bceb6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-54052",
      "pattern": "[vulnerability:name = 'CVE-2026-54052']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-54052: n8n-MCP: Cross-tenant acce",
          "url": "https://github.com/advisories/GHSA-j6r7-6fhx-77wx"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--10fdf846-adda-43a7-9adc-2970e515d691",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.37.32.179",
      "pattern": "[ipv4-addr:value = '193.37.32.179']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-15409 \u2014 SonicWall SMA1000 Appliances Serv",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-15410 \u2014 SonicWall SMA1000 Appliances Code",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--55d79478-3836-4c0a-b1dc-f0c924984f2b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.37.32.214",
      "pattern": "[ipv4-addr:value = '193.37.32.214']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-15409 \u2014 SonicWall SMA1000 Appliances Serv",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-15410 \u2014 SonicWall SMA1000 Appliances Code",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--618ab9cb-1031-485c-bbc1-73a679209580",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 216.73.163.151",
      "pattern": "[ipv4-addr:value = '216.73.163.151']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-15409 \u2014 SonicWall SMA1000 Appliances Serv",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-15410 \u2014 SonicWall SMA1000 Appliances Code",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4bc9a773-c64b-4f75-b6b3-3370d3083427",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 216.73.163.158",
      "pattern": "[ipv4-addr:value = '216.73.163.158']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-15409 \u2014 SonicWall SMA1000 Appliances Serv",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-15410 \u2014 SonicWall SMA1000 Appliances Code",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b4d56c18-3b30-4ee6-8af5-b068b73535b4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ipfs.io",
      "pattern": "[domain-name:value = 'ipfs.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "AsyncAPI npm packages backdoored via GitHub Actions",
          "url": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c677924-119a-47c0-adf7-c5678bd19a11",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 22bf76fe317ea6769bd38619bd440e42d119bd6b",
      "pattern": "[file:hashes.'SHA-1' = '22bf76fe317ea6769bd38619bd440e42d119bd6b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "AsyncAPI npm packages backdoored via GitHub Actions",
          "url": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--86594be1-4fd3-42a8-8887-2cdc63b0504f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 9890950adcbc2478e7a080234f053214adbad44e",
      "pattern": "[file:hashes.'SHA-1' = '9890950adcbc2478e7a080234f053214adbad44e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "AsyncAPI npm packages backdoored via GitHub Actions",
          "url": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--58a27c3c-84de-479b-b49b-e2cb40391bb3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: a7e18d96efd3cdb127ef4cdcad9e3ad26c482bf2",
      "pattern": "[file:hashes.'SHA-1' = 'a7e18d96efd3cdb127ef4cdcad9e3ad26c482bf2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "AsyncAPI npm packages backdoored via GitHub Actions",
          "url": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--328fb6da-6791-4448-801f-165e85704000",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: c70e105e212ff3c1daa04bb2a62507717f296b0b",
      "pattern": "[file:hashes.'SHA-1' = 'c70e105e212ff3c1daa04bb2a62507717f296b0b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "AsyncAPI npm packages backdoored via GitHub Actions",
          "url": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32f8c288-93bb-43c5-865f-49c8c860844d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: c8cb3f6d5b90c46686d2bf531dc1a5786e27edc5",
      "pattern": "[file:hashes.'SHA-1' = 'c8cb3f6d5b90c46686d2bf531dc1a5786e27edc5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "AsyncAPI npm packages backdoored via GitHub Actions",
          "url": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e1126e7c-4122-4f5f-9fb9-3262a6f57c92",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 082d733db0687dcd768104972b065d4b58cb1e6043688c6c20fa3702337f36ab",
      "pattern": "[file:hashes.'SHA-256' = '082d733db0687dcd768104972b065d4b58cb1e6043688c6c20fa3702337f36ab']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "AsyncAPI npm packages backdoored via GitHub Actions",
          "url": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--96ea253d-7e47-4626-a816-421e319f30c4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 34014776d3d3ff11bc4439b02fd7ac0f02a887eb3a052eeaffd236e2f6db8ad1",
      "pattern": "[file:hashes.'SHA-256' = '34014776d3d3ff11bc4439b02fd7ac0f02a887eb3a052eeaffd236e2f6db8ad1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "AsyncAPI npm packages backdoored via GitHub Actions",
          "url": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a62f48e5-d82d-46e3-8c93-ca83154bc7e9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9b2e65db653ca8575c9b10eefb9a80c6006404812c2ec212bf5675e3c690233b",
      "pattern": "[file:hashes.'SHA-256' = '9b2e65db653ca8575c9b10eefb9a80c6006404812c2ec212bf5675e3c690233b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "AsyncAPI npm packages backdoored via GitHub Actions",
          "url": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b4e499e9-b3c0-4c28-80be-1f73c7166126",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9e214f38537e69bf51c7fa1ddd35ae495e9cb897231ec010baf9e4f29407ee9a",
      "pattern": "[file:hashes.'SHA-256' = '9e214f38537e69bf51c7fa1ddd35ae495e9cb897231ec010baf9e4f29407ee9a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "AsyncAPI npm packages backdoored via GitHub Actions",
          "url": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a272905-d91a-4dfe-ba13-21cb27824b0a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: bfaeb987faa6de2b5a5eb63b1233d055215b09b0349a9394f2175fd7cdf385e4",
      "pattern": "[file:hashes.'SHA-256' = 'bfaeb987faa6de2b5a5eb63b1233d055215b09b0349a9394f2175fd7cdf385e4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "AsyncAPI npm packages backdoored via GitHub Actions",
          "url": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a5680b39-05e5-4d48-b575-84d4fddfd3ba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f873941d1907a97dc6c718fdecf59fd7d91f3f8212da2f7e5314b878b88bdc0b",
      "pattern": "[file:hashes.'SHA-256' = 'f873941d1907a97dc6c718fdecf59fd7d91f3f8212da2f7e5314b878b88bdc0b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "AsyncAPI npm packages backdoored via GitHub Actions",
          "url": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ba094bc3-1db9-45cc-b2be-f2a17377bbd0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-10797",
      "pattern": "[vulnerability:name = 'CVE-2026-10797']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Forgotten UEFI shims undermining Secure Boot",
          "url": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4cdbc79a-d56f-4495-b9b0-b3c97fe9dec1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-8863",
      "pattern": "[vulnerability:name = 'CVE-2026-8863']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Forgotten UEFI shims undermining Secure Boot",
          "url": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ab56ac4-eefa-475a-94b7-7c0a9fcb5454",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 236A9CB0D71951C36398A32EB660CE2CD4A52CCFA7CF751CC6A35D9DE549E19B",
      "pattern": "[file:hashes.'SHA-256' = '236A9CB0D71951C36398A32EB660CE2CD4A52CCFA7CF751CC6A35D9DE549E19B']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Forgotten UEFI shims undermining Secure Boot",
          "url": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e260d1a8-f706-4244-a298-c6783596b9f5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 410260B1B6F5AF5FBEEB9EA3220658435E876CB3247126EE907A437F312DB373",
      "pattern": "[file:hashes.'SHA-256' = '410260B1B6F5AF5FBEEB9EA3220658435E876CB3247126EE907A437F312DB373']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Forgotten UEFI shims undermining Secure Boot",
          "url": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc514db9-a99c-46fc-98ea-d962dfa2d8fc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5E594C448760A3135B1A3A83E07A4F2E6FBE49414EF2C7CAB1CBA77F284FA63B",
      "pattern": "[file:hashes.'SHA-256' = '5E594C448760A3135B1A3A83E07A4F2E6FBE49414EF2C7CAB1CBA77F284FA63B']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Forgotten UEFI shims undermining Secure Boot",
          "url": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--784081f1-7fb9-4361-b1f4-218b27e3f244",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7B2A3F5C96F95BD8086CE54B0825E300F9C8F11FE3401BB631B3215C8DE9EB10",
      "pattern": "[file:hashes.'SHA-256' = '7B2A3F5C96F95BD8086CE54B0825E300F9C8F11FE3401BB631B3215C8DE9EB10']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Forgotten UEFI shims undermining Secure Boot",
          "url": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--96696946-6e03-4623-941a-5e6d8f76b735",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8A964D5F8373948D20A1D4296FB92E545DAD4617A0C810F3B934B53D98AE8963",
      "pattern": "[file:hashes.'SHA-256' = '8A964D5F8373948D20A1D4296FB92E545DAD4617A0C810F3B934B53D98AE8963']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Forgotten UEFI shims undermining Secure Boot",
          "url": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--963260b0-628c-4eaa-9c18-ea9b83d0ff1c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 95B6D71FC0C0F8C5E1533A37AEF92CF6B0C961E2CC612A97117FA6759CE5FC06",
      "pattern": "[file:hashes.'SHA-256' = '95B6D71FC0C0F8C5E1533A37AEF92CF6B0C961E2CC612A97117FA6759CE5FC06']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Forgotten UEFI shims undermining Secure Boot",
          "url": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1ec8761d-2876-4fbc-a8ff-e56bb85ada5f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 96275DFD6282A522B011177EE049296952AC794832091F937FBBF92869028629",
      "pattern": "[file:hashes.'SHA-256' = '96275DFD6282A522B011177EE049296952AC794832091F937FBBF92869028629']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Forgotten UEFI shims undermining Secure Boot",
          "url": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aafcdf4a-33ba-463d-8013-7b14e62699d1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: A0DE9333442C1BF9349A460141AE5E80F911955C6506040FA3D021BF6C1AE3E4",
      "pattern": "[file:hashes.'SHA-256' = 'A0DE9333442C1BF9349A460141AE5E80F911955C6506040FA3D021BF6C1AE3E4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Forgotten UEFI shims undermining Secure Boot",
          "url": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e63e1ef3-be4a-4f16-bbb7-9c0c59103e80",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: AE75F0D82BA3DF824FBFC69340CC3B4D66C598373B1AB54CDB6C8BFD83A6B961",
      "pattern": "[file:hashes.'SHA-256' = 'AE75F0D82BA3DF824FBFC69340CC3B4D66C598373B1AB54CDB6C8BFD83A6B961']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Forgotten UEFI shims undermining Secure Boot",
          "url": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f78860ba-a0bd-4268-853b-d9b42ca01d06",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: EB86FA1386FE6E4533B8B938DCC1250616D2F1C14C15E2FCF80834A161018A0A",
      "pattern": "[file:hashes.'SHA-256' = 'EB86FA1386FE6E4533B8B938DCC1250616D2F1C14C15E2FCF80834A161018A0A']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Forgotten UEFI shims undermining Secure Boot",
          "url": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1094a1f0-c99c-4736-bfe2-3804dfb32676",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: FD23D6E57DE6F4E1F9D7118DA1C5F31A8AF6BE5E5D9E8170F9493447268D50C5",
      "pattern": "[file:hashes.'SHA-256' = 'FD23D6E57DE6F4E1F9D7118DA1C5F31A8AF6BE5E5D9E8170F9493447268D50C5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Forgotten UEFI shims undermining Secure Boot",
          "url": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6896f27b-7cdc-48fc-b127-3b8742d0d008",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2008-4128",
      "pattern": "[vulnerability:name = 'CVE-2008-4128']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2008-4128 \u2014 Cisco IOS Cross-Site Request Forge",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2a545a8a-424f-43e0-a256-63901a0a0d0d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-45579",
      "pattern": "[vulnerability:name = 'CVE-2026-45579']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-45579: DIRAC is vulnerable to RCE",
          "url": "https://github.com/advisories/GHSA-9jpv-c7p4-997x"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d0528f00-cd41-45c2-9bdd-6eb041fd59f9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-47677",
      "pattern": "[vulnerability:name = 'CVE-2026-47677']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-47677: FacturaScripts: Account ta",
          "url": "https://github.com/advisories/GHSA-c67f-gmxw-mj93"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1221414f-b593-4edb-a42e-956035028b40",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-61667",
      "pattern": "[vulnerability:name = 'CVE-2026-61667']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-61667: DIRAC is vulnerable to RCE",
          "url": "https://github.com/advisories/GHSA-m4m7-4cw8-62j6"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1bd34c33-05ee-4040-ace6-90dfb65bbace",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: giftshop.club",
      "pattern": "[domain-name:value = 'giftshop.club']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "What is a dependency firewall?",
          "url": "https://www.aikido.dev/blog/what-is-a-dependency-firewall"
        },
        {
          "source_name": "Code is being written everywhere, and the device is the only",
          "url": "https://www.aikido.dev/blog/code-is-written-everywhere"
        },
        {
          "source_name": "What MDM can't protect on developer machines (and what to do",
          "url": "https://www.aikido.dev/blog/what-mdm-cant-protect"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e4b488f6-5d70-4a44-9a39-37d972a25e48",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: webhook.site",
      "pattern": "[domain-name:value = 'webhook.site']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "How Aikido Intel detects malware and vulnerabilities first",
          "url": "https://www.aikido.dev/blog/aikido-intel-detects-malware-vulnerabilities-first"
        },
        {
          "source_name": "npm v12 delivers one of the biggest security improvements in",
          "url": "https://www.aikido.dev/blog/npm-v12-block-postinstall"
        },
        {
          "source_name": "kubernetes-el Compromised: How a Pwn Request Exploited a Pop",
          "url": "https://www.stepsecurity.io/blog/kubernetes-el-compromised-how-a-pwn-request-exploited-a-popular-emacs-package"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "StepSecurity",
        "Snyk",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a008a849-04d2-48a5-b5a9-d7d749e6a2f2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 46faab8ab153fae6e80e7cca38eab363075bb524edd79e42269217a083628f09",
      "pattern": "[file:hashes.'SHA-256' = '46faab8ab153fae6e80e7cca38eab363075bb524edd79e42269217a083628f09']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "How Aikido Intel detects malware and vulnerabilities first",
          "url": "https://www.aikido.dev/blog/aikido-intel-detects-malware-vulnerabilities-first"
        },
        {
          "source_name": "npm v12 delivers one of the biggest security improvements in",
          "url": "https://www.aikido.dev/blog/npm-v12-block-postinstall"
        },
        {
          "source_name": "Securing Vibe Coding and AI Coding Agents: An End-to-End App",
          "url": "https://www.stepsecurity.io/blog/securing-vibe-coding-and-ai-coding-agents-an-end-to-end-approach-with-stepsecurity"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e7918a12-996b-4239-a504-8c06bb83eedd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 62ee164b9b306250c1172583f138c9614139264f889fa99614903c12755468d0",
      "pattern": "[file:hashes.'SHA-256' = '62ee164b9b306250c1172583f138c9614139264f889fa99614903c12755468d0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "How Aikido Intel detects malware and vulnerabilities first",
          "url": "https://www.aikido.dev/blog/aikido-intel-detects-malware-vulnerabilities-first"
        },
        {
          "source_name": "npm v12 delivers one of the biggest security improvements in",
          "url": "https://www.aikido.dev/blog/npm-v12-block-postinstall"
        },
        {
          "source_name": "Securing Vibe Coding and AI Coding Agents: An End-to-End App",
          "url": "https://www.stepsecurity.io/blog/securing-vibe-coding-and-ai-coding-agents-an-end-to-end-approach-with-stepsecurity"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7005dc74-0dfb-4ce5-b745-123a39fc82c8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a3894003ad1d293ba96d77881ccd2071446dc3f65f434669b49b3da92421901a",
      "pattern": "[file:hashes.'SHA-256' = 'a3894003ad1d293ba96d77881ccd2071446dc3f65f434669b49b3da92421901a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "How Aikido Intel detects malware and vulnerabilities first",
          "url": "https://www.aikido.dev/blog/aikido-intel-detects-malware-vulnerabilities-first"
        },
        {
          "source_name": "npm v12 delivers one of the biggest security improvements in",
          "url": "https://www.aikido.dev/blog/npm-v12-block-postinstall"
        },
        {
          "source_name": "Securing Vibe Coding and AI Coding Agents: An End-to-End App",
          "url": "https://www.stepsecurity.io/blog/securing-vibe-coding-and-ai-coding-agents-an-end-to-end-approach-with-stepsecurity"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4400ff7-9306-4133-ba83-f49e19d82282",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: cbb9bc5a8496243e02f3cc080efbe3e4a1430ba0671f2e43a202bf45b05479cd",
      "pattern": "[file:hashes.'SHA-256' = 'cbb9bc5a8496243e02f3cc080efbe3e4a1430ba0671f2e43a202bf45b05479cd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "How Aikido Intel detects malware and vulnerabilities first",
          "url": "https://www.aikido.dev/blog/aikido-intel-detects-malware-vulnerabilities-first"
        },
        {
          "source_name": "npm v12 delivers one of the biggest security improvements in",
          "url": "https://www.aikido.dev/blog/npm-v12-block-postinstall"
        },
        {
          "source_name": "Securing Vibe Coding and AI Coding Agents: An End-to-End App",
          "url": "https://www.stepsecurity.io/blog/securing-vibe-coding-and-ai-coding-agents-an-end-to-end-approach-with-stepsecurity"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ed7bf38-c8bb-4de1-b79b-aa45b0b75fb2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f099c5d9ec417d4445a0328ac0ada9cde79fc37410914103ae9c609cbc0ee068",
      "pattern": "[file:hashes.'SHA-256' = 'f099c5d9ec417d4445a0328ac0ada9cde79fc37410914103ae9c609cbc0ee068']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "How Aikido Intel detects malware and vulnerabilities first",
          "url": "https://www.aikido.dev/blog/aikido-intel-detects-malware-vulnerabilities-first"
        },
        {
          "source_name": "npm v12 delivers one of the biggest security improvements in",
          "url": "https://www.aikido.dev/blog/npm-v12-block-postinstall"
        },
        {
          "source_name": "Securing Vibe Coding and AI Coding Agents: An End-to-End App",
          "url": "https://www.stepsecurity.io/blog/securing-vibe-coding-and-ai-coding-agents-an-end-to-end-approach-with-stepsecurity"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--01feff15-8029-463f-8e84-a650eef1b32c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-30066",
      "pattern": "[vulnerability:name = 'CVE-2025-30066']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "GitHub Secret Scanning Public Monitoring for Enterprises: Co",
          "url": "https://www.stepsecurity.io/blog/github-secret-scanning-public-monitoring-for-enterprises-coverage-and-gaps"
        },
        {
          "source_name": "StepSecurity Maintained Actions Are Now Free for Public Repo",
          "url": "https://www.stepsecurity.io/blog/stepsecurity-maintained-actions-are-now-free-for-public-repos"
        },
        {
          "source_name": "Harden-Runner detection: tj-actions/changed-files action is ",
          "url": "https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "CISA KEV",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0983d53c-2a76-429e-8ca4-b752c3bb2531",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: testnet.archival.chain.grpc-web.injective.network",
      "pattern": "[domain-name:value = 'testnet.archival.chain.grpc-web.injective.network']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Injective npm Supply Chain Attack: 18 Packages Backdoored to",
          "url": "https://www.stepsecurity.io/blog/injective-npm-supply-chain-attack-18-packages-backdoored-to-steal-crypto-wallet-keys"
        },
        {
          "source_name": "Compromised @injectivelabs/sdk-ts exfiltrates wallet keys th",
          "url": "https://www.aikido.dev/blog/compromised-injectivelabs-exfiltrates-keys"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eea7b978-6e30-4c0f-966d-823e137c2450",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 37.27.122.124",
      "pattern": "[ipv4-addr:value = '37.27.122.124']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "jscrambler npm package publishes malicious preinstall binary",
          "url": "https://www.stepsecurity.io/blog/jscrambler-npm-package-publishes-malicious-preinstall-binary"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e0b53f79-e6ed-472a-92d4-fa3cd82a8a6a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 57.128.246.79",
      "pattern": "[ipv4-addr:value = '57.128.246.79']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "jscrambler npm package publishes malicious preinstall binary",
          "url": "https://www.stepsecurity.io/blog/jscrambler-npm-package-publishes-malicious-preinstall-binary"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ca882bea-c93e-4e8d-9ba9-c437cd5e3a26",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 103c4e6181151c1bcfedc41506cd1815458c38375d08a8fcd9981dbe0b965ce0",
      "pattern": "[file:hashes.'SHA-256' = '103c4e6181151c1bcfedc41506cd1815458c38375d08a8fcd9981dbe0b965ce0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Injective npm Supply Chain Attack: 18 Packages Backdoored to",
          "url": "https://www.stepsecurity.io/blog/injective-npm-supply-chain-attack-18-packages-backdoored-to-steal-crypto-wallet-keys"
        },
        {
          "source_name": "Compromised @injectivelabs/sdk-ts exfiltrates wallet keys th",
          "url": "https://www.aikido.dev/blog/compromised-injectivelabs-exfiltrates-keys"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6504bbc1-2974-4132-8733-5097e26d7258",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9a59eb454f3ca3fe91214136ee5edd417cc47a80e6f169b52099d6561944baf9",
      "pattern": "[file:hashes.'SHA-256' = '9a59eb454f3ca3fe91214136ee5edd417cc47a80e6f169b52099d6561944baf9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Injective npm Supply Chain Attack: 18 Packages Backdoored to",
          "url": "https://www.stepsecurity.io/blog/injective-npm-supply-chain-attack-18-packages-backdoored-to-steal-crypto-wallet-keys"
        },
        {
          "source_name": "Compromised @injectivelabs/sdk-ts exfiltrates wallet keys th",
          "url": "https://www.aikido.dev/blog/compromised-injectivelabs-exfiltrates-keys"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--60ec7964-43a6-4091-a224-97bf884f78ba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b7ca95d1b23c8e67416a25cedf741de0917c2096bbc9d24649eea7853d054903",
      "pattern": "[file:hashes.'SHA-256' = 'b7ca95d1b23c8e67416a25cedf741de0917c2096bbc9d24649eea7853d054903']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "jscrambler npm package publishes malicious preinstall binary",
          "url": "https://www.stepsecurity.io/blog/jscrambler-npm-package-publishes-malicious-preinstall-binary"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--30185c7b-e16b-4ef9-b93b-04cd845d6209",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c8fd47d36bdf7c825378593ab82ed8c24d1dc52e26b507812393e24e1d5201fd",
      "pattern": "[file:hashes.'SHA-256' = 'c8fd47d36bdf7c825378593ab82ed8c24d1dc52e26b507812393e24e1d5201fd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "jscrambler npm package publishes malicious preinstall binary",
          "url": "https://www.stepsecurity.io/blog/jscrambler-npm-package-publishes-malicious-preinstall-binary"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b01deeda-d15e-4946-90b9-3681c797c8cd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: fbbcf4d8f98168f78f5c0c47a9ae56d59ec8ac84a7c9ca6b797fedfb8d62d2bd",
      "pattern": "[file:hashes.'SHA-256' = 'fbbcf4d8f98168f78f5c0c47a9ae56d59ec8ac84a7c9ca6b797fedfb8d62d2bd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "jscrambler npm package publishes malicious preinstall binary",
          "url": "https://www.stepsecurity.io/blog/jscrambler-npm-package-publishes-malicious-preinstall-binary"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2073988c-5016-40c2-8635-9ed076687728",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-48939",
      "pattern": "[vulnerability:name = 'CVE-2026-48939']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-48939 \u2014 iCagenda Unrestricted Upload of F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b1265715-5ada-4433-969d-cf8b24ceea46",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-50551",
      "pattern": "[vulnerability:name = 'CVE-2026-50551']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-50551: SiYuan: Stored XSS to RCE ",
          "url": "https://github.com/advisories/GHSA-56mp-4f3v-fgj2"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--85f79fa8-ae72-425e-b9a6-8669acb65bc5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-54067",
      "pattern": "[vulnerability:name = 'CVE-2026-54067']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-54067: SiYuan: Stored XSS to RCE ",
          "url": "https://github.com/advisories/GHSA-mvjr-vv3c-w4qv"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4e69955f-b0a7-441f-9a35-f5c057df9836",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-54069",
      "pattern": "[vulnerability:name = 'CVE-2026-54069']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-54069: SiYuan: Unauthenticated Ad",
          "url": "https://github.com/advisories/GHSA-hvr9-72v2-fff3"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1ab561ef-e3b2-485f-9b82-0329904ec865",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-54072",
      "pattern": "[vulnerability:name = 'CVE-2026-54072']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-54072: Authorizer: Unvalidated re",
          "url": "https://github.com/advisories/GHSA-h29v-hj44-q8cv"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc2995c7-7dc4-4b6c-956c-c11ff142906c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-54088",
      "pattern": "[vulnerability:name = 'CVE-2026-54088']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-54088: File Browser: Command Inje",
          "url": "https://github.com/advisories/GHSA-m93h-4hw7-5qcm"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--31148b58-bbfa-43db-ad5e-dc6870f4b507",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-54089",
      "pattern": "[vulnerability:name = 'CVE-2026-54089']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-54089: File Browser: Authenticati",
          "url": "https://github.com/advisories/GHSA-xqp3-jq6g-x3qm"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--178b0117-d49c-4f5f-8faf-2d7784681601",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-54158",
      "pattern": "[vulnerability:name = 'CVE-2026-54158']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-50551: SiYuan: Stored XSS to RCE ",
          "url": "https://github.com/advisories/GHSA-56mp-4f3v-fgj2"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--20fdd932-1c5d-4d0c-a251-c55ccddcee61",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-56291",
      "pattern": "[vulnerability:name = 'CVE-2026-56291']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-56291 \u2014 Balbooa Forms Unrestricted Upload",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4bbe63e1-5cbe-4a96-bcb6-c49048895efd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-61459",
      "pattern": "[vulnerability:name = 'CVE-2026-61459']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-61459: mcp-server-kubernetes argu",
          "url": "https://github.com/advisories/GHSA-wmg3-h8mf-wgvr"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--be3afa98-a02c-4d70-955c-ca8fa8555381",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-32803",
      "pattern": "[vulnerability:name = 'CVE-2021-32803']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Symlinks Are Still Scary (And Yes, You Can Commit Them to Gi",
          "url": "https://snyk.io/blog/symlinks-are-still-scary/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b90d5921-b353-4ef5-aeaf-6453cb7c36f9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-21626",
      "pattern": "[vulnerability:name = 'CVE-2024-21626']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Symlinks Are Still Scary (And Yes, You Can Commit Them to Gi",
          "url": "https://snyk.io/blog/symlinks-are-still-scary/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--678cbe07-cc84-4082-8268-26915638c1ea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-32002",
      "pattern": "[vulnerability:name = 'CVE-2024-32002']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Symlinks Are Still Scary (And Yes, You Can Commit Them to Gi",
          "url": "https://snyk.io/blog/symlinks-are-still-scary/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bbe26778-cb29-499d-b549-0255023a5562",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-12958",
      "pattern": "[vulnerability:name = 'CVE-2026-12958']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Symlinks Are Still Scary (And Yes, You Can Commit Them to Gi",
          "url": "https://snyk.io/blog/symlinks-are-still-scary/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f9db8d27-868b-43e0-b667-4c00704c4808",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-50549",
      "pattern": "[vulnerability:name = 'CVE-2026-50549']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Symlinks Are Still Scary (And Yes, You Can Commit Them to Gi",
          "url": "https://snyk.io/blog/symlinks-are-still-scary/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bf9f439d-824f-4e88-8aef-1845a792748d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-52766",
      "pattern": "[vulnerability:name = 'CVE-2026-52766']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-52766: YesWiki vulnerable to unau",
          "url": "https://github.com/advisories/GHSA-6x7x-gcmf-7r8x"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d487cbe-1e66-4bdd-b689-6041ff766277",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-52777",
      "pattern": "[vulnerability:name = 'CVE-2026-52777']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-52777: YesWiki Vulnerable to Auth",
          "url": "https://github.com/advisories/GHSA-9369-69wj-7m2f"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--71a362bc-ae37-426b-b681-b60b83bf933b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-52778",
      "pattern": "[vulnerability:name = 'CVE-2026-52778']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "[GHSA / CRITICAL] CVE-2026-52778: YesWiki has Unsafe eval() ",
          "url": "https://github.com/advisories/GHSA-px5m-h76g-p7p8"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "GitHub Security Advisories"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--84680d57-c0da-40a2-9c13-37f2c4173e62",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 142.171.183.8",
      "pattern": "[ipv4-addr:value = '142.171.183.8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "One Target, Two Flags | Rival Espionage Actors Converge On P",
          "url": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2638146d-c7e6-49bf-b0cd-24c4016c5dab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.111.233.105",
      "pattern": "[ipv4-addr:value = '172.111.233.105']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "One Target, Two Flags | Rival Espionage Actors Converge On P",
          "url": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a6c1741e-aebc-403a-b08a-e8d54ffba439",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.111.233.12",
      "pattern": "[ipv4-addr:value = '172.111.233.12']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "One Target, Two Flags | Rival Espionage Actors Converge On P",
          "url": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d10145d2-1351-4708-aa68-f3b4edc287a9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.111.233.26",
      "pattern": "[ipv4-addr:value = '172.111.233.26']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "One Target, Two Flags | Rival Espionage Actors Converge On P",
          "url": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--651aef47-1baf-43bc-89c2-615c676d9731",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.111.233.36",
      "pattern": "[ipv4-addr:value = '172.111.233.36']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "One Target, Two Flags | Rival Espionage Actors Converge On P",
          "url": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e02e6900-af03-45f1-9248-c0e2d508ec98",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.111.233.96",
      "pattern": "[ipv4-addr:value = '172.111.233.96']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "One Target, Two Flags | Rival Espionage Actors Converge On P",
          "url": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3feb0875-fc1d-4a9c-ac41-30e3ac178ed6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.94.9.19",
      "pattern": "[ipv4-addr:value = '172.94.9.19']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "One Target, Two Flags | Rival Espionage Actors Converge On P",
          "url": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3c6dac69-536e-4485-868f-1e1ebe4aa690",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.94.9.43",
      "pattern": "[ipv4-addr:value = '172.94.9.43']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "One Target, Two Flags | Rival Espionage Actors Converge On P",
          "url": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4f5ed1d-92b1-4fe6-8e91-a92262cf931f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.94.9.49",
      "pattern": "[ipv4-addr:value = '172.94.9.49']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "One Target, Two Flags | Rival Espionage Actors Converge On P",
          "url": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--532f461a-c4c2-4600-a224-6331c9b94109",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.42.25.65",
      "pattern": "[ipv4-addr:value = '193.42.25.65']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "One Target, Two Flags | Rival Espionage Actors Converge On P",
          "url": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2118d155-1feb-4202-9e57-f84aa4b27e10",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.125.32.218",
      "pattern": "[ipv4-addr:value = '45.125.32.218']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "One Target, Two Flags | Rival Espionage Actors Converge On P",
          "url": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1924d43b-34a3-48da-84b8-733c6578543b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.74.6.17",
      "pattern": "[ipv4-addr:value = '45.74.6.17']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "One Target, Two Flags | Rival Espionage Actors Converge On P",
          "url": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e797fb80-fe83-4599-b962-2efa967a1d2a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 89.31.121.220",
      "pattern": "[ipv4-addr:value = '89.31.121.220']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "One Target, Two Flags | Rival Espionage Actors Converge On P",
          "url": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a932a52-40d5-4080-90c6-4b6ec267c842",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: m-mgarg.com",
      "pattern": "[domain-name:value = 'm-mgarg.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET Threat Report H1 2026",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/"
        },
        {
          "source_name": "Cyber readiness for SMBs: Getting the basics right",
          "url": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--895e583f-4290-429a-acf6-360ac02da921",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: mgardownload.com",
      "pattern": "[domain-name:value = 'mgardownload.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET Threat Report H1 2026",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/"
        },
        {
          "source_name": "Cyber readiness for SMBs: Getting the basics right",
          "url": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b2a663bd-8d76-4d0b-9a7c-4d866d37f046",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.21.91.170",
      "pattern": "[ipv4-addr:value = '104.21.91.170']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET Threat Report H1 2026",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/"
        },
        {
          "source_name": "Cyber readiness for SMBs: Getting the basics right",
          "url": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2c0f17bf-92db-4644-83e6-99049183ecba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 52.222.205.45",
      "pattern": "[ipv4-addr:value = '52.222.205.45']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET Threat Report H1 2026",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/"
        },
        {
          "source_name": "Cyber readiness for SMBs: Getting the basics right",
          "url": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5151a571-ab4b-4d4d-b128-6bc01455a32f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 54.67.2.84",
      "pattern": "[ipv4-addr:value = '54.67.2.84']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET Threat Report H1 2026",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/"
        },
        {
          "source_name": "Cyber readiness for SMBs: Getting the basics right",
          "url": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c2592a5d-664d-4ce7-8c5e-d9c766fc6169",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 076801bd9c6eb78fc0331a4c7a22c73199cc3824",
      "pattern": "[file:hashes.'SHA-1' = '076801bd9c6eb78fc0331a4c7a22c73199cc3824']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET Threat Report H1 2026",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/"
        },
        {
          "source_name": "Cyber readiness for SMBs: Getting the basics right",
          "url": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--27b048a0-6062-4b35-aea4-b6f870457f62",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 375d7423e63c8f5f2cc814e8cfe697ba25168afa",
      "pattern": "[file:hashes.'SHA-1' = '375d7423e63c8f5f2cc814e8cfe697ba25168afa']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET Threat Report H1 2026",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/"
        },
        {
          "source_name": "Cyber readiness for SMBs: Getting the basics right",
          "url": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--293908ec-0379-410e-a763-39e71a231617",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 3978ac5cd14e357320e127d6c87f10cb70a1dcc2",
      "pattern": "[file:hashes.'SHA-1' = '3978ac5cd14e357320e127d6c87f10cb70a1dcc2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET Threat Report H1 2026",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/"
        },
        {
          "source_name": "Cyber readiness for SMBs: Getting the basics right",
          "url": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f490758c-84bd-4738-84ee-2badcc1a0034",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 6bbc9ab132ba066f63676e05da13d108598bc29b",
      "pattern": "[file:hashes.'SHA-1' = '6bbc9ab132ba066f63676e05da13d108598bc29b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET Threat Report H1 2026",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/"
        },
        {
          "source_name": "Cyber readiness for SMBs: Getting the basics right",
          "url": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--384d8c47-0dd3-4a86-848b-c0c9854a5111",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 8364730e9bb2cf3a4b016de1b34f38341c0ee2fa",
      "pattern": "[file:hashes.'SHA-1' = '8364730e9bb2cf3a4b016de1b34f38341c0ee2fa']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET Threat Report H1 2026",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/"
        },
        {
          "source_name": "Cyber readiness for SMBs: Getting the basics right",
          "url": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--11a43ccc-449e-4bc6-aed9-a72f1a3cf96a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 9b1723284e311794987997cb7e8814eb6014713f",
      "pattern": "[file:hashes.'SHA-1' = '9b1723284e311794987997cb7e8814eb6014713f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET Threat Report H1 2026",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/"
        },
        {
          "source_name": "Cyber readiness for SMBs: Getting the basics right",
          "url": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4dee2bce-dfeb-4775-aa40-c6a66adfa318",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: c14e9b062ed28115ede096788f62b47a6ed841ac",
      "pattern": "[file:hashes.'SHA-1' = 'c14e9b062ed28115ede096788f62b47a6ed841ac']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET Threat Report H1 2026",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/"
        },
        {
          "source_name": "Cyber readiness for SMBs: Getting the basics right",
          "url": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c1481f60-59da-4c05-bcda-31c1ecf2b12f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: e60d12017d2da579df87368f5596a0244621ae86",
      "pattern": "[file:hashes.'SHA-1' = 'e60d12017d2da579df87368f5596a0244621ae86']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET Threat Report H1 2026",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/"
        },
        {
          "source_name": "Cyber readiness for SMBs: Getting the basics right",
          "url": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2e409598-7d7e-4c34-8963-f1bb0e04e8b7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: f8f4c5bc498bcce907dc975dd88be8d594629909",
      "pattern": "[file:hashes.'SHA-1' = 'f8f4c5bc498bcce907dc975dd88be8d594629909']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET Threat Report H1 2026",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/"
        },
        {
          "source_name": "Cyber readiness for SMBs: Getting the basics right",
          "url": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eed37999-4ff5-46ef-9df8-16b75c759373",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-48282",
      "pattern": "[vulnerability:name = 'CVE-2026-48282']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-48282 \u2014 Adobe ColdFusion Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b51bca8d-c252-4803-bfe5-8a0b42c58b3c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-48908",
      "pattern": "[vulnerability:name = 'CVE-2026-48908']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-48908 \u2014 JoomShaper SP Page Builder Unrest",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c67dfc17-04e1-43a4-8404-053ddf27f08f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-55255",
      "pattern": "[vulnerability:name = 'CVE-2026-55255']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-55255 \u2014 Langflow Authorization Bypass Thr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--16bc0553-cbe0-48ae-800f-f19ad6fcd25c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-56290",
      "pattern": "[vulnerability:name = 'CVE-2026-56290']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-56290 \u2014 Joomlack Page Builder Improper Ac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--49f48f59-4d9a-49f9-b00a-b5ea01f03f26",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: secure.local",
      "pattern": "[domain-name:value = 'secure.local']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-48908 \u2014 JoomShaper SP Page Builder Unrest",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da5b7c3d-18ed-457a-a625-35ab4afb7128",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.207.14.220",
      "pattern": "[ipv4-addr:value = '103.207.14.220']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-48282 \u2014 Adobe ColdFusion Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c07c468b-4466-4180-8fcf-08b9e55569a8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.207.216.55",
      "pattern": "[ipv4-addr:value = '45.207.216.55']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-55255 \u2014 Langflow Authorization Bypass Thr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--22f95cd6-18d4-4ff9-8de3-f9d63f47b452",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-48611",
      "pattern": "[vulnerability:name = 'CVE-2026-48611']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Authentication Bypass in the default configuration phpBB",
          "url": "https://www.aikido.dev/blog/authentication-bypass-phpbb-technical-writeup"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b267536-08e9-4b00-82f0-bc4e4974d448",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 161cdcdb46fb8a348aec609a86ff5823752065d2",
      "pattern": "[file:hashes.'SHA-1' = '161cdcdb46fb8a348aec609a86ff5823752065d2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cyber readiness for SMBs: Getting the basics right",
          "url": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--22c229e8-a32f-4910-ab2d-577e17e1ab9c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 24bf7b72f54aa5b93c6681b4f69e579a47d7c102",
      "pattern": "[file:hashes.'SHA-1' = '24bf7b72f54aa5b93c6681b4f69e579a47d7c102']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cyber readiness for SMBs: Getting the basics right",
          "url": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--783dbcd7-f365-451f-a398-0bdfc876b9fe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 639dbc9b365096d6347142fcae64725bd9f73270",
      "pattern": "[file:hashes.'SHA-1' = '639dbc9b365096d6347142fcae64725bd9f73270']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cyber readiness for SMBs: Getting the basics right",
          "url": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2a0fd506-a5dd-471b-acaf-91a91a612902",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 8c7bcafce90f5fb121131ecb27346ecfc6e961c5",
      "pattern": "[file:hashes.'SHA-1' = '8c7bcafce90f5fb121131ecb27346ecfc6e961c5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cyber readiness for SMBs: Getting the basics right",
          "url": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--af9f733d-4b8e-4978-8c9b-aba6dc4619b9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: ad223fe2bb4563446aee5227357bbfdc8ada3797",
      "pattern": "[file:hashes.'SHA-1' = 'ad223fe2bb4563446aee5227357bbfdc8ada3797']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cyber readiness for SMBs: Getting the basics right",
          "url": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0b78ac1-b6f7-411d-9652-8a3b225a7d45",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: bb8fb75285bcd151132a3287f2786d4d91da58b8",
      "pattern": "[file:hashes.'SHA-1' = 'bb8fb75285bcd151132a3287f2786d4d91da58b8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cyber readiness for SMBs: Getting the basics right",
          "url": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb4d39a2-2b02-40c6-bf20-09839d20a479",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: f3f4c40c344695388e10cbf29ddb18ef3b61f7ef",
      "pattern": "[file:hashes.'SHA-1' = 'f3f4c40c344695388e10cbf29ddb18ef3b61f7ef']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cyber readiness for SMBs: Getting the basics right",
          "url": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fdffa5c3-0111-4d64-bb40-e555187305c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: scan.aquasecurtiy.org",
      "pattern": "[domain-name:value = 'scan.aquasecurtiy.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Suppl",
          "url": "https://www.stepsecurity.io/blog/10-layers-deep-how-stepsecurity-stops-teampcps-trivy-supply-chain-attack-on-github-actions"
        },
        {
          "source_name": "CanisterWorm: How a Self-Propagating npm Worm Is Spreading B",
          "url": "https://www.stepsecurity.io/blog/canisterworm-how-a-self-propagating-npm-worm-is-spreading-backdoors-across-the-ecosystem"
        },
        {
          "source_name": "Trivy Compromised a Second Time - Malicious v0.69.4 Release,",
          "url": "https://www.stepsecurity.io/blog/trivy-compromised-a-second-time---malicious-v0-69-4-release"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7ca3a9d5-056d-4d1f-87ae-020d42cd9960",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io",
      "pattern": "[domain-name:value = 'tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Suppl",
          "url": "https://www.stepsecurity.io/blog/10-layers-deep-how-stepsecurity-stops-teampcps-trivy-supply-chain-attack-on-github-actions"
        },
        {
          "source_name": "You Patched LiteLLM, But Do You Know Your AI Blast Radius?",
          "url": "https://snyk.io/blog/litellm-ai-blast-radius/"
        },
        {
          "source_name": "CanisterWorm: How a Self-Propagating npm Worm Is Spreading B",
          "url": "https://www.stepsecurity.io/blog/canisterworm-how-a-self-propagating-npm-worm-is-spreading-backdoors-across-the-ecosystem"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--664ae46d-639f-4edc-868b-4b426a5b2b78",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.148.10.212",
      "pattern": "[ipv4-addr:value = '45.148.10.212']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Suppl",
          "url": "https://www.stepsecurity.io/blog/10-layers-deep-how-stepsecurity-stops-teampcps-trivy-supply-chain-attack-on-github-actions"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d7a9068b-7d64-44b1-bb35-eac711ecdf25",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 0e58ed8671d6b60d0890c21b07f8835ace038e67",
      "pattern": "[file:hashes.'SHA-1' = '0e58ed8671d6b60d0890c21b07f8835ace038e67']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "StepSecurity Maintained Actions Are Now Free for Public Repo",
          "url": "https://www.stepsecurity.io/blog/stepsecurity-maintained-actions-are-now-free-for-public-repos"
        },
        {
          "source_name": "Harden-Runner detection: tj-actions/changed-files action is ",
          "url": "https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised"
        },
        {
          "source_name": "CISA KEV: CVE-2025-30154 \u2014 reviewdog/action-setup GitHub Act",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "CISA KEV",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--22788c13-13d0-473c-80e4-dc14f1463a73",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-45659",
      "pattern": "[vulnerability:name = 'CVE-2026-45659']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-45659 \u2014 Microsoft SharePoint Server Deser",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0bff3f0e-793b-408c-a5f6-f25d8cdad67e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: maskasd.com",
      "pattern": "[domain-name:value = 'maskasd.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Secure Registry now tells you which machine pulled a comprom",
          "url": "https://www.stepsecurity.io/blog/secure-registry-now-tells-you-which-machine-pulled-a-compromised-package"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fdcdf330-ba68-4e45-ac27-e0fb7f35af5a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: teams.onweblive.org",
      "pattern": "[domain-name:value = 'teams.onweblive.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Secure Registry now tells you which machine pulled a comprom",
          "url": "https://www.stepsecurity.io/blog/secure-registry-now-tells-you-which-machine-pulled-a-compromised-package"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--789b5302-7c3e-466c-ab77-9a82124eab8e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.254.164.123",
      "pattern": "[ipv4-addr:value = '23.254.164.123']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Secure Registry now tells you which machine pulled a comprom",
          "url": "https://www.stepsecurity.io/blog/secure-registry-now-tells-you-which-machine-pulled-a-compromised-package"
        },
        {
          "source_name": "npm now freezes high-impact accounts after risky account cha",
          "url": "https://www.aikido.dev/blog/npm-cooldown-account-changes-announcement"
        },
        {
          "source_name": "Everybody's shipping code they can't read",
          "url": "https://www.aikido.dev/blog/shipping-code-they-cant-read"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--41f489bc-d39e-4caf-849d-252a44119b09",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.254.164.92",
      "pattern": "[ipv4-addr:value = '23.254.164.92']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Secure Registry now tells you which machine pulled a comprom",
          "url": "https://www.stepsecurity.io/blog/secure-registry-now-tells-you-which-machine-pulled-a-compromised-package"
        },
        {
          "source_name": "npm now freezes high-impact accounts after risky account cha",
          "url": "https://www.aikido.dev/blog/npm-cooldown-account-changes-announcement"
        },
        {
          "source_name": "Everybody's shipping code they can't read",
          "url": "https://www.aikido.dev/blog/shipping-code-they-cant-read"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2b1a9a1b-44a9-4c51-8b21-727afe07b5ad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 6b9501e1889cc45c91726729610cf69c2442b8c5",
      "pattern": "[file:hashes.'SHA-1' = '6b9501e1889cc45c91726729610cf69c2442b8c5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Secure Registry now tells you which machine pulled a comprom",
          "url": "https://www.stepsecurity.io/blog/secure-registry-now-tells-you-which-machine-pulled-a-compromised-package"
        },
        {
          "source_name": "codfish/semantic-release-action GitHub Action has been compr",
          "url": "https://www.stepsecurity.io/blog/supply-chain-compromise-codfish-semantic-release-action"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3329016c-c069-4e67-9323-b0291b01e95f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 221c45a790dec2a296af57969e1165a16f8f49733aeab64c0bbd768d9943badf",
      "pattern": "[file:hashes.'SHA-256' = '221c45a790dec2a296af57969e1165a16f8f49733aeab64c0bbd768d9943badf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Secure Registry now tells you which machine pulled a comprom",
          "url": "https://www.stepsecurity.io/blog/secure-registry-now-tells-you-which-machine-pulled-a-compromised-package"
        },
        {
          "source_name": "npm now freezes high-impact accounts after risky account cha",
          "url": "https://www.aikido.dev/blog/npm-cooldown-account-changes-announcement"
        },
        {
          "source_name": "Everybody's shipping code they can't read",
          "url": "https://www.aikido.dev/blog/shipping-code-they-cant-read"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--16b15690-983b-4fe1-962d-a1fa7d790e1e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4a8860240e4231c3a74c81949be655a28e096a7d72f38fbe84e5b37636b98417",
      "pattern": "[file:hashes.'SHA-256' = '4a8860240e4231c3a74c81949be655a28e096a7d72f38fbe84e5b37636b98417']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Secure Registry now tells you which machine pulled a comprom",
          "url": "https://www.stepsecurity.io/blog/secure-registry-now-tells-you-which-machine-pulled-a-compromised-package"
        },
        {
          "source_name": "npm now freezes high-impact accounts after risky account cha",
          "url": "https://www.aikido.dev/blog/npm-cooldown-account-changes-announcement"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--805c6c92-8ff6-4d6f-ab66-69694cb45762",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ae70dd4f6bc0d1c8c2848e4e6b51934626c4818dcb5af99d080ddbd7dc337185",
      "pattern": "[file:hashes.'SHA-256' = 'ae70dd4f6bc0d1c8c2848e4e6b51934626c4818dcb5af99d080ddbd7dc337185']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Secure Registry now tells you which machine pulled a comprom",
          "url": "https://www.stepsecurity.io/blog/secure-registry-now-tells-you-which-machine-pulled-a-compromised-package"
        },
        {
          "source_name": "npm now freezes high-impact accounts after risky account cha",
          "url": "https://www.aikido.dev/blog/npm-cooldown-account-changes-announcement"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a1f18fbf-e399-4f3b-9bc1-9b2930fbe5ee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b122a9873bedf145ae2a7fd024b5f309007dbb025149f4dc4ac3f7e4f32a36a4",
      "pattern": "[file:hashes.'SHA-256' = 'b122a9873bedf145ae2a7fd024b5f309007dbb025149f4dc4ac3f7e4f32a36a4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Secure Registry now tells you which machine pulled a comprom",
          "url": "https://www.stepsecurity.io/blog/secure-registry-now-tells-you-which-machine-pulled-a-compromised-package"
        },
        {
          "source_name": "Everybody's shipping code they can't read",
          "url": "https://www.aikido.dev/blog/shipping-code-they-cant-read"
        },
        {
          "source_name": "A Forgotten Contributor Account Compromised the Entire Mastr",
          "url": "https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--320ec1cf-4873-4809-931c-b0bcba2ddd3c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b73de25c053c3225a077738a1fcbd9ca6966d7b3cd6f5494a30f0aa0eae55c7e",
      "pattern": "[file:hashes.'SHA-256' = 'b73de25c053c3225a077738a1fcbd9ca6966d7b3cd6f5494a30f0aa0eae55c7e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Secure Registry now tells you which machine pulled a comprom",
          "url": "https://www.stepsecurity.io/blog/secure-registry-now-tells-you-which-machine-pulled-a-compromised-package"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cee07f25-e17b-4505-97dc-6a2745d6f874",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ceff7c51d70832c3ec8dd2744b606a23b3c924ef664ae23439b9b742ea154108",
      "pattern": "[file:hashes.'SHA-256' = 'ceff7c51d70832c3ec8dd2744b606a23b3c924ef664ae23439b9b742ea154108']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Multiple @immobiliarelabs Backstage Plugins Compromised on n",
          "url": "https://www.stepsecurity.io/blog/immobiliarelabs-npm-packages-compromised"
        },
        {
          "source_name": "Wait, binding.gyp Can Do What? Exploring npm's Weirdest Buil",
          "url": "https://www.aikido.dev/blog/exploring-binding-gyp-npm-build-system"
        },
        {
          "source_name": "Node-gyp Supply Chain Compromise: A Self-Propagating npm Wor",
          "url": "https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gyp/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--97580cc9-d059-4ced-a595-789f3a00e89f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ef641e956f91d501b748085996303c96a64d67f63bfeef0dda175e5aa19cca90",
      "pattern": "[file:hashes.'SHA-256' = 'ef641e956f91d501b748085996303c96a64d67f63bfeef0dda175e5aa19cca90']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Multiple @immobiliarelabs Backstage Plugins Compromised on n",
          "url": "https://www.stepsecurity.io/blog/immobiliarelabs-npm-packages-compromised"
        },
        {
          "source_name": "Miasma Worm Hits Microsoft Again: Azure Functions Action and",
          "url": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents"
        },
        {
          "source_name": "Wait, binding.gyp Can Do What? Exploring npm's Weirdest Buil",
          "url": "https://www.aikido.dev/blog/exploring-binding-gyp-npm-build-system"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e998a6ab-5b82-40d1-8a97-3906f56dd8e7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: fasterxml.org",
      "pattern": "[domain-name:value = 'fasterxml.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Maven Support Comes to GitHub Checks and OSS Package Search",
          "url": "https://www.stepsecurity.io/blog/maven-support-comes-to-github-checks-and-oss-package-search"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--db13eecb-1b3d-42db-bb05-379589b33d60",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: https://github.com/oven-sh/bun/releases/download/bun-v1.3.13/bun-<os>-<arch>.zip",
      "pattern": "[domain-name:value = 'https://github.com/oven-sh/bun/releases/download/bun-v1.3.13/bun-<os>-<arch>.zip']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Multiple @immobiliarelabs Backstage Plugins Compromised on n",
          "url": "https://www.stepsecurity.io/blog/immobiliarelabs-npm-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--762deec6-b1e9-47a7-9db4-c64f9f82cc67",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: m.fasterxml.org",
      "pattern": "[domain-name:value = 'm.fasterxml.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Maven Support Comes to GitHub Checks and OSS Package Search",
          "url": "https://www.stepsecurity.io/blog/maven-support-comes-to-github-checks-and-oss-package-search"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--81c6979c-4767-4edb-9108-3a5455d8fe34",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.127.243.82",
      "pattern": "[ipv4-addr:value = '103.127.243.82']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Maven Support Comes to GitHub Checks and OSS Package Search",
          "url": "https://www.stepsecurity.io/blog/maven-support-comes-to-github-checks-and-oss-package-search"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d45a1afa-8265-4bc0-b85d-2f8e81d27ac2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 39.107.60.51",
      "pattern": "[ipv4-addr:value = '39.107.60.51']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "15 Malicious JetBrains Plugins Stole AI API Keys from 70,000",
          "url": "https://www.stepsecurity.io/blog/jetbrains-malicious-plugins-ai-api-key-theft"
        },
        {
          "source_name": "Multiple JetBrains IDE plugins caught stealing AI keys",
          "url": "https://www.aikido.dev/blog/multiple-jetbrains-ide-plugins-caught-stealing-ai-keys"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cbd46adf-31f3-438d-ade4-db1dd09170c3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 54089e0f368fa9a7e2050de9b0db121a",
      "pattern": "[file:hashes.MD5 = '54089e0f368fa9a7e2050de9b0db121a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compr",
          "url": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb7ab44b-298d-4f8c-b947-1ceac356b816",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: ad9f0ecdbf6075f8cc4ca8bdd62bd27c",
      "pattern": "[file:hashes.MD5 = 'ad9f0ecdbf6075f8cc4ca8bdd62bd27c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compr",
          "url": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--383fd518-e92b-4f7a-95dd-8be1af4b494b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 1a5a1445fcd73133f22a0e7895993ac0a42b56da",
      "pattern": "[file:hashes.'SHA-1' = '1a5a1445fcd73133f22a0e7895993ac0a42b56da']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compr",
          "url": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8afe670f-9001-44e3-a750-ebd090c96150",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 1dcc0a39e1cd7293a9058cfc41e1afe8b397c943",
      "pattern": "[file:hashes.'SHA-1' = '1dcc0a39e1cd7293a9058cfc41e1afe8b397c943']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compr",
          "url": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--79fd592e-5295-4a75-9b13-1e55f3e1a906",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 24a0d9e496ec07ca978fab602d5f5e0b39fa03a0",
      "pattern": "[file:hashes.'SHA-1' = '24a0d9e496ec07ca978fab602d5f5e0b39fa03a0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compr",
          "url": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--813e288c-9835-4506-824e-08d55f561280",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 47d73156df1c767bb168c4309fd17b92324d587d",
      "pattern": "[file:hashes.'SHA-1' = '47d73156df1c767bb168c4309fd17b92324d587d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compr",
          "url": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6fce48ac-96f3-483b-9feb-b3e9bcec9068",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 5792aba0e2180b9b80b77644370a6889d5817456",
      "pattern": "[file:hashes.'SHA-1' = '5792aba0e2180b9b80b77644370a6889d5817456']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "simonecorsi/mawesome GitHub Action has been compromised",
          "url": "https://www.stepsecurity.io/blog/simonecorsi-mawesome-github-action-has-been-compromised"
        },
        {
          "source_name": "codfish/semantic-release-action GitHub Action has been compr",
          "url": "https://www.stepsecurity.io/blog/supply-chain-compromise-codfish-semantic-release-action"
        },
        {
          "source_name": "Compromised GitHub action codfish/semantic-release-action st",
          "url": "https://www.aikido.dev/blog/compromised-github-action-codfish-steals-secrets"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--059fd980-7d7a-41e4-98b8-e1564f66a93c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 5e75c14b8acd5752819ab7a10874ddd6389f5238",
      "pattern": "[file:hashes.'SHA-1' = '5e75c14b8acd5752819ab7a10874ddd6389f5238']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compr",
          "url": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--040e923c-0f03-45ac-be11-69baa35e636c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 68a1cd589b2ce322f5f03fe7f85dc3f176a759d4",
      "pattern": "[file:hashes.'SHA-1' = '68a1cd589b2ce322f5f03fe7f85dc3f176a759d4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compr",
          "url": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--afc7327d-1275-4f77-9ca2-87ef6d69ba88",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 809ce3680adfdb8f0746189b68b6b5a6888a960f",
      "pattern": "[file:hashes.'SHA-1' = '809ce3680adfdb8f0746189b68b6b5a6888a960f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compr",
          "url": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--64354be9-dda9-4068-95e7-1788032c8416",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 888094a9b842cfe98e8e24c8f729be1fb6384563",
      "pattern": "[file:hashes.'SHA-1' = '888094a9b842cfe98e8e24c8f729be1fb6384563']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compr",
          "url": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1894d90f-db89-4931-88eb-35d1235a6b5e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 92221eb202e9f2ac577e5c33658c8a05c6d67556",
      "pattern": "[file:hashes.'SHA-1' = '92221eb202e9f2ac577e5c33658c8a05c6d67556']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compr",
          "url": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--385f7dac-4dae-4fff-815f-cb1bb9370d12",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 9be49287057cd6a54ef4a70a8d541a7259efbd2d",
      "pattern": "[file:hashes.'SHA-1' = '9be49287057cd6a54ef4a70a8d541a7259efbd2d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compr",
          "url": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--988c87f4-3059-4134-8971-d7b47db0b7cf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: a8cb86b78ca56befe90dc466642cb04b98079909",
      "pattern": "[file:hashes.'SHA-1' = 'a8cb86b78ca56befe90dc466642cb04b98079909']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compr",
          "url": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a6ae56fc-f922-44af-96fe-a77eaf6ad141",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: bcb6b1d409144318e8fad2171d6fe06d02299d1a",
      "pattern": "[file:hashes.'SHA-1' = 'bcb6b1d409144318e8fad2171d6fe06d02299d1a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "simonecorsi/mawesome GitHub Action has been compromised",
          "url": "https://www.stepsecurity.io/blog/simonecorsi-mawesome-github-action-has-been-compromised"
        },
        {
          "source_name": "codfish/semantic-release-action GitHub Action has been compr",
          "url": "https://www.stepsecurity.io/blog/supply-chain-compromise-codfish-semantic-release-action"
        },
        {
          "source_name": "Compromised GitHub action codfish/semantic-release-action st",
          "url": "https://www.aikido.dev/blog/compromised-github-action-codfish-steals-secrets"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6108c3fc-ceb8-41b2-8a5f-9b52367aa4ee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: be3b1f7f1b50f5d53b164a72fb3a9845f4734325",
      "pattern": "[file:hashes.'SHA-1' = 'be3b1f7f1b50f5d53b164a72fb3a9845f4734325']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compr",
          "url": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c7a1786d-ea50-465b-812c-e81432c5ba58",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: be6bb1cf88c46e9e4a6f1a68ed001b77769d58de",
      "pattern": "[file:hashes.'SHA-1' = 'be6bb1cf88c46e9e4a6f1a68ed001b77769d58de']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compr",
          "url": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5df2b350-dcf3-437d-aeec-24b97adacf88",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: d45ad3cffbcc7c4b354ebe9d71d002fa585379ec",
      "pattern": "[file:hashes.'SHA-1' = 'd45ad3cffbcc7c4b354ebe9d71d002fa585379ec']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compr",
          "url": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b4c78b99-b5d7-47ea-9fc8-2811fdc17db1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: d7224b6b1f5d2f9403f1cebc8f82518c20b4d0f7",
      "pattern": "[file:hashes.'SHA-1' = 'd7224b6b1f5d2f9403f1cebc8f82518c20b4d0f7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compr",
          "url": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8b476489-1acd-46ac-ac33-3596e2cffa38",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: e973173fb757d2dab9c6424b440dd9f7cbe4f14a",
      "pattern": "[file:hashes.'SHA-1' = 'e973173fb757d2dab9c6424b440dd9f7cbe4f14a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compr",
          "url": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2a0ad328-3dde-4918-9594-cb3fbba6d2a9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: ed9a17d6567101fa4f9f552a4a52cfcca88fa662",
      "pattern": "[file:hashes.'SHA-1' = 'ed9a17d6567101fa4f9f552a4a52cfcca88fa662']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compr",
          "url": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a9a6a6bd-091b-41a0-9ad5-de1fa7b1ce2a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: ef8bf6dd92cbc29ef8d23f3f0fa786ed20a856b1",
      "pattern": "[file:hashes.'SHA-1' = 'ef8bf6dd92cbc29ef8d23f3f0fa786ed20a856b1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compr",
          "url": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--364e19aa-8730-4a0e-aab9-f1f555cd0007",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: effa8576594fdd59907b5c5c07293ce28a9a3393",
      "pattern": "[file:hashes.'SHA-1' = 'effa8576594fdd59907b5c5c07293ce28a9a3393']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compr",
          "url": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c461491f-1fcf-4790-95f4-544cc360a0f5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: f03a3e0dca9ef402352ce61cad59e5d850744960",
      "pattern": "[file:hashes.'SHA-1' = 'f03a3e0dca9ef402352ce61cad59e5d850744960']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compr",
          "url": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b7610d39-6df6-472c-ad24-9556a05eb482",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 702161756dfd150ad3c214fbf97ce98fdc960ea7b3970b5300702ed8c953cafd",
      "pattern": "[file:hashes.'SHA-256' = '702161756dfd150ad3c214fbf97ce98fdc960ea7b3970b5300702ed8c953cafd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Maven Support Comes to GitHub Checks and OSS Package Search",
          "url": "https://www.stepsecurity.io/blog/maven-support-comes-to-github-checks-and-oss-package-search"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6a466501-b168-4046-8e68-a870b7622e20",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8bce95ebfb895537fec243e069d7193980361de9d916339906b11a14ffded94f",
      "pattern": "[file:hashes.'SHA-256' = '8bce95ebfb895537fec243e069d7193980361de9d916339906b11a14ffded94f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Maven Support Comes to GitHub Checks and OSS Package Search",
          "url": "https://www.stepsecurity.io/blog/maven-support-comes-to-github-checks-and-oss-package-search"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53c8cda8-42df-466b-a2b7-0714097a02f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9f93d77d32833a515bc406c46da477142bb1ac2babeecb6aa42f98669a6db015",
      "pattern": "[file:hashes.'SHA-256' = '9f93d77d32833a515bc406c46da477142bb1ac2babeecb6aa42f98669a6db015']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "simonecorsi/mawesome GitHub Action has been compromised",
          "url": "https://www.stepsecurity.io/blog/simonecorsi-mawesome-github-action-has-been-compromised"
        },
        {
          "source_name": "codfish/semantic-release-action GitHub Action has been compr",
          "url": "https://www.stepsecurity.io/blog/supply-chain-compromise-codfish-semantic-release-action"
        },
        {
          "source_name": "Compromised GitHub action codfish/semantic-release-action st",
          "url": "https://www.aikido.dev/blog/compromised-github-action-codfish-steals-secrets"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9f63c08b-f159-405a-bf82-79ebd7b79e07",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: da39146ef451d1b174a24d00b1e2a45cd38d54e849737f8f35333dcb22175707",
      "pattern": "[file:hashes.'SHA-256' = 'da39146ef451d1b174a24d00b1e2a45cd38d54e849737f8f35333dcb22175707']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Multiple @immobiliarelabs Backstage Plugins Compromised on n",
          "url": "https://www.stepsecurity.io/blog/immobiliarelabs-npm-packages-compromised"
        },
        {
          "source_name": "Node-gyp Supply Chain Compromise: A Self-Propagating npm Wor",
          "url": "https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gyp/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e61cbfb6-4115-44c6-974e-9e627467c086",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-48558",
      "pattern": "[vulnerability:name = 'CVE-2026-48558']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-48558 \u2014 SimpleHelp Authentication Bypass ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--60f830a9-8b26-47c0-bab3-605627f33acf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: flipboxstudio.info",
      "pattern": "[domain-name:value = 'flipboxstudio.info']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Packagist is now protected by Aikido Intel and other updates",
          "url": "https://www.aikido.dev/blog/composer-protected-aikido-packagist"
        },
        {
          "source_name": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple ",
          "url": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack"
        },
        {
          "source_name": "Laravel Lang Supply Chain Advisory",
          "url": "https://snyk.io/blog/laravel-lang-supply-chain-advisory/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6044f72-150d-470b-8d32-0afd60a77f60",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: hwsrv-1327785.hostwindsdns.com",
      "pattern": "[domain-name:value = 'hwsrv-1327785.hostwindsdns.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "npm now freezes high-impact accounts after risky account cha",
          "url": "https://www.aikido.dev/blog/npm-cooldown-account-changes-announcement"
        },
        {
          "source_name": "Everybody's shipping code they can't read",
          "url": "https://www.aikido.dev/blog/shipping-code-they-cant-read"
        },
        {
          "source_name": "A Forgotten Contributor Account Compromised the Entire Mastr",
          "url": "https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2984feff-a68c-482e-b589-9ad4edcbc6c8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sfrclak.com",
      "pattern": "[domain-name:value = 'sfrclak.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "npm now freezes high-impact accounts after risky account cha",
          "url": "https://www.aikido.dev/blog/npm-cooldown-account-changes-announcement"
        },
        {
          "source_name": "The full Snyk AI Security Platform, free for open source mai",
          "url": "https://snyk.io/blog/secure-developer-program/"
        },
        {
          "source_name": "npm v12 delivers one of the biggest security improvements in",
          "url": "https://www.aikido.dev/blog/npm-v12-block-postinstall"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Snyk",
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ee027efe-786d-4969-ad34-48e376579012",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 142.11.206.73",
      "pattern": "[ipv4-addr:value = '142.11.206.73']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "npm now freezes high-impact accounts after risky account cha",
          "url": "https://www.aikido.dev/blog/npm-cooldown-account-changes-announcement"
        },
        {
          "source_name": "The full Snyk AI Security Platform, free for open source mai",
          "url": "https://snyk.io/blog/secure-developer-program/"
        },
        {
          "source_name": "npm v12 delivers one of the biggest security improvements in",
          "url": "https://www.aikido.dev/blog/npm-v12-block-postinstall"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d7ae347-93bc-4226-8bbc-f044a98ada5d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 07d889e2dadce6f3910dcbc253317d28ca61c766",
      "pattern": "[file:hashes.'SHA-1' = '07d889e2dadce6f3910dcbc253317d28ca61c766']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "npm now freezes high-impact accounts after risky account cha",
          "url": "https://www.aikido.dev/blog/npm-cooldown-account-changes-announcement"
        },
        {
          "source_name": "The full Snyk AI Security Platform, free for open source mai",
          "url": "https://snyk.io/blog/secure-developer-program/"
        },
        {
          "source_name": "npm v12 delivers one of the biggest security improvements in",
          "url": "https://www.aikido.dev/blog/npm-v12-block-postinstall"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c8173f2c-7d84-4ced-b0d6-6b48349eef5b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 2553649f2322049666871cea80a5d0d6adc700ca",
      "pattern": "[file:hashes.'SHA-1' = '2553649f2322049666871cea80a5d0d6adc700ca']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "npm now freezes high-impact accounts after risky account cha",
          "url": "https://www.aikido.dev/blog/npm-cooldown-account-changes-announcement"
        },
        {
          "source_name": "npm v12 delivers one of the biggest security improvements in",
          "url": "https://www.aikido.dev/blog/npm-v12-block-postinstall"
        },
        {
          "source_name": "Code is being written everywhere, and the device is the only",
          "url": "https://www.aikido.dev/blog/code-is-written-everywhere"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ed1649bb-2f5e-4a78-9afd-1bcd58251804",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: d6f3f62fd3b9f5432f5782b62d8cfd5247d5ee71",
      "pattern": "[file:hashes.'SHA-1' = 'd6f3f62fd3b9f5432f5782b62d8cfd5247d5ee71']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "npm now freezes high-impact accounts after risky account cha",
          "url": "https://www.aikido.dev/blog/npm-cooldown-account-changes-announcement"
        },
        {
          "source_name": "The full Snyk AI Security Platform, free for open source mai",
          "url": "https://snyk.io/blog/secure-developer-program/"
        },
        {
          "source_name": "npm v12 delivers one of the biggest security improvements in",
          "url": "https://www.aikido.dev/blog/npm-v12-block-postinstall"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b4ae693b-da2f-452e-84aa-0351755faa9c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-8088",
      "pattern": "[vulnerability:name = 'CVE-2025-8088']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Gamaredon in 2025: Leveraging tunnels, workers, dead drops, ",
          "url": "https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/"
        },
        {
          "source_name": "CISA KEV: CVE-2025-8088 \u2014 RARLAB WinRAR Path Traversal Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9cfa14a0-ed8a-4f9c-8be9-9c5ea84408e0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-20230",
      "pattern": "[vulnerability:name = 'CVE-2026-20230']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-20230 \u2014 Cisco Unified Communications Mana",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5cca5822-7ffa-40bb-963c-8e7fdef7aad4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-4681",
      "pattern": "[vulnerability:name = 'CVE-2026-4681']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b71feb7b-7c70-4fa4-b7bd-a4303acb0139",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: hwsrv-1327786.hostwindsdns.com",
      "pattern": "[domain-name:value = 'hwsrv-1327786.hostwindsdns.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Everybody's shipping code they can't read",
          "url": "https://www.aikido.dev/blog/shipping-code-they-cant-read"
        },
        {
          "source_name": "A Forgotten Contributor Account Compromised the Entire Mastr",
          "url": "https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6789d0bd-12b8-48c1-ac69-55aed102d825",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.194.9.14",
      "pattern": "[ipv4-addr:value = '104.194.9.14']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--892638d9-feab-4fe3-9b27-95013f9a8afc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.243.35.131",
      "pattern": "[ipv4-addr:value = '104.243.35.131']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--79f392a1-05d0-4c97-a8d3-389d4f215f57",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.111.38.31",
      "pattern": "[ipv4-addr:value = '172.111.38.31']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e1a84ca6-478e-468a-910a-b0f3dab0f9ba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.227.83.236",
      "pattern": "[ipv4-addr:value = '185.227.83.236']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ff77af1-1417-4823-a647-fa6523443051",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 209.222.98.44",
      "pattern": "[ipv4-addr:value = '209.222.98.44']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e72c82b-70a1-484e-9dfe-90a0ebf75e47",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.60.157.212",
      "pattern": "[ipv4-addr:value = '38.60.157.212']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c00880a3-bb34-4ba2-b1e7-397a9de04f6c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 74.50.76.146",
      "pattern": "[ipv4-addr:value = '74.50.76.146']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c54502f1-d803-4f41-8313-cf4947341e3e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 78.128.113.10",
      "pattern": "[ipv4-addr:value = '78.128.113.10']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--63029499-9ec1-477d-a34f-1b545228f554",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9570f77a5e1511869f4e554e7166df9fde081f2583e293c2569621792ed7d9c9",
      "pattern": "[file:hashes.'SHA-256' = '9570f77a5e1511869f4e554e7166df9fde081f2583e293c2569621792ed7d9c9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Everybody's shipping code they can't read",
          "url": "https://www.aikido.dev/blog/shipping-code-they-cant-read"
        },
        {
          "source_name": "A Forgotten Contributor Account Compromised the Entire Mastr",
          "url": "https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b344173e-df7d-450e-a0ff-8de2072d37bc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c38954e85bf5433e61e7c8f4230336695624ae88b6953afabf7bf817aa91b638",
      "pattern": "[file:hashes.'SHA-256' = 'c38954e85bf5433e61e7c8f4230336695624ae88b6953afabf7bf817aa91b638']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Everybody's shipping code they can't read",
          "url": "https://www.aikido.dev/blog/shipping-code-they-cant-read"
        },
        {
          "source_name": "A Forgotten Contributor Account Compromised the Entire Mastr",
          "url": "https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--240e3eec-60c8-4721-8084-7cf91ac66c44",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: cdec8b20338beb708b5be8d3d7a3041a35a8b0fb92f9186262f312d55ff82066",
      "pattern": "[file:hashes.'SHA-256' = 'cdec8b20338beb708b5be8d3d7a3041a35a8b0fb92f9186262f312d55ff82066']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Everybody's shipping code they can't read",
          "url": "https://www.aikido.dev/blog/shipping-code-they-cant-read"
        },
        {
          "source_name": "A Forgotten Contributor Account Compromised the Entire Mastr",
          "url": "https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--075b4140-a444-42fc-bc3c-bb5b75fa2a40",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: wbound.com",
      "pattern": "[domain-name:value = 'wbound.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET takes part in Operation Endgame to disrupt Amadey and S",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c7561729-bd84-495b-8f52-30c976a17a14",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 176.111.174.140",
      "pattern": "[ipv4-addr:value = '176.111.174.140']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET takes part in Operation Endgame to disrupt Amadey and S",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1f9a540b-2f71-457c-919c-6f29ad3d4652",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 176.124.199.207",
      "pattern": "[ipv4-addr:value = '176.124.199.207']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET takes part in Operation Endgame to disrupt Amadey and S",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--62afc47d-38c0-4a1c-a050-6d1ead5e4985",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 188.114.96.1",
      "pattern": "[ipv4-addr:value = '188.114.96.1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET takes part in Operation Endgame to disrupt Amadey and S",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c471fcb-6d4d-4c0a-beea-6c6f57e05640",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.156.1.16",
      "pattern": "[ipv4-addr:value = '193.156.1.16']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET takes part in Operation Endgame to disrupt Amadey and S",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--682fc5ce-b07c-4bd3-9c61-dc3ab9dc3ca7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.26.192.191",
      "pattern": "[ipv4-addr:value = '194.26.192.191']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET takes part in Operation Endgame to disrupt Amadey and S",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d748d6dc-6c9f-4b3a-be85-b71238566398",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 196.251.107.130",
      "pattern": "[ipv4-addr:value = '196.251.107.130']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET takes part in Operation Endgame to disrupt Amadey and S",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1f2e424d-7a52-4300-bcd3-a74ea1f74e7f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 62.60.226.159",
      "pattern": "[ipv4-addr:value = '62.60.226.159']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET takes part in Operation Endgame to disrupt Amadey and S",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9cbff51c-3db1-4660-81d0-f448e1e0bec3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 64.188.91.237",
      "pattern": "[ipv4-addr:value = '64.188.91.237']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET takes part in Operation Endgame to disrupt Amadey and S",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b45d6bd2-0c44-4cdb-ade3-bae810a2bec0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 94.154.35.25",
      "pattern": "[ipv4-addr:value = '94.154.35.25']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET takes part in Operation Endgame to disrupt Amadey and S",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1f4a372d-adee-428a-964a-6d014530fae5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 95.85.238.4",
      "pattern": "[ipv4-addr:value = '95.85.238.4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET takes part in Operation Endgame to disrupt Amadey and S",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--376598d3-3563-4914-ab91-48e5aaaccb77",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-67038",
      "pattern": "[vulnerability:name = 'CVE-2025-67038']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-67038 \u2014 Lantronix EDS5000 Code Injection ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e61a81aa-15bb-4ac6-9aa0-159df0707235",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-34908",
      "pattern": "[vulnerability:name = 'CVE-2026-34908']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-34910 \u2014 Ubiquiti UniFi OS Improper Input ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-34909 \u2014 Ubiquiti UniFi OS Path Traversal ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-34908 \u2014 Ubiquiti UniFi OS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eae2545e-6809-4b96-9660-3cab32f88a21",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-34909",
      "pattern": "[vulnerability:name = 'CVE-2026-34909']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-34910 \u2014 Ubiquiti UniFi OS Improper Input ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-34909 \u2014 Ubiquiti UniFi OS Path Traversal ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-34908 \u2014 Ubiquiti UniFi OS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc8329b9-86f7-48a1-9516-1a7959e9fc1d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-34910",
      "pattern": "[vulnerability:name = 'CVE-2026-34910']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-34910 \u2014 Ubiquiti UniFi OS Improper Input ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-34909 \u2014 Ubiquiti UniFi OS Path Traversal ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-34908 \u2014 Ubiquiti UniFi OS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb46f165-32c8-459b-82ba-a759c0a23c1b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 154.219.113.56",
      "pattern": "[ipv4-addr:value = '154.219.113.56']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-67038 \u2014 Lantronix EDS5000 Code Injection ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a2aa5b31-4e30-41d0-be20-df5d09657c69",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 160.238.37.28",
      "pattern": "[ipv4-addr:value = '160.238.37.28']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-67038 \u2014 Lantronix EDS5000 Code Injection ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--064b8ee5-e93a-46a9-af30-5874ef310d94",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 218.13.42.36",
      "pattern": "[ipv4-addr:value = '218.13.42.36']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-67038 \u2014 Lantronix EDS5000 Code Injection ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--58bb7001-e993-47b4-812f-5a9a80f91ff7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.180.201.49",
      "pattern": "[ipv4-addr:value = '38.180.201.49']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-67038 \u2014 Lantronix EDS5000 Code Injection ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b5ac4b06-e483-4905-95de-79403230f29d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.207.136.2",
      "pattern": "[ipv4-addr:value = '38.207.136.2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-67038 \u2014 Lantronix EDS5000 Code Injection ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--94958372-d92b-41b3-8a34-8ccfc7053593",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 59.124.166.52",
      "pattern": "[ipv4-addr:value = '59.124.166.52']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-67038 \u2014 Lantronix EDS5000 Code Injection ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a5e057e6-df28-4982-bac4-46d6ff55bf14",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6328567511d88fdc2ae0939c5ef17b7a63d2a833881900de018a4f12f4982525",
      "pattern": "[file:hashes.'SHA-256' = '6328567511d88fdc2ae0939c5ef17b7a63d2a833881900de018a4f12f4982525']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the",
          "url": "https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb06729e-39ae-4952-b032-f91c923ba759",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 77b4fd46994992f0e57302cfe76ed23c0d90101381d2b89fc2ddf5c4536e77ca",
      "pattern": "[file:hashes.'SHA-256' = '77b4fd46994992f0e57302cfe76ed23c0d90101381d2b89fc2ddf5c4536e77ca']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the",
          "url": "https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f7f70298-b430-40b3-9393-5d1c0eb78726",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b3c56d689414343589f38394d19ba2fe9a518133281200faa0556ba4e4136394",
      "pattern": "[file:hashes.'SHA-256' = 'b3c56d689414343589f38394d19ba2fe9a518133281200faa0556ba4e4136394']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the",
          "url": "https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6f17ea54-0d31-42da-a114-b6514986e120",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: baabf249c77bc54c54ab0e66e15af798bd28aa5b4683554456a8b73ab8741239",
      "pattern": "[file:hashes.'SHA-256' = 'baabf249c77bc54c54ab0e66e15af798bd28aa5b4683554456a8b73ab8741239']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the",
          "url": "https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--39295db9-a535-4c61-be4a-5db1723f7781",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 138.226.246.94",
      "pattern": "[ipv4-addr:value = '138.226.246.94']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "When a vendor's breach becomes yours: lessons from the Klue ",
          "url": "https://snyk.io/blog/when-a-vendors-breach-becomes-yours-lessons-from-the-klue-incident/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5760379f-09ad-4816-8998-cdbb0d7e7e4c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 212.86.125.24",
      "pattern": "[ipv4-addr:value = '212.86.125.24']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "When a vendor's breach becomes yours: lessons from the Klue ",
          "url": "https://snyk.io/blog/when-a-vendors-breach-becomes-yours-lessons-from-the-klue-incident/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--704689be-4a06-448f-8446-f26d91cb9c60",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 213.111.148.90",
      "pattern": "[ipv4-addr:value = '213.111.148.90']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "When a vendor's breach becomes yours: lessons from the Klue ",
          "url": "https://snyk.io/blog/when-a-vendors-breach-becomes-yours-lessons-from-the-klue-incident/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fc65519d-2740-46ed-a977-3bdcfb236568",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 94.154.32.160",
      "pattern": "[ipv4-addr:value = '94.154.32.160']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "When a vendor's breach becomes yours: lessons from the Klue ",
          "url": "https://snyk.io/blog/when-a-vendors-breach-becomes-yours-lessons-from-the-klue-incident/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ef58114d-f151-4928-802c-2c055f0ed902",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-20253",
      "pattern": "[vulnerability:name = 'CVE-2026-20253']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-20253 \u2014 Splunk Enterprise Missing Authent",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e305bc39-7a6f-4b65-9269-e80a0e0bf993",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: github.com/fardewoak/nodejs-argo",
      "pattern": "[domain-name:value = 'github.com/fardewoak/nodejs-argo']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "400+ AUR Packages Hijacked: What the \u201cAtomic Arch\u201d Campaign ",
          "url": "https://www.stepsecurity.io/blog/400-aur-packages-hijacked-atomic-arch-campaign"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c8a475e-a7cc-48f2-aeea-82033d4ba11c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: temp.sh",
      "pattern": "[domain-name:value = 'temp.sh']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "400+ AUR Packages Hijacked: What the \u201cAtomic Arch\u201d Campaign ",
          "url": "https://www.stepsecurity.io/blog/400-aur-packages-hijacked-atomic-arch-campaign"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--74183df6-0e8a-47c0-a202-b4995481bd23",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7069e28a5806db4ab0273639667d203f5e31b401d403af7e36d9f360c1f6d655",
      "pattern": "[file:hashes.'SHA-256' = '7069e28a5806db4ab0273639667d203f5e31b401d403af7e36d9f360c1f6d655']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Miasma and Hades Are Spreading Now: Detect Them on Developer",
          "url": "https://www.stepsecurity.io/blog/miasma-and-hades-are-spreading-now-detect-them-on-developer-machines-with-suspicious-files"
        },
        {
          "source_name": "Red Hat npm Packages Compromised to Spread a Credential-Stea",
          "url": "https://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stealing-worm"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f7f28c5-d9c2-4b2a-9865-43374a37f6ba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b86c5ae9e95bd841a595440faa3eb6317441e746f241ae8fd641ab59ed1d1966",
      "pattern": "[file:hashes.'SHA-256' = 'b86c5ae9e95bd841a595440faa3eb6317441e746f241ae8fd641ab59ed1d1966']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Miasma and Hades Are Spreading Now: Detect Them on Developer",
          "url": "https://www.stepsecurity.io/blog/miasma-and-hades-are-spreading-now-detect-them-on-developer-machines-with-suspicious-files"
        },
        {
          "source_name": "Red Hat npm Packages Compromised to Spread a Credential-Stea",
          "url": "https://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stealing-worm"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bbf8fd76-e431-4bf6-9cda-73776a2c79d7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c539766062555d47716f8432e73adbe3a0c0c954a0b6c4005017a668975e275c",
      "pattern": "[file:hashes.'SHA-256' = 'c539766062555d47716f8432e73adbe3a0c0c954a0b6c4005017a668975e275c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Miasma and Hades Are Spreading Now: Detect Them on Developer",
          "url": "https://www.stepsecurity.io/blog/miasma-and-hades-are-spreading-now-detect-them-on-developer-machines-with-suspicious-files"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9f61a1e3-2faa-4bf5-9035-b33b8812eaa3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: dc48b09b2a5954f7ff79ab8a2fd80202bd3b59c08c7cdbc6025aa923cb4c0efe",
      "pattern": "[file:hashes.'SHA-256' = 'dc48b09b2a5954f7ff79ab8a2fd80202bd3b59c08c7cdbc6025aa923cb4c0efe']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Miasma and Hades Are Spreading Now: Detect Them on Developer",
          "url": "https://www.stepsecurity.io/blog/miasma-and-hades-are-spreading-now-detect-them-on-developer-machines-with-suspicious-files"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b84fca6-2eab-4712-987a-07f3a39bcc6b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e1342a80d4b5e83d2c7c22e1e0aaa95f2d88e3dbf0d853a4994b180c93a4b17d",
      "pattern": "[file:hashes.'SHA-256' = 'e1342a80d4b5e83d2c7c22e1e0aaa95f2d88e3dbf0d853a4994b180c93a4b17d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Miasma and Hades Are Spreading Now: Detect Them on Developer",
          "url": "https://www.stepsecurity.io/blog/miasma-and-hades-are-spreading-now-detect-them-on-developer-machines-with-suspicious-files"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bbe77d4c-866a-4dd4-a9e0-aa7fc9ae67bd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f7d335205b8d7b20208fb3ef93ee6dc817905dc3ae0c10a0b164f4e7d07121cd",
      "pattern": "[file:hashes.'SHA-256' = 'f7d335205b8d7b20208fb3ef93ee6dc817905dc3ae0c10a0b164f4e7d07121cd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The full Snyk AI Security Platform, free for open source mai",
          "url": "https://snyk.io/blog/secure-developer-program/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--27413f87-9a74-4a05-afc3-f1c265f26268",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-48907",
      "pattern": "[vulnerability:name = 'CVE-2026-48907']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-48907 \u2014 Widget Factory Joomla Content Edi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c54a92ca-ec9b-4c56-8299-e9129d8817ab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 107.149.130.5",
      "pattern": "[ipv4-addr:value = '107.149.130.5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-48907 \u2014 Widget Factory Joomla Content Edi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e7ac7680-8573-44ea-9365-e28e5e122fa6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.153.129.241",
      "pattern": "[ipv4-addr:value = '45.153.129.241']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-48907 \u2014 Widget Factory Joomla Content Edi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0502d7bb-1c1a-4f97-8c1d-9d72b6196d07",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 92.38.150.143",
      "pattern": "[ipv4-addr:value = '92.38.150.143']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-48907 \u2014 Widget Factory Joomla Content Edi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2fe9f0b6-2a50-4dcf-9e02-07729e5a5f8a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-24932",
      "pattern": "[vulnerability:name = 'CVE-2023-24932']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "url": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c035363d-415b-46d5-a298-18e0cc389b27",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 207.148.75.122",
      "pattern": "[ipv4-addr:value = '207.148.75.122']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "url": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7192f4be-862b-40c2-9726-0abea77bd533",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 207.148.78.36",
      "pattern": "[ipv4-addr:value = '207.148.78.36']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "url": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7a65281f-f671-421b-b8c8-2eb7d94ea7ca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 037DB2445F3D72388CB2CF8510563148E5A184BE",
      "pattern": "[file:hashes.'SHA-1' = '037DB2445F3D72388CB2CF8510563148E5A184BE']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "url": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a0ac55d8-3007-46bc-a32b-919e166fdcad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 2457EED2AB28E37741F10914EF929DAD2C8079D4",
      "pattern": "[file:hashes.'SHA-1' = '2457EED2AB28E37741F10914EF929DAD2C8079D4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "url": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--924ef25a-3051-4a76-9d6d-baa9cf8008ea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 44DC4A08C5EB0972C8E18B0E01284E06F09006BB",
      "pattern": "[file:hashes.'SHA-1' = '44DC4A08C5EB0972C8E18B0E01284E06F09006BB']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "url": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6833ffad-28e9-469b-bf66-74d88bf2d0e1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 5F3B87CEF56683D9A9E19186E0FD0D8019B559C4",
      "pattern": "[file:hashes.'SHA-1' = '5F3B87CEF56683D9A9E19186E0FD0D8019B559C4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "url": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--495d8e1f-e44f-40ce-8a4e-94b24962463a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 621D1952839BE4B0A1B0E66E87BCE5062CA368ED",
      "pattern": "[file:hashes.'SHA-1' = '621D1952839BE4B0A1B0E66E87BCE5062CA368ED']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "url": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--90913574-f181-4c29-bd6e-c19c2c28de23",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 6490B8E4AADE25A3EE2DA9A47F312DB2122470BC",
      "pattern": "[file:hashes.'SHA-1' = '6490B8E4AADE25A3EE2DA9A47F312DB2122470BC']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "url": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9b0df3df-4f70-4528-8a7f-9fd951359683",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 955BFC3DCC867256F9F46A606DEB0779FA3416D8",
      "pattern": "[file:hashes.'SHA-1' = '955BFC3DCC867256F9F46A606DEB0779FA3416D8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "url": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--72c0a200-7087-47b3-8dba-f2eca3b62bb1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: AB87B29B6F79487C75CA08D102E79001E536F083",
      "pattern": "[file:hashes.'SHA-1' = 'AB87B29B6F79487C75CA08D102E79001E536F083']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "url": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e591f6a9-3113-4ec3-852a-71840df2a4ca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: C793CA31E3F6628B5C8986146953BF66232E9A30",
      "pattern": "[file:hashes.'SHA-1' = 'C793CA31E3F6628B5C8986146953BF66232E9A30']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "url": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6a5e888-cde9-4813-9ef2-2af4290fe6fe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: D2C706B1EAF662BF0CE124B5032F73ED84BDA24A",
      "pattern": "[file:hashes.'SHA-1' = 'D2C706B1EAF662BF0CE124B5032F73ED84BDA24A']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "url": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--99bb2060-3dfb-46aa-8c75-4fe23c87e2b6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: E7484C24B88A1A2407A8F09D734F9A993670285B",
      "pattern": "[file:hashes.'SHA-1' = 'E7484C24B88A1A2407A8F09D734F9A993670285B']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "url": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4109d003-449f-4b4e-b511-bdf4e00ad9ac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-20262",
      "pattern": "[vulnerability:name = 'CVE-2026-20262']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-20262 \u2014 Cisco Catalyst SD-WAN Manager Dir",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0989b68e-2ab6-428f-8f8f-e0b93cb853a7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-54420",
      "pattern": "[vulnerability:name = 'CVE-2026-54420']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-54420 \u2014 LiteSpeed cPanel Plugin UNIX Symb",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5b6e8339-94b6-4322-a66b-554c0eea99fb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: authdocspro.com",
      "pattern": "[domain-name:value = 'authdocspro.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--939d9f79-4395-4bb0-a865-1a86785517c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: backdoor-hub.com",
      "pattern": "[domain-name:value = 'backdoor-hub.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e539b3a3-30fb-47e2-bcea-39485491344d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: bumpgames.net",
      "pattern": "[domain-name:value = 'bumpgames.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fa0b3a10-0f7d-4321-a978-c2a56846008a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: carbatterygurgaon.com",
      "pattern": "[domain-name:value = 'carbatterygurgaon.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d1c7c37d-11f4-466b-84e1-15b2c4646b78",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: careldutoit-el.co.za",
      "pattern": "[domain-name:value = 'careldutoit-el.co.za']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9aaa2573-758e-4101-91eb-d8dd3fefddd3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: dao.com.au",
      "pattern": "[domain-name:value = 'dao.com.au']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--639f0053-504a-47d6-9574-1cdca52484cc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: docusend.networkssolutionmail.com",
      "pattern": "[domain-name:value = 'docusend.networkssolutionmail.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a5af504d-fb38-49aa-960c-bca6b6a23b1e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: eqfit.co.za",
      "pattern": "[domain-name:value = 'eqfit.co.za']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4790ec06-a569-42dc-b518-d6e9ca72d7f1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: eventcalender-schedule.com",
      "pattern": "[domain-name:value = 'eventcalender-schedule.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--24a06041-b63f-4719-a927-5e08de1333b4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: evobothub.org",
      "pattern": "[domain-name:value = 'evobothub.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f8dd9fe-5833-4e44-80c6-f3754003aad9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: framebound.cloud",
      "pattern": "[domain-name:value = 'framebound.cloud']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--db17f39c-27ec-4af7-b28c-d79483e934f5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: infinitechai.org",
      "pattern": "[domain-name:value = 'infinitechai.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--125aff11-7f5b-4051-b9f5-96419af5fdc0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: internalmemorecord.bxwancheng.com",
      "pattern": "[domain-name:value = 'internalmemorecord.bxwancheng.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe0748be-a0fd-419b-9dd5-5c0d54ce41c0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: macmamo.com",
      "pattern": "[domain-name:value = 'macmamo.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--85c756eb-717c-4b5a-93f1-d84c40ea733a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: mirsanotolastik.com",
      "pattern": "[domain-name:value = 'mirsanotolastik.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f918af48-c2c4-401d-b16d-d8e71c8f874a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: mirzanyapi.com",
      "pattern": "[domain-name:value = 'mirzanyapi.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--be45adce-525b-446a-a63d-fd137bd7d440",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: newmobilepolojean.com",
      "pattern": "[domain-name:value = 'newmobilepolojean.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f1c5a2c7-88bb-4846-8d98-25ad088f7771",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: notificationsmanagersec.com",
      "pattern": "[domain-name:value = 'notificationsmanagersec.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b1639a1f-a1c7-4baa-be5d-3a4d1c38bcda",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: pelangiservice.com",
      "pattern": "[domain-name:value = 'pelangiservice.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--07c95773-6528-4c46-a82d-6ed009de1fb6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: prcservis.com",
      "pattern": "[domain-name:value = 'prcservis.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5ddda3b6-55cc-44bc-9153-9bac68a59451",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: promanager.outboundciwidey.com",
      "pattern": "[domain-name:value = 'promanager.outboundciwidey.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--62d876e3-243f-482f-ab47-feb9556000c9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: serenitygovsupplys.com",
      "pattern": "[domain-name:value = 'serenitygovsupplys.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dbf082d3-2048-4d99-8162-7d07e6485529",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: signaturerequired.thecoolcactus.com",
      "pattern": "[domain-name:value = 'signaturerequired.thecoolcactus.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--174ac142-3ea7-4ca2-924f-a6efc44a4751",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: smstltle.net",
      "pattern": "[domain-name:value = 'smstltle.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e646232c-a0bf-4be2-b369-819eaef3568f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: statushelper.aguasomos.com",
      "pattern": "[domain-name:value = 'statushelper.aguasomos.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2565b32a-930b-4477-9440-649bd7b8ef10",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: suctwocesonesstory.com",
      "pattern": "[domain-name:value = 'suctwocesonesstory.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a347683b-39d0-4dd0-a9c3-666502c16c02",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: thesafarigarden.com",
      "pattern": "[domain-name:value = 'thesafarigarden.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fd6fac28-8e6b-46ad-85b4-fdc1cb94ef51",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: topbuysella.com",
      "pattern": "[domain-name:value = 'topbuysella.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a01188a5-58c0-4893-9884-6fd20a364a13",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: totalhomesafe.com",
      "pattern": "[domain-name:value = 'totalhomesafe.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f27e7fb-d48f-4bbf-ba09-32463e34d78d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: youremplregroup.com",
      "pattern": "[domain-name:value = 'youremplregroup.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7a0b8f6e-53d2-4650-811c-252928655517",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 162.220.232.0",
      "pattern": "[ipv4-addr:value = '162.220.232.0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--80cc650f-508e-4b98-ab06-9cf7b9584efb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 162.220.234.0",
      "pattern": "[ipv4-addr:value = '162.220.234.0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9e5d8780-e50e-4e30-bba5-2542a707ef1f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.81.113.0",
      "pattern": "[ipv4-addr:value = '185.81.113.0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a3d01f7a-e611-4532-956b-d6a154471620",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 89.150.45.0",
      "pattern": "[ipv4-addr:value = '89.150.45.0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "EvilTokens: A phishing attack that doesn\u2019t steal your passwo",
          "url": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4ec0edb7-b740-4ce4-b38d-055a9213b51a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-35273",
      "pattern": "[vulnerability:name = 'CVE-2026-35273']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise Peop",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c6f0a99a-4063-4415-b848-03126b4cc4ba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: azurenetfiles.net",
      "pattern": "[domain-name:value = 'azurenetfiles.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise Peop",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--588c7464-9266-43fe-9832-cb7d81564100",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 142.11.200.186",
      "pattern": "[ipv4-addr:value = '142.11.200.186']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise Peop",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b725359b-373f-4ef1-8f26-c5ebd5b83b72",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 142.11.200.187",
      "pattern": "[ipv4-addr:value = '142.11.200.187']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise Peop",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--61f697e9-fa39-4e54-8f49-62c0a0c6de65",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 142.11.200.188",
      "pattern": "[ipv4-addr:value = '142.11.200.188']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise Peop",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1fc9645b-d271-4037-8f05-898c3b3ef9b6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 142.11.200.189",
      "pattern": "[ipv4-addr:value = '142.11.200.189']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise Peop",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--408fb7e9-aec1-4134-b835-e77fafd93dff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 142.11.200.190",
      "pattern": "[ipv4-addr:value = '142.11.200.190']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise Peop",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b037b108-2f5c-452d-95b2-8f04885463a7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 176.120.22.24",
      "pattern": "[ipv4-addr:value = '176.120.22.24']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise Peop",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4309f3ed-61ab-43ef-bc3a-63fa5efd340e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2ab684d93c1553fad87041b4dea97188a97e78589deee2a7bacff905564f3a35",
      "pattern": "[file:hashes.'SHA-256' = '2ab684d93c1553fad87041b4dea97188a97e78589deee2a7bacff905564f3a35']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise Peop",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f355c192-ae5d-4e51-831e-a30ba222fa27",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 68257a6f9ff196179ec03624e849927f26599eb180a7c82e14ef5bc4e93bc309",
      "pattern": "[file:hashes.'SHA-256' = '68257a6f9ff196179ec03624e849927f26599eb180a7c82e14ef5bc4e93bc309']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise Peop",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8972ce84-f0d5-4509-8133-7616b7c95628",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c7e9332731b06644fc73e0046a2a89eaa59b09f54250e9bd622467187351711f",
      "pattern": "[file:hashes.'SHA-256' = 'c7e9332731b06644fc73e0046a2a89eaa59b09f54250e9bd622467187351711f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise Peop",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e595a40a-2395-4044-9fbf-71ea432be492",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d83fdb9e53c5ff03c4cb0451ea1bebd79b53f29eadc1e2fa394c7af13a86ce2f",
      "pattern": "[file:hashes.'SHA-256' = 'd83fdb9e53c5ff03c4cb0451ea1bebd79b53f29eadc1e2fa394c7af13a86ce2f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise Peop",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bf9d66ca-8466-405e-be96-346cb0ce517f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f02a924c9ff92a8780ce812511341182c6b509d45bc59f3f7b522e37225d24fc",
      "pattern": "[file:hashes.'SHA-256' = 'f02a924c9ff92a8780ce812511341182c6b509d45bc59f3f7b522e37225d24fc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise Peop",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c2a39e25-a024-4052-a1b0-60e06a9071b3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-10520",
      "pattern": "[vulnerability:name = 'CVE-2026-10520']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-10520 \u2014 Ivanti Sentry OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e97995db-f2ea-48ae-b3e9-7efc7681f214",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-10523",
      "pattern": "[vulnerability:name = 'CVE-2026-10523']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-10520 \u2014 Ivanti Sentry OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--727eee59-cfb7-43c3-bfa5-f02557b731c9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: coachcybersecurity.com",
      "pattern": "[domain-name:value = 'coachcybersecurity.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f80a5f79-378e-4a0c-91e4-931e906eba57",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: financemachinelearning.com",
      "pattern": "[domain-name:value = 'financemachinelearning.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--54eb3d58-fe1e-47e6-acab-3bbb0646537f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: gatewayrvcenter.com",
      "pattern": "[domain-name:value = 'gatewayrvcenter.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f1896a03-2a89-41f2-b0b4-8e242dc148f8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: leadingfilipinoteams.com",
      "pattern": "[domain-name:value = 'leadingfilipinoteams.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c1375d71-7166-4bec-8ed1-8a4fa41ee7ff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: mxprodesign.com",
      "pattern": "[domain-name:value = 'mxprodesign.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c1225985-ef59-4725-b079-7a6cdc12c9ff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: power-sync-services.com",
      "pattern": "[domain-name:value = 'power-sync-services.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a85d6420-d193-447b-a971-7c4d41c1f994",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.119.47.104",
      "pattern": "[ipv4-addr:value = '103.119.47.104']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2be2431d-4f75-4aad-b7f7-6af521e11081",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 139.162.11.152",
      "pattern": "[ipv4-addr:value = '139.162.11.152']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0524d218-ae28-45e4-acef-872c5efd8c66",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 139.180.128.42",
      "pattern": "[ipv4-addr:value = '139.180.128.42']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a9e1e7f9-f2a4-42fd-8226-f1946520f77b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 139.99.33.239",
      "pattern": "[ipv4-addr:value = '139.99.33.239']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c425575c-d21d-48e9-a0df-46bef5c923b6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 142.91.98.77",
      "pattern": "[ipv4-addr:value = '142.91.98.77']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e1b51fd0-d6f6-423d-aa6a-dd216f95ae62",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 166.88.77.186",
      "pattern": "[ipv4-addr:value = '166.88.77.186']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c4ac85d-f3f6-4dc0-9f02-61917e7cebf0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.68.26.241",
      "pattern": "[ipv4-addr:value = '194.68.26.241']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b8017878-8f1e-425d-a0a1-7f5607b196f4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.60.245.37",
      "pattern": "[ipv4-addr:value = '38.60.245.37']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--412eb5c0-cac1-46e4-9ffc-3b4497f5174f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 0037DBB0FEA981D02F6F76DE81EBAEFCB68B7D20",
      "pattern": "[file:hashes.'SHA-1' = '0037DBB0FEA981D02F6F76DE81EBAEFCB68B7D20']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--72ca2983-fa85-4627-a319-6bb056189804",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 19A69F856EFA811C376F68E4FEB0997B4724F8BD",
      "pattern": "[file:hashes.'SHA-1' = '19A69F856EFA811C376F68E4FEB0997B4724F8BD']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e86e8d2-11d7-4fac-87d2-53669b16fc1f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 41CB8CD78B8DB76563E4F972ABE817CEEE9CF9B0",
      "pattern": "[file:hashes.'SHA-1' = '41CB8CD78B8DB76563E4F972ABE817CEEE9CF9B0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--071ae536-1779-4bd7-a634-180b146e4b69",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 490194E9BB5128ECA8693AD9E610891C2ED185AF",
      "pattern": "[file:hashes.'SHA-1' = '490194E9BB5128ECA8693AD9E610891C2ED185AF']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--18b1a3ac-fa2b-44f1-84ef-c66295045d96",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 4AD36AD6C165B5174967020CB1A3358F78D7A283",
      "pattern": "[file:hashes.'SHA-1' = '4AD36AD6C165B5174967020CB1A3358F78D7A283']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7767b9a3-8a55-473d-9436-e7b0f0ba4aeb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 51176139B0B2220B802C1578A4994DF68DF5BCD1",
      "pattern": "[file:hashes.'SHA-1' = '51176139B0B2220B802C1578A4994DF68DF5BCD1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0df937e4-3d27-475f-8a93-55b362d01447",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 57352B3CEEE32216E5AA20BAA848483D7AB5A6FB",
      "pattern": "[file:hashes.'SHA-1' = '57352B3CEEE32216E5AA20BAA848483D7AB5A6FB']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c0c5f12c-1c60-4ff4-99e9-4179db844d56",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 59A8553A4F8130F576AB234E0B220BE4D4DA0E98",
      "pattern": "[file:hashes.'SHA-1' = '59A8553A4F8130F576AB234E0B220BE4D4DA0E98']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1124bc92-599d-4034-9349-9ac67af20954",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 5D6194BB48FEBB91A10D1462461A012FAFC0918B",
      "pattern": "[file:hashes.'SHA-1' = '5D6194BB48FEBB91A10D1462461A012FAFC0918B']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--82c2ddf3-5ce5-429f-859a-cce002f181de",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 865A1739337D3303B3AB02C5E694C22B79C42B7D",
      "pattern": "[file:hashes.'SHA-1' = '865A1739337D3303B3AB02C5E694C22B79C42B7D']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f3c429b5-c660-4232-809f-218266ed8ef4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 91F042F59BE4BDCB6E5EA21B91DECD731C175B54",
      "pattern": "[file:hashes.'SHA-1' = '91F042F59BE4BDCB6E5EA21B91DECD731C175B54']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--892af670-24be-43c8-b6eb-e51390d9c870",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 9BC06DF9F932746A05EE728C8B103BD3BA6BF395",
      "pattern": "[file:hashes.'SHA-1' = '9BC06DF9F932746A05EE728C8B103BD3BA6BF395']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4d011bd7-6229-4ae1-aa1a-58fbfb194129",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 9CA1A5C7F79882DB913534C1E62B26BCDCB9F6DD",
      "pattern": "[file:hashes.'SHA-1' = '9CA1A5C7F79882DB913534C1E62B26BCDCB9F6DD']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--357f1409-cd1d-4c35-b3ad-8f52bce5ed6c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: A177ED0BFFEB1EFE1D9D31D72A82EF2625AE646D",
      "pattern": "[file:hashes.'SHA-1' = 'A177ED0BFFEB1EFE1D9D31D72A82EF2625AE646D']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a95a14d2-332f-4d75-a15d-c15588271429",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: A8E2BBBFCB86500322D2367744FA12755AB0C165",
      "pattern": "[file:hashes.'SHA-1' = 'A8E2BBBFCB86500322D2367744FA12755AB0C165']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--313b011b-3dcf-4e3c-9e42-46f1ef557936",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: B028E947150764A71DEEF498DE6F8C95ECCCB445",
      "pattern": "[file:hashes.'SHA-1' = 'B028E947150764A71DEEF498DE6F8C95ECCCB445']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb1140b5-a0f6-46f7-9f92-37618ec7aa98",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: B7B2D2DB544F9EEA74453CDF2B8BEEA58CF07C48",
      "pattern": "[file:hashes.'SHA-1' = 'B7B2D2DB544F9EEA74453CDF2B8BEEA58CF07C48']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4be4de8e-f53c-495f-8e1e-b5b3bbee3494",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: D511B77459673EC42163F19E300FF1D233B6C39F",
      "pattern": "[file:hashes.'SHA-1' = 'D511B77459673EC42163F19E300FF1D233B6C39F']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7f6ff6a8-eb6a-48ab-a4d8-2d06c60881fe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: F74F1FEB62B662CDA489FDB2453727824E55ACB9",
      "pattern": "[file:hashes.'SHA-1' = 'F74F1FEB62B662CDA489FDB2453727824E55ACB9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87cd4395-3c38-451b-839a-752527a61cea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: F8F8209987CA7F139DE6A62F9E6EE21BD2AE93A9",
      "pattern": "[file:hashes.'SHA-1' = 'F8F8209987CA7F139DE6A62F9E6EE21BD2AE93A9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "OceanLotus: From external espionage to domestic targeting",
          "url": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e8a6755a-78e0-4627-b149-a4dc02d2c584",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4b2399646573bb737c4969563303d8ee2e9ddbd1b271f1ca9e35ea78062538db",
      "pattern": "[file:hashes.'SHA-256' = '4b2399646573bb737c4969563303d8ee2e9ddbd1b271f1ca9e35ea78062538db']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "npm v12 delivers one of the biggest security improvements in",
          "url": "https://www.aikido.dev/blog/npm-v12-block-postinstall"
        },
        {
          "source_name": "Securing Vibe Coding and AI Coding Agents: An End-to-End App",
          "url": "https://www.stepsecurity.io/blog/securing-vibe-coding-and-ai-coding-agents-an-end-to-end-approach-with-stepsecurity"
        },
        {
          "source_name": "SHA1-Hulud, npm supply chain incident",
          "url": "https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4873bfd6-1be6-40b4-b150-79b75b1bbcfd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b74caeaa75e077c99f7d44f46daaf9796a3be43ecf24f2a1fd381844669da777",
      "pattern": "[file:hashes.'SHA-256' = 'b74caeaa75e077c99f7d44f46daaf9796a3be43ecf24f2a1fd381844669da777']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "npm v12 delivers one of the biggest security improvements in",
          "url": "https://www.aikido.dev/blog/npm-v12-block-postinstall"
        },
        {
          "source_name": "Securing Vibe Coding and AI Coding Agents: An End-to-End App",
          "url": "https://www.stepsecurity.io/blog/securing-vibe-coding-and-ai-coding-agents-an-end-to-end-approach-with-stepsecurity"
        },
        {
          "source_name": "SHA1-Hulud, npm supply chain incident",
          "url": "https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb23aee1-fa19-41f2-9ba1-8f1d380d3e1c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: dc67467a39b70d1cd4c1f7f7a459b35058163592f4a9e8fb4dffcbba98ef210c",
      "pattern": "[file:hashes.'SHA-256' = 'dc67467a39b70d1cd4c1f7f7a459b35058163592f4a9e8fb4dffcbba98ef210c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "npm v12 delivers one of the biggest security improvements in",
          "url": "https://www.aikido.dev/blog/npm-v12-block-postinstall"
        },
        {
          "source_name": "Securing Vibe Coding and AI Coding Agents: An End-to-End App",
          "url": "https://www.stepsecurity.io/blog/securing-vibe-coding-and-ai-coding-agents-an-end-to-end-approach-with-stepsecurity"
        },
        {
          "source_name": "SHA1-Hulud, npm supply chain incident",
          "url": "https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b81e3aaa-8345-4a66-9a0c-3fcd525fe1ad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: o4511539639222272.ingest.de.sentry.io",
      "pattern": "[domain-name:value = 'o4511539639222272.ingest.de.sentry.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Compromised Rust crate onering performs code exfiltration",
          "url": "https://www.aikido.dev/blog/compromised-rust-crate-onering-performs-code-exfiltration"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3fd78859-400a-485e-ab0d-292af6275856",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-29199",
      "pattern": "[vulnerability:name = 'CVE-2026-29199']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "10 year old critical vulnerability in phpBB affecting tens o",
          "url": "https://www.aikido.dev/blog/phpbb-authentication-bypass-rce"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1f8110ac-9020-456c-85a5-36c27328af68",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.32.150.251",
      "pattern": "[ipv4-addr:value = '45.32.150.251']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Code is being written everywhere, and the device is the only",
          "url": "https://www.aikido.dev/blog/code-is-written-everywhere"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8aa8d33b-a33d-4746-a33d-af485f9ca9d5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.32.151.157",
      "pattern": "[ipv4-addr:value = '45.32.151.157']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Code is being written everywhere, and the device is the only",
          "url": "https://www.aikido.dev/blog/code-is-written-everywhere"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--45ae53ae-0277-4f32-a882-e132bed3e730",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 70.34.242.255",
      "pattern": "[ipv4-addr:value = '70.34.242.255']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Code is being written everywhere, and the device is the only",
          "url": "https://www.aikido.dev/blog/code-is-written-everywhere"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--48ce8428-4302-4f58-9d26-8dd14b4161a1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-11645",
      "pattern": "[vulnerability:name = 'CVE-2026-11645']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-11645 \u2014 Google Chromium V8 Out-of-Bounds ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c99e6399-219d-4ee4-af97-ff7eb3991fdc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-20122",
      "pattern": "[vulnerability:name = 'CVE-2026-20122']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-20245 \u2014 Cisco Catalyst SD-WAN Manager Imp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-20122 \u2014 Cisco Catalyst SD-WAN Manager Inc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--42f8298e-b3f1-4b2a-a264-260aca4e9a1d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-20127",
      "pattern": "[vulnerability:name = 'CVE-2026-20127']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-20245 \u2014 Cisco Catalyst SD-WAN Manager Imp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-20127 \u2014 Cisco Catalyst SD-WAN Controller ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9245f5e5-e27f-472e-9eaf-135732a602ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-20128",
      "pattern": "[vulnerability:name = 'CVE-2026-20128']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-20245 \u2014 Cisco Catalyst SD-WAN Manager Imp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-20128 \u2014 Cisco Catalyst SD-WAN Manager Sto",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--be457545-178a-43b1-8fa8-b6e33d3610d1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-20133",
      "pattern": "[vulnerability:name = 'CVE-2026-20133']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-20245 \u2014 Cisco Catalyst SD-WAN Manager Imp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-20133 \u2014 Cisco Catalyst SD-WAN Manager Exp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ba6ca5ac-94b4-4fc0-bc61-61db8fca141a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-20182",
      "pattern": "[vulnerability:name = 'CVE-2026-20182']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-20245 \u2014 Cisco Catalyst SD-WAN Manager Imp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-20182 \u2014 Cisco Catalyst SD-WAN Controller ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a079355e-6477-4011-80bb-4e03de339818",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-20245",
      "pattern": "[vulnerability:name = 'CVE-2026-20245']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-20245 \u2014 Cisco Catalyst SD-WAN Manager Imp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b7d0f80-a27d-4c59-9a60-5a6d2881914e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-7473",
      "pattern": "[vulnerability:name = 'CVE-2026-7473']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-7473 \u2014 Arista Extensible Operating System",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--70bec6a3-ab1d-45a2-b9c7-27b02389f9ce",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: t.m-kosche.com",
      "pattern": "[domain-name:value = 't.m-kosche.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Miasma Worm Hits Microsoft Again: Azure Functions Action and",
          "url": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents"
        },
        {
          "source_name": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "url": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware"
        },
        {
          "source_name": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer I",
          "url": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e2a3bd60-eb9e-4df4-bfa7-5de04f25e50c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.95.159.32",
      "pattern": "[ipv4-addr:value = '185.95.159.32']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Miasma Worm Hits Microsoft Again: Azure Functions Action and",
          "url": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents"
        },
        {
          "source_name": "The AntV Supply Chain Campaign Expands: Microsoft's `durable",
          "url": "https://snyk.io/blog/durabletask-pypi-supply-chain-attack/"
        },
        {
          "source_name": "Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Publi",
          "url": "https://snyk.io/blog/mini-shai-hulud-antv-npm-supply-chain-attack/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d7859673-8905-44c9-b9d8-fedf4c24a18a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 069ac1dc7f7649b76bc72a11ac700f373804bfd81dab7e561157b703999f44ce",
      "pattern": "[file:hashes.'SHA-256' = '069ac1dc7f7649b76bc72a11ac700f373804bfd81dab7e561157b703999f44ce']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Miasma Worm Hits Microsoft Again: Azure Functions Action and",
          "url": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents"
        },
        {
          "source_name": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "url": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware"
        },
        {
          "source_name": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer I",
          "url": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e24faae3-f792-47e6-89fb-f9a43ad3d434",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 288f26c2eadcb1a7923fe376d16f5404216cce15d9fc162a4a78574dc7df399a",
      "pattern": "[file:hashes.'SHA-256' = '288f26c2eadcb1a7923fe376d16f5404216cce15d9fc162a4a78574dc7df399a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Wait, binding.gyp Can Do What? Exploring npm's Weirdest Buil",
          "url": "https://www.aikido.dev/blog/exploring-binding-gyp-npm-build-system"
        },
        {
          "source_name": "Node-gyp Supply Chain Compromise: A Self-Propagating npm Wor",
          "url": "https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gyp/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2b83b098-f6c8-41f0-a754-aed7fa249365",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e3dbe63aded45278f49c4746ab938ed9472b36def79b43e2dd2d7eff014481d1",
      "pattern": "[file:hashes.'SHA-256' = 'e3dbe63aded45278f49c4746ab938ed9472b36def79b43e2dd2d7eff014481d1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Wait, binding.gyp Can Do What? Exploring npm's Weirdest Buil",
          "url": "https://www.aikido.dev/blog/exploring-binding-gyp-npm-build-system"
        },
        {
          "source_name": "Node-gyp Supply Chain Compromise: A Self-Propagating npm Wor",
          "url": "https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gyp/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ca5d5d78-5aec-4fab-b08a-ca3b00148ff5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: dnsowl.com",
      "pattern": "[domain-name:value = 'dnsowl.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Miasma Worm Hits Microsoft Again: Azure Functions Action and",
          "url": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f1c67021-bde1-47a6-8ab5-5e898a9e1339",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 160.119.64.3",
      "pattern": "[ipv4-addr:value = '160.119.64.3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Miasma Worm Hits Microsoft Again: Azure Functions Action and",
          "url": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents"
        },
        {
          "source_name": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "url": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware"
        },
        {
          "source_name": "The AntV Supply Chain Campaign Expands: Microsoft's `durable",
          "url": "https://snyk.io/blog/durabletask-pypi-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--96ba128d-1bad-459d-890b-5080c5c8e69a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3a9db5ba0c8cd4c91e91717df6b1a141fc1e0fbc0558b5a78d7f5c23f5b2a150",
      "pattern": "[file:hashes.'SHA-256' = '3a9db5ba0c8cd4c91e91717df6b1a141fc1e0fbc0558b5a78d7f5c23f5b2a150']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Miasma Worm Hits Microsoft Again: Azure Functions Action and",
          "url": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ec237644-fe2f-426e-93d9-21347273d4ab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3de04fe2a76262743ed089efa7115f4508619838e77d60b9a1aab8b20d2cc8bf",
      "pattern": "[file:hashes.'SHA-256' = '3de04fe2a76262743ed089efa7115f4508619838e77d60b9a1aab8b20d2cc8bf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Miasma Worm Hits Microsoft Again: Azure Functions Action and",
          "url": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents"
        },
        {
          "source_name": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "url": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware"
        },
        {
          "source_name": "The AntV Supply Chain Campaign Expands: Microsoft's `durable",
          "url": "https://snyk.io/blog/durabletask-pypi-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--66a5d47c-5a34-4390-94a5-90305b82713b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 633c8410ee0413ca4b090a19c30b20c03f31598c25247c484846fa34c1df5b64",
      "pattern": "[file:hashes.'SHA-256' = '633c8410ee0413ca4b090a19c30b20c03f31598c25247c484846fa34c1df5b64']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Miasma Worm Hits Microsoft Again: Azure Functions Action and",
          "url": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--34bc61c8-8e03-41fa-bc2f-55710b9a5e50",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 85f54c089d78ebfb101454ec934c767065a342a43c9ee1beac8430cdd3b2086f",
      "pattern": "[file:hashes.'SHA-256' = '85f54c089d78ebfb101454ec934c767065a342a43c9ee1beac8430cdd3b2086f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Miasma Worm Hits Microsoft Again: Azure Functions Action and",
          "url": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents"
        },
        {
          "source_name": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "url": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware"
        },
        {
          "source_name": "The AntV Supply Chain Campaign Expands: Microsoft's `durable",
          "url": "https://snyk.io/blog/durabletask-pypi-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b29b008a-58df-47a1-abaa-5cf098fd8be8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c0b094e46842260936d4b97ce63e4539b99a3eae48b736798c700217c52569dc",
      "pattern": "[file:hashes.'SHA-256' = 'c0b094e46842260936d4b97ce63e4539b99a3eae48b736798c700217c52569dc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Miasma Worm Hits Microsoft Again: Azure Functions Action and",
          "url": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents"
        },
        {
          "source_name": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "url": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware"
        },
        {
          "source_name": "The AntV Supply Chain Campaign Expands: Microsoft's `durable",
          "url": "https://snyk.io/blog/durabletask-pypi-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--028f9e17-80b4-4298-afd8-898bd0f0b5e3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d630397de8b01af0f6f5cf4463da91b17f28195a2c50c8f3f38ad9f7873fdb8e",
      "pattern": "[file:hashes.'SHA-256' = 'd630397de8b01af0f6f5cf4463da91b17f28195a2c50c8f3f38ad9f7873fdb8e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Miasma Worm Hits Microsoft Again: Azure Functions Action and",
          "url": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--726f1563-2bd0-4e7e-9d09-ae8e7affc668",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-42271",
      "pattern": "[vulnerability:name = 'CVE-2026-42271']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-42271 \u2014 BerriAI LiteLLM Command Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9f7aaedc-8f49-4dc6-801f-082e47f5b9a5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-48710",
      "pattern": "[vulnerability:name = 'CVE-2026-48710']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-42271 \u2014 BerriAI LiteLLM Command Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fab9fdbf-fdbc-4d80-b522-e66a72eb2616",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 144.208.127.155",
      "pattern": "[ipv4-addr:value = '144.208.127.155']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Impr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--46d65b45-a85e-4248-855c-b800c4720da9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 162.33.177.101",
      "pattern": "[ipv4-addr:value = '162.33.177.101']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Impr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cc1bee11-a2f7-4444-b03a-0e2b9d226742",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 209.182.225.136",
      "pattern": "[ipv4-addr:value = '209.182.225.136']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Impr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1be3a4a9-c400-4a93-8598-94356fe902b5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.54.107.167",
      "pattern": "[ipv4-addr:value = '38.54.107.167']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Impr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bd31a2c2-7f78-41ab-8260-ae70e7037891",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.54.88.201",
      "pattern": "[ipv4-addr:value = '38.54.88.201']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Impr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--693aadc8-c706-43ac-b0c0-60c7c871e42a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.60.157.139",
      "pattern": "[ipv4-addr:value = '38.60.157.139']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Impr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1d1551da-9c04-47ce-a3cb-916d49ded94e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.61.136.173",
      "pattern": "[ipv4-addr:value = '45.61.136.173']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Impr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a9df76d9-844d-4dc8-930a-d8082c2a794a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.63.104.106",
      "pattern": "[ipv4-addr:value = '45.63.104.106']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Impr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d1f07e16-5877-4102-8c74-cbdaff0d27d0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.76.26.42",
      "pattern": "[ipv4-addr:value = '45.76.26.42']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Impr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c490fa7a-7be2-47f8-be30-9dc6089106a9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.77.149.152",
      "pattern": "[ipv4-addr:value = '45.77.149.152']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Impr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea21a27e-3691-4275-a04e-5d59d9bae32f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 66.42.99.200",
      "pattern": "[ipv4-addr:value = '66.42.99.200']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Impr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--300d7846-6b6f-41fc-91ec-2a6b42592a2e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 51d39aa39478beeac94f2d12f682ecce",
      "pattern": "[file:hashes.MD5 = '51d39aa39478beeac94f2d12f682ecce']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Impr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a2198e09-07bd-4962-9bc6-55a19efd86ff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 52fda5c1b9704544f32ee98d9060e689",
      "pattern": "[file:hashes.MD5 = '52fda5c1b9704544f32ee98d9060e689']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Impr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f682bbcc-fce3-4be5-98a7-be10aaf78e67",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-28318",
      "pattern": "[vulnerability:name = 'CVE-2026-28318']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-28318 \u2014 SolarWinds Serv-U Uncontrolled Re",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--33e4e677-5e84-4364-b7ee-b4e414002451",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-6514",
      "pattern": "[vulnerability:name = 'CVE-2025-6514']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "So You Have an AI Security Budget. Now what?",
          "url": "https://snyk.io/blog/ai-security-budget/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0453ea4-3334-4ab7-804b-6929a4c4ce5d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 608d01124cd6b5b8c55888e984b4c4d9b06fa686",
      "pattern": "[file:hashes.'SHA-1' = '608d01124cd6b5b8c55888e984b4c4d9b06fa686']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Node-gyp Supply Chain Compromise: A Self-Propagating npm Wor",
          "url": "https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gyp/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e815139d-7592-4f4f-be66-90a2e5299681",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 8bf051251ec3b973e39a313547e53421a2f8d2f6",
      "pattern": "[file:hashes.'SHA-1' = '8bf051251ec3b973e39a313547e53421a2f8d2f6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Node-gyp Supply Chain Compromise: A Self-Propagating npm Wor",
          "url": "https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gyp/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--89b1277e-2394-490b-b326-133c84723353",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: ab9903d9edc720d1e11ea7d3d3e7a1c456f44ff7",
      "pattern": "[file:hashes.'SHA-1' = 'ab9903d9edc720d1e11ea7d3d3e7a1c456f44ff7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Node-gyp Supply Chain Compromise: A Self-Propagating npm Wor",
          "url": "https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gyp/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fd2b2d4a-4c12-4953-9e1b-4fb2cda45ff2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5926b86b642e00672252953eb30d8f75cfb7797fe3118bd6fa2cfbee92905d61",
      "pattern": "[file:hashes.'SHA-256' = '5926b86b642e00672252953eb30d8f75cfb7797fe3118bd6fa2cfbee92905d61']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Node-gyp Supply Chain Compromise: A Self-Propagating npm Wor",
          "url": "https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gyp/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ad633250-0dd2-4ee1-aee8-dec3ee33c60c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 82d83274680df928fdda296a348e01802f595e412308c399565c320df444052a",
      "pattern": "[file:hashes.'SHA-256' = '82d83274680df928fdda296a348e01802f595e412308c399565c320df444052a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Node-gyp Supply Chain Compromise: A Self-Propagating npm Wor",
          "url": "https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gyp/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb462a3d-392b-4303-ae16-0970ba852577",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-45247",
      "pattern": "[vulnerability:name = 'CVE-2026-45247']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-45247 \u2014 Mirasvit Full Page Cache Warmer D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c7699ba-f702-44c3-9eea-8fc1fc3bd0ee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-0492",
      "pattern": "[vulnerability:name = 'CVE-2022-0492']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0492 \u2014 Linux Kernel Improper Authenticati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--26eb9462-515e-41b9-b833-23af5ae3d243",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-48595",
      "pattern": "[vulnerability:name = 'CVE-2025-48595']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-48595 \u2014 Android Framework Integer Overflo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--10c4abcb-db04-4c72-a08b-b1f789a25bea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 556d2b335d4d6d92139822017ee461b668afe375",
      "pattern": "[file:hashes.'SHA-1' = '556d2b335d4d6d92139822017ee461b668afe375']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple ",
          "url": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack"
        },
        {
          "source_name": "Laravel Lang Supply Chain Advisory",
          "url": "https://snyk.io/blog/laravel-lang-supply-chain-advisory/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e8c7e8bb-1cb0-41e8-ac65-bf643175eb22",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: a5ea2e8fa92ccf29cdb1d2dadbeb27722b2bff37",
      "pattern": "[file:hashes.'SHA-1' = 'a5ea2e8fa92ccf29cdb1d2dadbeb27722b2bff37']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple ",
          "url": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack"
        },
        {
          "source_name": "Laravel Lang Supply Chain Advisory",
          "url": "https://snyk.io/blog/laravel-lang-supply-chain-advisory/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7ceac7a3-b230-414f-977d-8a33d8a9eb99",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: bba2e443dc7ff1f8704f52a5375383e3f4f643b8",
      "pattern": "[file:hashes.'SHA-1' = 'bba2e443dc7ff1f8704f52a5375383e3f4f643b8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple ",
          "url": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack"
        },
        {
          "source_name": "Laravel Lang Supply Chain Advisory",
          "url": "https://snyk.io/blog/laravel-lang-supply-chain-advisory/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6bf5f126-74f3-46bb-8c88-7750cace3082",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1a4afce34918bdc74ae3f31edaffffaa0ee074d83618f53edfd88137927340b8",
      "pattern": "[file:hashes.'SHA-256' = '1a4afce34918bdc74ae3f31edaffffaa0ee074d83618f53edfd88137927340b8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Nx Console VS Code Extension Compromised",
          "url": "https://www.stepsecurity.io/blog/nx-console-vs-code-extension-compromised"
        },
        {
          "source_name": "What MDM can't protect on developer machines (and what to do",
          "url": "https://www.aikido.dev/blog/what-mdm-cant-protect"
        },
        {
          "source_name": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer I",
          "url": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--732092d8-8c06-4cfb-9396-01313fb63349",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7d80b3ef74ad7992b93c31966962612e4e2ceb93e7727cdbd1d2a9af47d44ba8",
      "pattern": "[file:hashes.'SHA-256' = '7d80b3ef74ad7992b93c31966962612e4e2ceb93e7727cdbd1d2a9af47d44ba8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "url": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware"
        },
        {
          "source_name": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer I",
          "url": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough"
        },
        {
          "source_name": "The AntV Supply Chain Campaign Expands: Microsoft's `durable",
          "url": "https://snyk.io/blog/durabletask-pypi-supply-chain-attack/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4ab83858-582d-4b96-b9ad-89abec149f4c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: aeaf583e20347bf850e2fabdcd6f4982996ba023f8c2cd56bbd299cfd56516f5",
      "pattern": "[file:hashes.'SHA-256' = 'aeaf583e20347bf850e2fabdcd6f4982996ba023f8c2cd56bbd299cfd56516f5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "url": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware"
        },
        {
          "source_name": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer I",
          "url": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough"
        },
        {
          "source_name": "The AntV Supply Chain Campaign Expands: Microsoft's `durable",
          "url": "https://snyk.io/blog/durabletask-pypi-supply-chain-attack/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dfec5e21-4294-4051-a994-ad5c58d3fff0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b0cefb66b953e5184b6adb3035e9e267335ac5eabfe1848e07834777b9397b74",
      "pattern": "[file:hashes.'SHA-256' = 'b0cefb66b953e5184b6adb3035e9e267335ac5eabfe1848e07834777b9397b74']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Nx Console VS Code Extension Compromised",
          "url": "https://www.stepsecurity.io/blog/nx-console-vs-code-extension-compromised"
        },
        {
          "source_name": "What MDM can't protect on developer machines (and what to do",
          "url": "https://www.aikido.dev/blog/what-mdm-cant-protect"
        },
        {
          "source_name": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer I",
          "url": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c19c7eda-ea27-41e1-94fd-0bf358d05662",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e7347d90653efc565f03733a95e9209d78f9cfa81e31ff2b2dd9d48d75a4b8b1",
      "pattern": "[file:hashes.'SHA-256' = 'e7347d90653efc565f03733a95e9209d78f9cfa81e31ff2b2dd9d48d75a4b8b1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Nx Console VS Code Extension Compromised",
          "url": "https://www.stepsecurity.io/blog/nx-console-vs-code-extension-compromised"
        },
        {
          "source_name": "What MDM can't protect on developer machines (and what to do",
          "url": "https://www.aikido.dev/blog/what-mdm-cant-protect"
        },
        {
          "source_name": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer I",
          "url": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--51b5a8d9-dc55-4153-b2fe-e74eafb32999",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: packages.npm.org",
      "pattern": "[domain-name:value = 'packages.npm.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "url": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d8efb154-5c6f-45e0-bd41-b80c755ceeba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 1713b19cbf609cb101ff5e216be41f7224269082",
      "pattern": "[file:hashes.'SHA-1' = '1713b19cbf609cb101ff5e216be41f7224269082']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple ",
          "url": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--297d7b4d-f9b0-4f75-851f-45dad5bb0c2e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 26c233e1a0d4fd2331e8e0f175e18f8eed904aa3",
      "pattern": "[file:hashes.'SHA-1' = '26c233e1a0d4fd2331e8e0f175e18f8eed904aa3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple ",
          "url": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9dff8fa4-a3fb-41c5-9c55-dfc64f440acb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 50ac0db454d19234c835716f297bbc5363c0a25c",
      "pattern": "[file:hashes.'SHA-1' = '50ac0db454d19234c835716f297bbc5363c0a25c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple ",
          "url": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d9d43de1-c59c-4491-a78b-97e07cc980bd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 6b1d5782a8c8c199d070857802d39bfe609eb6f2",
      "pattern": "[file:hashes.'SHA-1' = '6b1d5782a8c8c199d070857802d39bfe609eb6f2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple ",
          "url": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d95bee1f-0da2-4408-bb2f-0fe05f669662",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 722cee67326d932e7f71ba3438f62a255d779aa9",
      "pattern": "[file:hashes.'SHA-1' = '722cee67326d932e7f71ba3438f62a255d779aa9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple ",
          "url": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d15660f0-9f47-4c63-b290-e1d604c8a7f6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 9ee599d248cc322fa26054694a83a1f4558cc716",
      "pattern": "[file:hashes.'SHA-1' = '9ee599d248cc322fa26054694a83a1f4558cc716']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple ",
          "url": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a1de9c25-9972-4629-95aa-5db4c65efea9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: a9f8d88cf98e35988d3d0fd6d79547f980853041",
      "pattern": "[file:hashes.'SHA-1' = 'a9f8d88cf98e35988d3d0fd6d79547f980853041']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple ",
          "url": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6094ca51-3219-409f-804f-efbe59a78f40",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: ad24b980db8f0dca50ccb3ba6badb3c2331e0ef4",
      "pattern": "[file:hashes.'SHA-1' = 'ad24b980db8f0dca50ccb3ba6badb3c2331e0ef4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple ",
          "url": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--04a95a57-baef-4776-8eb2-50038ec1bc68",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: c45764e70285146da37025cd8601a921ab8a7eda",
      "pattern": "[file:hashes.'SHA-1' = 'c45764e70285146da37025cd8601a921ab8a7eda']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple ",
          "url": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--28c822ba-4294-42e2-9139-af7870e07cac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: d59561727927117e65b35f0183cae131baad19fe",
      "pattern": "[file:hashes.'SHA-1' = 'd59561727927117e65b35f0183cae131baad19fe']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple ",
          "url": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--72a210cf-2e4e-484a-88f3-631ad4ff4834",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: daa5212264bb73fb39fe7a36618b62717dc564a5",
      "pattern": "[file:hashes.'SHA-1' = 'daa5212264bb73fb39fe7a36618b62717dc564a5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple ",
          "url": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--51d5ee5e-84d0-48a5-9c89-f616ca169a2e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: db0c3ef246103fd0f6c318e0d48f26b5289044c3",
      "pattern": "[file:hashes.'SHA-1' = 'db0c3ef246103fd0f6c318e0d48f26b5289044c3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple ",
          "url": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0c1286e1-7032-4185-9a44-98a9496086f6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 877ff2531a63393c4cb9a3c86908b62d9c4fc3db971bc231c48537faae6cb3ec",
      "pattern": "[file:hashes.'SHA-256' = '877ff2531a63393c4cb9a3c86908b62d9c4fc3db971bc231c48537faae6cb3ec']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "url": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--31d82524-9732-46b0-a2d1-59bfedd6011d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 970ba1a06bfabaf7a7f17df75f12a19e48ad4667c938bc7949a6a0502f6160b6",
      "pattern": "[file:hashes.'SHA-256' = '970ba1a06bfabaf7a7f17df75f12a19e48ad4667c938bc7949a6a0502f6160b6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Protestware by open source maintainer to hinder agentic codi",
          "url": "https://snyk.io/blog/protestware-open-source-maintainer-qwik-1-10-0-prompt-injection/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ffd450f-b0dc-4dee-99a4-bf3d850d99ab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-21182",
      "pattern": "[vulnerability:name = 'CVE-2024-21182']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-21182 \u2014 Oracle WebLogic Server Unspecifie",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d122a090-98c6-4508-9829-bf3a24f223ca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-0257",
      "pattern": "[vulnerability:name = 'CVE-2026-0257']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1f5dfab2-6c36-4071-a3da-e0a621cb1880",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.207.144.154",
      "pattern": "[ipv4-addr:value = '104.207.144.154']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5906c504-ec39-46d9-b700-8ed771236489",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 146.19.216.119",
      "pattern": "[ipv4-addr:value = '146.19.216.119']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ba30fc54-d96a-4740-8f35-3ba366b89075",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 146.19.216.120",
      "pattern": "[ipv4-addr:value = '146.19.216.120']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--106551b8-95a0-41b0-86e4-3442a2a2604a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 146.19.216.125",
      "pattern": "[ipv4-addr:value = '146.19.216.125']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--13743dd5-64a2-4d0b-9db9-4328d6c666fb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 179.43.172.213",
      "pattern": "[ipv4-addr:value = '179.43.172.213']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--30e7e168-6728-4a5f-9c22-e10c88966786",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.195.232.139",
      "pattern": "[ipv4-addr:value = '185.195.232.139']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b4eeaa16-c4f1-4238-9a1d-4533c274d401",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 198.12.106.60",
      "pattern": "[ipv4-addr:value = '198.12.106.60']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--10ccb955-0cc5-4b8a-b813-032bbc4ef3aa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 202.144.192.47",
      "pattern": "[ipv4-addr:value = '202.144.192.47']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2cd40ba0-8d08-4192-8ca7-4034295f791c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 209.99.191.137",
      "pattern": "[ipv4-addr:value = '209.99.191.137']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--146d66f6-0393-4206-a4d6-40e5bbac0867",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.128.228.6",
      "pattern": "[ipv4-addr:value = '23.128.228.6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--62c369c6-7c0d-4b58-a6ee-f444e2f34e9e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 79.130.26.202",
      "pattern": "[ipv4-addr:value = '79.130.26.202']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d7726412-6bbf-42f1-a8e1-f672cd11fd5e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: filev2.getsession.org",
      "pattern": "[domain-name:value = 'filev2.getsession.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "What MDM can't protect on developer machines (and what to do",
          "url": "https://www.aikido.dev/blog/what-mdm-cant-protect"
        },
        {
          "source_name": "CISA KEV: CVE-2026-45321 \u2014 TanStack Unspecified Vulnerabilit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "Why developer machines are now the number one target for sup",
          "url": "https://www.aikido.dev/blog/developer-machines-supply-chain-attacks"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "CISA KEV",
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--377d47fd-7823-41d5-b8fa-f2b6f75e5ce7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 558b09d7ad0d1660e2a0fb8a06da81a6f42e06d2",
      "pattern": "[file:hashes.'SHA-1' = '558b09d7ad0d1660e2a0fb8a06da81a6f42e06d2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "What MDM can't protect on developer machines (and what to do",
          "url": "https://www.aikido.dev/blog/what-mdm-cant-protect"
        },
        {
          "source_name": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer I",
          "url": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough"
        },
        {
          "source_name": "The Wild West of VS Code extensions and how a poisoned exten",
          "url": "https://www.aikido.dev/blog/vs-code-extension-github-breach"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--683387c4-6e24-4d70-a893-f1eb2ee9447c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: ba642fe2c7c65e42dd7f6444b83023dc6827e08c",
      "pattern": "[file:hashes.'SHA-1' = 'ba642fe2c7c65e42dd7f6444b83023dc6827e08c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "What MDM can't protect on developer machines (and what to do",
          "url": "https://www.aikido.dev/blog/what-mdm-cant-protect"
        },
        {
          "source_name": "The Wild West of VS Code extensions and how a poisoned exten",
          "url": "https://www.aikido.dev/blog/vs-code-extension-github-breach"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--81962e04-ae9a-40d0-b98a-97abb1121195",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cyberhavenext.pro",
      "pattern": "[domain-name:value = 'cyberhavenext.pro']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "What MDM can't protect on developer machines (and what to do",
          "url": "https://www.aikido.dev/blog/what-mdm-cant-protect"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f080f87-618a-4603-81d4-c7bbd7a95e19",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-8398",
      "pattern": "[vulnerability:name = 'CVE-2026-8398']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f7f91a76-1804-4b24-8917-45c8a6ec4d5a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: api.masscan.cloud",
      "pattern": "[domain-name:value = 'api.masscan.cloud']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-45321 \u2014 TanStack Unspecified Vulnerabilit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "Why developer machines are now the number one target for sup",
          "url": "https://www.aikido.dev/blog/developer-machines-supply-chain-attacks"
        },
        {
          "source_name": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer I",
          "url": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV",
        "Aikido",
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3c338846-17a8-4142-b6bb-4b09dabc7c6f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: env-check.daemontools.cc",
      "pattern": "[domain-name:value = 'env-check.daemontools.cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb19f298-ea32-483a-95ff-08e0108bdd8d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: litter.catbox.moe",
      "pattern": "[domain-name:value = 'litter.catbox.moe']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-45321 \u2014 TanStack Unspecified Vulnerabilit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply C",
          "url": "https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV",
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--08694ed5-63a7-4817-a60f-fc6f6270308a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: seed1.getsession.org",
      "pattern": "[domain-name:value = 'seed1.getsession.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-45321 \u2014 TanStack Unspecified Vulnerabilit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "Why developer machines are now the number one target for sup",
          "url": "https://www.aikido.dev/blog/developer-machines-supply-chain-attacks"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8bb19542-5892-4482-b7d4-16c65c5577ad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: seed2.getsession.org",
      "pattern": "[domain-name:value = 'seed2.getsession.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-45321 \u2014 TanStack Unspecified Vulnerabilit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cdfd39db-0780-4044-afa3-93cbc325a4ff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: seed3.getsession.org",
      "pattern": "[domain-name:value = 'seed3.getsession.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-45321 \u2014 TanStack Unspecified Vulnerabilit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7f69d5c8-0f1b-4e3e-b1ed-5b2a4e303eab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.180.107.76",
      "pattern": "[ipv4-addr:value = '38.180.107.76']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d18618e1-5790-4f65-a60f-80e6dd86b34a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 00e2df8f42d14072e4385e500d4669ec783aa517",
      "pattern": "[file:hashes.'SHA-1' = '00e2df8f42d14072e4385e500d4669ec783aa517']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f87a3efd-8239-4a25-806e-5fa9ac17663a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 0456e2f5f56ec8ed16078941248e7cbba9f1c8eb",
      "pattern": "[file:hashes.'SHA-1' = '0456e2f5f56ec8ed16078941248e7cbba9f1c8eb']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--40e720cf-46ba-4513-a39e-c68125f2e9ea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 0c1d3da9c7a651ba40b40e12d48ebd32b3f31820",
      "pattern": "[file:hashes.'SHA-1' = '0c1d3da9c7a651ba40b40e12d48ebd32b3f31820']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5e33207-d452-44c9-ad72-6a2bd5c7a57f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 15ed5c3384e12fe4314ad6edbd1dcccf5ac1ee29",
      "pattern": "[file:hashes.'SHA-1' = '15ed5c3384e12fe4314ad6edbd1dcccf5ac1ee29']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fdaec617-e8c0-4ed2-8c95-505527a065e5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 28b72576d67ae21d9587d782942628ea46dcc870",
      "pattern": "[file:hashes.'SHA-1' = '28b72576d67ae21d9587d782942628ea46dcc870']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0e2ae692-392d-4e9b-bd49-a91ea5ec7b16",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 295ce86226b933e7262c2ce4b36bdd6c389aaaef",
      "pattern": "[file:hashes.'SHA-1' = '295ce86226b933e7262c2ce4b36bdd6c389aaaef']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a9bd3424-3ea2-4dc3-a3ab-d19839b1230d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 2d4eb55b01f59c62c6de9aacba9b47267d398fe4",
      "pattern": "[file:hashes.'SHA-1' = '2d4eb55b01f59c62c6de9aacba9b47267d398fe4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--64bb05d3-c93a-4cc8-904c-f9f88b852d0d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 2ecb292d27c36c1d4e47fb5cafa42af7ffbdda99",
      "pattern": "[file:hashes.'SHA-1' = '2ecb292d27c36c1d4e47fb5cafa42af7ffbdda99']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7f1c083a-42b2-4675-9ec0-c8e620a4c2d9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 3ee71d75020b2634b2c23866211a0c91b942c8d4",
      "pattern": "[file:hashes.'SHA-1' = '3ee71d75020b2634b2c23866211a0c91b942c8d4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b40f53e5-3c4d-4471-818e-669dac8a4286",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 427f1728682ebc7ffe3300fef67d0e3cb6b62948",
      "pattern": "[file:hashes.'SHA-1' = '427f1728682ebc7ffe3300fef67d0e3cb6b62948']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e6930bed-c2a0-498c-b8b1-88b109fa7acf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 46b90bf370e60d61075d3472828fdc0b85ab0492",
      "pattern": "[file:hashes.'SHA-1' = '46b90bf370e60d61075d3472828fdc0b85ab0492']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da7a52a0-af32-4606-8353-8eb85c7c61b6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 50d47adb6dd45215c7cb4c68bae28b129ca09645",
      "pattern": "[file:hashes.'SHA-1' = '50d47adb6dd45215c7cb4c68bae28b129ca09645']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--16bb726d-9f75-4e82-9737-8eed2b4bf175",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 524d2d92909eef80c406e87a0fc37d7bb4dadc14",
      "pattern": "[file:hashes.'SHA-1' = '524d2d92909eef80c406e87a0fc37d7bb4dadc14']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc8a0bfe-03a1-4044-b9a5-1bba1f9cd5a6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 6325179f442e5b1a716580cd70dea644ac9ecd18",
      "pattern": "[file:hashes.'SHA-1' = '6325179f442e5b1a716580cd70dea644ac9ecd18']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--50a51b93-af5e-4f62-83a0-3f72f2008a7a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 64462f751788f529c1eb09023b26a47792ecdc54",
      "pattern": "[file:hashes.'SHA-1' = '64462f751788f529c1eb09023b26a47792ecdc54']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1222be28-c700-4139-a83f-828e691602ee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 8d435918d304fc38d54b104a13f2e33e8e598c82",
      "pattern": "[file:hashes.'SHA-1' = '8d435918d304fc38d54b104a13f2e33e8e598c82']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c93cfa6-a981-4d23-bd35-d793e11fd6c4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 8e7eb0f5ac60dd3b4a9474d2544348c3bda48045",
      "pattern": "[file:hashes.'SHA-1' = '8e7eb0f5ac60dd3b4a9474d2544348c3bda48045']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bd33e230-fa58-47c6-b40f-24a031f8f46e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 98de8147394b74b27158e02ce9e7b0e25eb6e98a",
      "pattern": "[file:hashes.'SHA-1' = '98de8147394b74b27158e02ce9e7b0e25eb6e98a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5579099c-883a-462e-a6e3-3fb0d606d4f4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 9a09ad7b7e9ff7a465aa1150541e231189911afb",
      "pattern": "[file:hashes.'SHA-1' = '9a09ad7b7e9ff7a465aa1150541e231189911afb']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--38b26b80-ee2f-4212-a435-d14eb3652949",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 9ccd769624de98eeeb12714ff1707ec4f5bf196d",
      "pattern": "[file:hashes.'SHA-1' = '9ccd769624de98eeeb12714ff1707ec4f5bf196d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--39e8f82d-ddcd-40cb-a59d-4d83233d07fd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 9dbfc23ebf36b3c0b56d2f93116abb32656c42e4",
      "pattern": "[file:hashes.'SHA-1' = '9dbfc23ebf36b3c0b56d2f93116abb32656c42e4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e6017d10-4e61-4732-95f8-2a8afa4b827f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: a3e90653bd0a81ebe2ae387a67a59bb8d07ce7b5",
      "pattern": "[file:hashes.'SHA-1' = 'a3e90653bd0a81ebe2ae387a67a59bb8d07ce7b5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d8066dc-07f1-4270-a9d7-224f85babffe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: aea55e42c4436236278e5692d3dcbcbe5fe6ce0b",
      "pattern": "[file:hashes.'SHA-1' = 'aea55e42c4436236278e5692d3dcbcbe5fe6ce0b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--20940d88-1752-4a1f-ad79-0b190969bbda",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: bd8fbb5e6842df8683163adbd6a36136164eac58",
      "pattern": "[file:hashes.'SHA-1' = 'bd8fbb5e6842df8683163adbd6a36136164eac58']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0fc9f49d-5627-4671-8938-da753bcb7de4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7c12d8614c624c70d6dd6fc2ee289332474abaa38f70ebe2cdef064923ca3a9b",
      "pattern": "[file:hashes.'SHA-256' = '7c12d8614c624c70d6dd6fc2ee289332474abaa38f70ebe2cdef064923ca3a9b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-45321 \u2014 TanStack Unspecified Vulnerabilit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "Why developer machines are now the number one target for sup",
          "url": "https://www.aikido.dev/blog/developer-machines-supply-chain-attacks"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6851035f-362a-4a2f-b788-41ea4c059263",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: anyclaw.store",
      "pattern": "[domain-name:value = 'anyclaw.store']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Legitimate-Looking Codex Remote UI Secretly Steals Your AI T",
          "url": "https://www.aikido.dev/blog/codex-remote-ui-steals-ai-tokens"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cf6bae6a-2b4a-421b-9dea-cd97ff7062e5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: gyx.com",
      "pattern": "[domain-name:value = 'gyx.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Legitimate-Looking Codex Remote UI Secretly Steals Your AI T",
          "url": "https://www.aikido.dev/blog/codex-remote-ui-steals-ai-tokens"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4233a023-8d2a-4261-8d53-0f4ec19f0d55",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sentry.anyclaw.store",
      "pattern": "[domain-name:value = 'sentry.anyclaw.store']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Legitimate-Looking Codex Remote UI Secretly Steals Your AI T",
          "url": "https://www.aikido.dev/blog/codex-remote-ui-steals-ai-tokens"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--26cf3af7-75e7-407f-9045-1eb34ac99363",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-48172",
      "pattern": "[vulnerability:name = 'CVE-2026-48172']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-48172 \u2014 LiteSpeed cPanel Plugin Privilege",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4c192d77-9088-40c0-9289-c35b9d90092f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: arbsniper.com",
      "pattern": "[domain-name:value = 'arbsniper.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c17c2a2b-178a-496c-bc49-ef788f0dbdfb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.21.64.137",
      "pattern": "[ipv4-addr:value = '104.21.64.137']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--27666e7e-a5a2-4ab7-9a49-fbed2e18f898",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 142.251.183.138",
      "pattern": "[ipv4-addr:value = '142.251.183.138']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2825efdb-63c3-4532-b8ce-073a3769f96d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 173.194.193.138",
      "pattern": "[ipv4-addr:value = '173.194.193.138']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--814ff9a2-2e26-41bb-957c-011e843df54d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 173.194.194.94",
      "pattern": "[ipv4-addr:value = '173.194.194.94']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--455cef23-c929-403f-8125-052751cb0cda",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 173.194.206.106",
      "pattern": "[ipv4-addr:value = '173.194.206.106']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5413bf7-2133-48bb-87d0-519702c3ecda",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 178.156.177.192",
      "pattern": "[ipv4-addr:value = '178.156.177.192']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--91893d7a-d21c-458a-98d2-9f4827cc83d6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 191.101.131.250",
      "pattern": "[ipv4-addr:value = '191.101.131.250']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0e0da362-440d-4103-a1ee-a0af640e6f07",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 191.96.224.87",
      "pattern": "[ipv4-addr:value = '191.96.224.87']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--40aa74c5-d595-4fb7-b43e-c51f471d9243",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 191.96.225.241",
      "pattern": "[ipv4-addr:value = '191.96.225.241']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--88919446-80f2-45bf-9fd9-12bddec70fdb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 191.96.78.172",
      "pattern": "[ipv4-addr:value = '191.96.78.172']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6eb5fbeb-0f5b-49f5-b0f0-693e0bd171bd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 191.96.78.28",
      "pattern": "[ipv4-addr:value = '191.96.78.28']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c5d950c7-0fd3-47a1-a87c-4cc0421bb6ee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 191.96.79.133",
      "pattern": "[ipv4-addr:value = '191.96.79.133']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--13a9d5d9-beb1-4ff2-abbe-fdc94e4e90c4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 191.96.79.179",
      "pattern": "[ipv4-addr:value = '191.96.79.179']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--33bbedbb-e198-4ef5-ad5b-7947c1202853",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 191.96.79.41",
      "pattern": "[ipv4-addr:value = '191.96.79.41']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eac7ebc6-5a0b-4b9d-8ccb-48548172c0fc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.178.209.95",
      "pattern": "[ipv4-addr:value = '192.178.209.95']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb13e9da-c973-459c-b074-f3190350e84f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 195.160.221.203",
      "pattern": "[ipv4-addr:value = '195.160.221.203']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c4c542ef-6efd-4068-93eb-d4f246022578",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 200.9.155.153",
      "pattern": "[ipv4-addr:value = '200.9.155.153']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bf2bc76e-a3ab-44e0-aae3-aee04c5f3b02",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 74.125.132.95",
      "pattern": "[ipv4-addr:value = '74.125.132.95']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1672468b-5ade-4080-8629-8851693e752c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 74.125.202.103",
      "pattern": "[ipv4-addr:value = '74.125.202.103']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e0996bbd-2295-471b-8ddb-f528ecb3d577",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 78.135.93.123",
      "pattern": "[ipv4-addr:value = '78.135.93.123']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0a0ccfbd-9a3c-45d3-9d0b-f1310c6e783f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 79.133.57.141",
      "pattern": "[ipv4-addr:value = '79.133.57.141']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c40801c-59ea-4589-b1cd-496b75dca22f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 02A52C4CC11748D44C9B49D508EE4E46425661981FA1406F30EC0830CB69DDC5",
      "pattern": "[file:hashes.'SHA-256' = '02A52C4CC11748D44C9B49D508EE4E46425661981FA1406F30EC0830CB69DDC5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f333a261-c9e1-4be2-9da9-13911a58345f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 0A542751724A432A8448324613E0CE10393E41739A1800CBB7D5A2C648FCDC35",
      "pattern": "[file:hashes.'SHA-256' = '0A542751724A432A8448324613E0CE10393E41739A1800CBB7D5A2C648FCDC35']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f75c9d0b-2d20-4a60-be9a-4e2cc4a68fcd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 140A7F995B0336942691A2E93E2017FD575267C017C7D0728D69169306F91963",
      "pattern": "[file:hashes.'SHA-256' = '140A7F995B0336942691A2E93E2017FD575267C017C7D0728D69169306F91963']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1752f883-d54e-404a-adbf-7fe370369233",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 168F50BF9A87099094EF410E3AC33E676A6A8740A5437CD09E7B63D73DF8431A",
      "pattern": "[file:hashes.'SHA-256' = '168F50BF9A87099094EF410E3AC33E676A6A8740A5437CD09E7B63D73DF8431A']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b1104899-f026-4a26-b5ae-3392874a9687",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1A60CB5F7E2FB7C09FC3DC8459108B26AC98EE73131F37A28CFDAD5FC75B7A7D",
      "pattern": "[file:hashes.'SHA-256' = '1A60CB5F7E2FB7C09FC3DC8459108B26AC98EE73131F37A28CFDAD5FC75B7A7D']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dfc5c9b9-6345-4476-ae32-022e97c27931",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 244D81FD9908CD17815501D4EDADEB1BAF1C421AA25D8BD61C7CB481C939540E",
      "pattern": "[file:hashes.'SHA-256' = '244D81FD9908CD17815501D4EDADEB1BAF1C421AA25D8BD61C7CB481C939540E']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f598863-1d5b-4c9e-9caa-e95fd0ac4200",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2525D1E427A9983B0B4CA0906A4B44FFB9814B23D53FD8A2E3AB6512B027C733",
      "pattern": "[file:hashes.'SHA-256' = '2525D1E427A9983B0B4CA0906A4B44FFB9814B23D53FD8A2E3AB6512B027C733']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--36cfa385-27bb-4d74-9685-8697d367c86e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 26A2268281E8043125EF72B92F8980B42912048753D56894BC378FB54C7C188A",
      "pattern": "[file:hashes.'SHA-256' = '26A2268281E8043125EF72B92F8980B42912048753D56894BC378FB54C7C188A']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ad6696a4-546f-4b63-bc2c-74b69d84fc68",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 512EDE9F2FA794907999F3C26165557FDFD383B7AAD71BA022CE2C8BA6C0019D",
      "pattern": "[file:hashes.'SHA-256' = '512EDE9F2FA794907999F3C26165557FDFD383B7AAD71BA022CE2C8BA6C0019D']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ccfc36c-a190-4544-8aa3-3eb167078498",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 58AC130A8EBB09E37592AC69841483EDC5695D1545B1F04F23D5B760AC17CD94",
      "pattern": "[file:hashes.'SHA-256' = '58AC130A8EBB09E37592AC69841483EDC5695D1545B1F04F23D5B760AC17CD94']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3fafec2b-1a27-4620-9d2e-36c232b448d4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5AAAF972C8BF39A98F2748E526DE3CC0370BA831997D7D9765CDABA599645C0D",
      "pattern": "[file:hashes.'SHA-256' = '5AAAF972C8BF39A98F2748E526DE3CC0370BA831997D7D9765CDABA599645C0D']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--92d1f289-1b3b-4c6b-a0d7-86deff041f33",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6101D1E1811DB052F869F7EB3402DAD28DA7E92103D4A44EE43F95846A075012",
      "pattern": "[file:hashes.'SHA-256' = '6101D1E1811DB052F869F7EB3402DAD28DA7E92103D4A44EE43F95846A075012']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d9a36a7c-e1b3-483b-b56a-01a533a98661",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 676CB2D0A60403AFC06CEA1B572CB7261F706365FAC65621B5A4907893E7AC0D",
      "pattern": "[file:hashes.'SHA-256' = '676CB2D0A60403AFC06CEA1B572CB7261F706365FAC65621B5A4907893E7AC0D']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c74f99a-d626-4666-b2d6-442c45389e08",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6AE94CE710016D86ED7457236DEEF2C4C51478587F3609B6E827A348828B3931",
      "pattern": "[file:hashes.'SHA-256' = '6AE94CE710016D86ED7457236DEEF2C4C51478587F3609B6E827A348828B3931']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2c7a7f7e-3cdc-4254-83c8-c2acb75c7f46",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6BBA64FA9E8A7B11CB2476CD071DE08986DB44B0783EFF211C68FA5594EF8143",
      "pattern": "[file:hashes.'SHA-256' = '6BBA64FA9E8A7B11CB2476CD071DE08986DB44B0783EFF211C68FA5594EF8143']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--81793a3d-ef93-4c01-9399-edf7cc616020",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6F9832EBB4C3054BEE4A6CE5CCB69C00E2020053E1308353343097E6A4041109",
      "pattern": "[file:hashes.'SHA-256' = '6F9832EBB4C3054BEE4A6CE5CCB69C00E2020053E1308353343097E6A4041109']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5eb48ede-ab02-4dd1-9841-993c692ad3be",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 702261BA38B57ECC3A5407FED28B2F0611A74C2EC0C116AEA4F9E6DEF0899AED",
      "pattern": "[file:hashes.'SHA-256' = '702261BA38B57ECC3A5407FED28B2F0611A74C2EC0C116AEA4F9E6DEF0899AED']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cd568b1a-70e8-4caf-a806-59131b50efd3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 75DD4FB011ED598374A46FC0D9C0D1D64A298341C34AFC83A56A6983CFD27764",
      "pattern": "[file:hashes.'SHA-256' = '75DD4FB011ED598374A46FC0D9C0D1D64A298341C34AFC83A56A6983CFD27764']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0a7c231b-39fb-45bb-bae4-729ab7ea107c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7AC974899E8E05AAACD417577C97E382D5E8C5F7F4A85632CFFB47EC2F6AE4E0",
      "pattern": "[file:hashes.'SHA-256' = '7AC974899E8E05AAACD417577C97E382D5E8C5F7F4A85632CFFB47EC2F6AE4E0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c8dbe29-eb0b-4773-84ee-d3652f3847e9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8F09274E808E0063D51F34CAC82A5770B3DF30C792E426DA2F6A80657F27AFFC",
      "pattern": "[file:hashes.'SHA-256' = '8F09274E808E0063D51F34CAC82A5770B3DF30C792E426DA2F6A80657F27AFFC']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b8e3e13-980b-4624-a98f-e402bc85a162",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 97A0497DE585D3BE6EC75064AB3BD0979CD85561193C1F0669CCF4DB31330687",
      "pattern": "[file:hashes.'SHA-256' = '97A0497DE585D3BE6EC75064AB3BD0979CD85561193C1F0669CCF4DB31330687']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4c0c2e7-6b9a-4d86-9f70-47b4ff8fe19f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 998A7ED1572AD9DC11375BC25294E1954E606B7CFF9FABC5C120713E597CD274",
      "pattern": "[file:hashes.'SHA-256' = '998A7ED1572AD9DC11375BC25294E1954E606B7CFF9FABC5C120713E597CD274']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--51270e64-0a77-4a9a-9f50-e6b9866f4923",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: A1E457C52EAB430C20D48F2AC476E080386313F16EFB135A0471902CF68CE475",
      "pattern": "[file:hashes.'SHA-256' = 'A1E457C52EAB430C20D48F2AC476E080386313F16EFB135A0471902CF68CE475']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--93acd9fc-19c7-4e41-9f2b-82cf950a7a1c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: A764D73795ABE47AE640BA09999A18C47B5340E5ECC7B897AFEBF34F3F37638F",
      "pattern": "[file:hashes.'SHA-256' = 'A764D73795ABE47AE640BA09999A18C47B5340E5ECC7B897AFEBF34F3F37638F']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--62ac25a3-5716-4719-b534-4691adac3ed7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: C6199E175FB988CBBEACDF0F5ACDF9ED83F5BDAAE5C95B7A6C27EE72CD11B0B1",
      "pattern": "[file:hashes.'SHA-256' = 'C6199E175FB988CBBEACDF0F5ACDF9ED83F5BDAAE5C95B7A6C27EE72CD11B0B1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--99e55eea-ebf5-441d-8cbb-178770f20e69",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: C99139B0053C4C698EA0246D26D747F2A984C7ABA4613DA818ECD9F97899EF3A",
      "pattern": "[file:hashes.'SHA-256' = 'C99139B0053C4C698EA0246D26D747F2A984C7ABA4613DA818ECD9F97899EF3A']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a11cc9c4-ef80-4d26-b62b-8c49f5c9966f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: D55057CD9110D12A192281356F06B94F342B9FEBB305CF0A5898A7E6AF40758F",
      "pattern": "[file:hashes.'SHA-256' = 'D55057CD9110D12A192281356F06B94F342B9FEBB305CF0A5898A7E6AF40758F']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c012a4f-e35f-42d2-a50f-7cf994695e22",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: DDCE0219923D152B8FACD303F058A6286CF1F6924992B9FB9F5BF4D96436CC39",
      "pattern": "[file:hashes.'SHA-256' = 'DDCE0219923D152B8FACD303F058A6286CF1F6924992B9FB9F5BF4D96436CC39']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f7c5576a-edd9-4a59-bd95-4cc6eac283e0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: E5A9FDFF900DD502E8F3DCE52D2D1B69AA9AFAFB5094A28F9037E8770DB0E63B",
      "pattern": "[file:hashes.'SHA-256' = 'E5A9FDFF900DD502E8F3DCE52D2D1B69AA9AFAFB5094A28F9037E8770DB0E63B']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--03f2f39a-19e3-40ff-9df5-7859846b6165",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: F76B13040C634F82A8332FF9443D84C89A5BCED51AE9ADAD7FD15C05FADB4324",
      "pattern": "[file:hashes.'SHA-256' = 'F76B13040C634F82A8332FF9443D84C89A5BCED51AE9ADAD7FD15C05FADB4324']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "url": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6051a7da-62f0-40b6-bf91-9a9129df9ce3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-9082",
      "pattern": "[vulnerability:name = 'CVE-2026-9082']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-9082 \u2014 Drupal Core SQL Injection Vulnerab",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4ffff099-8632-49be-b121-d864ad30e316",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: actions-bot.com",
      "pattern": "[domain-name:value = 'actions-bot.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Megalodon: Mass GitHub Actions Secret Exfiltration Across 5,",
          "url": "https://www.stepsecurity.io/blog/megalodon-mass-github-actions-secret-exfiltration-across-5-500-public-repositories"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7396f3f4-9319-4d9e-a18a-4fd59c297424",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: github-ci.com",
      "pattern": "[domain-name:value = 'github-ci.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Megalodon: Mass GitHub Actions Secret Exfiltration Across 5,",
          "url": "https://www.stepsecurity.io/blog/megalodon-mass-github-actions-secret-exfiltration-across-5-500-public-repositories"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b98cf2ca-5e33-46e5-943e-be8387850597",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: fifa26.shop",
      "pattern": "[domain-name:value = 'fifa26.shop']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Foul play: Fake FIFA websites target soccer fans looking for",
          "url": "https://www.welivesecurity.com/en/cybersecurity/foul-play-fake-fifa-world-cup-websites-tickets/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0e471e4a-5847-4ee8-81cb-a63844fa6536",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: fifaworldcup26.hospitality.fifa.com",
      "pattern": "[domain-name:value = 'fifaworldcup26.hospitality.fifa.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Foul play: Fake FIFA websites target soccer fans looking for",
          "url": "https://www.welivesecurity.com/en/cybersecurity/foul-play-fake-fifa-world-cup-websites-tickets/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5ecf3ae4-b2f9-4977-b107-af7d3c2ecac7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-34291",
      "pattern": "[vulnerability:name = 'CVE-2025-34291']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-34291 \u2014 Langflow Origin Validation Error ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--515ba090-b64c-41de-aefc-8faf7944c8e6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-34926",
      "pattern": "[vulnerability:name = 'CVE-2026-34926']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-34926 \u2014 Trend Micro Apex One (On-Premise)",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b6f537d-40f5-4ad5-a82c-1997171fc27c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 1c9e803c80cc7fed000022d4c94f4b5bc2e90062",
      "pattern": "[file:hashes.'SHA-1' = '1c9e803c80cc7fed000022d4c94f4b5bc2e90062']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer I",
          "url": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d53c1366-96f4-46bd-8d4b-76ef86a93719",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 5c267592a87e92c2b005b338bd0d2724c2f64acb",
      "pattern": "[file:hashes.'SHA-1' = '5c267592a87e92c2b005b338bd0d2724c2f64acb']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer I",
          "url": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f94c9aa-89e8-48a6-80c1-4b5dbb7fcfca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 7f6120bb10c870b9fde146961a18e5bf0b3d4401",
      "pattern": "[file:hashes.'SHA-1' = '7f6120bb10c870b9fde146961a18e5bf0b3d4401']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer I",
          "url": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ace004c-cd7f-44b3-a9b3-ac3c399bca5d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 99b7f41bf9e14a2a2c7cc524731336543f552178",
      "pattern": "[file:hashes.'SHA-1' = '99b7f41bf9e14a2a2c7cc524731336543f552178']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer I",
          "url": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8e8334d-e14a-4fa8-bef4-e1e1994ec5df",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: b9c83f01929e190cda300e76f688bf7ea7e37a7a",
      "pattern": "[file:hashes.'SHA-1' = 'b9c83f01929e190cda300e76f688bf7ea7e37a7a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer I",
          "url": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7152e80a-a4c7-4468-ad5b-c1d5c816bdf2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: f0448c62fc57b8a5ce23d8acd6e795cdd76a3b6c",
      "pattern": "[file:hashes.'SHA-1' = 'f0448c62fc57b8a5ce23d8acd6e795cdd76a3b6c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer I",
          "url": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--94632889-ffcf-4021-b016-56846d71b9ae",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 43f2b001846c4966073ebffa5be8f15e491a1e7d32bbd805d57406ff540e0dd9",
      "pattern": "[file:hashes.'SHA-256' = '43f2b001846c4966073ebffa5be8f15e491a1e7d32bbd805d57406ff540e0dd9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer I",
          "url": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough"
        },
        {
          "source_name": "The Wild West of VS Code extensions and how a poisoned exten",
          "url": "https://www.aikido.dev/blog/vs-code-extension-github-breach"
        },
        {
          "source_name": "GitHub breached via a malicious VS Code extension: why devel",
          "url": "https://www.aikido.dev/blog/github-breached-vs-code-extension"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--81db9962-e635-4b30-bb0a-b593521abc90",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 877ff2531a63393c4cb9c3c86908b62d9c4fc3db971bc231c48537faae6cb3ec",
      "pattern": "[file:hashes.'SHA-256' = '877ff2531a63393c4cb9c3c86908b62d9c4fc3db971bc231c48537faae6cb3ec']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer I",
          "url": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough"
        },
        {
          "source_name": "The AntV Supply Chain Campaign Expands: Microsoft's `durable",
          "url": "https://snyk.io/blog/durabletask-pypi-supply-chain-attack/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4c5f149d-b9f5-4bcb-bbc3-36c71aa5401a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: cb86f4f223daa54467c7782a0d8607e9c84e2bb633e6f0e51d9a19579e200990",
      "pattern": "[file:hashes.'SHA-256' = 'cb86f4f223daa54467c7782a0d8607e9c84e2bb633e6f0e51d9a19579e200990']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer I",
          "url": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--91f33485-7f43-47de-9d08-b0816fc40e6f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2008-4250",
      "pattern": "[vulnerability:name = 'CVE-2008-4250']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2008-4250 \u2014 Microsoft Windows Buffer Overflow ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ec48ad16-5367-4d1b-8780-eea7a79fae34",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2009-1537",
      "pattern": "[vulnerability:name = 'CVE-2009-1537']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2009-1537 \u2014 Microsoft DirectX NULL Byte Overwr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--64386b97-e085-43a5-8ac5-fc9ce55226bb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2009-3459",
      "pattern": "[vulnerability:name = 'CVE-2009-3459']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2009-3459 \u2014 Adobe Acrobat and Reader Heap-Base",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a5f052e6-d33f-4336-9808-cc254056ba01",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-0249",
      "pattern": "[vulnerability:name = 'CVE-2010-0249']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2010-0806 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--583c74f3-5f45-4fba-95da-6e22aab6e38b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-0806",
      "pattern": "[vulnerability:name = 'CVE-2010-0806']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0806 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7ac4a05d-f11d-4ca4-b37b-6742aba7bf74",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-7692",
      "pattern": "[vulnerability:name = 'CVE-2017-7692']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Webworm: New burrowing techniques",
          "url": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--90ee7ca2-e84f-47ed-beab-cada68ce6db1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-41091",
      "pattern": "[vulnerability:name = 'CVE-2026-41091']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-41091 \u2014 Microsoft Defender Link Following",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4148c368-22de-4e4c-a7a2-1eeb5264b1e0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-45498",
      "pattern": "[vulnerability:name = 'CVE-2026-45498']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-45498 \u2014 Microsoft Defender Denial of Serv",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--00d5595e-ada3-4ff3-854f-921d683c7a35",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: 360.homeunix.com",
      "pattern": "[domain-name:value = '360.homeunix.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--534dec20-3b4c-481a-95c5-97799050864a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: blog1.servebeer.com",
      "pattern": "[domain-name:value = 'blog1.servebeer.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3c1fa3d0-f50e-470a-8af2-7256aa64d9ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: filoups.info",
      "pattern": "[domain-name:value = 'filoups.info']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9fd2f4d4-d026-4f04-8ea2-095e005e2973",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ftp2.homeunix.com",
      "pattern": "[domain-name:value = 'ftp2.homeunix.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e15352f4-c1d3-4c77-b753-81dd8f242173",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: github.com/anjsdgasdf/WordPress",
      "pattern": "[domain-name:value = 'github.com/anjsdgasdf/WordPress']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Webworm: New burrowing techniques",
          "url": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cd45d00f-d050-4410-a0a6-4f90ce035bbd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: google.homeunix.com",
      "pattern": "[domain-name:value = 'google.homeunix.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0456f463-f092-4a9b-9920-c7f69d153d26",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sl1.homelinux.org",
      "pattern": "[domain-name:value = 'sl1.homelinux.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--826903d4-29db-47a7-8420-26d8e21a9fe1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: update.ourhobby.com",
      "pattern": "[domain-name:value = 'update.ourhobby.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a4b29955-7916-46db-948e-1005c045791e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: voanews.ath.cx",
      "pattern": "[domain-name:value = 'voanews.ath.cx']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--39332b93-78e3-4b55-aa2f-4a67e4869d07",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: yahoo.blogdns.net",
      "pattern": "[domain-name:value = 'yahoo.blogdns.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f3538ab2-84f1-4dad-9124-2443b83c5ec6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ymail.ath.cx",
      "pattern": "[domain-name:value = 'ymail.ath.cx']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--04874215-ad5f-4a10-86bf-ad20eb1315ab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.243.23.43",
      "pattern": "[ipv4-addr:value = '104.243.23.43']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Webworm: New burrowing techniques",
          "url": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2d0babf9-d09f-4574-86b7-e8b7be0412e8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 108.61.200.151",
      "pattern": "[ipv4-addr:value = '108.61.200.151']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Webworm: New burrowing techniques",
          "url": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b069b8a-8781-4ba3-8736-617ef480df4b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 144.168.60.233",
      "pattern": "[ipv4-addr:value = '144.168.60.233']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Webworm: New burrowing techniques",
          "url": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7e2f1960-90b0-4f13-97c1-a31707e5c33e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.77.13.67",
      "pattern": "[ipv4-addr:value = '45.77.13.67']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Webworm: New burrowing techniques",
          "url": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--be9ca398-ea91-41ee-ab5d-5337baea1db8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 64.176.85.158",
      "pattern": "[ipv4-addr:value = '64.176.85.158']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Webworm: New burrowing techniques",
          "url": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f810d8d-0854-45b5-812c-cc5325c0700a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 0f9c5408335833e72fe73e6166b5a01b",
      "pattern": "[file:hashes.MD5 = '0f9c5408335833e72fe73e6166b5a01b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0ba50097-4576-4e1a-bc17-b9036597f5e4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 3a33013a47c5dd8d1b92a4cfdcda3765",
      "pattern": "[file:hashes.MD5 = '3a33013a47c5dd8d1b92a4cfdcda3765']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe2fd2f0-3cbf-4a74-ba22-2933bd7b70e3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 467eef090deb3517f05a48310fcfd4ee",
      "pattern": "[file:hashes.MD5 = '467eef090deb3517f05a48310fcfd4ee']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d7bbfb05-f147-4734-95a2-2c1bbfea2bd3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 4a47404fc21fff4a1bc492f9cd23139c",
      "pattern": "[file:hashes.MD5 = '4a47404fc21fff4a1bc492f9cd23139c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--74fac281-d7e8-4f84-bd85-18e0a8270a7d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 6a89fbe7b0d526e3d97b0da8418bf851",
      "pattern": "[file:hashes.MD5 = '6a89fbe7b0d526e3d97b0da8418bf851']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--40cadf91-6d25-40f7-bf49-14246ad5dcdd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 7a62295f70642fedf0d5a5637feb7986",
      "pattern": "[file:hashes.MD5 = '7a62295f70642fedf0d5a5637feb7986']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--914aa71d-7ebe-43b3-bbc9-af9770b1a354",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 9f880ac607cbd7cdfffa609c5883c708",
      "pattern": "[file:hashes.MD5 = '9f880ac607cbd7cdfffa609c5883c708']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dcc85308-67ab-4ba9-bd45-6b0403ae216d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: cd36a3071a315c3be6ac3366d80bb59c",
      "pattern": "[file:hashes.MD5 = 'cd36a3071a315c3be6ac3366d80bb59c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2670f8b8-fdc6-4f7d-a395-f077d27f41a2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e3798c71d25816611a4cab031ae3c27a",
      "pattern": "[file:hashes.MD5 = 'e3798c71d25816611a4cab031ae3c27a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e9928fa4-4a00-4acb-b9ef-53d6aaf4bd68",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 1DF40A4A31B30B62EC33DC6FECC2C4408302ADC7",
      "pattern": "[file:hashes.'SHA-1' = '1DF40A4A31B30B62EC33DC6FECC2C4408302ADC7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Webworm: New burrowing techniques",
          "url": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--84adcb67-7386-427d-9320-80e94a518679",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 77F1970D620216C5FFF4E14A6CCC13FCCC267217",
      "pattern": "[file:hashes.'SHA-1' = '77F1970D620216C5FFF4E14A6CCC13FCCC267217']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Webworm: New burrowing techniques",
          "url": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c9045948-98fd-47b5-81dc-877982a6aa56",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 7DCFE9EE25841DFD58D3D6871BF867FE32141DFB",
      "pattern": "[file:hashes.'SHA-1' = '7DCFE9EE25841DFD58D3D6871BF867FE32141DFB']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Webworm: New burrowing techniques",
          "url": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--727678b2-8f08-4c17-8b30-d4a5e7927c0e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 948159A7FC2E688386864BEA59FD40DFFC4B24D6",
      "pattern": "[file:hashes.'SHA-1' = '948159A7FC2E688386864BEA59FD40DFFC4B24D6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Webworm: New burrowing techniques",
          "url": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4a639139-9144-4232-afd6-e1e10c2741e2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 9d88f040c44b5f4d5f9db15ff89310776c168e99",
      "pattern": "[file:hashes.'SHA-1' = '9d88f040c44b5f4d5f9db15ff89310776c168e99']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Wild West of VS Code extensions and how a poisoned exten",
          "url": "https://www.aikido.dev/blog/vs-code-extension-github-breach"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d749a001-e77d-49a6-8418-322d36e5b23d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: A3C077BDF8898E612CCD65BC82E7960834ADB2A9",
      "pattern": "[file:hashes.'SHA-1' = 'A3C077BDF8898E612CCD65BC82E7960834ADB2A9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Webworm: New burrowing techniques",
          "url": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--baef3505-dd98-4907-bd72-e655ca0e920c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: acfc3f957a63b4cde93ff645f2b6bf26a8ed1bbf",
      "pattern": "[file:hashes.'SHA-1' = 'acfc3f957a63b4cde93ff645f2b6bf26a8ed1bbf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The Wild West of VS Code extensions and how a poisoned exten",
          "url": "https://www.aikido.dev/blog/vs-code-extension-github-breach"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b1938d4a-51b4-4930-9c49-965b9ae1a056",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: CB4E50433336707381429707F59C3CBE8D497D98",
      "pattern": "[file:hashes.'SHA-1' = 'CB4E50433336707381429707F59C3CBE8D497D98']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Webworm: New burrowing techniques",
          "url": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aefbde8e-027b-48d2-92e0-eb2dd6a43069",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sh.azurestaticprovider.net",
      "pattern": "[domain-name:value = 'sh.azurestaticprovider.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Active Supply Chain Attack: Malicious node-ipc Versions Publ",
          "url": "https://www.stepsecurity.io/blog/node-ipc-npm-supply-chain-attack"
        },
        {
          "source_name": "Malicious node-ipc versions published to npm in suspected ma",
          "url": "https://snyk.io/blog/malicious-node-ipc-versions-published-npm/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dcb8c8d7-81b9-40a9-9757-a3691157bf96",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a68dd1e6a6e35ec3771e1f94fe796f55dfe65a2b94560516ff4ac189390dfa1c",
      "pattern": "[file:hashes.'SHA-256' = 'a68dd1e6a6e35ec3771e1f94fe796f55dfe65a2b94560516ff4ac189390dfa1c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mini Shai-Hulud strikes again: npm worm compromises hundreds",
          "url": "https://www.aikido.dev/blog/mini-shai-hulud-antv-npm-supply-chain-attack"
        },
        {
          "source_name": "Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Publi",
          "url": "https://snyk.io/blog/mini-shai-hulud-antv-npm-supply-chain-attack/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ec73d311-fb33-42fc-9322-13a4f35ee865",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: bf9d8c0c3ed3ceaa831a13de27f1b1c7c7b7f01d2db4103bfdba4191940b0301",
      "pattern": "[file:hashes.'SHA-256' = 'bf9d8c0c3ed3ceaa831a13de27f1b1c7c7b7f01d2db4103bfdba4191940b0301']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Active Supply Chain Attack: Malicious node-ipc Versions Publ",
          "url": "https://www.stepsecurity.io/blog/node-ipc-npm-supply-chain-attack"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a20eb94c-9025-4b47-8d23-0439998910b9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: fb5c97557230a27460fdab01fafcfabeaa49590bafd5b6ef30501aa9e0a51142",
      "pattern": "[file:hashes.'SHA-256' = 'fb5c97557230a27460fdab01fafcfabeaa49590bafd5b6ef30501aa9e0a51142']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mini Shai-Hulud strikes again: npm worm compromises hundreds",
          "url": "https://www.aikido.dev/blog/mini-shai-hulud-antv-npm-supply-chain-attack"
        },
        {
          "source_name": "Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Publi",
          "url": "https://snyk.io/blog/mini-shai-hulud-antv-npm-supply-chain-attack/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53f13b96-9dbf-487d-8081-f62f34465e84",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: git-service.com",
      "pattern": "[domain-name:value = 'git-service.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Microsoft's durabletask package on PyPi Compromised. Mini Sh",
          "url": "https://www.aikido.dev/blog/durabletask-package-compromised-mini-shai-hulud"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b3669923-580d-48a8-baeb-e52a4bfb5be4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: m-kosche.com",
      "pattern": "[domain-name:value = 'm-kosche.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Publi",
          "url": "https://snyk.io/blog/mini-shai-hulud-antv-npm-supply-chain-attack/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2127dafc-0692-4b58-a5d3-05cff550e60d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: b06b126b9e26af03a7ef2f8b8e90d446",
      "pattern": "[file:hashes.MD5 = 'b06b126b9e26af03a7ef2f8b8e90d446']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Publi",
          "url": "https://snyk.io/blog/mini-shai-hulud-antv-npm-supply-chain-attack/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a0e77dd3-c70b-492e-908a-0a902ba72e7b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 783b4019fc5b942a29846132d28441c8fc31bed8",
      "pattern": "[file:hashes.'SHA-1' = '783b4019fc5b942a29846132d28441c8fc31bed8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Publi",
          "url": "https://snyk.io/blog/mini-shai-hulud-antv-npm-supply-chain-attack/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c434c00-6b17-4584-a545-335a44bc331a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-42897",
      "pattern": "[vulnerability:name = 'CVE-2026-42897']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-42897 \u2014 Microsoft Exchange Server Cross-S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--78d34393-2c84-4bd3-983d-dd026444ef0c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: azurestaticprovider.net",
      "pattern": "[domain-name:value = 'azurestaticprovider.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Malicious node-ipc versions published to npm in suspected ma",
          "url": "https://snyk.io/blog/malicious-node-ipc-versions-published-npm/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de252afe-72c8-46c1-b005-d5f44a117dbf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 37.16.75.69",
      "pattern": "[ipv4-addr:value = '37.16.75.69']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Malicious node-ipc versions published to npm in suspected ma",
          "url": "https://snyk.io/blog/malicious-node-ipc-versions-published-npm/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--35989cfd-48ba-48fe-adad-530e9f5a90c8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-38831",
      "pattern": "[vulnerability:name = 'CVE-2023-38831']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FrostyNeighbor: Fresh mischief and digital shenanigans",
          "url": "https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/"
        },
        {
          "source_name": "CISA KEV: CVE-2024-29988 \u2014 Microsoft SmartScreen Prompt Secu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-38831 \u2014 RARLAB WinRAR Code Execution Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d3a745b5-a388-4ccb-907a-cdfa14297718",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-42009",
      "pattern": "[vulnerability:name = 'CVE-2024-42009']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FrostyNeighbor: Fresh mischief and digital shenanigans",
          "url": "https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/"
        },
        {
          "source_name": "CISA KEV: CVE-2024-42009 \u2014 RoundCube Webmail Cross-Site Scri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--35e635f6-95f7-4f0c-8c4c-5056209a121c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: book-happy.needbinding.icu",
      "pattern": "[domain-name:value = 'book-happy.needbinding.icu']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FrostyNeighbor: Fresh mischief and digital shenanigans",
          "url": "https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2eb4c620-5472-4843-9880-76d516e7b75e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: nama-belakang.nebao.icu",
      "pattern": "[domain-name:value = 'nama-belakang.nebao.icu']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FrostyNeighbor: Fresh mischief and digital shenanigans",
          "url": "https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1ad5b7f4-0d5e-4e87-969a-547ec06a8e4b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: nebao.icu",
      "pattern": "[domain-name:value = 'nebao.icu']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FrostyNeighbor: Fresh mischief and digital shenanigans",
          "url": "https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5aec7493-22c8-422c-b3e9-7f20c1364e46",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: needbinding.icu",
      "pattern": "[domain-name:value = 'needbinding.icu']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FrostyNeighbor: Fresh mischief and digital shenanigans",
          "url": "https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1bdd8714-8688-4d35-8a36-b3a4ee1b80ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 43E30BE82D82B24A6496F6943ECB6877E83F88AB",
      "pattern": "[file:hashes.'SHA-1' = '43E30BE82D82B24A6496F6943ECB6877E83F88AB']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FrostyNeighbor: Fresh mischief and digital shenanigans",
          "url": "https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9dfb8dd1-78fc-44c5-9509-e6e7a836f38a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 776A43E46C36A539C916ED426745EE96E2392B39",
      "pattern": "[file:hashes.'SHA-1' = '776A43E46C36A539C916ED426745EE96E2392B39']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FrostyNeighbor: Fresh mischief and digital shenanigans",
          "url": "https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4a4c2a19-7da5-42f9-9ea4-a1ba3e6f3211",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 8D1F2A6DF51C7783F2EAF1A0FC0FF8D032E5B57F",
      "pattern": "[file:hashes.'SHA-1' = '8D1F2A6DF51C7783F2EAF1A0FC0FF8D032E5B57F']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FrostyNeighbor: Fresh mischief and digital shenanigans",
          "url": "https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--12081539-db20-4209-a6ad-6c5f4dde7b02",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: B65551D339AECE718EA1465BF3542C794C445EFC",
      "pattern": "[file:hashes.'SHA-1' = 'B65551D339AECE718EA1465BF3542C794C445EFC']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "FrostyNeighbor: Fresh mischief and digital shenanigans",
          "url": "https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3500a8ca-87ad-44f8-b65b-455fa57eb06a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 833fd59ebe66a4449982c6d18db656b4",
      "pattern": "[file:hashes.MD5 = '833fd59ebe66a4449982c6d18db656b4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, in",
          "url": "https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2443749e-019f-4c74-83bf-0ec2f8e470c5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: b82e54923f7e440664d2d75bd31588ca",
      "pattern": "[file:hashes.MD5 = 'b82e54923f7e440664d2d75bd31588ca']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, in",
          "url": "https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f724a530-7a2a-4f14-9422-d4ec8fa81600",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 12ed9a3c1f73617aefdb740480695c04405d7b4b",
      "pattern": "[file:hashes.'SHA-1' = '12ed9a3c1f73617aefdb740480695c04405d7b4b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, in",
          "url": "https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8638d21a-b30e-49eb-9390-4a634d57d6e7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-42208",
      "pattern": "[vulnerability:name = 'CVE-2026-42208']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-42208 \u2014 BerriAI LiteLLM SQL Injection Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--722acc5b-860e-44cb-bc2e-6d47c0fc79f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-29927",
      "pattern": "[vulnerability:name = 'CVE-2025-29927']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials a",
          "url": "https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/"
        },
        {
          "source_name": "CVE-2025-29927 Authorization Bypass in Next.js Middleware",
          "url": "https://snyk.io/blog/cve-2025-29927-authorization-bypass-in-next-js-middleware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "SentinelLabs",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b39d301-8eaa-4958-b171-35b47e43d42d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-48703",
      "pattern": "[vulnerability:name = 'CVE-2025-48703']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials a",
          "url": "https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/"
        },
        {
          "source_name": "CISA KEV: CVE-2025-48703 \u2014 CWP Control Web Panel OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "SentinelLabs",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0cb5a0aa-748b-447d-b673-b4cdc9e75330",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-55182",
      "pattern": "[vulnerability:name = 'CVE-2025-55182']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials a",
          "url": "https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/"
        },
        {
          "source_name": "CISA KEV: CVE-2025-55182 \u2014 Meta React Server Components Remo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "SentinelLabs",
        "CISA KEV",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ae86746d-2764-459e-adae-38c1d9dbb313",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-9501",
      "pattern": "[vulnerability:name = 'CVE-2025-9501']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials a",
          "url": "https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--91e08683-283a-4b21-853d-69887617611b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-1357",
      "pattern": "[vulnerability:name = 'CVE-2026-1357']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials a",
          "url": "https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "SentinelLabs"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d842fc6-5b83-4b66-91e7-3a2caf689a06",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-6973",
      "pattern": "[vulnerability:name = 'CVE-2026-6973']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-6973 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a5174705-15f6-42d8-b8c4-a935bf2b25de",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 799BB5127CA54239D3D4A14367DB3B712012CF14",
      "pattern": "[file:hashes.'SHA-1' = '799BB5127CA54239D3D4A14367DB3B712012CF14']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Fake call logs, real payments: How CallPhantom tricks Androi",
          "url": "https://www.welivesecurity.com/en/eset-research/fake-call-logs-real-payments-how-callphantom-tricks-android-users/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--66034663-d44b-4ef6-93c5-b2cb0cd62254",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-0300",
      "pattern": "[vulnerability:name = 'CVE-2026-0300']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-0300 \u2014 Palo Alto Networks PAN-OS Out-of-b",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0c5cbccd-a607-4722-b3b1-68fa7bc6bb3a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sqgame.com.cn",
      "pattern": "[domain-name:value = 'sqgame.com.cn']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "A rigged game: ScarCruft compromises gaming platform in a su",
          "url": "https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1aec90a4-3f4b-4e64-9f4b-3f47686a4bad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sqgame.net",
      "pattern": "[domain-name:value = 'sqgame.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "A rigged game: ScarCruft compromises gaming platform in a su",
          "url": "https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c1a52042-0de1-487d-bd0d-b0724e63b3f9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: xiazai.sqgame.com.cn",
      "pattern": "[domain-name:value = 'xiazai.sqgame.com.cn']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "A rigged game: ScarCruft compromises gaming platform in a su",
          "url": "https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b1f90fd-757e-4d75-97b9-6ae37510886d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 03E3ECE9F48CF4104AAFC535790CA2FB3C6B26CF",
      "pattern": "[file:hashes.'SHA-1' = '03E3ECE9F48CF4104AAFC535790CA2FB3C6B26CF']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "A rigged game: ScarCruft compromises gaming platform in a su",
          "url": "https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3f8c0c1e-ee8e-44e1-aed7-53e47a26bd80",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: FC0C691DB7E2D2BD3B0B4C1E24D18DF72168B7D9",
      "pattern": "[file:hashes.'SHA-1' = 'FC0C691DB7E2D2BD3B0B4C1E24D18DF72168B7D9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "A rigged game: ScarCruft compromises gaming platform in a su",
          "url": "https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8111f9d5-b6e3-426c-b8cb-61005b0e2b95",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cjn37-uyaaa-aaaac-qgnva-cai.raw.icp0.io",
      "pattern": "[domain-name:value = 'cjn37-uyaaa-aaaac-qgnva-cai.raw.icp0.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CanisterSprawl: pgserve Compromised on npm: Malicious Versio",
          "url": "https://www.stepsecurity.io/blog/pgserve-compromised-on-npm-malicious-versions-harvest-credentials"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d0c914ae-5977-4035-b1e0-8625e22143f0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: telemetry.api-monitor.com",
      "pattern": "[domain-name:value = 'telemetry.api-monitor.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CanisterSprawl: pgserve Compromised on npm: Malicious Versio",
          "url": "https://www.stepsecurity.io/blog/pgserve-compromised-on-npm-malicious-versions-harvest-credentials"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--94cbdb4a-aa5a-4d76-b8a2-eee8cbe3da03",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4066781fa830224c8bbcc3aa005a396657f9c8f9016f9a64ad44a9d7f5f45e34",
      "pattern": "[file:hashes.'SHA-256' = '4066781fa830224c8bbcc3aa005a396657f9c8f9016f9a64ad44a9d7f5f45e34']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4",
          "url": "https://www.stepsecurity.io/blog/shai-hulud-worm-pivots-to-multi-cloud-intercom-client-hijacked"
        },
        {
          "source_name": "Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Se",
          "url": "https://www.aikido.dev/blog/mini-shai-hulud-has-appeared"
        },
        {
          "source_name": "\"A Mini Shai-Hulud Has Appeared\": Bun-Based Stealer Hits SAP",
          "url": "https://snyk.io/blog/bun-based-stealer-hits-sap-cap-js-mbt-npm-packages/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c14282f-2046-498f-9f83-a3d3f04fe712",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 80a3d2877813968ef847ae73b5eeeb70b9435254e74d7f07d8cf4057f0a710ac",
      "pattern": "[file:hashes.'SHA-256' = '80a3d2877813968ef847ae73b5eeeb70b9435254e74d7f07d8cf4057f0a710ac']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4",
          "url": "https://www.stepsecurity.io/blog/shai-hulud-worm-pivots-to-multi-cloud-intercom-client-hijacked"
        },
        {
          "source_name": "Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Se",
          "url": "https://www.aikido.dev/blog/mini-shai-hulud-has-appeared"
        },
        {
          "source_name": "\"A Mini Shai-Hulud Has Appeared\": Bun-Based Stealer Hits SAP",
          "url": "https://snyk.io/blog/bun-based-stealer-hits-sap-cap-js-mbt-npm-packages/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--95db94bc-d2c2-42ee-9975-8bd09d5b5e04",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: igotnofriendsonlineorirl-imgonnakmslmao.skyhanni.cloud",
      "pattern": "[domain-name:value = 'igotnofriendsonlineorirl-imgonnakmslmao.skyhanni.cloud']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "elementary-data Compromised on PyPI and GHCR: Forged Release",
          "url": "https://www.stepsecurity.io/blog/elementary-data-compromised-on-pypi-and-ghcr-forged-release-pushed-via-github-actions-script-injection"
        },
        {
          "source_name": "Malicious Release of elementary-data PyPI Package Steals Clo",
          "url": "https://snyk.io/blog/malicious-release-of-elementary-data-pypi-package-steals-cloud-credentials-from-data-engineers/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cd8d6e9a-9205-464a-bba5-259da92e9e44",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-31431",
      "pattern": "[vulnerability:name = 'CVE-2026-31431']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-31431 \u2014 Linux Kernel Incorrect Resource T",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eefcc89f-de61-40b0-870f-4aeaa0228ae4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-41940",
      "pattern": "[vulnerability:name = 'CVE-2026-41940']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-41940 \u2014 WebPros cPanel & WHM and WP2 (Wor",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3e0784fc-9409-48db-8273-56b8fbbf8890",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: 22evxpggnkyrxpluewqsrv5j4jtde6hut2peq3w44d6ase676qlkoead.onion",
      "pattern": "[domain-name:value = '22evxpggnkyrxpluewqsrv5j4jtde6hut2peq3w44d6ase676qlkoead.onion']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "lightning PyPI Compromise: A Bun-Based Credential Stealer in",
          "url": "https://snyk.io/blog/lightning-pypi-compromise-bun-based-credential-stealer/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--946862cc-51d7-4266-9b82-b5ba9c684908",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 40d0f21b64ec8fb3a7a1959897252e09",
      "pattern": "[file:hashes.MD5 = '40d0f21b64ec8fb3a7a1959897252e09']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "lightning PyPI Compromise: A Bun-Based Credential Stealer in",
          "url": "https://snyk.io/blog/lightning-pypi-compromise-bun-based-credential-stealer/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ffee6c0f-90e0-47fd-a2d7-67fec0b6c994",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: f1b3e7b3eec3294c4d6b5f87854a52471f03997f",
      "pattern": "[file:hashes.'SHA-1' = 'f1b3e7b3eec3294c4d6b5f87854a52471f03997f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "lightning PyPI Compromise: A Bun-Based Credential Stealer in",
          "url": "https://snyk.io/blog/lightning-pypi-compromise-bun-based-credential-stealer/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--768e10dd-2da4-4dad-8de7-88cd95349bb6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 56070a9d8de0c0ffb1ec5c309953cf4679432df5a78df9aeb020fbb73d2be9fb",
      "pattern": "[file:hashes.'SHA-256' = '56070a9d8de0c0ffb1ec5c309953cf4679432df5a78df9aeb020fbb73d2be9fb']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "lightning PyPI Compromise: A Bun-Based Credential Stealer in",
          "url": "https://snyk.io/blog/lightning-pypi-compromise-bun-based-credential-stealer/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--192b299d-9ac6-4db3-9633-eb6eb52af8ff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5f5852b5f604369945118937b058e49064612ac69826e0adadca39a357dfb5b1",
      "pattern": "[file:hashes.'SHA-256' = '5f5852b5f604369945118937b058e49064612ac69826e0adadca39a357dfb5b1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Popular PyTorch Lightning Package Compromised by Mini Shai-H",
          "url": "https://www.aikido.dev/blog/pytorch-lightning-pypi-compromise-mini-shai-hulud"
        },
        {
          "source_name": "lightning PyPI Compromise: A Bun-Based Credential Stealer in",
          "url": "https://snyk.io/blog/lightning-pypi-compromise-bun-based-credential-stealer/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2191b97d-92bf-4b36-a2f5-d1ce57dad8e0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8046a11187c135da6959862ff3846e99ad15462d2ec8a2f77a30ad53ebd5dcf2",
      "pattern": "[file:hashes.'SHA-256' = '8046a11187c135da6959862ff3846e99ad15462d2ec8a2f77a30ad53ebd5dcf2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Popular PyTorch Lightning Package Compromised by Mini Shai-H",
          "url": "https://www.aikido.dev/blog/pytorch-lightning-pypi-compromise-mini-shai-hulud"
        },
        {
          "source_name": "lightning PyPI Compromise: A Bun-Based Credential Stealer in",
          "url": "https://snyk.io/blog/lightning-pypi-compromise-bun-based-credential-stealer/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1d1d1309-c6e2-4bf2-a867-b1cf0fdb4633",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 0af7415d65753f6aede8c9c0f39be478666b9c12",
      "pattern": "[file:hashes.'SHA-1' = '0af7415d65753f6aede8c9c0f39be478666b9c12']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Se",
          "url": "https://www.aikido.dev/blog/mini-shai-hulud-has-appeared"
        },
        {
          "source_name": "\"A Mini Shai-Hulud Has Appeared\": Bun-Based Stealer Hits SAP",
          "url": "https://snyk.io/blog/bun-based-stealer-hits-sap-cap-js-mbt-npm-packages/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5153ea90-4995-4fb4-9408-7ad993048e43",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 4b04304f6d51392e3f43856c94ca95800518a694",
      "pattern": "[file:hashes.'SHA-1' = '4b04304f6d51392e3f43856c94ca95800518a694']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Se",
          "url": "https://www.aikido.dev/blog/mini-shai-hulud-has-appeared"
        },
        {
          "source_name": "\"A Mini Shai-Hulud Has Appeared\": Bun-Based Stealer Hits SAP",
          "url": "https://snyk.io/blog/bun-based-stealer-hits-sap-cap-js-mbt-npm-packages/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--377bc174-9008-433e-9a97-0b5bb39e5c48",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 7b6a28e92149637e5d7c7f4a2d3e54acd507c929",
      "pattern": "[file:hashes.'SHA-1' = '7b6a28e92149637e5d7c7f4a2d3e54acd507c929']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Se",
          "url": "https://www.aikido.dev/blog/mini-shai-hulud-has-appeared"
        },
        {
          "source_name": "\"A Mini Shai-Hulud Has Appeared\": Bun-Based Stealer Hits SAP",
          "url": "https://snyk.io/blog/bun-based-stealer-hits-sap-cap-js-mbt-npm-packages/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8a1d4895-39f9-4e6d-810e-b9f6da746a3d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: e80824a19f48d778a746571bb15279b5679fd61c",
      "pattern": "[file:hashes.'SHA-1' = 'e80824a19f48d778a746571bb15279b5679fd61c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Se",
          "url": "https://www.aikido.dev/blog/mini-shai-hulud-has-appeared"
        },
        {
          "source_name": "\"A Mini Shai-Hulud Has Appeared\": Bun-Based Stealer Hits SAP",
          "url": "https://snyk.io/blog/bun-based-stealer-hits-sap-cap-js-mbt-npm-packages/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ef605a7-c78a-4573-8638-a397b95a61a4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 29ac906c8bd801dfe1cb39596197df49f80fff2270b3e7fbab52278c24e4f1a7",
      "pattern": "[file:hashes.'SHA-256' = '29ac906c8bd801dfe1cb39596197df49f80fff2270b3e7fbab52278c24e4f1a7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Se",
          "url": "https://www.aikido.dev/blog/mini-shai-hulud-has-appeared"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--19e166e7-47c9-424d-b355-1fe59375f21d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6f933d00b7d05678eb43c90963a80b8947c4ae6830182f89df31da9f568fea95",
      "pattern": "[file:hashes.'SHA-256' = '6f933d00b7d05678eb43c90963a80b8947c4ae6830182f89df31da9f568fea95']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Se",
          "url": "https://www.aikido.dev/blog/mini-shai-hulud-has-appeared"
        },
        {
          "source_name": "\"A Mini Shai-Hulud Has Appeared\": Bun-Based Stealer Hits SAP",
          "url": "https://snyk.io/blog/bun-based-stealer-hits-sap-cap-js-mbt-npm-packages/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Aikido",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea563cba-35d3-4a05-9416-4ac6074eaae7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-40478",
      "pattern": "[vulnerability:name = 'CVE-2026-40478']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Don't Panic: The Thymeleaf Template Injection That Only Hurt",
          "url": "https://snyk.io/blog/thymeleaf-injection/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--91eafdb6-07ad-4758-acb8-f0dd12047843",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: api.svix.com",
      "pattern": "[domain-name:value = 'api.svix.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Someone published four versions of a fake \"tanstack\" package",
          "url": "https://www.aikido.dev/blog/fake-tanstack-packages-steal-env-files"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c535bcd-32c5-4aaa-9f56-d461e859f13d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 35baf8316645372eea40b91d48acb067",
      "pattern": "[file:hashes.MD5 = '35baf8316645372eea40b91d48acb067']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "\"A Mini Shai-Hulud Has Appeared\": Bun-Based Stealer Hits SAP",
          "url": "https://snyk.io/blog/bun-based-stealer-hits-sap-cap-js-mbt-npm-packages/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--38a5f67c-bf19-42a3-919b-d91f12cf525b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 307d0fa7407d40e67d14e9d5a4c61ac5b4f20431",
      "pattern": "[file:hashes.'SHA-1' = '307d0fa7407d40e67d14e9d5a4c61ac5b4f20431']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "\"A Mini Shai-Hulud Has Appeared\": Bun-Based Stealer Hits SAP",
          "url": "https://snyk.io/blog/bun-based-stealer-hits-sap-cap-js-mbt-npm-packages/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b81fd63b-3357-4132-8e0b-5c5204a8f658",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 04ee5325c8900c9d644ed81c9012525b6fc19f21c65cef85b6ba98b6a0a23566",
      "pattern": "[file:hashes.'SHA-256' = '04ee5325c8900c9d644ed81c9012525b6fc19f21c65cef85b6ba98b6a0a23566']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Someone published four versions of a fake \"tanstack\" package",
          "url": "https://www.aikido.dev/blog/fake-tanstack-packages-steal-env-files"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--75f70c7e-670d-4229-b05c-3ceaf3790ba9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 72ec4571e27c06f1d48737477c2b38a4f90d699950dab8946b48591133dc4f90",
      "pattern": "[file:hashes.'SHA-256' = '72ec4571e27c06f1d48737477c2b38a4f90d699950dab8946b48591133dc4f90']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Someone published four versions of a fake \"tanstack\" package",
          "url": "https://www.aikido.dev/blog/fake-tanstack-packages-steal-env-files"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--29bd294a-deb0-4a27-8e19-9ddbe430dccf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7bb84e6ba893248814cd3bac70b7bdc115740fba9e13419940c73460cbcd7b6f",
      "pattern": "[file:hashes.'SHA-256' = '7bb84e6ba893248814cd3bac70b7bdc115740fba9e13419940c73460cbcd7b6f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Someone published four versions of a fake \"tanstack\" package",
          "url": "https://www.aikido.dev/blog/fake-tanstack-packages-steal-env-files"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d39dfa02-739d-4f54-836b-a69f3a3bb7b8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: abc164807947b102164488a08161adb4ee08be6b78a371350a6b156eed0d97d9",
      "pattern": "[file:hashes.'SHA-256' = 'abc164807947b102164488a08161adb4ee08be6b78a371350a6b156eed0d97d9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Someone published four versions of a fake \"tanstack\" package",
          "url": "https://www.aikido.dev/blog/fake-tanstack-packages-steal-env-files"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--04d1c69d-d13c-42da-86f6-cbcbfdb27470",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-1708",
      "pattern": "[vulnerability:name = 'CVE-2024-1708']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1708 \u2014 ConnectWise ScreenConnect Path Tra",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cf7bb6c6-7f85-4354-8324-e693ab755863",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-32202",
      "pattern": "[vulnerability:name = 'CVE-2026-32202']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-32202 \u2014 Microsoft Windows Protection Mech",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-21510 \u2014 Microsoft Windows Shell Protectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cc7a77b0-87f8-4210-978c-3252f76e083c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-3965",
      "pattern": "[vulnerability:name = 'CVE-2026-3965']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Qinglong task scheduler RCE vulnerabilities exploited in the",
          "url": "https://snyk.io/blog/qinglong-task-scheduler-rce-vulnerabilities/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aff13d48-c96b-4aa8-9896-02a8e047ea9e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-4047",
      "pattern": "[vulnerability:name = 'CVE-2026-4047']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Qinglong task scheduler RCE vulnerabilities exploited in the",
          "url": "https://snyk.io/blog/qinglong-task-scheduler-rce-vulnerabilities/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--68bfa147-f08d-4b67-9c6e-0a3163b9ffdd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: file.551911.xyz",
      "pattern": "[domain-name:value = 'file.551911.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Qinglong task scheduler RCE vulnerabilities exploited in the",
          "url": "https://snyk.io/blog/qinglong-task-scheduler-rce-vulnerabilities/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d866bab8-2c1d-4fb7-b75e-72ae458c266b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: b1e4b1f3aad0d489ab0e9208031c67402bbb8480",
      "pattern": "[file:hashes.'SHA-1' = 'b1e4b1f3aad0d489ab0e9208031c67402bbb8480']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Malicious Release of elementary-data PyPI Package Steals Clo",
          "url": "https://snyk.io/blog/malicious-release-of-elementary-data-pypi-package-steals-cloud-credentials-from-data-engineers/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6529cf01-87d8-4543-b4cd-56e7dcc204d7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 31ecc5939de6d24cf60c50d4ca26cf7a8c322db82a8ce4bd122ebd89cf634255",
      "pattern": "[file:hashes.'SHA-256' = '31ecc5939de6d24cf60c50d4ca26cf7a8c322db82a8ce4bd122ebd89cf634255']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Malicious Release of elementary-data PyPI Package Steals Clo",
          "url": "https://snyk.io/blog/malicious-release-of-elementary-data-pypi-package-steals-cloud-credentials-from-data-engineers/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--40090d8f-2bd0-497b-abac-974a1084ccda",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-57726",
      "pattern": "[vulnerability:name = 'CVE-2024-57726']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57726 \u2014 SimpleHelp Missing Authorization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-57727 \u2014 SimpleHelp Path Traversal Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--705ea3dc-c952-4c8c-9d00-f6a4397d3ec6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-57728",
      "pattern": "[vulnerability:name = 'CVE-2024-57728']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57728 \u2014 SimpleHelp Path Traversal Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-57727 \u2014 SimpleHelp Path Traversal Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--03a41833-8741-4c9c-92ca-11fb87603c04",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-7399",
      "pattern": "[vulnerability:name = 'CVE-2024-7399']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-7399 \u2014 Samsung MagicINFO 9 Server Path Tr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4632 \u2014 Samsung MagicINFO 9 Server Path Tr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fc464f18-5c57-47a6-ae5b-2f879a17ec8a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-29635",
      "pattern": "[vulnerability:name = 'CVE-2025-29635']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-29635 \u2014 D-Link DIR-823X Command Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--38e04dfd-4eb7-4be7-939e-7577ffbd2110",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.147.173.172",
      "pattern": "[ipv4-addr:value = '38.147.173.172']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-39987 \u2014 Marimo Remote Code Execution Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0a66b4c-5b6b-4e31-966c-0d6c99187dc0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 43.231.113.50",
      "pattern": "[ipv4-addr:value = '43.231.113.50']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "GopherWhisper: A burrow full of malware",
          "url": "https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c81a2607-ca1e-4e81-83dc-b68033f42576",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 039eb329a173fce7efeca18611a8f2c0f7d24609",
      "pattern": "[file:hashes.'SHA-1' = '039eb329a173fce7efeca18611a8f2c0f7d24609']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "GopherWhisper: A burrow full of malware",
          "url": "https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--859b1a00-ba4c-4c7f-8c75-9d6f13279f41",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 57c2490e4db194d3503ee85635fb1d6f26e8c534",
      "pattern": "[file:hashes.'SHA-1' = '57c2490e4db194d3503ee85635fb1d6f26e8c534']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "GopherWhisper: A burrow full of malware",
          "url": "https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--13dd416b-0fb3-4390-9c09-a728455ecdbd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 5a1bbb40c442b12594a913431f8c6757a3a66e8f",
      "pattern": "[file:hashes.'SHA-1' = '5a1bbb40c442b12594a913431f8c6757a3a66e8f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "GopherWhisper: A burrow full of malware",
          "url": "https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c1b93d3-688c-4d30-8315-5f47b2d66e1a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 716554dc580a82cc17a1035add302c0766590964",
      "pattern": "[file:hashes.'SHA-1' = '716554dc580a82cc17a1035add302c0766590964']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "GopherWhisper: A burrow full of malware",
          "url": "https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--965161ae-97c8-4bd2-9821-5bc1153c64d3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 926974facfd0383c65458d6ef1f31fbb7c769e18",
      "pattern": "[file:hashes.'SHA-1' = '926974facfd0383c65458d6ef1f31fbb7c769e18']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "GopherWhisper: A burrow full of malware",
          "url": "https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3c8bc5ea-3eb5-457b-bb3d-bdde5e18d35e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: ad7e264eb08415871617e45f21d03f7d71e4c36f",
      "pattern": "[file:hashes.'SHA-1' = 'ad7e264eb08415871617e45f21d03f7d71e4c36f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "GopherWhisper: A burrow full of malware",
          "url": "https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a0e15ea0-5e2d-4cfc-ab96-f44abc511f11",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: c72e7540d6f12d74d8e737b02f31568385f575d7",
      "pattern": "[file:hashes.'SHA-1' = 'c72e7540d6f12d74d8e737b02f31568385f575d7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "GopherWhisper: A burrow full of malware",
          "url": "https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aff5216b-50f2-4667-a04d-9d6c9a64581c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: fa9e65e58eb8fa41fde0a0a870b7d24b298026d9",
      "pattern": "[file:hashes.'SHA-1' = 'fa9e65e58eb8fa41fde0a0a870b7d24b298026d9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "GopherWhisper: A burrow full of malware",
          "url": "https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--13326b7f-6fdd-433d-813e-9ec1d6f0fe06",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 37f34aa3b86db6898065f3ca886031978580a15251f2576f6d24c3b778907336",
      "pattern": "[file:hashes.'SHA-256' = '37f34aa3b86db6898065f3ca886031978580a15251f2576f6d24c3b778907336']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Sel",
          "url": "https://www.aikido.dev/blog/shai-hulud-npm-bitwarden-cli-compromise"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0257a8e-ac20-4f48-89a4-609b9fff9e25",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sync.geeker.indevs.in",
      "pattern": "[domain-name:value = 'sync.geeker.indevs.in']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "GPT-Proxy Backdoor in npm and PyPI turns Servers into Chines",
          "url": "https://www.aikido.dev/blog/gpt-proxy-backdoor-npm-pypi-chinese-llm-relay"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5aad1aec-f0a0-4ed3-bd7d-fe7dc1c9b734",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3a3d8f8636fa1db21871005a49ecd7fa59688fa763622fa737ce6b899558b300",
      "pattern": "[file:hashes.'SHA-256' = '3a3d8f8636fa1db21871005a49ecd7fa59688fa763622fa737ce6b899558b300']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "GPT-Proxy Backdoor in npm and PyPI turns Servers into Chines",
          "url": "https://www.aikido.dev/blog/gpt-proxy-backdoor-npm-pypi-chinese-llm-relay"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--824a13d5-a2cb-41d5-834c-c2fb63d36ce2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5d58ce3119c37f2bd552f4d883a4f4896dfcb8fb04875f844f999497e4ca846d",
      "pattern": "[file:hashes.'SHA-256' = '5d58ce3119c37f2bd552f4d883a4f4896dfcb8fb04875f844f999497e4ca846d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "GPT-Proxy Backdoor in npm and PyPI turns Servers into Chines",
          "url": "https://www.aikido.dev/blog/gpt-proxy-backdoor-npm-pypi-chinese-llm-relay"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--053b01b3-00df-49ce-8e03-cf884a4469a0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b3405b8456f4e82f192cdff6fdd5b290a58fafda01fbc08174105b922bd7b3cf",
      "pattern": "[file:hashes.'SHA-256' = 'b3405b8456f4e82f192cdff6fdd5b290a58fafda01fbc08174105b922bd7b3cf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "GPT-Proxy Backdoor in npm and PyPI turns Servers into Chines",
          "url": "https://www.aikido.dev/blog/gpt-proxy-backdoor-npm-pypi-chinese-llm-relay"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3fab6e65-fbbe-4491-878e-1eefadd33207",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: fb3ae78d09c119ec335c3b99a95c97d9bb6f92fd2c7c9b0d3e875347e2f25bb2",
      "pattern": "[file:hashes.'SHA-256' = 'fb3ae78d09c119ec335c3b99a95c97d9bb6f92fd2c7c9b0d3e875347e2f25bb2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "GPT-Proxy Backdoor in npm and PyPI turns Servers into Chines",
          "url": "https://www.aikido.dev/blog/gpt-proxy-backdoor-npm-pypi-chinese-llm-relay"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c1b7e36a-1ba3-4f0f-b642-4de76480fe71",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-27351",
      "pattern": "[vulnerability:name = 'CVE-2023-27351']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27351 \u2014 PaperCut NG/MF Improper Authentic",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-27350 \u2014 PaperCut MF/NG Improper Access Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0cd092e4-a71f-420b-b8ac-8a8e40e4a519",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-27199",
      "pattern": "[vulnerability:name = 'CVE-2024-27199']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27199 \u2014 JetBrains TeamCity Relative Path ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4cbd3846-6a4a-4494-97e5-89e2182fea3f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-2749",
      "pattern": "[vulnerability:name = 'CVE-2025-2749']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2749 \u2014 Kentico Xperience Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-2746 \u2014 Kentico Xperience CMS Authenticati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e52ebd3a-83f6-46b7-bb89-142fc1008247",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-32975",
      "pattern": "[vulnerability:name = 'CVE-2025-32975']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-32975 \u2014 Quest KACE Systems Management App",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d9fb2abe-b993-4338-944e-2d8748924acd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-48700",
      "pattern": "[vulnerability:name = 'CVE-2025-48700']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-48700 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bf113737-e2ee-4fec-8d86-a466a81f0e4a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-34197",
      "pattern": "[vulnerability:name = 'CVE-2026-34197']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-34197 \u2014 Apache ActiveMQ Improper Input Va",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7acd1013-a1ae-4127-a167-4f8a02dbdbed",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2009-0238",
      "pattern": "[vulnerability:name = 'CVE-2009-0238']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2009-0238 \u2014 Microsoft Office Remote Code Execu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb3e338c-d34f-46d9-9249-f2e7f6b8b50a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-32201",
      "pattern": "[vulnerability:name = 'CVE-2026-32201']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-32201 \u2014 Microsoft SharePoint Server Impro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb0f94dd-cb6f-4e79-b34a-85a72a912eec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-1854",
      "pattern": "[vulnerability:name = 'CVE-2012-1854']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-1854 \u2014 Microsoft Visual Basic for Applica",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f5894e2c-fd11-469b-902e-15ad5bdf750c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-9715",
      "pattern": "[vulnerability:name = 'CVE-2020-9715']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-9715 \u2014 Adobe Acrobat Use-After-Free Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--22082496-0282-4779-9a84-53d8f1073b6f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-21529",
      "pattern": "[vulnerability:name = 'CVE-2023-21529']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-21529 \u2014 Microsoft Exchange Server Deseria",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e47c8f79-25c1-4f3e-bd60-ad7aa4b44529",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-36424",
      "pattern": "[vulnerability:name = 'CVE-2023-36424']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-36424 \u2014 Microsoft Windows Out-of-Bounds R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b73ba01-be97-4563-aa95-3c2b75db30e4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-60710",
      "pattern": "[vulnerability:name = 'CVE-2025-60710']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-60710 \u2014 Microsoft Windows Link Following ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b517c101-ac71-4554-abe4-88f2a5119de5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-21643",
      "pattern": "[vulnerability:name = 'CVE-2026-21643']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-21643 \u2014 Fortinet FortiClient EMS SQL Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f047143-7b11-40f5-97f7-1d16df8b610a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-34621",
      "pattern": "[vulnerability:name = 'CVE-2026-34621']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-34621 \u2014 Adobe Acrobat and Reader Prototyp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f10d6011-8f6b-4cae-9c98-27fbf8179cf5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: api.metrics-trustwallet.com",
      "pattern": "[domain-name:value = 'api.metrics-trustwallet.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Securing Vibe Coding and AI Coding Agents: An End-to-End App",
          "url": "https://www.stepsecurity.io/blog/securing-vibe-coding-and-ai-coding-agents-an-end-to-end-approach-with-stepsecurity"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e28170d7-2ea8-43e1-b5c8-56afa1e5fcd3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: metrics-trustwallet.com",
      "pattern": "[domain-name:value = 'metrics-trustwallet.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Securing Vibe Coding and AI Coding Agents: An End-to-End App",
          "url": "https://www.stepsecurity.io/blog/securing-vibe-coding-and-ai-coding-agents-an-end-to-end-approach-with-stepsecurity"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a08f9219-8ae5-409b-8242-ac77608ec4dd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-25253",
      "pattern": "[vulnerability:name = 'CVE-2026-25253']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cline Supply Chain Attack Detected: cline@2.3.0 Silently Ins",
          "url": "https://www.stepsecurity.io/blog/cline-supply-chain-attack-detected-cline-2-3-0-silently-installs-openclaw"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aedb8099-77c9-47b6-8cf9-e5b3041a54ca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: hackmoltrepeat.com",
      "pattern": "[domain-name:value = 'hackmoltrepeat.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub",
          "url": "https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--16a18ea8-764d-42f1-b09a-79b27d90f8c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: recv.hackmoltrepeat.com",
      "pattern": "[domain-name:value = 'recv.hackmoltrepeat.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub",
          "url": "https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6c68cbbb-fca5-4137-8ca3-da907b45622d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-1340",
      "pattern": "[vulnerability:name = 'CVE-2026-1340']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-1340 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d8c01a13-9108-47ba-b3d5-2bc490fe5c32",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: github.com/ColossusQuailPray/oiegjqde",
      "pattern": "[domain-name:value = 'github.com/ColossusQuailPray/oiegjqde']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "GlassWorm goes native: New Zig dropper infects every IDE on ",
          "url": "https://www.aikido.dev/blog/glassworm-zig-dropper-infects-every-ide-on-your-machine"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aad0e961-cf31-4c9b-9322-20501caafc2f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 112d1b33dd9b0244525f51e59e6a79ac5ae452bf6e98c310e7b4fa7902e4db44",
      "pattern": "[file:hashes.'SHA-256' = '112d1b33dd9b0244525f51e59e6a79ac5ae452bf6e98c310e7b4fa7902e4db44']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "GlassWorm goes native: New Zig dropper infects every IDE on ",
          "url": "https://www.aikido.dev/blog/glassworm-zig-dropper-infects-every-ide-on-your-machine"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de129ccb-232b-4834-ba67-8121a8bc39d8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2819ea44e22b9c47049e86894e544f3fd0de1d8afc7b545314bd3bc718bf2e02",
      "pattern": "[file:hashes.'SHA-256' = '2819ea44e22b9c47049e86894e544f3fd0de1d8afc7b545314bd3bc718bf2e02']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "GlassWorm goes native: New Zig dropper infects every IDE on ",
          "url": "https://www.aikido.dev/blog/glassworm-zig-dropper-infects-every-ide-on-your-machine"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Aikido"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7326084e-5b0f-45c3-88e5-46ed7306ac0b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-35616",
      "pattern": "[vulnerability:name = 'CVE-2026-35616']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-35616 \u2014 Fortinet FortiClient EMS Improper",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--82019aa6-5ba5-48e8-b907-a47a9aa855cc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-3502",
      "pattern": "[vulnerability:name = 'CVE-2026-3502']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-3502 \u2014 TrueConf Client Download of Code W",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc4ef53b-a3e7-40f2-968a-f03013f95c2e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cdn.rraghh.com",
      "pattern": "[domain-name:value = 'cdn.rraghh.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Malicious IoliteLabs VSCode Extensions Target Solidity Devel",
          "url": "https://www.stepsecurity.io/blog/malicious-iolitelabs-vscode-extensions-target-solidity-developers-on-windows-macos-and-linux-with-backdoor"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fc4b191a-38e7-4f3a-8e8b-312a7a283d3a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: championships-peoples-point-cassette.trycloudflare.com",
      "pattern": "[domain-name:value = 'championships-peoples-point-cassette.trycloudflare.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "You Patched LiteLLM, But Do You Know Your AI Blast Radius?",
          "url": "https://snyk.io/blog/litellm-ai-blast-radius/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ba940b4b-0010-40e4-a4c3-5ca1575cabfe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: investigation-launches-hearings-copying.trycloudflare.com",
      "pattern": "[domain-name:value = 'investigation-launches-hearings-copying.trycloudflare.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "You Patched LiteLLM, But Do You Know Your AI Blast Radius?",
          "url": "https://snyk.io/blog/litellm-ai-blast-radius/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--40f365c8-d247-4923-94f4-566f25f99c32",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: oortt.com",
      "pattern": "[domain-name:value = 'oortt.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Malicious IoliteLabs VSCode Extensions Target Solidity Devel",
          "url": "https://www.stepsecurity.io/blog/malicious-iolitelabs-vscode-extensions-target-solidity-developers-on-windows-macos-and-linux-with-backdoor"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da8c3dfe-3bce-459a-be79-d1237bec173b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: rraghh.com",
      "pattern": "[domain-name:value = 'rraghh.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Malicious IoliteLabs VSCode Extensions Target Solidity Devel",
          "url": "https://www.stepsecurity.io/blog/malicious-iolitelabs-vscode-extensions-target-solidity-developers-on-windows-macos-and-linux-with-backdoor"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9a48fccc-6b87-414d-94a3-34919159fd48",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: souls-entire-defined-routes.trycloudflare.com",
      "pattern": "[domain-name:value = 'souls-entire-defined-routes.trycloudflare.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "You Patched LiteLLM, But Do You Know Your AI Blast Radius?",
          "url": "https://snyk.io/blog/litellm-ai-blast-radius/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--472e3d5d-6d9b-402c-92c1-55ebde27122e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e903ae267bf7ed1d02b218c1dc7cf6d87257e87de9fbda411a13f9154716bfa3",
      "pattern": "[file:hashes.'SHA-256' = 'e903ae267bf7ed1d02b218c1dc7cf6d87257e87de9fbda411a13f9154716bfa3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Malicious IoliteLabs VSCode Extensions Target Solidity Devel",
          "url": "https://www.stepsecurity.io/blog/malicious-iolitelabs-vscode-extensions-target-solidity-developers-on-windows-macos-and-linux-with-backdoor"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--041af57c-6d99-49a1-ad57-43c2d5e4d774",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: fcd398abc51fd16e8bc93ef8d88a23d7dec28081b6dfce4b933020322a610508",
      "pattern": "[file:hashes.'SHA-256' = 'fcd398abc51fd16e8bc93ef8d88a23d7dec28081b6dfce4b933020322a610508']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Malicious IoliteLabs VSCode Extensions Target Solidity Devel",
          "url": "https://www.stepsecurity.io/blog/malicious-iolitelabs-vscode-extensions-target-solidity-developers-on-windows-macos-and-linux-with-backdoor"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--feb2e15c-4108-45b3-b8e9-ce918393a2a5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-5281",
      "pattern": "[vulnerability:name = 'CVE-2026-5281']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-5281 \u2014 Google Dawn Use-After-Free Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--38f32ade-94cf-4350-b92e-cadb179b0b63",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 617b67a8e1210e4fc87c92d1d1da45a2f311c08d26e89b12307cf583c900d101",
      "pattern": "[file:hashes.'SHA-256' = '617b67a8e1210e4fc87c92d1d1da45a2f311c08d26e89b12307cf583c900d101']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Axios npm Package Compromised: Supply Chain Attack Delivers ",
          "url": "https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--64009b5a-ac97-48f2-9943-b6a1df592624",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 92ff08773995ebc8d55ec4b8e1a225d0d1e51efa4ef88b8849d0071230c9645a",
      "pattern": "[file:hashes.'SHA-256' = '92ff08773995ebc8d55ec4b8e1a225d0d1e51efa4ef88b8849d0071230c9645a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Axios npm Package Compromised: Supply Chain Attack Delivers ",
          "url": "https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--78c2a00c-2e85-4efc-9634-b906b634fa4e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: fcb81618bb15edfdedfb638b4c08a2af9cac9ecfa551af135a8402bf980375cf",
      "pattern": "[file:hashes.'SHA-256' = 'fcb81618bb15edfdedfb638b4c08a2af9cac9ecfa551af135a8402bf980375cf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Axios npm Package Compromised: Supply Chain Attack Delivers ",
          "url": "https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea745ca3-2725-4cb7-8202-30a0d4aee4b8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-53521",
      "pattern": "[vulnerability:name = 'CVE-2025-53521']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-53521 \u2014 F5 BIG-IP Stack-Based Buffer Over",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--db345d29-9f42-469c-89d1-a31c83b4951d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cloudflareguard.vercel.app",
      "pattern": "[domain-name:value = 'cloudflareguard.vercel.app']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Malicious Polymarket Bot Hides in Hijacked dev-protocol GitH",
          "url": "https://www.stepsecurity.io/blog/malicious-polymarket-bot-hides-in-hijacked-dev-protocol-github-org-and-steals-wallet-keys"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2f92224e-a9e2-4860-a1b5-e86697716db9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cloudflareinsights.vercel.app",
      "pattern": "[domain-name:value = 'cloudflareinsights.vercel.app']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Malicious Polymarket Bot Hides in Hijacked dev-protocol GitH",
          "url": "https://www.stepsecurity.io/blog/malicious-polymarket-bot-hides-in-hijacked-dev-protocol-github-org-and-steals-wallet-keys"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--212184a7-8055-46d4-aeb9-4e47b5d16eb2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: finney.metagraph-stats.com",
      "pattern": "[domain-name:value = 'finney.metagraph-stats.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfilt",
          "url": "https://www.stepsecurity.io/blog/bittensor-wallet-4-0-2-compromised-on-pypi---backdoor-exfiltrates-private-keys"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8aeb6988-45d2-4ff1-95ff-eddf64600ec7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: finney.opentensor-metrics.com",
      "pattern": "[domain-name:value = 'finney.opentensor-metrics.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfilt",
          "url": "https://www.stepsecurity.io/blog/bittensor-wallet-4-0-2-compromised-on-pypi---backdoor-exfiltrates-private-keys"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6195ac5a-d744-4198-88df-d20b206cbea5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: finney.subtensor-telemetry.com",
      "pattern": "[domain-name:value = 'finney.subtensor-telemetry.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfilt",
          "url": "https://www.stepsecurity.io/blog/bittensor-wallet-4-0-2-compromised-on-pypi---backdoor-exfiltrates-private-keys"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--63820811-d86d-4085-9233-e797f4a16383",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: opentensor-cdn.com",
      "pattern": "[domain-name:value = 'opentensor-cdn.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfilt",
          "url": "https://www.stepsecurity.io/blog/bittensor-wallet-4-0-2-compromised-on-pypi---backdoor-exfiltrates-private-keys"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--44bdd44e-5eec-46c4-9e0c-417ab3c811d9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: t.opentensor-cdn.com",
      "pattern": "[domain-name:value = 't.opentensor-cdn.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfilt",
          "url": "https://www.stepsecurity.io/blog/bittensor-wallet-4-0-2-compromised-on-pypi---backdoor-exfiltrates-private-keys"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bd4e4b8b-e390-401f-9bb0-7c8cda848e40",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: tbqcbkpbhy.opentensor-cdn.com",
      "pattern": "[domain-name:value = 'tbqcbkpbhy.opentensor-cdn.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfilt",
          "url": "https://www.stepsecurity.io/blog/bittensor-wallet-4-0-2-compromised-on-pypi---backdoor-exfiltrates-private-keys"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--120a2ec7-cc38-4bcf-8586-2111e75f5861",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: tuwyqibtvy.opentensor-cdn.com",
      "pattern": "[domain-name:value = 'tuwyqibtvy.opentensor-cdn.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfilt",
          "url": "https://www.stepsecurity.io/blog/bittensor-wallet-4-0-2-compromised-on-pypi---backdoor-exfiltrates-private-keys"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--edba75f8-ee11-4043-872b-e56a567fc3e2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: yccansiwfr.opentensor-cdn.com",
      "pattern": "[domain-name:value = 'yccansiwfr.opentensor-cdn.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfilt",
          "url": "https://www.stepsecurity.io/blog/bittensor-wallet-4-0-2-compromised-on-pypi---backdoor-exfiltrates-private-keys"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--27e50169-faac-4480-b908-6c772c66d931",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 217.69.0.159",
      "pattern": "[ipv4-addr:value = '217.69.0.159']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ForceMemo: Hundreds of GitHub Python Repos Compromised via A",
          "url": "https://www.stepsecurity.io/blog/forcememo-hundreds-of-github-python-repos-compromised-via-account-takeover-and-force-push"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a99221a9-5290-4481-84bf-ca4cf1b73b81",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6a416b72ff24804abc12484a3b41413a8580acedd8a5f8c84224fcf0732c2f8e",
      "pattern": "[file:hashes.'SHA-256' = '6a416b72ff24804abc12484a3b41413a8580acedd8a5f8c84224fcf0732c2f8e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfilt",
          "url": "https://www.stepsecurity.io/blog/bittensor-wallet-4-0-2-compromised-on-pypi---backdoor-exfiltrates-private-keys"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3abdb79e-8ba1-4140-81f9-31958e92dcbe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: security-verify.91.214.78.178.nip.io",
      "pattern": "[domain-name:value = 'security-verify.91.214.78.178.nip.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "xygeni-action Compromised: C2 Reverse Shell Backdoor Injecte",
          "url": "https://www.stepsecurity.io/blog/xygeni-action-compromised-c2-reverse-shell-backdoor-injected-via-tag-poisoning"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ad932e0b-cf12-4155-a8d7-eaa5414ac07b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 91.214.78.178",
      "pattern": "[ipv4-addr:value = '91.214.78.178']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "xygeni-action Compromised: C2 Reverse Shell Backdoor Injecte",
          "url": "https://www.stepsecurity.io/blog/xygeni-action-compromised-c2-reverse-shell-backdoor-injected-via-tag-poisoning"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea8165c9-76c6-4472-8b86-c522694b3cb3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-31277",
      "pattern": "[vulnerability:name = 'CVE-2025-31277']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-43510 \u2014 Apple Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-31277 \u2014 Apple Multiple Products Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5e6032ef-8e2a-4a1e-9432-dc6674b7e4a1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-32432",
      "pattern": "[vulnerability:name = 'CVE-2025-32432']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-32432 \u2014 Craft CMS Code Injection Vulnerab",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-35939 \u2014 Craft CMS External Control of Ass",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-58136 \u2014 Yiiframework Yii Improper Protect",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5036681-a373-4400-8ff3-49bd7f62841c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-43510",
      "pattern": "[vulnerability:name = 'CVE-2025-43510']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-43510 \u2014 Apple Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-31277 \u2014 Apple Multiple Products Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4c8bcd88-b2e2-4230-a0b9-18dea2428f65",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-43520",
      "pattern": "[vulnerability:name = 'CVE-2025-43520']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-43510 \u2014 Apple Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-43520 \u2014 Apple Multiple Products Classic B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f6e10b64-9bb0-4d7e-bbd1-9ff602fbda2c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-54068",
      "pattern": "[vulnerability:name = 'CVE-2025-54068']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54068 \u2014 Laravel Livewire Code Injection V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b3e45e2b-443a-4844-8853-1e38e8a75d92",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-20131",
      "pattern": "[vulnerability:name = 'CVE-2026-20131']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-20131 \u2014 Cisco Secure Firewall Management ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6440cfde-d82e-419f-8516-37bb89b89627",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-20963",
      "pattern": "[vulnerability:name = 'CVE-2026-20963']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-20963 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b4f18fe2-f1a6-42fc-a5bb-b38d621e3334",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-47813",
      "pattern": "[vulnerability:name = 'CVE-2025-47813']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-47813 \u2014 Wing FTP Server Information Discl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0d90fdd0-825a-4702-b8c8-61c595004c69",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-3909",
      "pattern": "[vulnerability:name = 'CVE-2026-3909']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-3909 \u2014 Google Skia Out-of-Bounds Write Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--af7d4ee2-1001-47ec-9d60-3d6c0c978151",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-3910",
      "pattern": "[vulnerability:name = 'CVE-2026-3910']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-3910 \u2014 Google Chromium V8 Improper Restri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--465e06bb-5ebb-4605-a758-98bf7af1bba5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: iili.io",
      "pattern": "[domain-name:value = 'iili.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd5d18a1-183a-4ef6-a970-6f50c7387fc9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: pastefy.app",
      "pattern": "[domain-name:value = 'pastefy.app']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb8da933-ad80-423f-be70-7cf0eb84c113",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: short-link.net",
      "pattern": "[domain-name:value = 'short-link.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--03f46314-8f7c-4a24-827c-f343fe850c6d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 188.137.228.162",
      "pattern": "[ipv4-addr:value = '188.137.228.162']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--04c011a1-cbb9-4a4e-9f82-ca294be9a038",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 80.89.224.13",
      "pattern": "[ipv4-addr:value = '80.89.224.13']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0c64694a-8345-4229-9df0-91f43a6526fd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 107b2badfc93fcdd3ffda7d3999477ced3f39f43f458dd0f6a424c9ab52681c3",
      "pattern": "[file:hashes.'SHA-256' = '107b2badfc93fcdd3ffda7d3999477ced3f39f43f458dd0f6a424c9ab52681c3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--604a8559-9b72-484e-bc4e-5f90edab51e9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 21fefc3913d3d2dfde7f0dff54800ca7512eb5df9513b1a457a2af25fdd51b26",
      "pattern": "[file:hashes.'SHA-256' = '21fefc3913d3d2dfde7f0dff54800ca7512eb5df9513b1a457a2af25fdd51b26']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7e7ca077-c235-4ed1-9503-f060e03a8b62",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2b5d8f8db5fd38ae1c34807dcba35b057cffa61eb14ba3b558f82eb630480c3f",
      "pattern": "[file:hashes.'SHA-256' = '2b5d8f8db5fd38ae1c34807dcba35b057cffa61eb14ba3b558f82eb630480c3f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--85ca40d7-08f5-46b5-a417-930d60eb9718",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 32973ef02e10a585a4a0196b013265e29fc57d8e1c50752f7b39e43b9f388715",
      "pattern": "[file:hashes.'SHA-256' = '32973ef02e10a585a4a0196b013265e29fc57d8e1c50752f7b39e43b9f388715']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--db5f856e-865e-4816-a43b-7ed45f2793b5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 352f34ea5cc40e2b3ec056ae60fa19a368dbd42503ef225cb1ca57956eb05e81",
      "pattern": "[file:hashes.'SHA-256' = '352f34ea5cc40e2b3ec056ae60fa19a368dbd42503ef225cb1ca57956eb05e81']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c525932d-81da-4856-b606-272ca9387bfa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 51e86408904c0ca3778361cde746783a0f2b9fd2a6782aa7e062aa597151876e",
      "pattern": "[file:hashes.'SHA-256' = '51e86408904c0ca3778361cde746783a0f2b9fd2a6782aa7e062aa597151876e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--65df1f8c-ca23-4535-a9b0-003b65a29f15",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5b978cdc46afa28d83e532cd19622d9097bebedf87efc4c87bd35d8ffad9e672",
      "pattern": "[file:hashes.'SHA-256' = '5b978cdc46afa28d83e532cd19622d9097bebedf87efc4c87bd35d8ffad9e672']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--17ca17e3-60d6-4925-a24f-875b46ab27d1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6178b1af51057c0bac75a842afff500a8fa3ed957d79a712a6ef089bec7e7a8b",
      "pattern": "[file:hashes.'SHA-256' = '6178b1af51057c0bac75a842afff500a8fa3ed957d79a712a6ef089bec7e7a8b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--56af380d-b5b5-421d-b71b-e8d171612562",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 66a7828bc8c6c783b2ffa3c906d53f6dae1bbddc019283cc369d7d73247c5181",
      "pattern": "[file:hashes.'SHA-256' = '66a7828bc8c6c783b2ffa3c906d53f6dae1bbddc019283cc369d7d73247c5181']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--47bace88-0ae1-457b-ad7a-978e539aa733",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6fea579685d2433cedb1c32ef704575dcbc1d0a623769e824023ffccd0dedaae",
      "pattern": "[file:hashes.'SHA-256' = '6fea579685d2433cedb1c32ef704575dcbc1d0a623769e824023ffccd0dedaae']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--14af39e0-0171-4f4f-ac2c-e78c7875351e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 76eb713e38f145ee68b89f2febd8f9a28bbb2b464da61cb029d84433a0b2c746",
      "pattern": "[file:hashes.'SHA-256' = '76eb713e38f145ee68b89f2febd8f9a28bbb2b464da61cb029d84433a0b2c746']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4ad22f40-18ad-44e4-9dd7-67537ec93d19",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 801c47550799831bfb1ac6c5c3fd698be95da19fc85bd65f5d8639f26244d2a9",
      "pattern": "[file:hashes.'SHA-256' = '801c47550799831bfb1ac6c5c3fd698be95da19fc85bd65f5d8639f26244d2a9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--41902b4a-0c0f-46e1-badf-9c4970f3c48f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 886df55794cbca146de96dcc626471b3c097a5c20ba488033b24f4347aa20a14",
      "pattern": "[file:hashes.'SHA-256' = '886df55794cbca146de96dcc626471b3c097a5c20ba488033b24f4347aa20a14']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--77fae041-5f4b-4ebe-8f6c-450dd3030c67",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8c6ea44ce7f4ed4e4e7e19e11b3b345d58785c93b33aa795ddd1b0d753236b05",
      "pattern": "[file:hashes.'SHA-256' = '8c6ea44ce7f4ed4e4e7e19e11b3b345d58785c93b33aa795ddd1b0d753236b05']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e868294a-1829-4c11-9637-0407b732026c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9367f4b4d2775ff47279d143dd9a0ef544ddff81946aab33da9350a49f14e1e1",
      "pattern": "[file:hashes.'SHA-256' = '9367f4b4d2775ff47279d143dd9a0ef544ddff81946aab33da9350a49f14e1e1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--35ab2f6e-142d-424f-9c07-b08cd8bab1f9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 993d55f60414bf2092f421c3d0ac6af1897a21cc4ea260ae8e610a402bf4c81c",
      "pattern": "[file:hashes.'SHA-256' = '993d55f60414bf2092f421c3d0ac6af1897a21cc4ea260ae8e610a402bf4c81c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6f212d26-7994-4a83-bddf-7744656157ea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a545908c931ec47884b5ccfb1f112435f5d0cdac140e664673672c9df9016672",
      "pattern": "[file:hashes.'SHA-256' = 'a545908c931ec47884b5ccfb1f112435f5d0cdac140e664673672c9df9016672']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e78195ea-0dfa-449c-9603-2498bf77347f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ac60eefc2607216f8126c0b22b6243f3862ef2bb265c585deee0d00a20a436b3",
      "pattern": "[file:hashes.'SHA-256' = 'ac60eefc2607216f8126c0b22b6243f3862ef2bb265c585deee0d00a20a436b3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a0a94cf0-c676-4807-9616-02b2acaf7371",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b891fa118db5190f07b18be46eb9bc10677f9afab1406a7d52ce587522ab3d28",
      "pattern": "[file:hashes.'SHA-256' = 'b891fa118db5190f07b18be46eb9bc10677f9afab1406a7d52ce587522ab3d28']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--14f12246-bd60-467f-8a0b-dcaa86026fab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: bad7c6f6ca25363a02eaceb3ed1e378218dc4a246a63d723cfcc5feee3af5056",
      "pattern": "[file:hashes.'SHA-256' = 'bad7c6f6ca25363a02eaceb3ed1e378218dc4a246a63d723cfcc5feee3af5056']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--60f27e02-0761-4f31-8c01-a6643fb0fc10",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c6905bae088982a2b234451b45db742098f2e2ab4fd6ca62c8f4e801160552aa",
      "pattern": "[file:hashes.'SHA-256' = 'c6905bae088982a2b234451b45db742098f2e2ab4fd6ca62c8f4e801160552aa']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--978d3427-24ab-4f3e-a05f-0d2ed3d6b3a0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ccb7d999ee4d979e175b8c87e09ccda0cbc93b6140471283e3a1f1f9da33759d",
      "pattern": "[file:hashes.'SHA-256' = 'ccb7d999ee4d979e175b8c87e09ccda0cbc93b6140471283e3a1f1f9da33759d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53be0e8e-fca7-4426-b235-bd2fd0d5126b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e20831cecd763d0dc91fb39f3bd61d17002608c5a40a6cf0bd16111f4e50d341",
      "pattern": "[file:hashes.'SHA-256' = 'e20831cecd763d0dc91fb39f3bd61d17002608c5a40a6cf0bd16111f4e50d341']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--23891645-280f-454b-9f24-d7ec9685a0d0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: eb9c1649e01db6a9a94d5d50373e54865d672b14ad6f221c98047c562d3cc0f3",
      "pattern": "[file:hashes.'SHA-256' = 'eb9c1649e01db6a9a94d5d50373e54865d672b14ad6f221c98047c562d3cc0f3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d3c5f410-a85f-4b1e-960b-8425e7808f37",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ee90b01b16099e0bb23d4653607a3a559590fc8d0c43120b8456fb1860d2e630",
      "pattern": "[file:hashes.'SHA-256' = 'ee90b01b16099e0bb23d4653607a3a559590fc8d0c43120b8456fb1860d2e630']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--940a7f4d-2128-4a1a-9da8-b983d1f838cd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: fb16933b09a4fcca5beff93da05566e924017fb534a2f45caf57b57a633f43a6",
      "pattern": "[file:hashes.'SHA-256' = 'fb16933b09a4fcca5beff93da05566e924017fb534a2f45caf57b57a633f43a6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DRILLAPP: new backdoor targeting Ukrainian entities with pos",
          "url": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0f1187e-0e39-454a-9218-a1bd9ecbe16a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 929c6399c4fde4fe236bd6712b2c53f750d9ad3a",
      "pattern": "[file:hashes.'SHA-1' = '929c6399c4fde4fe236bd6712b2c53f750d9ad3a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "kubernetes-el Compromised: How a Pwn Request Exploited a Pop",
          "url": "https://www.stepsecurity.io/blog/kubernetes-el-compromised-how-a-pwn-request-exploited-a-popular-emacs-package"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "StepSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--851f7bb0-66fb-42a8-a28c-2a923814205c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 99B454262DC26B081600E844371982A49D334E5E",
      "pattern": "[file:hashes.'SHA-1' = '99B454262DC26B081600E844371982A49D334E5E']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Sednit reloaded: Back in the trenches",
          "url": "https://www.welivesecurity.com/en/eset-research/sednit-reloaded-back-trenches/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--18e21883-8b14-41d7-9632-df7e4685f9ed",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: D0DB619A7A160949528D46D20FC0151BF9775C32",
      "pattern": "[file:hashes.'SHA-1' = 'D0DB619A7A160949528D46D20FC0151BF9775C32']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Sednit reloaded: Back in the trenches",
          "url": "https://www.welivesecurity.com/en/eset-research/sednit-reloaded-back-trenches/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cc813435-d752-458e-87a8-40d2cdd0ba9b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-22054",
      "pattern": "[vulnerability:name = 'CVE-2021-22054']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-22054 \u2014 Omnissa Workspace ONE Server-Side",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dfacffda-0317-4967-b613-50f739c2cbb8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-26399",
      "pattern": "[vulnerability:name = 'CVE-2025-26399']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-26399 \u2014 SolarWinds Web Help Desk Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67e0dc8c-9835-42c9-ae30-4b67c02ed754",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-40536",
      "pattern": "[vulnerability:name = 'CVE-2025-40536']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-26399 \u2014 SolarWinds Web Help Desk Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-40536 \u2014 SolarWinds Web Help Desk Security",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--994d53fb-b815-4d4d-8a46-2aa5d2cf3f25",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-40551",
      "pattern": "[vulnerability:name = 'CVE-2025-40551']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-26399 \u2014 SolarWinds Web Help Desk Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-40551 \u2014 SolarWinds Web Help Desk Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a56c05d7-5747-4f51-82bd-9117e418204d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-1603",
      "pattern": "[vulnerability:name = 'CVE-2026-1603']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-1603 \u2014 Ivanti Endpoint Manager (EPM) Auth",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--173dc685-edd4-473b-b0d3-4c4801d9ec43",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: auth.qgtxtebl.workers.dev",
      "pattern": "[domain-name:value = 'auth.qgtxtebl.workers.dev']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-26399 \u2014 SolarWinds Web Help Desk Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--265a6392-088f-41a1-88a5-78aa40b84eb3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: files.catbox.moe",
      "pattern": "[domain-name:value = 'files.catbox.moe']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-26399 \u2014 SolarWinds Web Help Desk Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a7e47ff8-0cb0-4ea2-b95f-eacb53f2ac8a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: v2-api.mooo.com",
      "pattern": "[domain-name:value = 'v2-api.mooo.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-26399 \u2014 SolarWinds Web Help Desk Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2cce8c7c-7880-4fec-85bc-bb7054d007e9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: vdfccjpnedujhrzscjtq.supabase.co",
      "pattern": "[domain-name:value = 'vdfccjpnedujhrzscjtq.supabase.co']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-26399 \u2014 SolarWinds Web Help Desk Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--78b4d7d5-536d-4e64-8644-0f415f2fbaf8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 34b2a6c334813adb2cc70f5bd666c4afbdc4a6d8a58cc1c7a902b13bbd2381f4",
      "pattern": "[file:hashes.'SHA-256' = '34b2a6c334813adb2cc70f5bd666c4afbdc4a6d8a58cc1c7a902b13bbd2381f4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-26399 \u2014 SolarWinds Web Help Desk Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4294b0a5-016e-4612-8e60-eb41bcacc728",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 46831be6e577e3120084ee992168cca5af2047d4a08e3fd67ecd90396393b751",
      "pattern": "[file:hashes.'SHA-256' = '46831be6e577e3120084ee992168cca5af2047d4a08e3fd67ecd90396393b751']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-26399 \u2014 SolarWinds Web Help Desk Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--93a149ea-0174-4efd-9ed8-8b3ab26c5965",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 897eae49e6c32de3f4bfa229ad4f2d6e56bcf7a39c6c962d02e5c85cd538a189",
      "pattern": "[file:hashes.'SHA-256' = '897eae49e6c32de3f4bfa229ad4f2d6e56bcf7a39c6c962d02e5c85cd538a189']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-26399 \u2014 SolarWinds Web Help Desk Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--deefad43-44a8-4099-915e-32038812eb2e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: bbd6e120bf55309141f75c85cc94455b1337a1a4333f6868b245b2edfa97ef44",
      "pattern": "[file:hashes.'SHA-256' = 'bbd6e120bf55309141f75c85cc94455b1337a1a4333f6868b245b2edfa97ef44']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-26399 \u2014 SolarWinds Web Help Desk Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--560173fc-c821-44c7-a807-56fef61ce08f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-7921",
      "pattern": "[vulnerability:name = 'CVE-2017-7921']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-7921 \u2014 Hikvision Multiple Products Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-25078 \u2014 D-Link DCS-2530L and DCS-2670L De",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fb6a4f76-0a02-4d0a-9245-2e6609a0c3d1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-22681",
      "pattern": "[vulnerability:name = 'CVE-2021-22681']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-22681 \u2014 Rockwell Multiple Products Insuff",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--175c8c65-f02f-43b5-b7a6-8b4752c3c838",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30952",
      "pattern": "[vulnerability:name = 'CVE-2021-30952']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30952 \u2014 Apple Multiple Products Integer O",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32c8dde6-4571-42c2-9356-073d6aa10377",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-41974",
      "pattern": "[vulnerability:name = 'CVE-2023-41974']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41974 \u2014 Apple iOS and iPadOS Use-After-Fr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4d4ce4e3-e97d-49ab-b2e1-58ffa1a8128a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-43000",
      "pattern": "[vulnerability:name = 'CVE-2023-43000']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-43000 \u2014 Apple Multiple products Use-After",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41974 \u2014 Apple iOS and iPadOS Use-After-Fr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f187ac07-7c7b-4fcf-8cdf-3bd40df0f8f4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-23222",
      "pattern": "[vulnerability:name = 'CVE-2024-23222']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41974 \u2014 Apple iOS and iPadOS Use-After-Fr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-23222 \u2014 Apple Multiple Products WebKit Ty",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c8f5f99b-e6b1-4578-a321-95854aa7e437",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-21385",
      "pattern": "[vulnerability:name = 'CVE-2026-21385']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-21385 \u2014 Qualcomm Multiple Chipsets Memory",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5098611c-dbe0-4fb1-a862-ecf95e6fd027",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-22719",
      "pattern": "[vulnerability:name = 'CVE-2026-22719']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-22719 \u2014 Broadcom VMware Aria Operations C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0eb782ce-fa67-42cd-9b8a-4b7381fe82ee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: decoorat.net",
      "pattern": "[domain-name:value = 'decoorat.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d7c4aa56-e322-4903-acee-5b3135f0be88",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: decoraat.net",
      "pattern": "[domain-name:value = 'decoraat.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e257059c-7e37-4778-8966-60d1b89883e0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: gesecole.net",
      "pattern": "[domain-name:value = 'gesecole.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--143cf77b-ead7-4226-9cbc-f45b8d53eb33",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: onedow.gesecole.net",
      "pattern": "[domain-name:value = 'onedow.gesecole.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7e40923d-088b-494e-905f-d8c5457f2121",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: onedown.gesecole.net",
      "pattern": "[domain-name:value = 'onedown.gesecole.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--143b9c89-dd99-4cd6-89b9-0c236ecf51eb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 381247c1d4c68a406237d7d3aa030930",
      "pattern": "[file:hashes.MD5 = '381247c1d4c68a406237d7d3aa030930']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--24a2fc85-d980-4358-90d2-534cf095d4d5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 769687f93869a70511aac1ef7c752455",
      "pattern": "[file:hashes.MD5 = '769687f93869a70511aac1ef7c752455']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b7adace8-91a2-4540-a988-cd4bc05ddfb8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 7a75e713db41c28378e823322fdea0fd",
      "pattern": "[file:hashes.MD5 = '7a75e713db41c28378e823322fdea0fd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87c09b7d-da86-4dbf-b0bf-d1f6b29f4df9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 9f331a11a054f33664fe86543fc34cf0",
      "pattern": "[file:hashes.MD5 = '9f331a11a054f33664fe86543fc34cf0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--83716625-b937-48e6-af8b-dedb69895115",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e7cb954f4bbdbadbd2c0206577621683",
      "pattern": "[file:hashes.MD5 = 'e7cb954f4bbdbadbd2c0206577621683']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c1b84daa-212b-4507-9ef1-df88ac864128",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 1151100a0aa1ed88f7897709444fd3b3b1044c10",
      "pattern": "[file:hashes.'SHA-1' = '1151100a0aa1ed88f7897709444fd3b3b1044c10']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cbdfa22c-1933-45f0-80c7-4acd5f1595aa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 2336c9a20ecd53ec1be468282bae94c8160eb93a",
      "pattern": "[file:hashes.'SHA-1' = '2336c9a20ecd53ec1be468282bae94c8160eb93a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ee7ecb4e-c997-482f-9703-7dd4ed806ec2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: ad833604d230b241e180950980ea462b3812f82a",
      "pattern": "[file:hashes.'SHA-1' = 'ad833604d230b241e180950980ea462b3812f82a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--171146e4-f753-4ca3-960c-8352e0498e8d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: d1a86ed06b18efef5ce724d2129cf1583b779b44",
      "pattern": "[file:hashes.'SHA-1' = 'd1a86ed06b18efef5ce724d2129cf1583b779b44']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--97d57293-73a7-416a-8f6e-74b97177f8f0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: f06da8e29c3f0fafabfc3a524ae8b21730b57ed3",
      "pattern": "[file:hashes.'SHA-1' = 'f06da8e29c3f0fafabfc3a524ae8b21730b57ed3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3f90a19c-bf1c-479a-93b7-d67c0a38ee31",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 29cd44aa2a51a200d82cca578d97dc13241bc906ea6a33b132c6ca567dc8f3ad",
      "pattern": "[file:hashes.'SHA-256' = '29cd44aa2a51a200d82cca578d97dc13241bc906ea6a33b132c6ca567dc8f3ad']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e34f6140-1a92-4d81-8d86-e8812b9d59e6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 46314092c8d00ab93cbbdc824b9fc39dec9303169163b9625bae3b1717d70ebc",
      "pattern": "[file:hashes.'SHA-256' = '46314092c8d00ab93cbbdc824b9fc39dec9303169163b9625bae3b1717d70ebc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b85b2320-daab-4e17-831f-da4eaefcc28d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5f9af68db10b029453264cfc9b8eee4265549a2855bb79668ccfc571fb11f5fc",
      "pattern": "[file:hashes.'SHA-256' = '5f9af68db10b029453264cfc9b8eee4265549a2855bb79668ccfc571fb11f5fc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--579269e4-a944-48e0-b94b-619508e5b582",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6df8649bf4e233ee86a896ee8e5a3b3179c168ef927ac9283b945186f8629ee7",
      "pattern": "[file:hashes.'SHA-256' = '6df8649bf4e233ee86a896ee8e5a3b3179c168ef927ac9283b945186f8629ee7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9aad2886-2acd-4741-8b47-ccc58af5c344",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8421e7995778faf1f2a902fb2c51d85ae39481f443b7b3186068d5c33c472d99",
      "pattern": "[file:hashes.'SHA-256' = '8421e7995778faf1f2a902fb2c51d85ae39481f443b7b3186068d5c33c472d99']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--961add3b-9b0a-4baf-b215-11a063e30171",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d293ded5a63679b81556d2c622c78be6253f500b6751d4eeb271e6500a23b21e",
      "pattern": "[file:hashes.'SHA-256' = 'd293ded5a63679b81556d2c622c78be6253f500b6751d4eeb271e6500a23b21e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cf7faec5-baba-448d-b113-d84756d9b3a1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: de8ddc2451fb1305d76ab20661725d11c77625aeeaa1447faf3fbf56706c87f1",
      "pattern": "[file:hashes.'SHA-256' = 'de8ddc2451fb1305d76ab20661725d11c77625aeeaa1447faf3fbf56706c87f1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--15b1db91-11d9-4484-90f8-9114c6766ac4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e7ed0cd4115f3ff35c38d36cc50c6a13eba2d845554439a36108789cd1e05b17",
      "pattern": "[file:hashes.'SHA-256' = 'e7ed0cd4115f3ff35c38d36cc50c6a13eba2d845554439a36108789cd1e05b17']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlugX Meeting Invitation via MSBuild and GDATA",
          "url": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Lab52"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0ff95055-e1e5-4ff0-afd3-6cae640b0e07",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-20775",
      "pattern": "[vulnerability:name = 'CVE-2022-20775']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-20775 \u2014 Cisco SD-WAN Path Traversal Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e8b46be0-4bc7-4bdb-96f9-77163cb29637",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-25108",
      "pattern": "[vulnerability:name = 'CVE-2026-25108']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-25108 \u2014 Soliton Systems K.K FileZen OS Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4c4fcd6-9ceb-4961-89c0-91fac93a11b3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-68461",
      "pattern": "[vulnerability:name = 'CVE-2025-68461']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-68461 \u2014 RoundCube Webmail Cross-site Scri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--696c20f6-3a40-4e7b-b527-5b9af8aec9c6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: attacker.oastify.com",
      "pattern": "[domain-name:value = 'attacker.oastify.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "How \u201cClinejection\u201d Turned an AI Bot into a Supply Chain Atta",
          "url": "https://snyk.io/blog/cline-supply-chain-attack-prompt-injection-github-actions/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2bf4a110-46b0-40ad-91fb-ac243bcdaab3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-22175",
      "pattern": "[vulnerability:name = 'CVE-2021-22175']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-22175 \u2014 GitLab Server-Side Request Forger",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4f18ac4-2be9-4ebe-9028-608f4e160a6e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-22769",
      "pattern": "[vulnerability:name = 'CVE-2026-22769']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-22769 \u2014 Dell RecoverPoint for Virtual Mac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--edca813a-529f-4bb9-b133-f901fb40ec3b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2008-0015",
      "pattern": "[vulnerability:name = 'CVE-2008-0015']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2008-0015 \u2014  Microsoft Windows Video ActiveX C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ead5c52b-0972-4738-9abc-6d985619b1f6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-7796",
      "pattern": "[vulnerability:name = 'CVE-2020-7796']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-7796 \u2014 Synacor Zimbra Collaboration Suite",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b366d460-1c4c-45e5-bf86-646ae4cd20e7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-7694",
      "pattern": "[vulnerability:name = 'CVE-2024-7694']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-7694 \u2014 TeamT5 ThreatSonar Anti-Ransomware",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--820519ee-1aed-409d-8ad9-8cce4260d270",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-2441",
      "pattern": "[vulnerability:name = 'CVE-2026-2441']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-2441 \u2014 Google Chromium CSS Use-After-Free",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--19697488-cc04-4bf1-b414-32707d8fa185",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-3094",
      "pattern": "[vulnerability:name = 'CVE-2024-3094']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "2024 in Review: The Evolution of CI/CD Security & What's Nex",
          "url": "https://www.stepsecurity.io/blog/2024-in-review-the-evolution-of-ci-cd-security-whats-next"
        },
        {
          "source_name": "The XZ backdoor CVE-2024-3094",
          "url": "https://snyk.io/blog/the-xz-backdoor-cve-2024-3094/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--05b463f1-0a41-4d06-9a2d-f884ac3bc5e5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 319feb5a9cddd81955d915b5632b4a5f8f9080281fb46e2f6d69d53f693c23ae",
      "pattern": "[file:hashes.'SHA-256' = '319feb5a9cddd81955d915b5632b4a5f8f9080281fb46e2f6d69d53f693c23ae']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "2024 in Review: The Evolution of CI/CD Security & What's Nex",
          "url": "https://www.stepsecurity.io/blog/2024-in-review-the-evolution-of-ci-cd-security-whats-next"
        },
        {
          "source_name": "The XZ backdoor CVE-2024-3094",
          "url": "https://snyk.io/blog/the-xz-backdoor-cve-2024-3094/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--044fac73-9755-4a11-bf71-738c49e97a89",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5448850cdc3a7ae41ff53b433c2adbd0ff492515012412ee63a40d2685db3049",
      "pattern": "[file:hashes.'SHA-256' = '5448850cdc3a7ae41ff53b433c2adbd0ff492515012412ee63a40d2685db3049']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "2024 in Review: The Evolution of CI/CD Security & What's Nex",
          "url": "https://www.stepsecurity.io/blog/2024-in-review-the-evolution-of-ci-cd-security-whats-next"
        },
        {
          "source_name": "The XZ backdoor CVE-2024-3094",
          "url": "https://snyk.io/blog/the-xz-backdoor-cve-2024-3094/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a3dc31e6-ae54-49ac-b715-2dbe91cbe242",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 605861f833fc181c7cdcabd5577ddb8989bea332648a8f498b4eef89b8f85ad4",
      "pattern": "[file:hashes.'SHA-256' = '605861f833fc181c7cdcabd5577ddb8989bea332648a8f498b4eef89b8f85ad4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "2024 in Review: The Evolution of CI/CD Security & What's Nex",
          "url": "https://www.stepsecurity.io/blog/2024-in-review-the-evolution-of-ci-cd-security-whats-next"
        },
        {
          "source_name": "The XZ backdoor CVE-2024-3094",
          "url": "https://snyk.io/blog/the-xz-backdoor-cve-2024-3094/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a4ce0cd1-6a93-4877-8837-76e8049aeaad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8fa641c454c3e0f76de73b7cc3446096b9c8b9d33d406d38b8ac76090b0344fd",
      "pattern": "[file:hashes.'SHA-256' = '8fa641c454c3e0f76de73b7cc3446096b9c8b9d33d406d38b8ac76090b0344fd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "2024 in Review: The Evolution of CI/CD Security & What's Nex",
          "url": "https://www.stepsecurity.io/blog/2024-in-review-the-evolution-of-ci-cd-security-whats-next"
        },
        {
          "source_name": "The XZ backdoor CVE-2024-3094",
          "url": "https://snyk.io/blog/the-xz-backdoor-cve-2024-3094/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ddba88e6-eab9-40ee-b365-47ffbd2599c8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b418bfd34aa246b2e7b5cb5d263a640e5d080810f767370c4d2c24662a274963",
      "pattern": "[file:hashes.'SHA-256' = 'b418bfd34aa246b2e7b5cb5d263a640e5d080810f767370c4d2c24662a274963']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "2024 in Review: The Evolution of CI/CD Security & What's Nex",
          "url": "https://www.stepsecurity.io/blog/2024-in-review-the-evolution-of-ci-cd-security-whats-next"
        },
        {
          "source_name": "The XZ backdoor CVE-2024-3094",
          "url": "https://snyk.io/blog/the-xz-backdoor-cve-2024-3094/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cbb8f42e-3379-4768-851e-a5fb2bb6ae38",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: cbeef92e67bf41ca9c015557d81f39adaba67ca9fb3574139754999030b83537",
      "pattern": "[file:hashes.'SHA-256' = 'cbeef92e67bf41ca9c015557d81f39adaba67ca9fb3574139754999030b83537']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "2024 in Review: The Evolution of CI/CD Security & What's Nex",
          "url": "https://www.stepsecurity.io/blog/2024-in-review-the-evolution-of-ci-cd-security-whats-next"
        },
        {
          "source_name": "The XZ backdoor CVE-2024-3094",
          "url": "https://snyk.io/blog/the-xz-backdoor-cve-2024-3094/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "StepSecurity",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9106f192-c50a-4fec-8a60-d171448f3e2e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-1731",
      "pattern": "[vulnerability:name = 'CVE-2026-1731']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-1731 \u2014 BeyondTrust Remote Support (RS) an",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32935d2f-c4d0-4798-a07c-36b80b4fc94f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-43468",
      "pattern": "[vulnerability:name = 'CVE-2024-43468']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-43468 \u2014 Microsoft Configuration Manager S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--133ce544-bf30-428d-bacd-34cbff65cf05",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-15556",
      "pattern": "[vulnerability:name = 'CVE-2025-15556']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-15556 \u2014 Notepad++ Download of Code Withou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9d21b4ee-11aa-4fa8-b42e-1a88a6cc1146",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-20700",
      "pattern": "[vulnerability:name = 'CVE-2026-20700']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-20700 \u2014 Apple Multiple Buffer Overflow Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67e1f888-ef20-4e44-8699-26202f54c98e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-21510",
      "pattern": "[vulnerability:name = 'CVE-2026-21510']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-21510 \u2014 Microsoft Windows Shell Protectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a516a3e6-4792-4a79-b6c7-4105d55a1780",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-21513",
      "pattern": "[vulnerability:name = 'CVE-2026-21513']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-21513 \u2014 Microsoft MSHTML Framework Protec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2026-21510 \u2014 Microsoft Windows Shell Protectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8bf4e163-8e4b-4ee4-a708-957c6f2ef5ea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-21514",
      "pattern": "[vulnerability:name = 'CVE-2026-21514']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-21514 \u2014 Microsoft Office Word Reliance on",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8e1e735a-a48f-4d56-9b80-9992e21f02e8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-21519",
      "pattern": "[vulnerability:name = 'CVE-2026-21519']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-21519 \u2014 Microsoft Windows Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--96368351-6642-4b99-9eab-40836108e728",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-21525",
      "pattern": "[vulnerability:name = 'CVE-2026-21525']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-21525 \u2014 Microsoft Windows NULL Pointer De",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7a7737f6-bd69-437f-9f0d-a154f4161174",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-21533",
      "pattern": "[vulnerability:name = 'CVE-2026-21533']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-21533 \u2014 Microsoft Windows Improper Privil",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ab1f09ed-f77e-4fcf-a062-08bb7f938057",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: github.com/aztr0nutz/NET_NINJA.v1.2",
      "pattern": "[domain-name:value = 'github.com/aztr0nutz/NET_NINJA.v1.2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "How a Malicious Google Skill on ClawHub Tricks Users Into In",
          "url": "https://snyk.io/blog/clawhub-malicious-google-skill-openclaw-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--42fedc45-8342-456d-805a-37d5d3cfca22",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: github.com/denboss99/openclaw-core",
      "pattern": "[domain-name:value = 'github.com/denboss99/openclaw-core']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "How a Malicious Google Skill on ClawHub Tricks Users Into In",
          "url": "https://snyk.io/blog/clawhub-malicious-google-skill-openclaw-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--19390380-a24d-4784-ac80-b8d99e78a233",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: rentry.co/openclaw-core",
      "pattern": "[domain-name:value = 'rentry.co/openclaw-core']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "How a Malicious Google Skill on ClawHub Tricks Users Into In",
          "url": "https://snyk.io/blog/clawhub-malicious-google-skill-openclaw-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e36c1663-b700-4e70-87d0-bbea52e2f660",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: setup-service.com",
      "pattern": "[domain-name:value = 'setup-service.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "How a Malicious Google Skill on ClawHub Tricks Users Into In",
          "url": "https://snyk.io/blog/clawhub-malicious-google-skill-openclaw-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9495f362-4489-4a19-bdb0-1a41d00a054d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-11953",
      "pattern": "[vulnerability:name = 'CVE-2025-11953']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-11953 \u2014 React Native Community CLI OS Com",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4c511855-050a-4fa8-a144-92a7ffdbbd4e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-24423",
      "pattern": "[vulnerability:name = 'CVE-2026-24423']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-24423 \u2014 SmarterTools SmarterMail Missing ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f56af1c2-8c3b-4a10-8b77-998426c6b604",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-19006",
      "pattern": "[vulnerability:name = 'CVE-2019-19006']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-19006 \u2014  Sangoma FreePBX Improper Authent",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb1c2c3b-7c87-4bc4-97a9-796d3047b529",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-39935",
      "pattern": "[vulnerability:name = 'CVE-2021-39935']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-39935 \u2014 GitLab Community and Enterprise E",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cfff00ee-6f9d-4b87-8b55-346ac6026ff7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-64328",
      "pattern": "[vulnerability:name = 'CVE-2025-64328']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-64328 \u2014 Sangoma FreePBX OS Command Inject",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32d78c23-da6b-4f2f-beb0-b419c817e1fd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: progamevl.ru",
      "pattern": "[domain-name:value = 'progamevl.ru']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DynoWiper update: Technical analysis and attribution",
          "url": "https://www.welivesecurity.com/en/eset-research/dynowiper-update-technical-analysis-attribution/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e84e8d2b-0cdc-48c9-b0f5-ea2cf6bd05c9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 31.172.71.5",
      "pattern": "[ipv4-addr:value = '31.172.71.5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "DynoWiper update: Technical analysis and attribution",
          "url": "https://www.welivesecurity.com/en/eset-research/dynowiper-update-technical-analysis-attribution/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d26b5a2a-64fb-4ced-8277-41248c8649f0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-1281",
      "pattern": "[vulnerability:name = 'CVE-2026-1281']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-1281 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--214b3207-2469-40c8-ac84-842a4a6c85d4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-24858",
      "pattern": "[vulnerability:name = 'CVE-2026-24858']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-24858 \u2014 Fortinet Multiple Products Authen",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a964aeea-8c3d-4d28-bd56-a211810e44d9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-14634",
      "pattern": "[vulnerability:name = 'CVE-2018-14634']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-14634 \u2014 Linux Kernel Integer Overflow Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b5b7fa53-e910-463b-9d84-c2381d01df71",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-52691",
      "pattern": "[vulnerability:name = 'CVE-2025-52691']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-52691 \u2014 SmarterTools SmarterMail Unrestri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3dee5b73-14ef-4636-a1df-9321c7fb227c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-21509",
      "pattern": "[vulnerability:name = 'CVE-2026-21509']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-21509 \u2014 Microsoft Office Security Feature",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4a19753-838f-483e-ba7d-7bd374e8364f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-23760",
      "pattern": "[vulnerability:name = 'CVE-2026-23760']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-23760 \u2014 SmarterTools SmarterMail Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d3543c53-6d1d-4010-ac3c-3cc0486ba2b6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-24061",
      "pattern": "[vulnerability:name = 'CVE-2026-24061']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-24061 \u2014 GNU InetUtils Argument Injection ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--80a77fdd-57ef-4e29-8617-a80a775e6b2a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-37079",
      "pattern": "[vulnerability:name = 'CVE-2024-37079']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-37079 \u2014 Broadcom VMware vCenter Server Ou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c23995d-a5a3-4b15-9245-108bc519feb3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 4ec3c90846af6b79ee1a5188eefa3fd21f6d4cf6",
      "pattern": "[file:hashes.'SHA-1' = '4ec3c90846af6b79ee1a5188eefa3fd21f6d4cf6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "ESET Research: Sandworm behind cyberattack on Poland\u2019s power",
          "url": "https://www.welivesecurity.com/en/eset-research/eset-research-sandworm-cyberattack-poland-power-grid-late-2025/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e2ffa67b-99d3-43ad-8682-e5c330e33dff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-31125",
      "pattern": "[vulnerability:name = 'CVE-2025-31125']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31125 \u2014 Vite Vitejs Improper Access Contr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--98062afc-4d4d-4cb5-a98a-4c287d0a9c2b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-34026",
      "pattern": "[vulnerability:name = 'CVE-2025-34026']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-34026 \u2014 Versa Concerto Improper Authentic",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--734efca6-4203-4cb3-a25c-7eddfba0a323",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-54313",
      "pattern": "[vulnerability:name = 'CVE-2025-54313']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54313 \u2014 Prettier eslint-config-prettier E",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "Maintainers of ESLint Prettier Plugin Attacked via npm Suppl",
          "url": "https://snyk.io/blog/maintainers-of-eslint-prettier-plugin-attacked-via-npm-supply-chain-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8bc4ed2e-00f7-4c58-84b5-e3817952c69f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-68645",
      "pattern": "[vulnerability:name = 'CVE-2025-68645']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-68645 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1190dc83-fd9a-4b1f-b162-45b64f32f16f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-20045",
      "pattern": "[vulnerability:name = 'CVE-2026-20045']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-20045 \u2014 Cisco Unified Communications Prod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--28b35cd8-b9b9-4009-b22c-1c932a459593",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2026-20805",
      "pattern": "[vulnerability:name = 'CVE-2026-20805']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2026-20805 \u2014 Microsoft Windows Information Dis",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a29d9c63-fe04-4b50-89c2-153477fea8e8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-8110",
      "pattern": "[vulnerability:name = 'CVE-2025-8110']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-8110 \u2014 Gogs Path Traversal Vulnerability",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--638a2417-8381-49f9-a4ea-75f59f0aefc4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2009-0556",
      "pattern": "[vulnerability:name = 'CVE-2009-0556']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2009-0556 \u2014 Microsoft Office PowerPoint Code I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7ac0b9b1-e848-460b-ae6a-7db5622efa3f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-37164",
      "pattern": "[vulnerability:name = 'CVE-2025-37164']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-37164 \u2014 Hewlett Packard Enterprise (HPE) ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cd5091e8-9388-411b-8a78-a9fe997c983e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-14847",
      "pattern": "[vulnerability:name = 'CVE-2025-14847']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-14847 \u2014 MongoDB and MongoDB Server Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e937d29a-e82c-4b69-abbd-96b791eb03ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-52163",
      "pattern": "[vulnerability:name = 'CVE-2023-52163']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-52163 \u2014 Digiever DS-2105 Pro Missing Auth",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7ec8dffc-d820-484a-8e3c-f1f066c1e79a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-50165",
      "pattern": "[vulnerability:name = 'CVE-2025-50165']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Revisiting CVE-2025-50165: A critical flaw in Windows Imagin",
          "url": "https://www.welivesecurity.com/en/eset-research/revisiting-cve-2025-50165-critical-flaw-windows-imaging-component/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--07059479-38f3-469c-9594-bce57a9aaaec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-14733",
      "pattern": "[vulnerability:name = 'CVE-2025-14733']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-14733 \u2014 WatchGuard Firebox Out of Bounds ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4af9a62-b7a5-4957-8638-2984962c12a7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-20393",
      "pattern": "[vulnerability:name = 'CVE-2025-20393']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-20393 \u2014 Cisco Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f7203e70-d6eb-4579-b24b-2040b6fa2ad2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-40602",
      "pattern": "[vulnerability:name = 'CVE-2025-40602']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-40602 \u2014 SonicWall SMA1000 Missing Authori",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--99afce69-0442-4143-8935-bccdcdb8c855",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-59374",
      "pattern": "[vulnerability:name = 'CVE-2025-59374']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-59374 \u2014 ASUS Live Update Embedded Malicio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--907902be-c721-4911-9e4e-7b3ee18ee4d2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-59718",
      "pattern": "[vulnerability:name = 'CVE-2025-59718']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-59718 \u2014 Fortinet Multiple Products Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4bf72084-9288-4002-b66b-b01db8f6d564",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-59719",
      "pattern": "[vulnerability:name = 'CVE-2025-59719']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-59718 \u2014 Fortinet Multiple Products Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b7164fe-f618-451c-a89a-73a46e183009",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-14611",
      "pattern": "[vulnerability:name = 'CVE-2025-14611']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-14611 \u2014 Gladinet CentreStack and Triofox ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb5873ac-7258-4d64-b753-b9290878eabc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-43529",
      "pattern": "[vulnerability:name = 'CVE-2025-43529']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-43529 \u2014 Apple Multiple Products Use-After",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c366455-068c-42e0-a1fa-d22648784ad9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-4063",
      "pattern": "[vulnerability:name = 'CVE-2018-4063']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-4063 \u2014 Sierra Wireless AirLink ALEOS Unre",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d1a1d639-affc-4daf-b664-4f213c038d62",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-14174",
      "pattern": "[vulnerability:name = 'CVE-2025-14174']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-14174 \u2014 Google Chromium Out of Bounds Mem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fa97b4ba-e78f-47df-8c6f-d224ced97d8a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-58360",
      "pattern": "[vulnerability:name = 'CVE-2025-58360']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-58360 \u2014 OSGeo GeoServer Improper Restrict",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1ab6dbd5-b212-4a03-aaca-55d21f4eb75e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-6218",
      "pattern": "[vulnerability:name = 'CVE-2025-6218']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-6218 \u2014 RARLAB WinRAR Path Traversal Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b8766ebd-0669-4948-9d6d-662e5c7d5b5a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-62221",
      "pattern": "[vulnerability:name = 'CVE-2025-62221']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-62221 \u2014 Microsoft Windows Use After Free ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c5390289-2b5e-4e12-ac76-7ff8d783e7be",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-66644",
      "pattern": "[vulnerability:name = 'CVE-2025-66644']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-66644 \u2014 Array Networks ArrayOS AG OS Comm",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--227bcff6-7371-4a25-a106-37c08b8aa0c7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-26828",
      "pattern": "[vulnerability:name = 'CVE-2021-26828']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26828 \u2014 OpenPLC ScadaBR Unrestricted Uplo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--93875f25-fe94-43cb-9cf7-fae5a2bbbf43",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-66478",
      "pattern": "[vulnerability:name = 'CVE-2025-66478']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4bf0f5c8-bc09-49b7-97b3-88c74afd4afa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: anywherehost.site",
      "pattern": "[domain-name:value = 'anywherehost.site']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a50f8c9b-85a7-4b13-966f-51a2130ad319",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: donaldjtrmp.anondns.net",
      "pattern": "[domain-name:value = 'donaldjtrmp.anondns.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ba881798-ed88-4145-b7bc-172a7cea345f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ghostbin.axel.org",
      "pattern": "[domain-name:value = 'ghostbin.axel.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--efc62b0d-5a71-4419-9ddf-18a237997254",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: help.093214.xyz",
      "pattern": "[domain-name:value = 'help.093214.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--01f99a92-0b9b-4738-b984-9cf965483f96",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: keep.camdvr.org",
      "pattern": "[domain-name:value = 'keep.camdvr.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--48a8d581-9a39-4373-9d09-6aadbaa250d7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: krebsec.anondns.net",
      "pattern": "[domain-name:value = 'krebsec.anondns.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8882dc13-090b-4d3c-8de7-4b7566f34c55",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: labubu.anondns.net",
      "pattern": "[domain-name:value = 'labubu.anondns.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--39bc5a0f-0258-4dfe-b7a2-a8278d8dc0b5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: overcome-pmc-conferencing-books.trycloudflare.com",
      "pattern": "[domain-name:value = 'overcome-pmc-conferencing-books.trycloudflare.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e704d6d2-36b3-45aa-9385-719707bb83df",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: reactcdn.windowserrorapis.com",
      "pattern": "[domain-name:value = 'reactcdn.windowserrorapis.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b2f0db91-cd00-4bd7-b9c7-51c3d0028227",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: res.qiqigece.top",
      "pattern": "[domain-name:value = 'res.qiqigece.top']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5e8ebfbc-f8f3-4735-8735-5d4eb98b8baa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: superminecraft.net.br",
      "pattern": "[domain-name:value = 'superminecraft.net.br']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8316d23d-c148-4439-97ca-57f97511a886",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: vip.kof97.lol",
      "pattern": "[domain-name:value = 'vip.kof97.lol']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--21a9b74c-37d0-4c77-b46a-6ea136ba5f39",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: vps-zap812595-1.zap-srv.com",
      "pattern": "[domain-name:value = 'vps-zap812595-1.zap-srv.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d7ed5790-d3fe-40d7-8068-e08fa7ce0cb2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: xpertclient.net",
      "pattern": "[domain-name:value = 'xpertclient.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--46285d0e-bb05-49cf-97fd-19e936af0840",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 115.42.60.223",
      "pattern": "[ipv4-addr:value = '115.42.60.223']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--51c39659-9d3a-4997-8e7a-1a3c62b7e3a7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 140.99.223.178",
      "pattern": "[ipv4-addr:value = '140.99.223.178']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b591827d-3833-4814-985a-6d3540b999ee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 146.88.129.138",
      "pattern": "[ipv4-addr:value = '146.88.129.138']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3c3039ef-a1f8-4f3b-aaf7-7aab35ed3fcb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 156.234.209.103",
      "pattern": "[ipv4-addr:value = '156.234.209.103']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ce7a5662-032d-4a5a-ab05-9dfaab96ef37",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 162.215.170.26",
      "pattern": "[ipv4-addr:value = '162.215.170.26']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2d7033e3-d3d7-4825-a55b-9bde86fc6486",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.238.202.17",
      "pattern": "[ipv4-addr:value = '192.238.202.17']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2426374d-f9b4-4ecb-983e-416b9ff1f837",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.24.123.68",
      "pattern": "[ipv4-addr:value = '193.24.123.68']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ce9a3d4a-070e-47d0-bf3b-af1dbf0e2129",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.34.213.150",
      "pattern": "[ipv4-addr:value = '193.34.213.150']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--12fa5477-3d95-49de-9858-251f1363927e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.69.203.32",
      "pattern": "[ipv4-addr:value = '194.69.203.32']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d671ae34-3266-419b-b920-dd450ed98a4c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 196.251.100.191",
      "pattern": "[ipv4-addr:value = '196.251.100.191']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c1b2c38d-9817-480c-90b1-ec326d4f9462",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 216.158.232.43",
      "pattern": "[ipv4-addr:value = '216.158.232.43']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5909dde1-44c4-4437-ad09-2a9b87ac44fe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 31.56.27.76",
      "pattern": "[ipv4-addr:value = '31.56.27.76']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--778406a4-8b13-43b7-a226-09545b2ff8eb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 31.57.46.28",
      "pattern": "[ipv4-addr:value = '31.57.46.28']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c9203f30-a4ee-4231-bd49-f67df3f83d40",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.162.112.141",
      "pattern": "[ipv4-addr:value = '38.162.112.141']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bbc16b4f-1fd3-49bf-96f6-49fa247a2b6e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.32.158.54",
      "pattern": "[ipv4-addr:value = '45.32.158.54']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5ff431f6-0e5b-461c-b843-9e9f5c023fa3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 46.36.37.85",
      "pattern": "[ipv4-addr:value = '46.36.37.85']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d7330b62-8926-4eac-9f23-52d308e9f5f9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 47.84.57.207",
      "pattern": "[ipv4-addr:value = '47.84.57.207']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f09e3b81-9e48-4c44-8f1a-e87bbb8fc34b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 47.84.79.46",
      "pattern": "[ipv4-addr:value = '47.84.79.46']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1a4aa7d0-0ab4-4816-a187-73d216121a2b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 72.62.67.33",
      "pattern": "[ipv4-addr:value = '72.62.67.33']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--770d189c-5299-4f2e-b1da-892e96a72550",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 92.246.87.48",
      "pattern": "[ipv4-addr:value = '92.246.87.48']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cf14cced-3c0a-4b98-a1f2-10c7b4429be1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 95.169.180.135",
      "pattern": "[ipv4-addr:value = '95.169.180.135']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67c3b550-1d88-4c7c-8b0d-739c4471f74b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1663d98c259001f1b03f82d0c5bee7cfd3c7623ccb83759c994f9ab845939665",
      "pattern": "[file:hashes.'SHA-256' = '1663d98c259001f1b03f82d0c5bee7cfd3c7623ccb83759c994f9ab845939665']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b1ade229-7615-4a6d-824a-4115e18b4d4f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 18c68a982f91f665effe769f663c51cb0567ea2bfc7fab6a1a40d4fe50fc382b",
      "pattern": "[file:hashes.'SHA-256' = '18c68a982f91f665effe769f663c51cb0567ea2bfc7fab6a1a40d4fe50fc382b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d4e84850-5bf4-47d7-816e-203339548dc8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1a3e7b4ee2b2858dbac2d73dd1c52b1ea1d69c6ebb24cc434d1e15e43325b74e",
      "pattern": "[file:hashes.'SHA-256' = '1a3e7b4ee2b2858dbac2d73dd1c52b1ea1d69c6ebb24cc434d1e15e43325b74e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9f555e29-288d-44e5-882f-abca16ac1d0b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1cdd9b0434eb5b06173c7516f99a832dc4614ac10dda171c8eed3272a5e63d20",
      "pattern": "[file:hashes.'SHA-256' = '1cdd9b0434eb5b06173c7516f99a832dc4614ac10dda171c8eed3272a5e63d20']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f2d8a746-96c7-4d19-a2ee-0a174d38cc05",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1e31dc074a4ea7f400cb969ea80e8855b5e7486660aab415da17591bc284ac5b",
      "pattern": "[file:hashes.'SHA-256' = '1e31dc074a4ea7f400cb969ea80e8855b5e7486660aab415da17591bc284ac5b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87e71347-9c67-45a2-9ef4-8888e6d518c0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1f3f0695c7ec63723b2b8e9d50b1838df304821fcb22c7902db1f8248a812035",
      "pattern": "[file:hashes.'SHA-256' = '1f3f0695c7ec63723b2b8e9d50b1838df304821fcb22c7902db1f8248a812035']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b10ba47-ccaf-4531-b7c3-d57e88b8cde7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2b0dc27f035ba1417990a21dafb361e083e4ed94a75a1c49dc45690ecf463de4",
      "pattern": "[file:hashes.'SHA-256' = '2b0dc27f035ba1417990a21dafb361e083e4ed94a75a1c49dc45690ecf463de4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4583ed1a-d62b-4f77-b26b-1a62b97ae753",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2ca913556efd6c45109fd8358edb18d22a10fb6a36c1ab7b2df7594cd5b0adbc",
      "pattern": "[file:hashes.'SHA-256' = '2ca913556efd6c45109fd8358edb18d22a10fb6a36c1ab7b2df7594cd5b0adbc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7d71498c-4c62-4387-aaae-172d2fb7a0e1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 33641bfbbdd5a9cd2320c61f65fe446a2226d8a48e3bd3c29e8f916f0592575f",
      "pattern": "[file:hashes.'SHA-256' = '33641bfbbdd5a9cd2320c61f65fe446a2226d8a48e3bd3c29e8f916f0592575f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--63af77a4-b9a5-4891-aa99-09d8307593f9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4745703f395282a0687def2c7dcf82ed1683f3128bef1686bd74c966273ce1c5",
      "pattern": "[file:hashes.'SHA-256' = '4745703f395282a0687def2c7dcf82ed1683f3128bef1686bd74c966273ce1c5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--06018e31-03a6-4220-a341-1807167d7914",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4a759cbc219bcb3a1f8380a959307b39873fb36a9afd0d57ba0736ad7a02763b",
      "pattern": "[file:hashes.'SHA-256' = '4a759cbc219bcb3a1f8380a959307b39873fb36a9afd0d57ba0736ad7a02763b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe045fcf-bfe4-4cfe-a10b-901985803421",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4ff096fbea443778fec6f960bf2b9c84da121e6d63e189aebaaa6397d9aac948",
      "pattern": "[file:hashes.'SHA-256' = '4ff096fbea443778fec6f960bf2b9c84da121e6d63e189aebaaa6397d9aac948']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--69819257-4ec3-408c-b531-939d29f3612f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 55ae00bc8482afd085fd128965b108cca4adb5a3a8a0ee2957d76f33edd5a864",
      "pattern": "[file:hashes.'SHA-256' = '55ae00bc8482afd085fd128965b108cca4adb5a3a8a0ee2957d76f33edd5a864']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b7e32ce4-92da-4f76-85b1-81d8b6087a79",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 62e9a01307bcf85cdaeecafd6efb5be72a622c43a10f06d6d6d3b566b072228d",
      "pattern": "[file:hashes.'SHA-256' = '62e9a01307bcf85cdaeecafd6efb5be72a622c43a10f06d6d6d3b566b072228d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--08b22760-319d-452e-9a3f-aedc3b7625d8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7d25a97be42b357adcc6d7f56ab01111378a3190134aa788b1f04336eb924b53",
      "pattern": "[file:hashes.'SHA-256' = '7d25a97be42b357adcc6d7f56ab01111378a3190134aa788b1f04336eb924b53']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9eda87c3-3685-4829-be51-bc80abf7e1ea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7f05bad031d22c2bb4352bf0b6b9ee2ca064a4c0e11a317e6fedc694de37737a",
      "pattern": "[file:hashes.'SHA-256' = '7f05bad031d22c2bb4352bf0b6b9ee2ca064a4c0e11a317e6fedc694de37737a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bf0402b1-ba71-4b0b-a7f7-94bbe9b1b650",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9c931f7f7d511108263b0a75f7b9fcbbf9fd67ebcc7cd2e5dcd1266b75053624",
      "pattern": "[file:hashes.'SHA-256' = '9c931f7f7d511108263b0a75f7b9fcbbf9fd67ebcc7cd2e5dcd1266b75053624']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--34db3222-36a1-4210-8efe-8052cdcede96",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a455731133c00fdd2a141bdfba4def34ae58195126f762cdf951056b0ef161d4",
      "pattern": "[file:hashes.'SHA-256' = 'a455731133c00fdd2a141bdfba4def34ae58195126f762cdf951056b0ef161d4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b6fa1a69-7cf8-4a05-b1ef-03eb0f61d9dd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ac2182dfbf56d58b4d63cde3ad6e7a52fed54e52959e4c82d6fc999f20f8d693",
      "pattern": "[file:hashes.'SHA-256' = 'ac2182dfbf56d58b4d63cde3ad6e7a52fed54e52959e4c82d6fc999f20f8d693']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b92adebf-e8bb-40f2-b578-c97d5ea71713",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ac7027f30514d0c00d9e8b379b5ad8150c9827c827dc7ee54d906fc2585b6bf6",
      "pattern": "[file:hashes.'SHA-256' = 'ac7027f30514d0c00d9e8b379b5ad8150c9827c827dc7ee54d906fc2585b6bf6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fb2ebaf2-0f2d-4189-a8f9-8811899708fe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b38ec4c803a2d84277d9c598bfa5434fb8561ddad0ec38da6f9b8ece8104d787",
      "pattern": "[file:hashes.'SHA-256' = 'b38ec4c803a2d84277d9c598bfa5434fb8561ddad0ec38da6f9b8ece8104d787']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76c4fe5f-ca38-4e06-b9c6-f36ad220b77e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: bc31561c44a36e1305692d0af673bc5406f4a5bb2c3f2ffdb613c09b4e80fa9f",
      "pattern": "[file:hashes.'SHA-256' = 'bc31561c44a36e1305692d0af673bc5406f4a5bb2c3f2ffdb613c09b4e80fa9f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8d779426-888a-4ea1-b40f-5264556d9a87",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: bf602b11d99e815e26c88a3a47eb63997d43db8b8c60db06d6fbddf386fd8c4a",
      "pattern": "[file:hashes.'SHA-256' = 'bf602b11d99e815e26c88a3a47eb63997d43db8b8c60db06d6fbddf386fd8c4a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--96b855dd-16e9-40cf-996d-455b925a1317",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c2867570f3bbb71102373a94c7153239599478af84b9c81f2a0368de36f14a7c",
      "pattern": "[file:hashes.'SHA-256' = 'c2867570f3bbb71102373a94c7153239599478af84b9c81f2a0368de36f14a7c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5df40401-21e0-4f79-8aa1-135cd9388eed",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d704541cde64a3eef5c4f80d0d7f96dc96bae8083804c930111024b274557b16",
      "pattern": "[file:hashes.'SHA-256' = 'd704541cde64a3eef5c4f80d0d7f96dc96bae8083804c930111024b274557b16']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a7428c5e-d5d7-40a5-85ef-aef8a1e84c48",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d9313f949af339ed9fafb12374600e66b870961eeb9b2b0d4a3172fd1aa34ed0",
      "pattern": "[file:hashes.'SHA-256' = 'd9313f949af339ed9fafb12374600e66b870961eeb9b2b0d4a3172fd1aa34ed0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87b526cf-7cab-483d-8ea2-82f9f17321c6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e2d7c8491436411474cef5d3b51116ddecfee68bab1e15081752a54772559879",
      "pattern": "[file:hashes.'SHA-256' = 'e2d7c8491436411474cef5d3b51116ddecfee68bab1e15081752a54772559879']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e716e5ea-7f7b-4b48-a522-2d18097ec26f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ebdb85704b2e7ced3673b12c6f3687bc0177a7b1b3caef110213cc93a75da837",
      "pattern": "[file:hashes.'SHA-256' = 'ebdb85704b2e7ced3673b12c6f3687bc0177a7b1b3caef110213cc93a75da837']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--43a902b1-4f0a-4cf8-96e2-c0214dbb8db7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f88ce150345787dd1bcfbc301350033404e32273c9a140f22da80810e3a3f6ea",
      "pattern": "[file:hashes.'SHA-256' = 'f88ce150345787dd1bcfbc301350033404e32273c9a140f22da80810e3a3f6ea']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d8ecb0da-5fcb-4457-a34f-bdd80b377c0a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: fc9e53675e315edeea2292069c3fbc91337c972c936ca0f535da01760814b125",
      "pattern": "[file:hashes.'SHA-256' = 'fc9e53675e315edeea2292069c3fbc91337c972c936ca0f535da01760814b125']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security Advisory: Critical RCE Vulnerabilities in React Ser",
          "url": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b140202-2a43-4345-a4d2-852ea64488c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-48572",
      "pattern": "[vulnerability:name = 'CVE-2025-48572']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-48572 \u2014 Android Framework Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7594f5a8-883e-4d6e-92b8-b4d1e036c232",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-48633",
      "pattern": "[vulnerability:name = 'CVE-2025-48633']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-48633 \u2014 Android Framework Information Dis",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc106330-df89-4c6a-8ff1-a9708598c6cb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-26829",
      "pattern": "[vulnerability:name = 'CVE-2021-26829']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26829 \u2014 OpenPLC ScadaBR Cross-site Script",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b428b329-d370-4541-8eb3-4b0cc563376c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 3d7570d14d34b0ba137d502f042b27b0f37a59fa",
      "pattern": "[file:hashes.'SHA-1' = '3d7570d14d34b0ba137d502f042b27b0f37a59fa']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "SHA1-Hulud, npm supply chain incident",
          "url": "https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--95d01b39-13a3-4001-8589-8d4a334abcb1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: d1829b4708126dcc7bea7437c04d1f10eacd4a16",
      "pattern": "[file:hashes.'SHA-1' = 'd1829b4708126dcc7bea7437c04d1f10eacd4a16']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "SHA1-Hulud, npm supply chain incident",
          "url": "https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a3ed06d8-d28a-4c2e-96bf-85b30cd5f484",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: d60ec97eea19fffb4809bc35b91033b52490ca11",
      "pattern": "[file:hashes.'SHA-1' = 'd60ec97eea19fffb4809bc35b91033b52490ca11']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "SHA1-Hulud, npm supply chain incident",
          "url": "https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a658f177-9c66-447b-a771-f34324ab3d4f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-61757",
      "pattern": "[vulnerability:name = 'CVE-2025-61757']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61757 \u2014 Oracle Fusion Middleware Missing ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ed39599f-b1bb-4719-9c86-26b3f903da18",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-13223",
      "pattern": "[vulnerability:name = 'CVE-2025-13223']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-13223 \u2014 Google Chromium V8 Type Confusion",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e5fff745-7a45-45af-a0c4-e01b158fc524",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ds20221202.dsc.wcsset.com",
      "pattern": "[domain-name:value = 'ds20221202.dsc.wcsset.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlushDaemon compromises network devices for adversary-in-the",
          "url": "https://www.welivesecurity.com/en/eset-research/plushdaemon-compromises-network-devices-for-adversary-in-the-middle-attacks/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2689c174-862a-4cd6-90b8-e6e297c0bc1f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: test.dsc.wcsset.com",
      "pattern": "[domain-name:value = 'test.dsc.wcsset.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlushDaemon compromises network devices for adversary-in-the",
          "url": "https://www.welivesecurity.com/en/eset-research/plushdaemon-compromises-network-devices-for-adversary-in-the-middle-attacks/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--10cf06a9-53c8-4c89-9bbe-4de0d78aa963",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 119.136.153.0",
      "pattern": "[ipv4-addr:value = '119.136.153.0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlushDaemon compromises network devices for adversary-in-the",
          "url": "https://www.welivesecurity.com/en/eset-research/plushdaemon-compromises-network-devices-for-adversary-in-the-middle-attacks/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f61cc911-5994-4072-8272-bc5c0c81810c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 47.242.198.250",
      "pattern": "[ipv4-addr:value = '47.242.198.250']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "PlushDaemon compromises network devices for adversary-in-the",
          "url": "https://www.welivesecurity.com/en/eset-research/plushdaemon-compromises-network-devices-for-adversary-in-the-middle-attacks/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "ESET WeLiveSecurity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8990dfda-3a5e-4775-a3b7-761aa24b4b62",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-58034",
      "pattern": "[vulnerability:name = 'CVE-2025-58034']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-58034 \u2014 Fortinet FortiWeb OS Command Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--db622a4f-087d-451d-82dd-9035455ccc44",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-64446",
      "pattern": "[vulnerability:name = 'CVE-2025-64446']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-64446 \u2014 Fortinet FortiWeb Path Traversal ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--85064895-8b6e-46b7-b726-bb8ab2d5b29f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-12480",
      "pattern": "[vulnerability:name = 'CVE-2025-12480']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-12480 \u2014 Gladinet Triofox Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b23093ed-9e7d-40cf-9de0-9bacf51cd630",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-62215",
      "pattern": "[vulnerability:name = 'CVE-2025-62215']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-62215 \u2014 Microsoft Windows Race Condition ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6a69ede2-d6be-4f06-b660-0267c9676529",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-9242",
      "pattern": "[vulnerability:name = 'CVE-2025-9242']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-9242 \u2014 WatchGuard Firebox Out-of-Bounds W",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--91f8ee13-34f2-477c-b410-8d86d3128407",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-21042",
      "pattern": "[vulnerability:name = 'CVE-2025-21042']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--29fda4d1-bb3d-46ca-8417-896aed40bcda",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-21043",
      "pattern": "[vulnerability:name = 'CVE-2025-21043']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f3b7178c-2fd4-471e-8dd1-b2cfd7215785",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-43300",
      "pattern": "[vulnerability:name = 'CVE-2025-43300']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-55177 \u2014 Meta Platforms WhatsApp Incorrect",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-43300 \u2014 Apple iOS, iPadOS, and macOS Out-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0676991a-0aee-4a61-8985-cd0e3ad6f9fd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-55177",
      "pattern": "[vulnerability:name = 'CVE-2025-55177']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-55177 \u2014 Meta Platforms WhatsApp Incorrect",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fcfdb2ed-2b24-4b30-ad47-4591544c2d16",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: brightvideodesigns.com",
      "pattern": "[domain-name:value = 'brightvideodesigns.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--31e505a1-07ad-4aa2-b53b-9f5a1b44333c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: healthyeatingontherun.com",
      "pattern": "[domain-name:value = 'healthyeatingontherun.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cbfd8110-e8ef-46fb-b08f-5628b826d08a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: hotelsitereview.com",
      "pattern": "[domain-name:value = 'hotelsitereview.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--919dadff-fac0-4026-8bce-97fb1d481ae2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: projectmanagerskills.com",
      "pattern": "[domain-name:value = 'projectmanagerskills.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a5c60b7d-acda-468f-9cc1-f1b59601f5ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.36.57.56",
      "pattern": "[ipv4-addr:value = '192.36.57.56']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--11629b4d-7971-497d-9a84-116e8579cb7a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.76.224.127",
      "pattern": "[ipv4-addr:value = '194.76.224.127']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5fe797e4-5ff2-4338-a89c-64bfeda1d1d9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.155.250.158",
      "pattern": "[ipv4-addr:value = '45.155.250.158']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c3d370ba-60a8-4d30-9014-52c328305923",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 46.246.28.75",
      "pattern": "[ipv4-addr:value = '46.246.28.75']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7fb70558-76dc-45da-b8e0-6ed5fcd1e97d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 91.132.92.35",
      "pattern": "[ipv4-addr:value = '91.132.92.35']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0330d8ee-7260-472d-b500-92cdc5fe1b0f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 92.243.65.240",
      "pattern": "[ipv4-addr:value = '92.243.65.240']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5ed8205c-8d57-42a5-96a2-9aecb1cf0c42",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 211311468f3673f005031d5f77d4d716e80cbf3c1f0bb1f148f2200920513261",
      "pattern": "[file:hashes.'SHA-256' = '211311468f3673f005031d5f77d4d716e80cbf3c1f0bb1f148f2200920513261']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4d0cec58-f909-4820-abc4-96d9642a4814",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2425f15eb542fca82892fd107ac19d63d4d112ddbfe698650f0c25acf6f8d78a",
      "pattern": "[file:hashes.'SHA-256' = '2425f15eb542fca82892fd107ac19d63d4d112ddbfe698650f0c25acf6f8d78a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bce9b80c-e8e7-4432-8f6c-44ed650fc541",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 29882a3c426273a7302e852aa77662e168b6d44dcebfca53757e29a9cdf02483",
      "pattern": "[file:hashes.'SHA-256' = '29882a3c426273a7302e852aa77662e168b6d44dcebfca53757e29a9cdf02483']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--baa0c03f-fbf3-480d-9a28-55e27fba0978",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 384f073d3d51e0f2e1586b6050af62de886ff448735d963dfc026580096d81bd",
      "pattern": "[file:hashes.'SHA-256' = '384f073d3d51e0f2e1586b6050af62de886ff448735d963dfc026580096d81bd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7058ef33-f1b5-4ed7-8f9c-7511b1d8010e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 69cf56ac6f3888efa7a1306977f431fd1edb369a5fd4591ce37b72b7e01955ee",
      "pattern": "[file:hashes.'SHA-256' = '69cf56ac6f3888efa7a1306977f431fd1edb369a5fd4591ce37b72b7e01955ee']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe4a4e1a-8370-4c09-9e84-631735540418",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9297888746158e38d320b05b27b0032b2cc29231be8990d87bc46f1e06456f93",
      "pattern": "[file:hashes.'SHA-256' = '9297888746158e38d320b05b27b0032b2cc29231be8990d87bc46f1e06456f93']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6c48de46-2c90-4888-86bd-1bab58d9850a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a62a2400bf93ed84ebadf22b441924f904d3fcda7d1507ba309a4b1801d44495",
      "pattern": "[file:hashes.'SHA-256' = 'a62a2400bf93ed84ebadf22b441924f904d3fcda7d1507ba309a4b1801d44495']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3fccfcfc-1c73-4887-a75e-767dc4ea7dcb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b06dec10e8ad0005ebb9da24204c96cb2e297bd8d418bc1c8983d066c0997756",
      "pattern": "[file:hashes.'SHA-256' = 'b06dec10e8ad0005ebb9da24204c96cb2e297bd8d418bc1c8983d066c0997756']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f51b306b-5cd6-4d33-ba1f-3c7256c0aee4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b45817ffb0355badcc89f2d7d48eecf00ebdf2b966ac986514f9d971f6c57d18",
      "pattern": "[file:hashes.'SHA-256' = 'b45817ffb0355badcc89f2d7d48eecf00ebdf2b966ac986514f9d971f6c57d18']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c39ecf0-39b5-492d-a169-6fdc960c4c85",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b975b499baa3119ac5c2b3379306d4e50b9610e9bba3e56de7dfd3927a96032d",
      "pattern": "[file:hashes.'SHA-256' = 'b975b499baa3119ac5c2b3379306d4e50b9610e9bba3e56de7dfd3927a96032d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--274b8e6f-b4bc-4952-8a2d-e30be790d18e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c0f30c2a2d6f95b57128e78dc0b7180e69315057e62809de1926b75f86516b2e",
      "pattern": "[file:hashes.'SHA-256' = 'c0f30c2a2d6f95b57128e78dc0b7180e69315057e62809de1926b75f86516b2e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7241d504-79fe-4e96-89b7-5cf0e1abc5b5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d2fafc7100f33a11089e98b660a85bd479eab761b137cca83b1f6d19629dd3b0",
      "pattern": "[file:hashes.'SHA-256' = 'd2fafc7100f33a11089e98b660a85bd479eab761b137cca83b1f6d19629dd3b0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--48dae953-38a0-472b-8b34-d2fe4adcde6b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ffeeb0356abb56c5084756a5ab0a39002832403bca5290bb6d794d14b642ffe2",
      "pattern": "[file:hashes.'SHA-256' = 'ffeeb0356abb56c5084756a5ab0a39002832403bca5290bb6d794d14b642ffe2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e7f22111-3609-467e-ac4b-f85926e7024d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-11371",
      "pattern": "[vulnerability:name = 'CVE-2025-11371']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-11371 \u2014 Gladinet CentreStack and Triofox ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--24112716-ee5f-4255-8dfd-8657ba29e824",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-30406",
      "pattern": "[vulnerability:name = 'CVE-2025-30406']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-11371 \u2014 Gladinet CentreStack and Triofox ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-30406 \u2014 Gladinet CentreStack and Triofox ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--01cc5725-d3c7-4942-bad7-f9ed2ca5e0c0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 146.70.134.50",
      "pattern": "[ipv4-addr:value = '146.70.134.50']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-11371 \u2014 Gladinet CentreStack and Triofox ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-30406 \u2014 Gladinet CentreStack and Triofox ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--37156a5c-b959-4d6f-ad19-b8525e6ef56f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 147.124.216.205",
      "pattern": "[ipv4-addr:value = '147.124.216.205']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-11371 \u2014 Gladinet CentreStack and Triofox ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-30406 \u2014 Gladinet CentreStack and Triofox ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4c67ca90-a979-4f47-a57d-9170609a654c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-24893",
      "pattern": "[vulnerability:name = 'CVE-2025-24893']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24893 \u2014 XWiki Platform Eval Injection Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e54830d1-b2b0-4c7c-814c-ca64f4ed7d86",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-41244",
      "pattern": "[vulnerability:name = 'CVE-2025-41244']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-41244 \u2014 Broadcom VMware Aria Operations a",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a7e46840-8668-4f6a-8fc3-c8e953d93728",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: c3pool.org",
      "pattern": "[domain-name:value = 'c3pool.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24893 \u2014 XWiki Platform Eval Injection Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ddff7d5f-1dc5-41b3-be1c-b7f65b000ebc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 123.25.249.88",
      "pattern": "[ipv4-addr:value = '123.25.249.88']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24893 \u2014 XWiki Platform Eval Injection Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d0dea47d-e8b9-4b9a-a077-1b5c4a450c28",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.32.208.24",
      "pattern": "[ipv4-addr:value = '193.32.208.24']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24893 \u2014 XWiki Platform Eval Injection Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f3915414-87b6-4acb-b01a-cab19db5357e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 0b907eee9a85d39f8f0d7c503cc1f84a71c4de10",
      "pattern": "[file:hashes.'SHA-1' = '0b907eee9a85d39f8f0d7c503cc1f84a71c4de10']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24893 \u2014 XWiki Platform Eval Injection Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--610692c3-7e2f-4eb0-912a-eb994255b601",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 2abd6f68a24b0a5df5809276016e6b85c77e5f7f",
      "pattern": "[file:hashes.'SHA-1' = '2abd6f68a24b0a5df5809276016e6b85c77e5f7f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24893 \u2014 XWiki Platform Eval Injection Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2c50b336-3915-43ff-a93e-a37c779b055b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 5abc337dbc04fee7206956dad1e0b6d43921a868",
      "pattern": "[file:hashes.'SHA-1' = '5abc337dbc04fee7206956dad1e0b6d43921a868']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24893 \u2014 XWiki Platform Eval Injection Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e31b52f6-1472-4336-a507-e44cc9e17d7e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 90d274c7600fbdca5fe035250d0baff20889ec2b",
      "pattern": "[file:hashes.'SHA-1' = '90d274c7600fbdca5fe035250d0baff20889ec2b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24893 \u2014 XWiki Platform Eval Injection Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--860980ff-d2d6-421c-9ede-f142907ff401",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: de082aeb01d41dd81cfb79bc5bfa33453b0022ed",
      "pattern": "[file:hashes.'SHA-1' = 'de082aeb01d41dd81cfb79bc5bfa33453b0022ed']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24893 \u2014 XWiki Platform Eval Injection Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ffa4fea-6775-4178-b162-5b4a290cb5cb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-6204",
      "pattern": "[vulnerability:name = 'CVE-2025-6204']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-6204 \u2014 Dassault Syst\u00e8mes DELMIA Apriso Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-6205 \u2014 Dassault Syst\u00e8mes DELMIA Apriso Mi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d8748cd-2a15-46ff-8525-851613e3948e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-6205",
      "pattern": "[vulnerability:name = 'CVE-2025-6205']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-6204 \u2014 Dassault Syst\u00e8mes DELMIA Apriso Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-6205 \u2014 Dassault Syst\u00e8mes DELMIA Apriso Mi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b5d7f8d8-5c9b-4640-ae25-912ef46bcd0f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-54236",
      "pattern": "[vulnerability:name = 'CVE-2025-54236']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3c110018-de19-4491-8943-1e57d65c37c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-59287",
      "pattern": "[vulnerability:name = 'CVE-2025-59287']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-59287 \u2014 Microsoft Windows Server Update S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f78f4e3-1017-4313-890b-eac62fe1b0cc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sagecrafft.com",
      "pattern": "[domain-name:value = 'sagecrafft.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--16fc3edb-0ecb-465a-9a6e-9001f5098311",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: tecnokauf.ru",
      "pattern": "[domain-name:value = 'tecnokauf.ru']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--846188f7-bc72-4ea6-8100-ae134e3b8c43",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: webhook.site/22b6b8c8-2e07-4878-a681-b772e569aa6a",
      "pattern": "[domain-name:value = 'webhook.site/22b6b8c8-2e07-4878-a681-b772e569aa6a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-59287 \u2014 Microsoft Windows Server Update S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--575880f2-53c0-439e-ad2d-1ad4da1c5a24",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: worcksbot.com",
      "pattern": "[domain-name:value = 'worcksbot.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9b9612ca-45fa-4c7e-9746-b67a6faeccec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.215.237.26",
      "pattern": "[ipv4-addr:value = '103.215.237.26']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0d6bffb-5578-4a21-9cb5-0b6f6e7a108f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 141.11.62.221",
      "pattern": "[ipv4-addr:value = '141.11.62.221']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d186023f-2cab-4156-94d3-15fa4cde28d8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 143.244.44.172",
      "pattern": "[ipv4-addr:value = '143.244.44.172']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--01d8b8b0-990d-4fdc-9553-298edde7ee02",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 149.28.33.250",
      "pattern": "[ipv4-addr:value = '149.28.33.250']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--df0881d7-1a69-4a05-8fbc-bc5bc2a88b24",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 155.117.84.134",
      "pattern": "[ipv4-addr:value = '155.117.84.134']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1fbad203-a619-40de-9b28-44281b32cda9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 155.138.226.245",
      "pattern": "[ipv4-addr:value = '155.138.226.245']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--460a3a3c-3f07-42c2-9b7b-fe721fb3d2a3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 156.244.16.170",
      "pattern": "[ipv4-addr:value = '156.244.16.170']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f8d90171-d91c-475c-91a5-6166c08e143f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 157.245.52.111",
      "pattern": "[ipv4-addr:value = '157.245.52.111']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e8aaefdb-79b1-4b13-a5a7-22241e1e63c8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 159.89.12.166",
      "pattern": "[ipv4-addr:value = '159.89.12.166']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--429bbff9-6ba3-46ba-9f25-ce5448672fbe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 198.144.182.13",
      "pattern": "[ipv4-addr:value = '198.144.182.13']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5248bcdd-ac15-4640-ad16-f911a770a94c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 212.8.248.191",
      "pattern": "[ipv4-addr:value = '212.8.248.191']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--796aadd4-1d1c-435c-a836-6b4f0506c752",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.146.184.93",
      "pattern": "[ipv4-addr:value = '23.146.184.93']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c36c042-c728-4d10-8675-73370ba77def",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.249.27.221",
      "pattern": "[ipv4-addr:value = '23.249.27.221']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b942bfe2-9307-4f87-97be-2fae603bc1cc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 34.227.25.4",
      "pattern": "[ipv4-addr:value = '34.227.25.4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b1d57d1d-29b6-45e4-8dac-c0b6b9d47a29",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 44.212.43.34",
      "pattern": "[ipv4-addr:value = '44.212.43.34']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--45eb0ebf-308a-460b-93e3-7b1fdb985194",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.143.20.147",
      "pattern": "[ipv4-addr:value = '45.143.20.147']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3e9f9985-a917-4abd-b23b-800ff8240561",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.32.66.51",
      "pattern": "[ipv4-addr:value = '45.32.66.51']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7778a545-0a75-4656-ab95-ebdf73e48033",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 46.39.230.243",
      "pattern": "[ipv4-addr:value = '46.39.230.243']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f6fe6882-bcce-4361-9bd8-805e1f89604c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 54.205.171.35",
      "pattern": "[ipv4-addr:value = '54.205.171.35']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0e068e3c-b36d-48c8-a179-7da4b9c8d54f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 54.226.181.219",
      "pattern": "[ipv4-addr:value = '54.226.181.219']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2d58f50f-2a6d-4e89-ba44-8e9d956eec8a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 80.78.25.213",
      "pattern": "[ipv4-addr:value = '80.78.25.213']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8a1772cc-693c-4687-a9c4-7a37045090d3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 86.203.185.51",
      "pattern": "[ipv4-addr:value = '86.203.185.51']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9b5af6a4-7203-49ab-9fa8-2197a024a2ea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 99.246.176.115",
      "pattern": "[ipv4-addr:value = '99.246.176.115']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--674e2ee9-2a75-48d0-bd24-c06bb7750041",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-61932",
      "pattern": "[vulnerability:name = 'CVE-2025-61932']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--002ae0e9-fc9c-4b99-9bea-50b1b7b8d60e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 108.61.161.118",
      "pattern": "[ipv4-addr:value = '108.61.161.118']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a774abb8-8e8d-49f6-9465-59cfce59eee0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.54.56.10",
      "pattern": "[ipv4-addr:value = '38.54.56.10']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--58df6812-fd76-4cff-b5fb-750d5f7b4637",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.54.56.57",
      "pattern": "[ipv4-addr:value = '38.54.56.57']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c8a8fea2-4794-42ef-baa0-1be3d3cf3ed0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.54.88.172",
      "pattern": "[ipv4-addr:value = '38.54.88.172']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0c21c80-15d2-4a4d-8476-1e94ee7a7663",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 4946b0de3b705878c514e2eead096e1e",
      "pattern": "[file:hashes.MD5 = '4946b0de3b705878c514e2eead096e1e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1e6e5399-1918-4ca4-bf5c-c1851f30467a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 932c91020b74aaa7ffc687e21da0119c",
      "pattern": "[file:hashes.MD5 = '932c91020b74aaa7ffc687e21da0119c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--076e5f7f-06f0-499b-ad7a-ee7fcbad3f17",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 1406b4e905c65ba1599eb9c619c196fa5e1c3bf7",
      "pattern": "[file:hashes.'SHA-1' = '1406b4e905c65ba1599eb9c619c196fa5e1c3bf7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1ba90a4b-9a6f-43b1-814d-354d4eacfd16",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 8124940a41d4b7608eada0d2b546b73c010e30b1",
      "pattern": "[file:hashes.'SHA-1' = '8124940a41d4b7608eada0d2b546b73c010e30b1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eaaa5ad1-e457-4e4d-8b8b-586c3184d292",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: be75458b489468e0acdea6ebbb424bc898b3db29",
      "pattern": "[file:hashes.'SHA-1' = 'be75458b489468e0acdea6ebbb424bc898b3db29']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb253e2c-6a9d-462f-831c-375716779c3b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3c96c1a9b3751339390be9d7a5c3694df46212fb97ebddc074547c2338a4c7ba",
      "pattern": "[file:hashes.'SHA-256' = '3c96c1a9b3751339390be9d7a5c3694df46212fb97ebddc074547c2338a4c7ba']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--54c506be-498d-4e90-abdd-587a4aecbbee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 704e697441c0af67423458a99f30318c57f1a81c4146beb4dd1a88a88a8c97c3",
      "pattern": "[file:hashes.'SHA-256' = '704e697441c0af67423458a99f30318c57f1a81c4146beb4dd1a88a88a8c97c3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c3e3df52-dca5-4b19-af57-19dba0b338c7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9e581d0506d2f6ec39226f052a58bc5a020ebc81ae539fa3a6b7fc0db1b94946",
      "pattern": "[file:hashes.'SHA-256' = '9e581d0506d2f6ec39226f052a58bc5a020ebc81ae539fa3a6b7fc0db1b94946']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--58d05049-879c-40d1-90b8-e973956302f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-48503",
      "pattern": "[vulnerability:name = 'CVE-2022-48503']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-48503 \u2014 Apple Multiple Products Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7d55c648-7f1c-47d5-a086-a76816b4043f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-2746",
      "pattern": "[vulnerability:name = 'CVE-2025-2746']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2746 \u2014 Kentico Xperience CMS Authenticati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-2747 \u2014 Kentico Xperience CMS Authenticati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2d8ebcb-5f56-4237-8280-4e64e04b6f65",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-2747",
      "pattern": "[vulnerability:name = 'CVE-2025-2747']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2746 \u2014 Kentico Xperience CMS Authenticati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-2747 \u2014 Kentico Xperience CMS Authenticati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--519d0c1f-8447-43d5-91b3-9365c6e2ae1e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-33073",
      "pattern": "[vulnerability:name = 'CVE-2025-33073']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-33073 \u2014 Microsoft Windows SMB Client Impr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c229c07d-7f25-4a0a-b17d-f3b96909537d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-61882",
      "pattern": "[vulnerability:name = 'CVE-2025-61882']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61884 \u2014 Oracle E-Business Suite Server-Si",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-61882 \u2014 Oracle E-Business Suite Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--61e895c3-a53c-4e67-b067-41168ef7bd9f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-61884",
      "pattern": "[vulnerability:name = 'CVE-2025-61884']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61884 \u2014 Oracle E-Business Suite Server-Si",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-61882 \u2014 Oracle E-Business Suite Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3cdcdfa4-b1e4-445f-8535-d7efa32fd1e7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: pubstorm.com",
      "pattern": "[domain-name:value = 'pubstorm.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61884 \u2014 Oracle E-Business Suite Server-Si",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-61882 \u2014 Oracle E-Business Suite Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7e698e6c-2956-4d34-9d40-9cd4cf9688f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: pubstorm.net",
      "pattern": "[domain-name:value = 'pubstorm.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61884 \u2014 Oracle E-Business Suite Server-Si",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-61882 \u2014 Oracle E-Business Suite Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--16d7dbce-5082-4999-a574-8b8cbead6d7c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.194.11.200",
      "pattern": "[ipv4-addr:value = '104.194.11.200']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61884 \u2014 Oracle E-Business Suite Server-Si",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-61882 \u2014 Oracle E-Business Suite Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d7145938-4774-4d43-ac57-166cb3d013f5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 161.97.99.49",
      "pattern": "[ipv4-addr:value = '161.97.99.49']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61884 \u2014 Oracle E-Business Suite Server-Si",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-61882 \u2014 Oracle E-Business Suite Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ec3d429e-572e-4c8f-aa31-183c3951151a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 162.55.17.215",
      "pattern": "[ipv4-addr:value = '162.55.17.215']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61884 \u2014 Oracle E-Business Suite Server-Si",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-61882 \u2014 Oracle E-Business Suite Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a9bdb685-b48c-4c0e-96ca-b1bab7eeea61",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 200.107.207.26",
      "pattern": "[ipv4-addr:value = '200.107.207.26']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61884 \u2014 Oracle E-Business Suite Server-Si",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-61882 \u2014 Oracle E-Business Suite Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--58fcd063-349a-46ba-836c-8de016e25c36",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-54253",
      "pattern": "[vulnerability:name = 'CVE-2025-54253']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54253 \u2014 Adobe Experience Manager Forms Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--29bd48a4-5a42-4beb-bfa5-4cc72b3514bd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-54254",
      "pattern": "[vulnerability:name = 'CVE-2025-54254']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54253 \u2014 Adobe Experience Manager Forms Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b525d1d6-2a66-4e84-a4af-47ba71f634b6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-7836",
      "pattern": "[vulnerability:name = 'CVE-2016-7836']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-7836 \u2014 SKYSEA Client View Improper Authen",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aa2e5cb7-f4dd-4d70-9b66-23bc7d964981",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-24990",
      "pattern": "[vulnerability:name = 'CVE-2025-24990']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24990 \u2014 Microsoft Windows Untrusted Point",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fbcf8ecb-9f08-4d20-854f-7b7dc1b46b70",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-47827",
      "pattern": "[vulnerability:name = 'CVE-2025-47827']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-47827 \u2014 IGEL OS Use of a Key Past its Exp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f8f525fe-9fa7-4300-b2fd-319b1ae9f495",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-59230",
      "pattern": "[vulnerability:name = 'CVE-2025-59230']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-59230 \u2014 Microsoft Windows Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a430b47d-6875-470b-9d78-e0feeb6f9947",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-43798",
      "pattern": "[vulnerability:name = 'CVE-2021-43798']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-43798 \u2014 Grafana Path Traversal Vulnerabil",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--24e2425e-04bf-4d4e-8063-7ac66278e6c0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cfn.fejyhy.com",
      "pattern": "[domain-name:value = 'cfn.fejyhy.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Phishing Campaign Leveraging the NPM Ecosystem",
          "url": "https://snyk.io/blog/phishing-campaign-leveraging-the-npm-ecosystem/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f3b945b3-7470-4280-9766-0f2f7cb0de18",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cfn.fenamu.com",
      "pattern": "[domain-name:value = 'cfn.fenamu.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Phishing Campaign Leveraging the NPM Ecosystem",
          "url": "https://snyk.io/blog/phishing-campaign-leveraging-the-npm-ecosystem/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--33822051-307e-42bd-8486-e6ad10a80a34",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cfn.jackpotmastersdanske.com",
      "pattern": "[domain-name:value = 'cfn.jackpotmastersdanske.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Phishing Campaign Leveraging the NPM Ecosystem",
          "url": "https://snyk.io/blog/phishing-campaign-leveraging-the-npm-ecosystem/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2c816e3f-32f0-4894-bf08-fb138a8c8708",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cfn.notwinningbutpartici.com",
      "pattern": "[domain-name:value = 'cfn.notwinningbutpartici.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Phishing Campaign Leveraging the NPM Ecosystem",
          "url": "https://snyk.io/blog/phishing-campaign-leveraging-the-npm-ecosystem/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dcaeb181-ef54-4565-8bf7-3108b24dc0a6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: elkendinsc.com",
      "pattern": "[domain-name:value = 'elkendinsc.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Phishing Campaign Leveraging the NPM Ecosystem",
          "url": "https://snyk.io/blog/phishing-campaign-leveraging-the-npm-ecosystem/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e9de94af-30f7-4a7a-9a42-52dbf24c2852",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: musicboxcr.com",
      "pattern": "[domain-name:value = 'musicboxcr.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Phishing Campaign Leveraging the NPM Ecosystem",
          "url": "https://snyk.io/blog/phishing-campaign-leveraging-the-npm-ecosystem/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7a3c7d20-2934-4a96-ba6d-5e896828cc0c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: villasmbuva.co.mz",
      "pattern": "[domain-name:value = 'villasmbuva.co.mz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Phishing Campaign Leveraging the NPM Ecosystem",
          "url": "https://snyk.io/blog/phishing-campaign-leveraging-the-npm-ecosystem/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b9c3457c-e471-4ff5-a3e0-66066f73a406",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-27915",
      "pattern": "[vulnerability:name = 'CVE-2025-27915']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-27915 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3c639e18-55a5-4e65-84ef-787822c69c3b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ffrk.net",
      "pattern": "[domain-name:value = 'ffrk.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-27915 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f7a61ff-fcd2-46ac-ad40-df85575059da",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.29.58.37",
      "pattern": "[ipv4-addr:value = '193.29.58.37']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-27915 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2311da44-9868-46d9-9035-3004da0b581c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-3765",
      "pattern": "[vulnerability:name = 'CVE-2010-3765']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-3765 \u2014 Mozilla Multiple Products Remote C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--afc3dec5-2e66-4765-b637-59ff9ba92ea5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-3962",
      "pattern": "[vulnerability:name = 'CVE-2010-3962']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-3962 \u2014 Microsoft Internet Explorer Uninit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2bf70393-4949-4bd1-bb3b-d325bbe642f6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2011-3402",
      "pattern": "[vulnerability:name = 'CVE-2011-3402']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-3402 \u2014 Microsoft Windows Remote Code Exec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0e9564d2-7c08-4713-8a2c-ff2cf737a723",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-3918",
      "pattern": "[vulnerability:name = 'CVE-2013-3918']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3918 \u2014 Microsoft Windows Out-of-Bounds Wr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e155901c-18dd-41e9-abc4-ee05aa97c5de",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-22555",
      "pattern": "[vulnerability:name = 'CVE-2021-22555']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-22555 \u2014 Linux Kernel Heap Out-of-Bounds W",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--506de411-0716-494a-af77-63045fbfd376",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-43226",
      "pattern": "[vulnerability:name = 'CVE-2021-43226']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-43226 \u2014 Microsoft Windows Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--249b02ed-3f31-4785-9b25-30efc23c3506",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: dxcdfghg.com",
      "pattern": "[domain-name:value = 'dxcdfghg.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-3962 \u2014 Microsoft Internet Explorer Uninit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8fdce89b-46f4-4b7c-b3d3-1668ee862764",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: l-3com.dyndns-work.com",
      "pattern": "[domain-name:value = 'l-3com.dyndns-work.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-3765 \u2014 Mozilla Multiple Products Remote C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b256abde-e8c8-4752-8015-55fd43c240c5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: l-3com.dyndns.tv",
      "pattern": "[domain-name:value = 'l-3com.dyndns.tv']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-3765 \u2014 Mozilla Multiple Products Remote C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--60bcd850-df6f-4d6a-942e-08e9cd571dd6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.181.60.11",
      "pattern": "[ipv4-addr:value = '185.181.60.11']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61882 \u2014 Oracle E-Business Suite Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6a5cde9a-0794-4a67-8b3b-c304f739dda9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 76b6d36e04e367a2334c445b51e1ecce97e4c614e88dfb4f72b104ca0f31235d",
      "pattern": "[file:hashes.'SHA-256' = '76b6d36e04e367a2334c445b51e1ecce97e4c614e88dfb4f72b104ca0f31235d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-61882 \u2014 Oracle E-Business Suite Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--463742d7-3709-46b2-9cb6-2ba8f5ed6adb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-6271",
      "pattern": "[vulnerability:name = 'CVE-2014-6271']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-6278 \u2014 GNU Bash OS Command Injection Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2014-6271 \u2014 GNU Bourne-Again Shell (Bash) Arbi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f206ed0b-7e56-4786-9c86-6b6746865c47",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-6277",
      "pattern": "[vulnerability:name = 'CVE-2014-6277']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-6278 \u2014 GNU Bash OS Command Injection Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--33c09f73-adeb-47a8-8f26-6add71466be6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-6278",
      "pattern": "[vulnerability:name = 'CVE-2014-6278']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-6278 \u2014 GNU Bash OS Command Injection Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b09230bf-fbd7-4fc1-be33-c3ccab7bc930",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-7169",
      "pattern": "[vulnerability:name = 'CVE-2014-7169']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-6278 \u2014 GNU Bash OS Command Injection Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2014-6271 \u2014 GNU Bourne-Again Shell (Bash) Arbi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9d267888-a046-468d-965b-b23695d2d8dd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-7186",
      "pattern": "[vulnerability:name = 'CVE-2014-7186']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-6278 \u2014 GNU Bash OS Command Injection Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9531d457-f331-4f88-b9e3-dfc73d9fdc37",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-7187",
      "pattern": "[vulnerability:name = 'CVE-2014-7187']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-6278 \u2014 GNU Bash OS Command Injection Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f2d4cc57-b29b-4a72-9cf0-d61e63d0400a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-7755",
      "pattern": "[vulnerability:name = 'CVE-2015-7755']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-7755 \u2014 Juniper ScreenOS Improper Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ddcb5efc-f640-45ee-ac9a-af831d8de13c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-7756",
      "pattern": "[vulnerability:name = 'CVE-2015-7756']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-7755 \u2014 Juniper ScreenOS Improper Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2ddf6ff4-b0e0-4511-bb8f-73c85f62469f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-1000353",
      "pattern": "[vulnerability:name = 'CVE-2017-1000353']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-1000353 \u2014 Jenkins Remote Code Execution V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cdf3be27-ca0d-48cc-956a-e93489b9773e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-4008",
      "pattern": "[vulnerability:name = 'CVE-2025-4008']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4008 \u2014 Smartbedded Meteobridge Command In",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--35d3ab62-ac0a-470e-a388-68535d4cb128",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-3881",
      "pattern": "[vulnerability:name = 'CVE-2017-3881']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-20352 \u2014 Cisco IOS and IOS XE Software SNM",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-3881 \u2014 Cisco IOS and IOS XE Remote Code E",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3c08a01e-8713-4cdc-9bde-53ebbc6c343a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-21311",
      "pattern": "[vulnerability:name = 'CVE-2021-21311']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21311 \u2014 Adminer Server-Side Request Forge",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--55ffe546-f5d4-4b02-a31a-d3fdda88f8b5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-10035",
      "pattern": "[vulnerability:name = 'CVE-2025-10035']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-10035 \u2014 Fortra GoAnywhere MFT Deserializa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0fee3401-113f-4941-ba2e-e4dc2ea2147c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-20352",
      "pattern": "[vulnerability:name = 'CVE-2025-20352']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-20352 \u2014 Cisco IOS and IOS XE Software SNM",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5182815d-51b9-4c90-aea1-61f3b0967ab6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-32463",
      "pattern": "[vulnerability:name = 'CVE-2025-32463']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-32463 \u2014 Sudo Inclusion of Functionality f",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--34733943-50d2-40d4-9591-f72052f432d7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-59689",
      "pattern": "[vulnerability:name = 'CVE-2025-59689']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-59689 \u2014 Libraesva Email Security Gateway ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--51a3b1d8-38cb-4e11-86f5-c576aadf7638",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 213.183.63.41",
      "pattern": "[ipv4-addr:value = '213.183.63.41']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-10035 \u2014 Fortra GoAnywhere MFT Deserializa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c2cdc775-3bc0-4564-a049-408700c55918",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 31.220.45.120",
      "pattern": "[ipv4-addr:value = '31.220.45.120']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-10035 \u2014 Fortra GoAnywhere MFT Deserializa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8a45f899-5e9c-401d-bd5b-3d50516a2c41",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.11.183.123",
      "pattern": "[ipv4-addr:value = '45.11.183.123']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-10035 \u2014 Fortra GoAnywhere MFT Deserializa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cab2719b-a99a-4058-91b7-39aa94e37eb3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 235dc2d8c92661e5e2797a03bccd2653272ca1ac93401d194d7784930ca17a5a",
      "pattern": "[file:hashes.'SHA-256' = '235dc2d8c92661e5e2797a03bccd2653272ca1ac93401d194d7784930ca17a5a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-20352 \u2014 Cisco IOS and IOS XE Software SNM",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--69a98463-7856-4284-a18a-d0f1173096c1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2abc874435c16aa5cfd431b0d9c26095ef4b9429bd82306f054c367e96df49b2",
      "pattern": "[file:hashes.'SHA-256' = '2abc874435c16aa5cfd431b0d9c26095ef4b9429bd82306f054c367e96df49b2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-20352 \u2014 Cisco IOS and IOS XE Software SNM",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4867fc7d-ce5a-46c3-9c3f-d5bccdd2365a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3a524bc40ca7c11b68283504f0119caeefd7589edea621d43d5d0cd973354675",
      "pattern": "[file:hashes.'SHA-256' = '3a524bc40ca7c11b68283504f0119caeefd7589edea621d43d5d0cd973354675']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-20352 \u2014 Cisco IOS and IOS XE Software SNM",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--49c46658-8159-48dd-8719-8ba8e1725fb0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4106c35ff46bb6f2f4a42d63a2b8a619f1e1df72414122ddf6fd1b1a644b3220",
      "pattern": "[file:hashes.'SHA-256' = '4106c35ff46bb6f2f4a42d63a2b8a619f1e1df72414122ddf6fd1b1a644b3220']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-10035 \u2014 Fortra GoAnywhere MFT Deserializa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea16e55b-b134-4908-934d-355044da0847",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5ba7de7d5115789b952d9b1c6cff440c9128f438de933ff9044a68fff8496d19",
      "pattern": "[file:hashes.'SHA-256' = '5ba7de7d5115789b952d9b1c6cff440c9128f438de933ff9044a68fff8496d19']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-10035 \u2014 Fortra GoAnywhere MFT Deserializa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3098151e-088a-491b-94e5-b8162e87a1ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 69d761bdde73ea8e33384cf986d7e9c2d9011f7aad8933e8af64e60a77091e11",
      "pattern": "[file:hashes.'SHA-256' = '69d761bdde73ea8e33384cf986d7e9c2d9011f7aad8933e8af64e60a77091e11']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-20352 \u2014 Cisco IOS and IOS XE Software SNM",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76571f06-55c9-4b5d-a9af-43316dc2f4fb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7cc7aed51adb426e55d82fd74c55b78f6ecbb895a315be721ef149a17f4b3a9b",
      "pattern": "[file:hashes.'SHA-256' = '7cc7aed51adb426e55d82fd74c55b78f6ecbb895a315be721ef149a17f4b3a9b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-20352 \u2014 Cisco IOS and IOS XE Software SNM",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6f135c2-cbb6-40f2-b599-6bb5a9dc3cf6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 81b35152768f28a479ba9f7e27d66042b0d7edcd79355481aa401f3f47a7733b",
      "pattern": "[file:hashes.'SHA-256' = '81b35152768f28a479ba9f7e27d66042b0d7edcd79355481aa401f3f47a7733b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-20352 \u2014 Cisco IOS and IOS XE Software SNM",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--948f3d25-98ed-4ddc-adef-9fab735c757a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9b8a896aa2057f46e17b18bbe091d85fb816b1d3232a3178d6aba94df3a92f6a",
      "pattern": "[file:hashes.'SHA-256' = '9b8a896aa2057f46e17b18bbe091d85fb816b1d3232a3178d6aba94df3a92f6a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-20352 \u2014 Cisco IOS and IOS XE Software SNM",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c961c65a-c515-4a52-928b-b7f2be370f53",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b08877f6f1c6c097240a6a8aa4a23243e3b14a1432170bc3fa5fa9886a2b19b4",
      "pattern": "[file:hashes.'SHA-256' = 'b08877f6f1c6c097240a6a8aa4a23243e3b14a1432170bc3fa5fa9886a2b19b4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-20352 \u2014 Cisco IOS and IOS XE Software SNM",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9f0aa6cf-08d4-4433-851e-22792154dbdc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c7e2632702d0e22598b90ea226d3cde4830455d9232bd8b33ebcb13827e99bc3",
      "pattern": "[file:hashes.'SHA-256' = 'c7e2632702d0e22598b90ea226d3cde4830455d9232bd8b33ebcb13827e99bc3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-10035 \u2014 Fortra GoAnywhere MFT Deserializa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--28b89d1e-4ba1-47e5-84ca-06848a4237b7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: cd5aa589873d777c6e919c4438afe8bceccad6bbe57739e2ccb70b39aee1e8b3",
      "pattern": "[file:hashes.'SHA-256' = 'cd5aa589873d777c6e919c4438afe8bceccad6bbe57739e2ccb70b39aee1e8b3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-10035 \u2014 Fortra GoAnywhere MFT Deserializa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ee0f24e5-5bed-47e8-988d-69f93a564fb2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e303d0c6c59b4dc55edc0212a9319702e9db7fa03185ae9177777b874c02d4c1",
      "pattern": "[file:hashes.'SHA-256' = 'e303d0c6c59b4dc55edc0212a9319702e9db7fa03185ae9177777b874c02d4c1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-20352 \u2014 Cisco IOS and IOS XE Software SNM",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--36053b84-6933-42a7-b0d1-c5bf0ccb55ce",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-20333",
      "pattern": "[vulnerability:name = 'CVE-2025-20333']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-20362 \u2014 Cisco Secure Firewall Adaptive Se",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0a193c2b-6f11-4ea3-a626-495ac194a43e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-20362",
      "pattern": "[vulnerability:name = 'CVE-2025-20362']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-20362 \u2014 Cisco Secure Firewall Adaptive Se",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--729bcbef-21b2-4b8f-bb86-251be8c9880c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-20363",
      "pattern": "[vulnerability:name = 'CVE-2025-20363']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-20362 \u2014 Cisco Secure Firewall Adaptive Se",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2655250-4d1a-4e54-9312-b4d948bae11b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-10585",
      "pattern": "[vulnerability:name = 'CVE-2025-10585']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-10585 \u2014 Google Chromium V8 Type Confusion",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1a5aa05f-e45b-414e-85d7-5dc7351742e5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-5086",
      "pattern": "[vulnerability:name = 'CVE-2025-5086']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-5086 \u2014 Dassault Syst\u00e8mes DELMIA Apriso De",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2b34a4d8-cb8b-4708-ac29-bac46d290507",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 156.244.33.162",
      "pattern": "[ipv4-addr:value = '156.244.33.162']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-5086 \u2014 Dassault Syst\u00e8mes DELMIA Apriso De",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff4c194f-56ef-4d0b-b62a-51a32f040ae3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 292ea9dbc5a1d15b769edb5df1602418931122455223081064ad7ea4e8ab6821",
      "pattern": "[file:hashes.'SHA-256' = '292ea9dbc5a1d15b769edb5df1602418931122455223081064ad7ea4e8ab6821']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-5086 \u2014 Dassault Syst\u00e8mes DELMIA Apriso De",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1fe75bb6-1031-4fac-8774-f2e14f4400f4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: websocket-api2.publicvm.com",
      "pattern": "[domain-name:value = 'websocket-api2.publicvm.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "npm Supply Chain Attack via Open Source maintainer compromis",
          "url": "https://snyk.io/blog/npm-supply-chain-attack-via-open-source-maintainer-compromise/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76a476b8-4d7f-40bb-b485-827998266b37",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-38352",
      "pattern": "[vulnerability:name = 'CVE-2025-38352']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-38352 \u2014 Linux Kernel Time-of-Check Time-o",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ee8e3d7f-1123-4397-bf3b-da5e59f228f5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-48543",
      "pattern": "[vulnerability:name = 'CVE-2025-48543']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-48543 \u2014 Android Runtime Use-After-Free Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d68f7d3e-e8cd-4a95-91b2-6db1469b68f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-53690",
      "pattern": "[vulnerability:name = 'CVE-2025-53690']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deseri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c509127d-f837-40a5-a593-3594b666ef7f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.235.46.102",
      "pattern": "[ipv4-addr:value = '103.235.46.102']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deseri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb4e5620-a964-41dd-a3b4-8a0cb6a05a41",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 130.33.156.194",
      "pattern": "[ipv4-addr:value = '130.33.156.194']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deseri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5bacb85f-2278-4575-8702-c97eaf1f6783",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 117305c6c8222162d7246f842c4bb014",
      "pattern": "[file:hashes.MD5 = '117305c6c8222162d7246f842c4bb014']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deseri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c578503-929b-408a-88fa-d3affcfefbdc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 62483e732553c8ba051b792949f3c6d0",
      "pattern": "[file:hashes.MD5 = '62483e732553c8ba051b792949f3c6d0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deseri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1b1e045f-bbe8-41dd-8551-57b353d02935",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 63d22ae0568b760b5e3aabb915313e44",
      "pattern": "[file:hashes.MD5 = '63d22ae0568b760b5e3aabb915313e44']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deseri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f04ebf10-13a8-4be8-94f2-9e1ec08e6efa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: a39696e95a34a017be1435db7ff139d5",
      "pattern": "[file:hashes.MD5 = 'a39696e95a34a017be1435db7ff139d5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deseri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--703bf962-1880-4f8a-a903-0de932b102b5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: be7e2c6a9a4654b51a16f8b10a2be175",
      "pattern": "[file:hashes.MD5 = 'be7e2c6a9a4654b51a16f8b10a2be175']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deseri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9a1b8b57-7725-4286-9037-3fddfb743ec5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: f410d88429b93786b224e489c960bf5c",
      "pattern": "[file:hashes.MD5 = 'f410d88429b93786b224e489c960bf5c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deseri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f47bf6bd-a018-4ece-9738-a6442b337eff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 223b873c50380fe9a39f1a22b6abf8d46db506e1c08d08312902f6f3cd1f7ac3",
      "pattern": "[file:hashes.'SHA-256' = '223b873c50380fe9a39f1a22b6abf8d46db506e1c08d08312902f6f3cd1f7ac3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deseri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e34cd4a0-2979-4649-bc4c-6c6e338a12e0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 61f897ed69646e0509f6802fb2d7c5e88c3e3b93c4ca86942e24d203aa878863",
      "pattern": "[file:hashes.'SHA-256' = '61f897ed69646e0509f6802fb2d7c5e88c3e3b93c4ca86942e24d203aa878863']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deseri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7e5536da-bc65-4fc1-9150-1ee48ed500c0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a566cceaf9a66332470a978a234a8a8e2bbdd4d6aa43c2c75c25a80b3b744307",
      "pattern": "[file:hashes.'SHA-256' = 'a566cceaf9a66332470a978a234a8a8e2bbdd4d6aa43c2c75c25a80b3b744307']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deseri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b9be808f-744e-44f4-b119-5bf5b08fb24d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b3f83721f24f7ee5eb19f24747b7668ff96da7dfd9be947e6e24a688ecc0a52b",
      "pattern": "[file:hashes.'SHA-256' = 'b3f83721f24f7ee5eb19f24747b7668ff96da7dfd9be947e6e24a688ecc0a52b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deseri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6796bbf-249b-4636-99dd-923e2f9c8f01",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-50224",
      "pattern": "[vulnerability:name = 'CVE-2023-50224']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-50224 \u2014 TP-Link TL-WR841N Authentication ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-9377 \u2014 TP-Link Archer C7(EU) and TL-WR841",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--30f85b32-caf7-4e3b-a23d-d8dbe16e3d0c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-9377",
      "pattern": "[vulnerability:name = 'CVE-2025-9377']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-50224 \u2014 TP-Link TL-WR841N Authentication ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-9377 \u2014 TP-Link Archer C7(EU) and TL-WR841",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--df63d83f-4e73-4edd-b163-64fc75cd4f3d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-24363",
      "pattern": "[vulnerability:name = 'CVE-2020-24363']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-24363 \u2014 TP-link TL-WA855RE Missing Authen",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8eceefc2-0825-4e3d-9d3e-a722cfb2c912",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-57819",
      "pattern": "[vulnerability:name = 'CVE-2025-57819']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-57819 \u2014 Sangoma FreePBX Authentication By",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2aa3d219-2edb-4e7a-8899-2760748a074f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-7775",
      "pattern": "[vulnerability:name = 'CVE-2025-7775']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-7775 \u2014 Citrix NetScaler Memory Overflow V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f7f7ea52-e807-409f-a1a6-5e2ab08d63a7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-7776",
      "pattern": "[vulnerability:name = 'CVE-2025-7776']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-7775 \u2014 Citrix NetScaler Memory Overflow V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b193655a-4cee-4675-b528-ad2987e9c920",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-8424",
      "pattern": "[vulnerability:name = 'CVE-2025-8424']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-7775 \u2014 Citrix NetScaler Memory Overflow V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d34da7dd-eabe-4f9a-8542-7bba5e7c7220",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-8068",
      "pattern": "[vulnerability:name = 'CVE-2024-8068']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-8068 \u2014 Citrix Session Recording Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0c4180bd-358c-485f-845c-97dd31f4bf0a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-8069",
      "pattern": "[vulnerability:name = 'CVE-2024-8069']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-8068 \u2014 Citrix Session Recording Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8069 \u2014 Citrix Session Recording Deseriali",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9728db2f-a745-45ef-b8b0-2e0843d2c4f6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-48384",
      "pattern": "[vulnerability:name = 'CVE-2025-48384']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-48384 \u2014 Git Link Following Vulnerability",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b9eac548-e5fd-4d32-8fc5-eaf0aa3bca6e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-54948",
      "pattern": "[vulnerability:name = 'CVE-2025-54948']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54948 \u2014 Trend Micro Apex One OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1beb1154-4c9d-4a1d-8229-26cae36d101c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-54987",
      "pattern": "[vulnerability:name = 'CVE-2025-54987']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54948 \u2014 Trend Micro Apex One OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aa7475be-ca50-44fa-9fc8-9c47321561cb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-8875",
      "pattern": "[vulnerability:name = 'CVE-2025-8875']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-8875 \u2014 N-able N-Central Insecure Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--05f98ffc-441e-4731-b95a-22e33fff3ec7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-8876",
      "pattern": "[vulnerability:name = 'CVE-2025-8876']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-8876 \u2014 N-able N-Central Command Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da69556a-a7c1-4002-a465-487736b8eeb8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2007-0671",
      "pattern": "[vulnerability:name = 'CVE-2007-0671']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2007-0671 \u2014 Microsoft Office Excel Remote Code",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a3abdac5-c76e-425a-a9df-f446f2cf32b0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-3893",
      "pattern": "[vulnerability:name = 'CVE-2013-3893']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2013-3897 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aafe5db6-a660-4e10-a4f6-a2988942caa1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ali.blankchair.com",
      "pattern": "[domain-name:value = 'ali.blankchair.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d9e300e-8d80-4c46-b5f3-d7989d9f5d0c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: blankchair.com",
      "pattern": "[domain-name:value = 'blankchair.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b190cde6-7648-4218-855e-7ff4cc1b5014",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: dll.freshdns.org",
      "pattern": "[domain-name:value = 'dll.freshdns.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aa9116b8-31a2-438b-91b7-1c935a3853da",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: downloadmp3server.servemp3.com",
      "pattern": "[domain-name:value = 'downloadmp3server.servemp3.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--21a70425-2c29-49a1-8da9-a39e2da5554a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ea.blankchair.com",
      "pattern": "[domain-name:value = 'ea.blankchair.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--be8b5e3f-01f3-440c-882d-f98fe0b94825",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: rt.blankchair.com",
      "pattern": "[domain-name:value = 'rt.blankchair.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e9429d31-4cec-468a-8aa9-ddf3f869e697",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: yahooeast.net",
      "pattern": "[domain-name:value = 'yahooeast.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4904760-1611-40d5-9f3d-a940d6d48229",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.17.117.90",
      "pattern": "[ipv4-addr:value = '103.17.117.90']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e6371958-515d-44de-b448-e03877cab322",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 110.45.158.5",
      "pattern": "[ipv4-addr:value = '110.45.158.5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--782f5c08-1be8-43fe-8802-9f0357b7bbf1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 180.150.228.102",
      "pattern": "[ipv4-addr:value = '180.150.228.102']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d3da146c-eaf8-4b9e-8584-31d67e9cf4c1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.192.91.6",
      "pattern": "[ipv4-addr:value = '192.192.91.6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c386845-8062-4445-8bdf-0be4ac9e0181",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 210.176.3.130",
      "pattern": "[ipv4-addr:value = '210.176.3.130']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d8e97c49-75fb-412f-8544-09fcc44cf848",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 210.177.74.45",
      "pattern": "[ipv4-addr:value = '210.177.74.45']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--52152003-3488-490f-8cc8-6dfee9ba00a3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 211.23.103.221",
      "pattern": "[ipv4-addr:value = '211.23.103.221']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0de3bbdb-685c-4c4a-8866-72a1fcb2d6e4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 61.63.47.27",
      "pattern": "[ipv4-addr:value = '61.63.47.27']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3005da5d-cc43-471b-9bc9-b4df4a311c35",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 66.153.86.14",
      "pattern": "[ipv4-addr:value = '66.153.86.14']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8def048a-70ad-4f46-96b7-d038812e80e9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 1b03e3de1ef3e7135fbf9d5ce7e7ccf6",
      "pattern": "[file:hashes.MD5 = '1b03e3de1ef3e7135fbf9d5ce7e7ccf6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a87129cc-5353-44b6-98f9-b0c1f858ee39",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 4d257e569539973ab0bbafee8fb87582",
      "pattern": "[file:hashes.MD5 = '4d257e569539973ab0bbafee8fb87582']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1a0c9fe1-b33f-41dd-b1e3-2236257365d0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 58dc05118ef8b11dcb5f5c596ab772fd",
      "pattern": "[file:hashes.MD5 = '58dc05118ef8b11dcb5f5c596ab772fd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c0fc482d-33f2-47e5-9f0c-140f7ec06d21",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 645e29b7c6319295ae8b13ce8575dc1d",
      "pattern": "[file:hashes.MD5 = '645e29b7c6319295ae8b13ce8575dc1d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c60f1d84-607f-454b-8678-aa6719a16232",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: bf891c72e4c29cfbe533756ea5685314",
      "pattern": "[file:hashes.MD5 = 'bf891c72e4c29cfbe533756ea5685314']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da44394b-f402-4d9c-b77e-c6f117faf7c9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: dbdb1032d7bb4757d6011fb1d077856c",
      "pattern": "[file:hashes.MD5 = 'dbdb1032d7bb4757d6011fb1d077856c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5ee23c15-d5ec-4da9-88a2-8b765840720e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e9c73997694a897d3c6aadb26ed34797",
      "pattern": "[file:hashes.MD5 = 'e9c73997694a897d3c6aadb26ed34797']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resour",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ecd124f-b135-4cb0-8ddc-12bb15413240",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-9995",
      "pattern": "[vulnerability:name = 'CVE-2018-9995']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25078 \u2014 D-Link DCS-2530L and DCS-2670L De",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e982d710-c459-4840-a502-cbdcc46d0894",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-25078",
      "pattern": "[vulnerability:name = 'CVE-2020-25078']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25078 \u2014 D-Link DCS-2530L and DCS-2670L De",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cf9159a6-8e68-4368-91bb-4639e55f458b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-25079",
      "pattern": "[vulnerability:name = 'CVE-2020-25079']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25079 \u2014 D-Link DCS-2530L and DCS-2670L Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb513acf-44c8-4aa8-a290-20e4c52b3b61",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-33044",
      "pattern": "[vulnerability:name = 'CVE-2021-33044']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25078 \u2014 D-Link DCS-2530L and DCS-2670L De",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-33044 \u2014 Dahua IP Camera Authentication By",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2c7ee290-d47a-481e-93c5-6626166cc250",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-40799",
      "pattern": "[vulnerability:name = 'CVE-2022-40799']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-40799 \u2014 D-Link DNR-322L Download of Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3fc4c94f-170e-42b3-8db7-471616cbdb3b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-2533",
      "pattern": "[vulnerability:name = 'CVE-2023-2533']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2533 \u2014 PaperCut NG/MF Cross-Site Request ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e93fb265-f1e5-46ac-b613-7584ec59fd1d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-20281",
      "pattern": "[vulnerability:name = 'CVE-2025-20281']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-20337 \u2014 Cisco Identity Services Engine In",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-20281 \u2014 Cisco Identity Services Engine In",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--42daf329-8429-4b22-b42e-6b5229313b4e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-20282",
      "pattern": "[vulnerability:name = 'CVE-2025-20282']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-20337 \u2014 Cisco Identity Services Engine In",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b7500487-0786-4d1d-9831-84d961904b3d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-20337",
      "pattern": "[vulnerability:name = 'CVE-2025-20337']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-20337 \u2014 Cisco Identity Services Engine In",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--936fc74e-2dbc-430d-9a34-1c2307cdba51",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-5777",
      "pattern": "[vulnerability:name = 'CVE-2025-5777']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-20337 \u2014 Cisco Identity Services Engine In",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-5777 \u2014 Citrix NetScaler ADC and Gateway O",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4469f093-0d5d-4b5c-8e7a-5f6b4936b1f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-36394",
      "pattern": "[vulnerability:name = 'CVE-2024-36394']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2775 \u2014 SysAid On-Prem Improper Restrictio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-2776 \u2014 SysAid On-Prem Improper Restrictio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2c2ac17a-6ef9-4880-bf88-2677207e71c5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-2775",
      "pattern": "[vulnerability:name = 'CVE-2025-2775']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2775 \u2014 SysAid On-Prem Improper Restrictio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-2776 \u2014 SysAid On-Prem Improper Restrictio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d619c49a-033b-49b1-9de4-9475ff1562e4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-2776",
      "pattern": "[vulnerability:name = 'CVE-2025-2776']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2775 \u2014 SysAid On-Prem Improper Restrictio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-2776 \u2014 SysAid On-Prem Improper Restrictio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d926a029-ab71-4789-af65-1e3dc9b58585",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-2777",
      "pattern": "[vulnerability:name = 'CVE-2025-2777']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2775 \u2014 SysAid On-Prem Improper Restrictio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-2776 \u2014 SysAid On-Prem Improper Restrictio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0cee7fb5-b71e-4cba-9910-108e5a8dbfd7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-49704",
      "pattern": "[vulnerability:name = 'CVE-2025-49704']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--897318c1-87f8-48af-8721-7c942023f4ef",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-49706",
      "pattern": "[vulnerability:name = 'CVE-2025-49706']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f1a9aaf0-1957-4e09-b4d3-835bc08af6ea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-53770",
      "pattern": "[vulnerability:name = 'CVE-2025-53770']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6b40c370-0592-4773-ab14-7f305344fe0d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-53771",
      "pattern": "[vulnerability:name = 'CVE-2025-53771']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c8d3e83b-33f0-4423-b56a-2323b50bab26",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-54309",
      "pattern": "[vulnerability:name = 'CVE-2025-54309']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-54309 \u2014  CrushFTP Unprotected Alternate C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7bb94a58-fdce-4bd5-9360-f69b7044acb4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-6558",
      "pattern": "[vulnerability:name = 'CVE-2025-6558']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-6558 \u2014 Google Chromium ANGLE and GPU Impr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2032e286-f140-4bb1-8783-7620ad928436",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: bpp.theinnovationfactory.it",
      "pattern": "[domain-name:value = 'bpp.theinnovationfactory.it']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4b3e4752-0f72-4a4c-bff7-20c6534eadb6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: c34718cbb4c6.ngrok-free.app",
      "pattern": "[domain-name:value = 'c34718cbb4c6.ngrok-free.app']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bd0391db-ef6a-4ca4-89d9-28cb7ceebcff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ice.theinnovationfactory.it",
      "pattern": "[domain-name:value = 'ice.theinnovationfactory.it']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9e7a24f9-20a9-490f-896b-f582bd7ec8a3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: msupdate.updatemicfosoft.com",
      "pattern": "[domain-name:value = 'msupdate.updatemicfosoft.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8a5baed1-5e16-4595-82ec-d61172e8d1f5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: npnjs.com",
      "pattern": "[domain-name:value = 'npnjs.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Maintainers of ESLint Prettier Plugin Attacked via npm Suppl",
          "url": "https://snyk.io/blog/maintainers-of-eslint-prettier-plugin-attacked-via-npm-supply-chain-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f36a0bd1-116e-486d-a57f-a32828cd0570",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: update.updatemicfosoft.com",
      "pattern": "[domain-name:value = 'update.updatemicfosoft.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f41647d5-eae9-4c98-935b-fffe537c0c16",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.238.159.149",
      "pattern": "[ipv4-addr:value = '104.238.159.149']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--880f89d4-6fc5-45c4-a0ce-a82d389d648e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 107.191.58.76",
      "pattern": "[ipv4-addr:value = '107.191.58.76']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4a6ea119-85e7-40ab-972b-0eb10a94d834",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 128.199.240.182",
      "pattern": "[ipv4-addr:value = '128.199.240.182']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ebda5f87-8315-432c-805c-fb3ef811c432",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 131.226.2.6",
      "pattern": "[ipv4-addr:value = '131.226.2.6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff3ca2d4-705f-494d-b913-ce9f5505c129",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 134.199.202.205",
      "pattern": "[ipv4-addr:value = '134.199.202.205']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d1b30da0-73cb-4731-96e6-3955f5062ab6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 139.144.199.41",
      "pattern": "[ipv4-addr:value = '139.144.199.41']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--131031eb-f50b-4711-9215-57280818308f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 145.239.97.206",
      "pattern": "[ipv4-addr:value = '145.239.97.206']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb220c9c-4b82-41c7-ab6b-ebced5fe0a40",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 149.28.124.70",
      "pattern": "[ipv4-addr:value = '149.28.124.70']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fd53e26c-9692-433c-9dd8-42b84c06308f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 149.40.50.15",
      "pattern": "[ipv4-addr:value = '149.40.50.15']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--765e5059-f514-4f67-a240-95d8fd52eff0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 154.223.19.106",
      "pattern": "[ipv4-addr:value = '154.223.19.106']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1a99f171-c34e-44bc-b4ef-7c5296c4c1d0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.197.248.131",
      "pattern": "[ipv4-addr:value = '185.197.248.131']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e2d324c3-1ee9-4d34-b59a-72bf6b170d1f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 188.130.206.168",
      "pattern": "[ipv4-addr:value = '188.130.206.168']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5d0d12e-e869-46ea-8bbe-9e7420976651",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 206.166.251.228",
      "pattern": "[ipv4-addr:value = '206.166.251.228']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e8c8b020-81b9-45cb-9cde-b148b89f5048",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 212.125.27.102",
      "pattern": "[ipv4-addr:value = '212.125.27.102']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--08079aae-0674-4b43-bdcc-46b305bbe311",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.77.155.170",
      "pattern": "[ipv4-addr:value = '45.77.155.170']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--34a3194b-fec0-44b0-ba1b-79c326d91d64",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.86.231.241",
      "pattern": "[ipv4-addr:value = '45.86.231.241']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--537a39a1-daee-47e6-8bb0-a8a0455a2eaf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 51.161.152.26",
      "pattern": "[ipv4-addr:value = '51.161.152.26']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f915fc2f-84bc-469f-8a18-88e94d34c310",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 64.176.50.109",
      "pattern": "[ipv4-addr:value = '64.176.50.109']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f506296b-0b28-4371-af0a-22e356a2c4df",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 65.38.121.198",
      "pattern": "[ipv4-addr:value = '65.38.121.198']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--03f1a329-96b8-4737-9c47-fa7364f6b25d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 86.48.9.38",
      "pattern": "[ipv4-addr:value = '86.48.9.38']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ffed9c97-0a0b-45b6-8793-e9f0da1525b6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 89.46.223.88",
      "pattern": "[ipv4-addr:value = '89.46.223.88']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--88519c8c-c90c-4160-8ca5-b6aaf6cc5782",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 91.132.95.60",
      "pattern": "[ipv4-addr:value = '91.132.95.60']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--59b1a982-2d12-40d6-a54f-d1496fc32648",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 91.236.230.76",
      "pattern": "[ipv4-addr:value = '91.236.230.76']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ef0b6b3a-2921-421f-add8-f0a3a1fb74ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 92.222.167.88",
      "pattern": "[ipv4-addr:value = '92.222.167.88']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--218f6d96-951e-4836-970a-f22bd26bc06b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 95.179.158.42",
      "pattern": "[ipv4-addr:value = '95.179.158.42']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5b7b0882-a8bc-4a2f-bf64-a0bef1776a63",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 96.9.125.147",
      "pattern": "[ipv4-addr:value = '96.9.125.147']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1bb70dc4-c806-4c61-aa7a-2c9549f1f3dd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1eb914c09c873f0a7bcf81475ab0f6bdfaccc6b63bf7e5f2dbf19295106af192",
      "pattern": "[file:hashes.'SHA-256' = '1eb914c09c873f0a7bcf81475ab0f6bdfaccc6b63bf7e5f2dbf19295106af192']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d68a018e-e0e9-4163-af51-01c280cc2ecc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 24480dbe306597da1ba393b6e30d542673066f98826cc07ac4b9033137f37dbf",
      "pattern": "[file:hashes.'SHA-256' = '24480dbe306597da1ba393b6e30d542673066f98826cc07ac4b9033137f37dbf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e25294df-0413-492f-9027-40e13f53d1dc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 33067028e35982c7b9fdcfe25eb4029463542451fdff454007832cf953feaf1e",
      "pattern": "[file:hashes.'SHA-256' = '33067028e35982c7b9fdcfe25eb4029463542451fdff454007832cf953feaf1e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9bef738f-9de4-4977-8dd9-dd997e68e923",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 390665bdd93a656f48c463bb6c11a4d45b7d5444bdd1d1f7a5879b0f6f9aac7e",
      "pattern": "[file:hashes.'SHA-256' = '390665bdd93a656f48c463bb6c11a4d45b7d5444bdd1d1f7a5879b0f6f9aac7e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--730bbf87-6b45-4814-8ad5-4ff5c1d130ed",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 445a37279d3a229ed18513e85f0c8d861c6f560e0f914a5869df14a74b679b86",
      "pattern": "[file:hashes.'SHA-256' = '445a37279d3a229ed18513e85f0c8d861c6f560e0f914a5869df14a74b679b86']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f5109ef-6500-48f5-b5b7-bdc4f3a83e68",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4a02a72aedc3356d8cb38f01f0e0b9f26ddc5ccb7c0f04a561337cf24aa84030",
      "pattern": "[file:hashes.'SHA-256' = '4a02a72aedc3356d8cb38f01f0e0b9f26ddc5ccb7c0f04a561337cf24aa84030']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--46cbd8ae-8a50-4131-956c-518ad4ecd12c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4c1750a14915bf2c0b093c2cb59063912dfa039a2adfe6d26d6914804e2ae928",
      "pattern": "[file:hashes.'SHA-256' = '4c1750a14915bf2c0b093c2cb59063912dfa039a2adfe6d26d6914804e2ae928']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b4ca730c-41bf-4f6a-be94-fe60a9339cd3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 567cb8e8c8bd0d909870c656b292b57bcb24eb55a8582b884e0a228e298e7443",
      "pattern": "[file:hashes.'SHA-256' = '567cb8e8c8bd0d909870c656b292b57bcb24eb55a8582b884e0a228e298e7443']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4c981f03-d75b-4d67-b9cd-8bcf649a8bfa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 62881359e75c9e8899c4bc9f452ef9743e68ce467f8b3e4398bebacde9550dea",
      "pattern": "[file:hashes.'SHA-256' = '62881359e75c9e8899c4bc9f452ef9743e68ce467f8b3e4398bebacde9550dea']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ac50802-dddc-4cda-a202-8b30ffbaadbd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 66af332ce5f93ce21d2fe408dffd49d4ae31e364d6802fff97d95ed593ff3082",
      "pattern": "[file:hashes.'SHA-256' = '66af332ce5f93ce21d2fe408dffd49d4ae31e364d6802fff97d95ed593ff3082']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--22632543-5e46-4ad0-b8d8-1937d8379e6d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6753b840cec65dfba0d7d326ec768bff2495784c60db6a139f51c5e83349ac4d",
      "pattern": "[file:hashes.'SHA-256' = '6753b840cec65dfba0d7d326ec768bff2495784c60db6a139f51c5e83349ac4d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--837e3a97-ae63-42d7-8414-ad1202b86274",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6b273c2179518dacb1218201fd37ee2492a5e1713be907e69bf7ea56ceca53a5",
      "pattern": "[file:hashes.'SHA-256' = '6b273c2179518dacb1218201fd37ee2492a5e1713be907e69bf7ea56ceca53a5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--010e4893-84ce-4d0f-8aed-f7b80075a46f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6f6db63ece791c6dc1054f1e1231b5bbcf6c051a49bad0784569271753e24619",
      "pattern": "[file:hashes.'SHA-256' = '6f6db63ece791c6dc1054f1e1231b5bbcf6c051a49bad0784569271753e24619']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fc1622d6-73bd-474a-ad61-d9173087eae3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7ae971e40528d364fa52f3bb5e0660ac25ef63e082e3bbd54f153e27b31eae68",
      "pattern": "[file:hashes.'SHA-256' = '7ae971e40528d364fa52f3bb5e0660ac25ef63e082e3bbd54f153e27b31eae68']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c71046d5-273b-41bb-883f-44cb00e135b9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7baf220eb89f2a216fcb2d0e9aa021b2a10324f0641caf8b7a9088e4e45bec95",
      "pattern": "[file:hashes.'SHA-256' = '7baf220eb89f2a216fcb2d0e9aa021b2a10324f0641caf8b7a9088e4e45bec95']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9198938c-564a-47d9-a8fc-bdaa48133f08",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 83705c75731e1d590b08f9357bc3b0f04741e92a033618736387512b40dab060",
      "pattern": "[file:hashes.'SHA-256' = '83705c75731e1d590b08f9357bc3b0f04741e92a033618736387512b40dab060']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--95ab8d20-f88f-4966-9dd9-fb5690709bce",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514",
      "pattern": "[file:hashes.'SHA-256' = '92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f39dd418-5b39-4984-8f29-688a5015eb13",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b180ab0a5845ed619939154f67526d2b04d28713fcc1904fbd666275538f431d",
      "pattern": "[file:hashes.'SHA-256' = 'b180ab0a5845ed619939154f67526d2b04d28713fcc1904fbd666275538f431d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7f4fbb69-d5e7-4fc0-904e-86f22b4b4528",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b39c14becb62aeb55df7fd55c814afbb0d659687d947d917512fe67973100b70",
      "pattern": "[file:hashes.'SHA-256' = 'b39c14becb62aeb55df7fd55c814afbb0d659687d947d917512fe67973100b70']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0fce80e9-e8fd-4ded-935b-66ba1d2de0c1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b5a78616f709859a0d9f830d28ff2f9dbbb2387df1753739407917e96dadf6b0",
      "pattern": "[file:hashes.'SHA-256' = 'b5a78616f709859a0d9f830d28ff2f9dbbb2387df1753739407917e96dadf6b0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6adb222-6fee-42c0-a87c-f7f34f35c428",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c27b725ff66fdfb11dd6487a3815d1d1eba89d61b0e919e4d06ed3ac6a74fe94",
      "pattern": "[file:hashes.'SHA-256' = 'c27b725ff66fdfb11dd6487a3815d1d1eba89d61b0e919e4d06ed3ac6a74fe94']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c19dffa1-5068-4ee4-ab5f-46f17f3063d3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c2c1fec7856e8d49f5d49267e69993837575dbbec99cd702c5be134a85b2c139",
      "pattern": "[file:hashes.'SHA-256' = 'c2c1fec7856e8d49f5d49267e69993837575dbbec99cd702c5be134a85b2c139']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c94e807d-17b0-43ce-a6d2-732b3ec9974f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c68e42f416f482d43653f36cd14384270b54b68d6496a8e34ce887687de5b441",
      "pattern": "[file:hashes.'SHA-256' = 'c68e42f416f482d43653f36cd14384270b54b68d6496a8e34ce887687de5b441']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Maintainers of ESLint Prettier Plugin Attacked via npm Suppl",
          "url": "https://snyk.io/blog/maintainers-of-eslint-prettier-plugin-attacked-via-npm-supply-chain-malware/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4ebd7ceb-d2ce-484e-8b56-e17726fc00d5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d6da885c90a5d1fb88d0a3f0b5d9817a82d5772d5510a0773c80ca581ce2486d",
      "pattern": "[file:hashes.'SHA-256' = 'd6da885c90a5d1fb88d0a3f0b5d9817a82d5772d5510a0773c80ca581ce2486d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2825310f-cf34-4595-8d12-749d06ece9bc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f54ae00a9bae73da001c4d3d690d26ddf5e8e006b5562f936df472ec5e299441",
      "pattern": "[file:hashes.'SHA-256' = 'f54ae00a9bae73da001c4d3d690d26ddf5e8e006b5562f936df472ec5e299441']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9acd917b-e175-491b-8cc8-7c4bb2f3d8e5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: fa3a74a6c015c801f5341c02be2cbdfb301c6ed60633d49fc0bc723617741af7",
      "pattern": "[file:hashes.'SHA-256' = 'fa3a74a6c015c801f5341c02be2cbdfb301c6ed60633d49fc0bc723617741af7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ef40497c-5945-4a35-8990-923c6a951539",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ffbc9dfc284b147e07a430fe9471e66c716a84a1f18976474a54bee82605fa9a",
      "pattern": "[file:hashes.'SHA-256' = 'ffbc9dfc284b147e07a430fe9471e66c716a84a1f18976474a54bee82605fa9a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b8dbdae3-bf30-4dfd-a331-bdeb06950ea1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: angelic.su",
      "pattern": "[domain-name:value = 'angelic.su']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cursor IDE Malware Extension Compromise in $500k Crypto Heis",
          "url": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--19240131-fe14-488e-bae3-dd372470fb6b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: begalinokotobananinotrippitroppacrocofanclub.su",
      "pattern": "[domain-name:value = 'begalinokotobananinotrippitroppacrocofanclub.su']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cursor IDE Malware Extension Compromise in $500k Crypto Heis",
          "url": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bcadeb21-ac99-4f41-bb99-eb8f03911c51",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: lmfao.su",
      "pattern": "[domain-name:value = 'lmfao.su']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cursor IDE Malware Extension Compromise in $500k Crypto Heis",
          "url": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--721c0469-76ee-44c8-bc5f-60b29995fe88",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: m-vn.ws",
      "pattern": "[domain-name:value = 'm-vn.ws']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cursor IDE Malware Extension Compromise in $500k Crypto Heis",
          "url": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d93a5db-ac9d-4aa7-8cd9-ee1b4851a0d9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: myaunet.su",
      "pattern": "[domain-name:value = 'myaunet.su']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cursor IDE Malware Extension Compromise in $500k Crypto Heis",
          "url": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2dc1b928-5a0a-4e27-a72c-b3c471d56ade",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: relay.lmfao.su",
      "pattern": "[domain-name:value = 'relay.lmfao.su']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cursor IDE Malware Extension Compromise in $500k Crypto Heis",
          "url": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2d075588-6df8-43f1-bdbc-f4f0f0d46c02",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: solidity.bot",
      "pattern": "[domain-name:value = 'solidity.bot']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cursor IDE Malware Extension Compromise in $500k Crypto Heis",
          "url": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff0af237-1568-4642-875f-10079e347d62",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: staketree.net",
      "pattern": "[domain-name:value = 'staketree.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cursor IDE Malware Extension Compromise in $500k Crypto Heis",
          "url": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--86d22961-3a54-4446-ab99-837479c2aece",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 144.172.112.84",
      "pattern": "[ipv4-addr:value = '144.172.112.84']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cursor IDE Malware Extension Compromise in $500k Crypto Heis",
          "url": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eac7671d-c23f-4f39-b276-8272143cfb1c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 209fb5bb2440ffe1a631dfe3b574229105a33c5153eded023cc77d8e8f81d1de",
      "pattern": "[file:hashes.'SHA-256' = '209fb5bb2440ffe1a631dfe3b574229105a33c5153eded023cc77d8e8f81d1de']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cursor IDE Malware Extension Compromise in $500k Crypto Heis",
          "url": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b38d6cd-fe49-4dff-9446-587f78525f35",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2c471e265409763024cdc33579c84d88d5aaf9aea1911266b875d3b7604a0eeb",
      "pattern": "[file:hashes.'SHA-256' = '2c471e265409763024cdc33579c84d88d5aaf9aea1911266b875d3b7604a0eeb']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cursor IDE Malware Extension Compromise in $500k Crypto Heis",
          "url": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e8e565d4-468b-48ea-ada2-5881eb8a610a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 404dd413f10ccfeea23bfb00b0e403532fa8651bfb456d84b6a16953355a800a",
      "pattern": "[file:hashes.'SHA-256' = '404dd413f10ccfeea23bfb00b0e403532fa8651bfb456d84b6a16953355a800a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cursor IDE Malware Extension Compromise in $500k Crypto Heis",
          "url": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bccbe6de-0242-479e-98f4-f8e64b3349b1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 70309bf3d2aed946bba51fc3eedb2daa3e8044b60151f0b5c1550831fbc6df17",
      "pattern": "[file:hashes.'SHA-256' = '70309bf3d2aed946bba51fc3eedb2daa3e8044b60151f0b5c1550831fbc6df17']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cursor IDE Malware Extension Compromise in $500k Crypto Heis",
          "url": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c863ce8a-b972-41cf-8d24-bc70985e8316",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 84d4a4c6d7e55e201b20327ca2068992180d9ec08a6827faa4ff3534b96c3d6f",
      "pattern": "[file:hashes.'SHA-256' = '84d4a4c6d7e55e201b20327ca2068992180d9ec08a6827faa4ff3534b96c3d6f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cursor IDE Malware Extension Compromise in $500k Crypto Heis",
          "url": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5ce927ed-c5e3-4b56-93cf-23da9fd05059",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a1eadd41327bd8736e275627d3953944fe7089c032d72a3e429ff18ad0958ada",
      "pattern": "[file:hashes.'SHA-256' = 'a1eadd41327bd8736e275627d3953944fe7089c032d72a3e429ff18ad0958ada']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cursor IDE Malware Extension Compromise in $500k Crypto Heis",
          "url": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--58502ba4-2b8d-4e09-b3b3-95882607c3e3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c3684164933c3f54d5b0b242a8a906a85d633de479079a820bb804c0f73c0f58",
      "pattern": "[file:hashes.'SHA-256' = 'c3684164933c3f54d5b0b242a8a906a85d633de479079a820bb804c0f73c0f58']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cursor IDE Malware Extension Compromise in $500k Crypto Heis",
          "url": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--12924807-0ce4-463c-8feb-962889876dc6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c5c0228a1e0ba2bb748219325f66acf17078a26165b45728d8e98150377aa068",
      "pattern": "[file:hashes.'SHA-256' = 'c5c0228a1e0ba2bb748219325f66acf17078a26165b45728d8e98150377aa068']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cursor IDE Malware Extension Compromise in $500k Crypto Heis",
          "url": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0ca40766-8e9b-4446-abaa-78e0ab95141c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ce72b79e324371134db762fe70b8b1789af899d7217461bc3658a6bd84743eb6",
      "pattern": "[file:hashes.'SHA-256' = 'ce72b79e324371134db762fe70b8b1789af899d7217461bc3658a6bd84743eb6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cursor IDE Malware Extension Compromise in $500k Crypto Heis",
          "url": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--495ea4dd-9678-4118-b183-17a441388dae",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e0ca66c1a9a68b319b24a7c6b8fdca219dffd802dd4de2d59f602c4d90f40d6c",
      "pattern": "[file:hashes.'SHA-256' = 'e0ca66c1a9a68b319b24a7c6b8fdca219dffd802dd4de2d59f602c4d90f40d6c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cursor IDE Malware Extension Compromise in $500k Crypto Heis",
          "url": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--281d43fe-60d9-4917-812a-cc4e0231520c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e19d5d8f941b9a98fbb3b65e1e6077fa00d97529e351e455297b0204ec07e9ed",
      "pattern": "[file:hashes.'SHA-256' = 'e19d5d8f941b9a98fbb3b65e1e6077fa00d97529e351e455297b0204ec07e9ed']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cursor IDE Malware Extension Compromise in $500k Crypto Heis",
          "url": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--73a7eb3a-2cb9-4918-94fa-91f35f087208",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: eb5b35057dedb235940b2c41da9e3ae0553969f1c89a16e3f66ba6f6005c6fa8",
      "pattern": "[file:hashes.'SHA-256' = 'eb5b35057dedb235940b2c41da9e3ae0553969f1c89a16e3f66ba6f6005c6fa8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cursor IDE Malware Extension Compromise in $500k Crypto Heis",
          "url": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d7e30aef-c387-4d64-ba5c-7de5d37b404e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f4721f32b8d6eb856364327c21ea3c703f1787cfb4c043f87435a8876d903b2c",
      "pattern": "[file:hashes.'SHA-256' = 'f4721f32b8d6eb856364327c21ea3c703f1787cfb4c043f87435a8876d903b2c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cursor IDE Malware Extension Compromise in $500k Crypto Heis",
          "url": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f49b7f20-16dc-4b53-a464-b96a88b12b92",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 141.164.60.10",
      "pattern": "[ipv4-addr:value = '141.164.60.10']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ed665514-e1b6-4283-b9f9-9dd55574d350",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-25257",
      "pattern": "[vulnerability:name = 'CVE-2025-25257']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-25257 \u2014 Fortinet FortiWeb SQL Injection V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--645cb2b4-5f3c-4cd9-853b-b7b96659ae4f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-47812",
      "pattern": "[vulnerability:name = 'CVE-2025-47812']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-47812 \u2014 Wing FTP Server Improper Neutrali",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f13a17e1-4930-42f2-aab8-f59cbd549c41",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: instance-y9tbyl-relay.screenconnect.com",
      "pattern": "[domain-name:value = 'instance-y9tbyl-relay.screenconnect.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-47812 \u2014 Wing FTP Server Improper Neutrali",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a2920f99-4551-4be8-a80e-01eff1fbd570",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: oooooooo11.screenconnect.com",
      "pattern": "[domain-name:value = 'oooooooo11.screenconnect.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-47812 \u2014 Wing FTP Server Improper Neutrali",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d37315b1-3246-4c41-aa3c-7bc46b4fc82b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.88.141.42",
      "pattern": "[ipv4-addr:value = '103.88.141.42']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-47812 \u2014 Wing FTP Server Improper Neutrali",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53bae4a5-97c9-4376-b24c-67760482780d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 146.70.11.39",
      "pattern": "[ipv4-addr:value = '146.70.11.39']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-47812 \u2014 Wing FTP Server Improper Neutrali",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--026d793d-b46c-4b4b-b476-46ed3f4dc379",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 149.248.44.88",
      "pattern": "[ipv4-addr:value = '149.248.44.88']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-47812 \u2014 Wing FTP Server Improper Neutrali",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f85af559-1854-4224-b975-d32a4479f594",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.196.9.225",
      "pattern": "[ipv4-addr:value = '185.196.9.225']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-47812 \u2014 Wing FTP Server Improper Neutrali",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--37298288-5011-4f87-8e56-2a296c6bd018",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 223.160.131.104",
      "pattern": "[ipv4-addr:value = '223.160.131.104']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-47812 \u2014 Wing FTP Server Improper Neutrali",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5de5e461-5927-4669-8bf2-437b732e1fe7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c637ec00bd22da4539ec6def89cd9f7196a303d17632b1131a89d65e4f5698f4",
      "pattern": "[file:hashes.'SHA-256' = 'c637ec00bd22da4539ec6def89cd9f7196a303d17632b1131a89d65e4f5698f4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-47812 \u2014 Wing FTP Server Improper Neutrali",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4a965d3d-40c2-494c-b33c-f034ecdeb5fa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f0fcc638cd93bdd6fb4745d75b491395a7a1b2cb08e0153a2eb417cb2f58d8ac",
      "pattern": "[file:hashes.'SHA-256' = 'f0fcc638cd93bdd6fb4745d75b491395a7a1b2cb08e0153a2eb417cb2f58d8ac']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-47812 \u2014 Wing FTP Server Improper Neutrali",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--25c820ca-ecd4-482d-9c9d-0d99413d8865",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-3931",
      "pattern": "[vulnerability:name = 'CVE-2014-3931']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-3931 \u2014 Multi-Router Looking Glass (MRLG) ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f5f458a0-61b8-43cc-aae6-262ce1a226c6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-10033",
      "pattern": "[vulnerability:name = 'CVE-2016-10033']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-10033 \u2014 PHPMailer Command Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8872a4e3-a0ca-4107-93e4-e2815da19456",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-10045",
      "pattern": "[vulnerability:name = 'CVE-2016-10045']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-10033 \u2014 PHPMailer Command Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1b76c076-0310-4180-b279-eaeec7cd63ad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-5418",
      "pattern": "[vulnerability:name = 'CVE-2019-5418']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-5418 \u2014 Rails Ruby on Rails Path Traversal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4e765aee-bba2-44ef-a16c-0d38250b4e78",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-9621",
      "pattern": "[vulnerability:name = 'CVE-2019-9621']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-9621 \u2014 Synacor Zimbra Collaboration Suite",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d252ffdb-ef70-4590-9044-804e9e6c2b13",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-9670",
      "pattern": "[vulnerability:name = 'CVE-2019-9670']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-9621 \u2014 Synacor Zimbra Collaboration Suite",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-9670 \u2014 Synacor Zimbra Collaboration Suite",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--37dbacff-32d7-4bbe-bc86-6f4eef50da89",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-6554",
      "pattern": "[vulnerability:name = 'CVE-2025-6554']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-6554 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ecab5af0-bcdf-4ce7-9057-1409ad3206f7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-48927",
      "pattern": "[vulnerability:name = 'CVE-2025-48927']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-48928 \u2014 TeleMessage TM SGNL Exposure of C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-48927 \u2014 TeleMessage TM SGNL Initializatio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de3af30a-7cc3-4e5f-b51e-786c4f320e31",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-48928",
      "pattern": "[vulnerability:name = 'CVE-2025-48928']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-48928 \u2014 TeleMessage TM SGNL Exposure of C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--43910738-f1b6-4b44-b4f2-75299b8ca21e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-6543",
      "pattern": "[vulnerability:name = 'CVE-2025-6543']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-6543 \u2014 Citrix NetScaler ADC and Gateway B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--159b347f-3b64-413e-a67c-f38e031ced58",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-6693",
      "pattern": "[vulnerability:name = 'CVE-2019-6693']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-6693 \u2014 Fortinet FortiOS Use of Hard-Coded",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b8a71a5a-be95-4e39-ab6a-3245db3ca22a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-26872",
      "pattern": "[vulnerability:name = 'CVE-2022-26872']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-54085 \u2014 AMI MegaRAC SPx Authentication By",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d08cc32-0df8-4e07-bf8d-ab466291a099",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-2827",
      "pattern": "[vulnerability:name = 'CVE-2022-2827']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-54085 \u2014 AMI MegaRAC SPx Authentication By",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c02cb1e9-9f17-4597-b2ca-ceca26ec0e97",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-40242",
      "pattern": "[vulnerability:name = 'CVE-2022-40242']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-54085 \u2014 AMI MegaRAC SPx Authentication By",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f8fa67f-e5a0-4e69-ad97-1c58cc1c5b16",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-40258",
      "pattern": "[vulnerability:name = 'CVE-2022-40258']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-54085 \u2014 AMI MegaRAC SPx Authentication By",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d2968ac-52ee-479d-b260-6e73257860ae",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-40259",
      "pattern": "[vulnerability:name = 'CVE-2022-40259']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-54085 \u2014 AMI MegaRAC SPx Authentication By",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f57e8ec0-2c47-4be5-a4cd-ecde8e65cd0b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-34329",
      "pattern": "[vulnerability:name = 'CVE-2023-34329']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-54085 \u2014 AMI MegaRAC SPx Authentication By",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7616a501-e1d7-4ecf-a30e-8078f66ee9c3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-34330",
      "pattern": "[vulnerability:name = 'CVE-2023-34330']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-54085 \u2014 AMI MegaRAC SPx Authentication By",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ddb3026e-96ac-440c-b068-abea01919ef3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-0769",
      "pattern": "[vulnerability:name = 'CVE-2024-0769']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-0769 \u2014  D-Link DIR-859 Router Path Traver",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fd912baa-1425-4bed-8211-2af4b435ebb9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-54085",
      "pattern": "[vulnerability:name = 'CVE-2024-54085']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-54085 \u2014 AMI MegaRAC SPx Authentication By",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cc18842c-4ec4-4191-b876-901f34edc717",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-0386",
      "pattern": "[vulnerability:name = 'CVE-2023-0386']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-0386 \u2014 Linux Kernel Improper Ownership Ma",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--269d5599-494f-42c9-b963-ccb4110ffb31",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-33538",
      "pattern": "[vulnerability:name = 'CVE-2023-33538']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--006825c6-5589-4efb-a7db-de14ff0d64ce",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-43200",
      "pattern": "[vulnerability:name = 'CVE-2025-43200']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-43200 \u2014 Apple Multiple Products Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2485863a-e359-4e15-a0d2-9e9fd5fa96df",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: bot.ddosvps.cc",
      "pattern": "[domain-name:value = 'bot.ddosvps.cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb5d2988-1fb3-48f7-b160-814318b232e1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cnc.vietdediserver.shop",
      "pattern": "[domain-name:value = 'cnc.vietdediserver.shop']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9956893d-8441-4bab-a857-1ae5904d3f7d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 51.38.137.113",
      "pattern": "[ipv4-addr:value = '51.38.137.113']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f643499-997e-4d7c-9223-12d2c3cea9e0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 00078aeeaca54b5d3c1237e964e9f956690b782e4ea160d81edc3c6b44e7f620",
      "pattern": "[file:hashes.'SHA-256' = '00078aeeaca54b5d3c1237e964e9f956690b782e4ea160d81edc3c6b44e7f620']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5210cde3-7a05-4687-b724-2e3edd535094",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3fbd2a2e82ceb5e91eadbad02cb45ac618324da9b1895d81ebe7de765dca30e7",
      "pattern": "[file:hashes.'SHA-256' = '3fbd2a2e82ceb5e91eadbad02cb45ac618324da9b1895d81ebe7de765dca30e7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cf8475c3-74ec-48a8-a244-491cb3ffdd52",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4caaa18982cd4056fead54b98d57f9a2a1ddd654cf19a7ba2366dfadbd6033da",
      "pattern": "[file:hashes.'SHA-256' = '4caaa18982cd4056fead54b98d57f9a2a1ddd654cf19a7ba2366dfadbd6033da']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2b28f781-37b1-4e5c-b4cf-736d1c65b413",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 534b654531a6a540a144da9545ee343e1046f843d7de4c1091b46c3ee66a508b",
      "pattern": "[file:hashes.'SHA-256' = '534b654531a6a540a144da9545ee343e1046f843d7de4c1091b46c3ee66a508b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--18b3ed0a-a05e-4d3f-80f8-41e4376593f5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 56f21f412e898ad9e3ee05d5f44c44d9d7bcb9ecbfbdb9de11b8fa5a637aeef6",
      "pattern": "[file:hashes.'SHA-256' = '56f21f412e898ad9e3ee05d5f44c44d9d7bcb9ecbfbdb9de11b8fa5a637aeef6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--df7c3124-4941-450f-a7c3-008617d83d38",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7bbb21fec19512d932b7a92652ed0c8f0fedea89f34b9d6f267cf39de0eb9b20",
      "pattern": "[file:hashes.'SHA-256' = '7bbb21fec19512d932b7a92652ed0c8f0fedea89f34b9d6f267cf39de0eb9b20']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--087bc27a-3d1e-4a63-b31a-33bf1a49e148",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 919f292a07a37f163f88527e725406187c8ecc637387ad24853fe49ce4e6ddf4",
      "pattern": "[file:hashes.'SHA-256' = '919f292a07a37f163f88527e725406187c8ecc637387ad24853fe49ce4e6ddf4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--af763c5a-0495-4217-babf-01c06c4cbe98",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9df711c3aef2bba17b622ddfd955452f8d8eb55899528fbc13d9540c52f13402",
      "pattern": "[file:hashes.'SHA-256' = '9df711c3aef2bba17b622ddfd955452f8d8eb55899528fbc13d9540c52f13402']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cba45512-1b5d-42fa-82f0-bc0ed764458f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c321933e4e5970ba7299fe21778dab9398994c22ca0ba0422c6cbc3fbb95ea26",
      "pattern": "[file:hashes.'SHA-256' = 'c321933e4e5970ba7299fe21778dab9398994c22ca0ba0422c6cbc3fbb95ea26']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e5a3b042-0859-4616-857a-9e830c7266ce",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-8361",
      "pattern": "[vulnerability:name = 'CVE-2014-8361']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2014-8361 \u2014 Realtek SDK Improper Input Validat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5237bd77-5009-42e9-a0ba-0086d9961f93",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-17215",
      "pattern": "[vulnerability:name = 'CVE-2017-17215']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-45382 \u2014 D-Link Multiple Routers Remote Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e37e4810-4a37-40c3-b92a-a681af65696c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-18368",
      "pattern": "[vulnerability:name = 'CVE-2017-18368']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-18368 \u2014 Zyxel P660HN-T1A Routers Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ee5454b4-0d42-43b7-b823-091d0b963b90",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-3721",
      "pattern": "[vulnerability:name = 'CVE-2024-3721']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2470a296-e8e9-48cb-a501-5371d50fcaec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-24016",
      "pattern": "[vulnerability:name = 'CVE-2025-24016']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0ae10cf7-a666-404b-b4c0-b5dc1d3e57ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-33053",
      "pattern": "[vulnerability:name = 'CVE-2025-33053']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Contr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--79afebc7-ed68-40f1-be83-53cce538e263",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cbot.galaxias.cc",
      "pattern": "[domain-name:value = 'cbot.galaxias.cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--688a5b00-7735-4cca-acc6-77cf006dc711",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cyclingonlineshop.com",
      "pattern": "[domain-name:value = 'cyclingonlineshop.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Contr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8bd7bb24-34f9-4245-91df-a8b340503d53",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: downloadessays.net",
      "pattern": "[domain-name:value = 'downloadessays.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Contr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32419604-f761-465c-8bcf-70592545eecb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: fastfilebackup.com",
      "pattern": "[domain-name:value = 'fastfilebackup.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Contr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ad1b357-b259-4a78-9d3d-021ab392a69b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: galaxias.cc",
      "pattern": "[domain-name:value = 'galaxias.cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--81ffa21e-a92f-41f7-b1fe-8a1a53e5fef9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: gestisciweb.com",
      "pattern": "[domain-name:value = 'gestisciweb.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7a874bae-2242-4146-9aaf-e23e5a7ae3bd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: healthherofit.com",
      "pattern": "[domain-name:value = 'healthherofit.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Contr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9438a490-4735-4b8d-b51c-3a0bea3f683d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: joinushealth.com",
      "pattern": "[domain-name:value = 'joinushealth.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Contr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--17ec3350-b191-4669-9b0e-c01de3f9333c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: luxuryfitnesslabs.com",
      "pattern": "[domain-name:value = 'luxuryfitnesslabs.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Contr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--75166802-c846-4fe4-a58c-129b5e1d1e5a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: mystartupblog.com",
      "pattern": "[domain-name:value = 'mystartupblog.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Contr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--98ccc079-4a73-43d9-8d8a-a59b3e14dd78",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: nuklearcnc.duckdns.org",
      "pattern": "[domain-name:value = 'nuklearcnc.duckdns.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b566b5c5-09f8-4e0e-abfb-2f0364f72ab7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: purvoyage.com",
      "pattern": "[domain-name:value = 'purvoyage.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Contr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--884b3f20-9033-4bb0-9fe6-3ebba45547cb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: radiotimesignal.com",
      "pattern": "[domain-name:value = 'radiotimesignal.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Contr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d188efb-a8bd-4b13-8231-bc2e623cf3d1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: roundedbullets.com",
      "pattern": "[domain-name:value = 'roundedbullets.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Contr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87ae16c6-39d3-42c5-a3a7-d471432b4b9a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: summerartcamp.net",
      "pattern": "[domain-name:value = 'summerartcamp.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Contr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cd63c2ca-af06-4de0-a788-6e51074efb9b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: worryfreetransport.com",
      "pattern": "[domain-name:value = 'worryfreetransport.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Contr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--83a6fd96-53a4-4fb0-84e7-748ab85536b3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.168.101.27",
      "pattern": "[ipv4-addr:value = '104.168.101.27']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4a9dd337-d761-449d-a0d6-a90e465a9221",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 176.65.134.62",
      "pattern": "[ipv4-addr:value = '176.65.134.62']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da0fdd69-ca60-4576-8475-4afc0625bfb7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 176.65.142.137",
      "pattern": "[ipv4-addr:value = '176.65.142.137']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0bca78c-a250-44d6-a6a7-1669343e526b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 196.251.86.49",
      "pattern": "[ipv4-addr:value = '196.251.86.49']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e4b668b0-5069-4ab0-946a-363fb5e2b1ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 209.141.34.106",
      "pattern": "[ipv4-addr:value = '209.141.34.106']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--55d3345c-66b7-4f9d-b271-1a04425f1f12",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 42.112.26.36",
      "pattern": "[ipv4-addr:value = '42.112.26.36']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c0eaad01-97f7-4210-802f-9c6aca99fb85",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 65.222.202.53",
      "pattern": "[ipv4-addr:value = '65.222.202.53']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d21c6e9-0a61-4b96-af88-c6f868620f92",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1d95a44f341435da50878eea1ec0a1aab6ae0ee91644c497378266290a6ef1d8",
      "pattern": "[file:hashes.'SHA-256' = '1d95a44f341435da50878eea1ec0a1aab6ae0ee91644c497378266290a6ef1d8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Contr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3e33c5e1-6806-43d4-b2d4-0c1427d67cb8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 257c63a9e21b829bb4b9f8b0e352379444b0e573176530107a3e6c279d1919da",
      "pattern": "[file:hashes.'SHA-256' = '257c63a9e21b829bb4b9f8b0e352379444b0e573176530107a3e6c279d1919da']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Contr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7e4f83e0-fc21-445f-9d75-8af301c5649e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 66a893728a0ac1a7fae39ee134ad4182d674e719219fbf5d9b7cd4fd4f07f535",
      "pattern": "[file:hashes.'SHA-256' = '66a893728a0ac1a7fae39ee134ad4182d674e719219fbf5d9b7cd4fd4f07f535']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Contr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4e75ff6a-4ca1-4651-a631-8961f84af4db",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 700b422556f070325b327325e31ddf597f98cc319f29ef8638c7b0508c632cee",
      "pattern": "[file:hashes.'SHA-256' = '700b422556f070325b327325e31ddf597f98cc319f29ef8638c7b0508c632cee']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Contr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0ddba2e8-a8e6-4c9b-9727-33293eb397d9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: da3bb6e38b3f4d83e69d31783f00c10ce062abd008e81e983a9bd4317a9482aa",
      "pattern": "[file:hashes.'SHA-256' = 'da3bb6e38b3f4d83e69d31783f00c10ce062abd008e81e983a9bd4317a9482aa']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Contr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5b2c4afc-689c-401b-bc21-0a5a5993d4c1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ddce79afe9f67b78e83f6e530c3e03265533eb3f4530e7c89fdc357f7093a80b",
      "pattern": "[file:hashes.'SHA-256' = 'ddce79afe9f67b78e83f6e530c3e03265533eb3f4530e7c89fdc357f7093a80b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Contr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76135a36-fdea-4364-bad1-1b61e1bfd135",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-32433",
      "pattern": "[vulnerability:name = 'CVE-2025-32433']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-32433 \u2014 Erlang Erlang/OTP SSH Server Miss",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ec138b95-b2c8-424c-8b62-f74068cc9165",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: a.mpk-krakow.pl",
      "pattern": "[domain-name:value = 'a.mpk-krakow.pl']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-42009 \u2014 RoundCube Webmail Cross-Site Scri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b5272d1c-613a-40a9-a5d5-a890fda09897",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: dns.outbound.watchtowr.com",
      "pattern": "[domain-name:value = 'dns.outbound.watchtowr.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-32433 \u2014 Erlang Erlang/OTP SSH Server Miss",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9cdffc48-dd75-4aa7-8cd6-8978583bc854",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 146.103.40.203",
      "pattern": "[ipv4-addr:value = '146.103.40.203']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-32433 \u2014 Erlang Erlang/OTP SSH Server Miss",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d436532a-65a0-4131-999f-eab2ea80bd1d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.165.16.71",
      "pattern": "[ipv4-addr:value = '194.165.16.71']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-32433 \u2014 Erlang Erlang/OTP SSH Server Miss",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd216d17-f7c3-4e29-8fad-32a5b2ef2610",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 70cea07c972a30597cda7a1d3cd4cd8f75acad75940ca311a5a2033e6a1dd149",
      "pattern": "[file:hashes.'SHA-256' = '70cea07c972a30597cda7a1d3cd4cd8f75acad75940ca311a5a2033e6a1dd149']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-42009 \u2014 RoundCube Webmail Cross-Site Scri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c4b2abe0-f461-437d-b4f4-b6c52ddfc170",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-5419",
      "pattern": "[vulnerability:name = 'CVE-2025-5419']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-5419 \u2014 Google Chromium V8 Out-of-Bounds R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--55de85dd-a382-4d67-af25-64e32d2d9772",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-21479",
      "pattern": "[vulnerability:name = 'CVE-2025-21479']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21479 \u2014 Qualcomm Multiple Chipsets Incorr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21480 \u2014 Qualcomm Multiple Chipsets Incorr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-27038 \u2014 Qualcomm Multiple Chipsets Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea365f8f-0ebe-4be6-84a4-f3ba4b141671",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-21480",
      "pattern": "[vulnerability:name = 'CVE-2025-21480']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21479 \u2014 Qualcomm Multiple Chipsets Incorr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21480 \u2014 Qualcomm Multiple Chipsets Incorr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-27038 \u2014 Qualcomm Multiple Chipsets Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f395e900-f9ad-4b01-8265-8ee803f5369e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-27038",
      "pattern": "[vulnerability:name = 'CVE-2025-27038']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21479 \u2014 Qualcomm Multiple Chipsets Incorr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21480 \u2014 Qualcomm Multiple Chipsets Incorr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-27038 \u2014 Qualcomm Multiple Chipsets Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb9333f9-09e3-43c5-8059-374ed0cfb813",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-32030",
      "pattern": "[vulnerability:name = 'CVE-2021-32030']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-32030 \u2014 ASUS Routers Improper Authenticat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9ffeb928-18f0-4676-83d7-f3462f520493",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-39780",
      "pattern": "[vulnerability:name = 'CVE-2023-39780']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-32030 \u2014 ASUS Routers Improper Authenticat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-39780 \u2014 ASUS RT-AX55 Routers OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d70e40d3-cd94-42bd-a2c1-1a98d586025f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-56145",
      "pattern": "[vulnerability:name = 'CVE-2024-56145']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-56145 \u2014 Craft CMS Code Injection Vulnerab",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ddad912a-0df9-4375-b03e-c586e01b7eac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-58136",
      "pattern": "[vulnerability:name = 'CVE-2024-58136']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-35939 \u2014 Craft CMS External Control of Ass",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-58136 \u2014 Yiiframework Yii Improper Protect",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cdc9429a-1a2c-4c2e-9f59-81f7f2c2542e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-35939",
      "pattern": "[vulnerability:name = 'CVE-2025-35939']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-35939 \u2014 Craft CMS External Control of Ass",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--59869819-3a51-4a1b-94e5-eb8c47c5d50c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-3935",
      "pattern": "[vulnerability:name = 'CVE-2025-3935']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-3935 \u2014 ConnectWise ScreenConnect Improper",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--207b71fe-c0e9-47f1-a299-9e397a812806",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 101.99.91.151",
      "pattern": "[ipv4-addr:value = '101.99.91.151']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-32030 \u2014 ASUS Routers Improper Authenticat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-39780 \u2014 ASUS RT-AX55 Routers OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eaaf9029-5213-44db-a136-675e78d6bc72",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 101.99.94.173",
      "pattern": "[ipv4-addr:value = '101.99.94.173']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-32030 \u2014 ASUS Routers Improper Authenticat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-39780 \u2014 ASUS RT-AX55 Routers OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4dc2e4da-2334-4a73-bd43-537c47fd0957",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.106.66.123",
      "pattern": "[ipv4-addr:value = '103.106.66.123']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-35939 \u2014 Craft CMS External Control of Ass",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc60f232-1b7d-45cd-863e-640dd67571f9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.161.32.11",
      "pattern": "[ipv4-addr:value = '104.161.32.11']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-35939 \u2014 Craft CMS External Control of Ass",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de15bb5c-06fc-462a-aa13-cc40af2ac4a7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 111.90.146.237",
      "pattern": "[ipv4-addr:value = '111.90.146.237']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-32030 \u2014 ASUS Routers Improper Authenticat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-39780 \u2014 ASUS RT-AX55 Routers OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--795eefd5-3bd1-4879-847e-3b33490e12be",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 154.211.22.213",
      "pattern": "[ipv4-addr:value = '154.211.22.213']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-35939 \u2014 Craft CMS External Control of Ass",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--14941310-40b9-4421-b6b0-22a9b87ca890",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.86.113.137",
      "pattern": "[ipv4-addr:value = '172.86.113.137']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-35939 \u2014 Craft CMS External Control of Ass",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--afb23f00-c5e0-47e8-9113-712dae1248f1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.145.208.231",
      "pattern": "[ipv4-addr:value = '38.145.208.231']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-35939 \u2014 Craft CMS External Control of Ass",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2d558835-25df-412f-92f6-dddf98015bea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 79.141.163.179",
      "pattern": "[ipv4-addr:value = '79.141.163.179']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-32030 \u2014 ASUS Routers Improper Authenticat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-39780 \u2014 ASUS RT-AX55 Routers OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5aa87bb-d2de-4cb2-934c-d1c37282306f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: d8fddbd85e6af76c91bfa17118dbecc6",
      "pattern": "[file:hashes.MD5 = 'd8fddbd85e6af76c91bfa17118dbecc6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-35939 \u2014 Craft CMS External Control of Ass",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--24bd6f6f-c669-41d0-8acf-5e16e7017ddb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: e6c3e12f6712719f69f40fb6f06e2b60facd8e61",
      "pattern": "[file:hashes.'SHA-1' = 'e6c3e12f6712719f69f40fb6f06e2b60facd8e61']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-35939 \u2014 Craft CMS External Control of Ass",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e01e8765-7c49-41f1-82b9-a720ffd493d5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: dce988346f98d55b97f7ca7a4c49cef2883b80855a0ecb6371df4063e7ecc40d",
      "pattern": "[file:hashes.'SHA-256' = 'dce988346f98d55b97f7ca7a4c49cef2883b80855a0ecb6371df4063e7ecc40d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-35939 \u2014 Craft CMS External Control of Ass",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c83eb843-807b-402c-9276-33fd521a4e80",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-4632",
      "pattern": "[vulnerability:name = 'CVE-2025-4632']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4632 \u2014 Samsung MagicINFO 9 Server Path Tr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f764175-ad3f-485a-94f3-0b2bbb167392",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-12641",
      "pattern": "[vulnerability:name = 'CVE-2020-12641']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-12641 \u2014 Roundcube Webmail Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--99c4128b-c2e0-49f6-8cb5-78b869422472",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-35730",
      "pattern": "[vulnerability:name = 'CVE-2020-35730']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-5631 \u2014 Roundcube Webmail Persistent Cross",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--99715270-3f73-43a7-8a3d-abf11f282a4e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-44026",
      "pattern": "[vulnerability:name = 'CVE-2021-44026']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-44026 \u2014 Roundcube Webmail SQL Injection V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d732df79-1ae5-4d5f-801d-219ccbe05e20",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-38950",
      "pattern": "[vulnerability:name = 'CVE-2023-38950']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-38950 \u2014 ZKTeco BioTime Path Traversal Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--93466981-1d90-42a4-ae13-7ed48d6401cd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-43770",
      "pattern": "[vulnerability:name = 'CVE-2023-43770']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-43770 \u2014 Roundcube Webmail Persistent Cros",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0ecacec-1649-4409-a790-0540d31dbf46",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-11182",
      "pattern": "[vulnerability:name = 'CVE-2024-11182']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bf398e4e-a276-4095-b177-f34882cfd7c6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-27443",
      "pattern": "[vulnerability:name = 'CVE-2024-27443']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e385c35d-272f-4f8e-9448-c2100a23a226",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-27920",
      "pattern": "[vulnerability:name = 'CVE-2025-27920']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-27920 \u2014 Srimax Output Messenger Directory",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0e77d285-4e19-449f-8ba8-abcf2090f950",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-35036",
      "pattern": "[vulnerability:name = 'CVE-2025-35036']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4a9ed24d-2921-4c00-9375-96dc714244b2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-4427",
      "pattern": "[vulnerability:name = 'CVE-2025-4427']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--90d5568b-b11e-42c0-b6cf-3ea52e7c5700",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-4428",
      "pattern": "[vulnerability:name = 'CVE-2025-4428']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6564aa46-4fad-48f0-a6ee-1fe7f05f41ac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: api.wordinfos.com",
      "pattern": "[domain-name:value = 'api.wordinfos.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-27920 \u2014 Srimax Output Messenger Directory",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e99c301-3090-49a1-9be6-afe6932587ed",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: censysinspect.com",
      "pattern": "[domain-name:value = 'censysinspect.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb1cb5e0-96a2-4e1d-95a5-502df60dc92c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: craft-dev.greenenaftaligallery.com",
      "pattern": "[domain-name:value = 'craft-dev.greenenaftaligallery.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9ef301a4-5621-4ec2-94d6-5176e6f48a5d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: e-wago.pl",
      "pattern": "[domain-name:value = 'e-wago.pl']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c46cafd-e4d3-497a-ad73-4f5f412e9a9b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: elektrobohater.pl",
      "pattern": "[domain-name:value = 'elektrobohater.pl']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7216ead2-c61d-4c07-9d26-8f9684fc1c4c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: hfuu.de",
      "pattern": "[domain-name:value = 'hfuu.de']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c95e5fcf-f9de-427e-b711-e514cc79b761",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: hijx.xyz",
      "pattern": "[domain-name:value = 'hijx.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d143b0a-78d4-4436-9da9-ba3a8ae6a7ce",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ikses.net",
      "pattern": "[domain-name:value = 'ikses.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--43b47892-b1e6-4f5d-a120-eb8b808bb3f6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: jiaw.shop",
      "pattern": "[domain-name:value = 'jiaw.shop']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--55544e97-773d-42e8-83e5-515d092d54e6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: lsjb.digital",
      "pattern": "[domain-name:value = 'lsjb.digital']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--39b79a0d-0bed-4b7e-89c2-6e9ba2118109",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ns1.cybertunnel.run",
      "pattern": "[domain-name:value = 'ns1.cybertunnel.run']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f2abbdbb-80ae-47a2-afba-c8383589b738",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: raxia.top",
      "pattern": "[domain-name:value = 'raxia.top']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--37f7a498-faa6-4127-a201-e4c15ccd1b75",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: rnl.world",
      "pattern": "[domain-name:value = 'rnl.world']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67822ade-0af4-4b7c-a59c-a1e0b0c8e73e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sqj.fr",
      "pattern": "[domain-name:value = 'sqj.fr']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ac2256d7-1c0f-4db0-b6a8-e3e9ac942df4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: tgh24.xyz",
      "pattern": "[domain-name:value = 'tgh24.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76674f85-8c1d-41c9-bb6f-833c6dc47081",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: tuo.world",
      "pattern": "[domain-name:value = 'tuo.world']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--115286d5-f28d-4f2b-9738-e00847ffe6d5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: wagodirect.pl",
      "pattern": "[domain-name:value = 'wagodirect.pl']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7fa57cc9-b179-485e-a493-15c214b9173c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 100.26.51.59",
      "pattern": "[ipv4-addr:value = '100.26.51.59']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b8f2f257-6e43-4cad-97ff-1d4cccb68024",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.244.88.125",
      "pattern": "[ipv4-addr:value = '103.244.88.125']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--70471f92-f4ad-48e3-974f-2ea8d394cf3d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 111.90.151.167",
      "pattern": "[ipv4-addr:value = '111.90.151.167']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e71adff1-d308-4efa-aa2d-32d0b0178c8a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 124.223.202.90",
      "pattern": "[ipv4-addr:value = '124.223.202.90']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--38bc9b54-5ebe-4d13-a2cc-b46d286d8b81",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 146.70.125.79",
      "pattern": "[ipv4-addr:value = '146.70.125.79']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6736a11b-2b04-49cf-941a-80aa1d39df80",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 146.70.87.67",
      "pattern": "[ipv4-addr:value = '146.70.87.67']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--61c505d1-677b-46bc-935f-a2aaa0d9a085",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 150.241.71.231",
      "pattern": "[ipv4-addr:value = '150.241.71.231']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a0cca8e-2f0b-45f1-8e46-12d029113cd2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 150.241.97.83",
      "pattern": "[ipv4-addr:value = '150.241.97.83']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--27d8f94f-d15b-4849-91ef-d1e89356d369",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.193.125.65",
      "pattern": "[ipv4-addr:value = '185.193.125.65']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5ea7e035-99e1-49a0-a21c-a1f16d81f366",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.195.237.106",
      "pattern": "[ipv4-addr:value = '185.195.237.106']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c661b02e-857a-4aaa-b70b-97c4490096ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.225.69.223",
      "pattern": "[ipv4-addr:value = '185.225.69.223']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5343b5ea-8a2c-40a7-8aff-31d62c925f48",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.29.104.152",
      "pattern": "[ipv4-addr:value = '193.29.104.152']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8e35983a-c829-4024-8c6c-bbfe92a959f0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 27.25.148.183",
      "pattern": "[ipv4-addr:value = '27.25.148.183']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0a5f91b4-457e-4567-92dd-72dc919f1af1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 37.219.84.22",
      "pattern": "[ipv4-addr:value = '37.219.84.22']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f921f55-9e3f-4178-94e4-1a44aecbf9fb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.137.222.24",
      "pattern": "[ipv4-addr:value = '45.137.222.24']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6b3ba8a1-b95c-4d15-b1c4-e8807106448c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.38.17.43",
      "pattern": "[ipv4-addr:value = '45.38.17.43']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--01c36eca-e09b-46f0-99ee-fae805d3615c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 47.120.74.19",
      "pattern": "[ipv4-addr:value = '47.120.74.19']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--93caed6c-07a7-4b7e-b191-3e3e8a7a0982",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.181.159.149",
      "pattern": "[ipv4-addr:value = '5.181.159.149']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--502a9382-d06e-4629-b154-347cb6ab6b99",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 75.170.92.132",
      "pattern": "[ipv4-addr:value = '75.170.92.132']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dde11bdd-29fc-42b4-a63c-4ed42553a062",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 77.221.158.154",
      "pattern": "[ipv4-addr:value = '77.221.158.154']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7bea955a-cc12-45c2-89e3-97570528afce",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 82.132.235.212",
      "pattern": "[ipv4-addr:value = '82.132.235.212']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd3b704c-ca4a-458b-930d-05184ba1df83",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 83.229.126.234",
      "pattern": "[ipv4-addr:value = '83.229.126.234']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--790deec7-7e4b-451b-926b-a723592d38f5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 88.194.29.21",
      "pattern": "[ipv4-addr:value = '88.194.29.21']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c5d48d82-84e3-400f-89e0-55cdeabb5056",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 89.44.9.74",
      "pattern": "[ipv4-addr:value = '89.44.9.74']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--72385104-e89d-4dfb-8aaa-bc3907959b81",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 91.193.19.109",
      "pattern": "[ipv4-addr:value = '91.193.19.109']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a9da2115-5b14-46b1-ac28-db763ed13870",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 91.237.124.153",
      "pattern": "[ipv4-addr:value = '91.237.124.153']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0a069fab-5bde-4944-a666-249060b67244",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 91.237.124.164",
      "pattern": "[ipv4-addr:value = '91.237.124.164']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c1beb81-7792-4039-a3ee-8f59a84e2be8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 1078C587FE2B246D618AF74D157F941078477579",
      "pattern": "[file:hashes.'SHA-1' = '1078C587FE2B246D618AF74D157F941078477579']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e6e66a8a-d83e-429e-a7e6-0c1e023e000c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 19b4df629f5b15e5ff742c70d2c7dc4dac29a7ce",
      "pattern": "[file:hashes.'SHA-1' = '19b4df629f5b15e5ff742c70d2c7dc4dac29a7ce']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aa6f640e-be68-4a53-9e36-d4e031433df5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 1b1dda5e8e26da568559e0577769697c624df30e",
      "pattern": "[file:hashes.'SHA-1' = '1b1dda5e8e26da568559e0577769697c624df30e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--54072234-1562-45da-ba07-65f20c4dcfd0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 2664593E2F5DCFDA9AAA1A2DF7C4CE7EEB1EDBB6",
      "pattern": "[file:hashes.'SHA-1' = '2664593E2F5DCFDA9AAA1A2DF7C4CE7EEB1EDBB6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4c536711-ef46-4273-8eb3-eb0ee86f5203",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 2bd61ce5bdd258c7dcbef53aedb1b018b8e0ae26",
      "pattern": "[file:hashes.'SHA-1' = '2bd61ce5bdd258c7dcbef53aedb1b018b8e0ae26']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--17efa230-b110-4f7d-874b-091f0b5909bc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 2bd61ce5bdf258c7dcbef53aedb1b018b8e0ae26",
      "pattern": "[file:hashes.'SHA-1' = '2bd61ce5bdf258c7dcbef53aedb1b018b8e0ae26']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6c20328e-5a90-4e7a-b451-7fd32393bdba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 41FE2EFB38E0C7DD10E6009A68BD26687D6DBF4C",
      "pattern": "[file:hashes.'SHA-1' = '41FE2EFB38E0C7DD10E6009A68BD26687D6DBF4C']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8121375d-4216-46ce-b4dc-46d419e20c38",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 60D592765B0F4E08078D42B2F3DE4F5767F88773",
      "pattern": "[file:hashes.'SHA-1' = '60D592765B0F4E08078D42B2F3DE4F5767F88773']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--91ca9c3a-c525-4b1c-b304-9b0d6ac2efa1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 65A8D221B9ECED76B9C17A3E1992DF9B085CECD7",
      "pattern": "[file:hashes.'SHA-1' = '65A8D221B9ECED76B9C17A3E1992DF9B085CECD7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--924853f6-d3b6-4945-9d58-4b65245e6105",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 6EF845938F064DE39F4BF6450119A0CDBB61378C",
      "pattern": "[file:hashes.'SHA-1' = '6EF845938F064DE39F4BF6450119A0CDBB61378C']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d92cb86-5e51-498c-b8b6-85fbeb3b6913",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 8E6C07F38EF920B5154FD081BA252B9295E8184D",
      "pattern": "[file:hashes.'SHA-1' = '8E6C07F38EF920B5154FD081BA252B9295E8184D']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1dfda85e-81c7-4bb4-b59d-d8fbdbb76bf3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 8EBBBC9EB54E216EFFB437A28B9F2C7C9DA3A0FA",
      "pattern": "[file:hashes.'SHA-1' = '8EBBBC9EB54E216EFFB437A28B9F2C7C9DA3A0FA']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e40d771b-c5c3-492e-a153-b057653669b7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: A5948E1E45D50A8DB063D7DFA5B6F6E249F61652",
      "pattern": "[file:hashes.'SHA-1' = 'A5948E1E45D50A8DB063D7DFA5B6F6E249F61652']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c3812b79-e3cd-4678-99cd-82b682a1e91b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: aa2cfeeca6c8e7743ad1a5996fe5ccc3d52e901d",
      "pattern": "[file:hashes.'SHA-1' = 'aa2cfeeca6c8e7743ad1a5996fe5ccc3d52e901d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dfa393aa-56a2-4bce-b548-a8305969d64d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: ac389c8b7f3d2fcf4fd73891f881b12b8343665b",
      "pattern": "[file:hashes.'SHA-1' = 'ac389c8b7f3d2fcf4fd73891f881b12b8343665b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d7ae5bdf-a8fc-4e2e-be90-ae91c20c6686",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: AD3C590D1C0963D62702445E8108DB025EEBEC70",
      "pattern": "[file:hashes.'SHA-1' = 'AD3C590D1C0963D62702445E8108DB025EEBEC70']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d4b483f5-de43-4bde-94b8-f5d20b875033",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: B6C340549700470C651031865C2772D3A4C81310",
      "pattern": "[file:hashes.'SHA-1' = 'B6C340549700470C651031865C2772D3A4C81310']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f8fc52c0-cd6a-4a33-b739-d0424f296a51",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: dce8faf5fcf5998b6802995914caa988ee1ebd92",
      "pattern": "[file:hashes.'SHA-1' = 'dce8faf5fcf5998b6802995914caa988ee1ebd92']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ce83403d-f968-429f-a98b-b65b7f6e9384",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: EBF794E421BE60C9532091EB432C1977517D1BE5",
      "pattern": "[file:hashes.'SHA-1' = 'EBF794E421BE60C9532091EB432C1977517D1BE5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f28f3d92-dff5-46af-9cd9-053a23106b81",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: EBF794E421BE60C9532091EB432D1977517D1BE5",
      "pattern": "[file:hashes.'SHA-1' = 'EBF794E421BE60C9532091EB432D1977517D1BE5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea8c41d7-64d4-42fe-b6b0-70519bc2c0d8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: f780151c151b6cec853a278b4e847ef2af3dbc5d",
      "pattern": "[file:hashes.'SHA-1' = 'f780151c151b6cec853a278b4e847ef2af3dbc5d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c92c7313-c303-4cf2-8579-55059d38eb34",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: F81DE9584F0BF3E55C6CF1B465F00B2671DAA230",
      "pattern": "[file:hashes.'SHA-1' = 'F81DE9584F0BF3E55C6CF1B465F00B2671DAA230']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb3673c7-741b-414c-8307-4d041cd943a7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: F95F26F1C097D4CA38304ECC692DBAC7424A5E8D",
      "pattern": "[file:hashes.'SHA-1' = 'F95F26F1C097D4CA38304ECC692DBAC7424A5E8D']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--11e0c4b8-393a-427b-b8fd-b7ac4e91ef5c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 150ccd3b24a1b40630e46300100a3f810aa7a6badeb6806b59ed6ba7bafb7b21",
      "pattern": "[file:hashes.'SHA-256' = '150ccd3b24a1b40630e46300100a3f810aa7a6badeb6806b59ed6ba7bafb7b21']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--19875634-7e02-478b-bf58-09f481d7e5d5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1df959e4d2f48c4066fddcb5b3fd00b0b25ae44f350f5f35a86571abb2852e39",
      "pattern": "[file:hashes.'SHA-256' = '1df959e4d2f48c4066fddcb5b3fd00b0b25ae44f350f5f35a86571abb2852e39']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-27920 \u2014 Srimax Output Messenger Directory",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a5594e43-cea9-4d81-9510-63f148a45c8c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 29ae4fa86329bf6d0955020319b618d4c183d433830187b80979d392bf159768",
      "pattern": "[file:hashes.'SHA-256' = '29ae4fa86329bf6d0955020319b618d4c183d433830187b80979d392bf159768']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0bd18984-b280-4c81-b3f2-ff4bec08fda7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2b7b65d6f8815dbe18cabaa20c01be655d8475fc429388a4541eff193596ae63",
      "pattern": "[file:hashes.'SHA-256' = '2b7b65d6f8815dbe18cabaa20c01be655d8475fc429388a4541eff193596ae63']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-27920 \u2014 Srimax Output Messenger Directory",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e6fbbc8-80d3-4826-8c6e-b069da8ef61f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 44c4a0d1826369993d1a2c4fcc00a86bf45723342cfd9f3a8b44b673eee6733a",
      "pattern": "[file:hashes.'SHA-256' = '44c4a0d1826369993d1a2c4fcc00a86bf45723342cfd9f3a8b44b673eee6733a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ecad2399-88fe-4863-8234-7cf62a830441",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 64764ffe4b1e4fc5b9fe27b513e02f0392f659c4e033d23a4ba7a3b7f20c6d30",
      "pattern": "[file:hashes.'SHA-256' = '64764ffe4b1e4fc5b9fe27b513e02f0392f659c4e033d23a4ba7a3b7f20c6d30']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--36e7a142-ec87-40d8-8277-26c39723a475",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7a4e0eb5fbab9709c8f42beb322a5dfefbc4ec5f914938a8862f8e26a31d30a5",
      "pattern": "[file:hashes.'SHA-256' = '7a4e0eb5fbab9709c8f42beb322a5dfefbc4ec5f914938a8862f8e26a31d30a5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4e0ceebe-1c9b-4bb0-b47f-a23e0b6ce04f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b422645db18e95aa0b4daaf5277417b73322bed306f42385ecfd6d49be26bfab",
      "pattern": "[file:hashes.'SHA-256' = 'b422645db18e95aa0b4daaf5277417b73322bed306f42385ecfd6d49be26bfab']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1047bc53-8ddb-45c1-97c8-4244b3c17f95",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f34db4ea8ec3c2cbe53fde3d73229ccaa2a9e7168cd96d9a49bf89adef5ab47c",
      "pattern": "[file:hashes.'SHA-256' = 'f34db4ea8ec3c2cbe53fde3d73229ccaa2a9e7168cd96d9a49bf89adef5ab47c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--52142fa2-8b97-418d-a0fb-b9162ee3ff99",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-12987",
      "pattern": "[vulnerability:name = 'CVE-2024-12987']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--47c020d9-4f60-4475-b592-3dea5e0944d1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-42999",
      "pattern": "[vulnerability:name = 'CVE-2025-42999']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-42999 \u2014 SAP NetWeaver Deserialization Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e642e76f-4be9-4f25-adec-77b15fef752e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: dvrhelper.anondns.net",
      "pattern": "[domain-name:value = 'dvrhelper.anondns.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2f9a2607-d61f-48df-9492-754ecbaab787",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: miraisucks.anondns.net",
      "pattern": "[domain-name:value = 'miraisucks.anondns.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d6290f3-6784-4e48-af99-39210e4a14a8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: rustbot.anondns.net",
      "pattern": "[domain-name:value = 'rustbot.anondns.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2958e274-477d-49a6-bb8e-51473f7f933a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: techsupport.anondns.net",
      "pattern": "[domain-name:value = 'techsupport.anondns.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e1b805d8-786c-487c-8fa2-3e0cc11ba1ea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.255.125.150",
      "pattern": "[ipv4-addr:value = '5.255.125.150']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--633bfa63-70e3-4cdf-8799-86c5ea50cb04",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 66.63.187.69",
      "pattern": "[ipv4-addr:value = '66.63.187.69']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8248fb7a-0480-4c95-af5c-5f2d6890e48a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 114b460012412411363c9a3ab0246e48a584ce86fc6c0b7855495ec531dd05a1",
      "pattern": "[file:hashes.'SHA-256' = '114b460012412411363c9a3ab0246e48a584ce86fc6c0b7855495ec531dd05a1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--985ec70d-afda-43ae-b461-4d638cf5c0ee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 15c9d7a63fa419305d7f2710b63f71cc38178973c0ccf6d437ce8b6feeca4ee1",
      "pattern": "[file:hashes.'SHA-256' = '15c9d7a63fa419305d7f2710b63f71cc38178973c0ccf6d437ce8b6feeca4ee1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0831e6ac-4d11-4e7a-aeef-0b310cd33ae4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1697fd5230f7f09a7b43fee1a1693013ed98beeb7a182cd3f0393d93dd1b7576",
      "pattern": "[file:hashes.'SHA-256' = '1697fd5230f7f09a7b43fee1a1693013ed98beeb7a182cd3f0393d93dd1b7576']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fb52a8e9-3d86-4a3b-893f-08d2df8c486f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 427399864232c6c099f183704b23bff241c7e0de642e9eec66cc56890e8a6304",
      "pattern": "[file:hashes.'SHA-256' = '427399864232c6c099f183704b23bff241c7e0de642e9eec66cc56890e8a6304']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dcafd811-f18e-4ebb-bb62-331071b86a3e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 44a526f20c592fd95b4f7d61974c6f87701e33776b68a5d0b44ccd2fa3f48c5d",
      "pattern": "[file:hashes.'SHA-256' = '44a526f20c592fd95b4f7d61974c6f87701e33776b68a5d0b44ccd2fa3f48c5d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--72d43a61-eb5e-4a2f-a9b3-520fcc4fa580",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4f0ba25183ecb79a0721037a0ff9452fa8c19448f82943deca01b36555f2cc99",
      "pattern": "[file:hashes.'SHA-256' = '4f0ba25183ecb79a0721037a0ff9452fa8c19448f82943deca01b36555f2cc99']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b06c964c-478c-4d36-9d05-6dc4e236913b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5dc90cbb0f69f283ccf52a2a79b3dfe94ee8b3474cf6474cfcbe9f66f245a55d",
      "pattern": "[file:hashes.'SHA-256' = '5dc90cbb0f69f283ccf52a2a79b3dfe94ee8b3474cf6474cfcbe9f66f245a55d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f1ab3cba-fbc6-4d7f-8349-d991f6185a30",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9a9b5bdeb1f23736ceffba623c8950d627a791a0b40c4d44ae2f80e02a43955d",
      "pattern": "[file:hashes.'SHA-256' = '9a9b5bdeb1f23736ceffba623c8950d627a791a0b40c4d44ae2f80e02a43955d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--30513a33-025e-40d3-9ff6-d04b74941203",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9e660ce74e1bdb0a75293758200b03efd5f807e7896665addb684e0ffb53afd2",
      "pattern": "[file:hashes.'SHA-256' = '9e660ce74e1bdb0a75293758200b03efd5f807e7896665addb684e0ffb53afd2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4ead6c6a-530d-4ef3-bf76-ab0abc0835f5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9f098920613bd0390d6485936256a67ae310b633124cfbf503936904e69a81bf",
      "pattern": "[file:hashes.'SHA-256' = '9f098920613bd0390d6485936256a67ae310b633124cfbf503936904e69a81bf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6095cadb-4f8b-4749-a934-8b8959c26a43",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b68e2d852ad157fc01da34e11aa24a5ab30845b706d7827b8119a3e648ce2cf1",
      "pattern": "[file:hashes.'SHA-256' = 'b68e2d852ad157fc01da34e11aa24a5ab30845b706d7827b8119a3e648ce2cf1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2b376234-b526-480d-b2dc-5f757b9ad3f8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b910e77ee686d7d6769fab8cb8f9b17a4609c4e164bb4ed80d9717d9ddad364f",
      "pattern": "[file:hashes.'SHA-256' = 'b910e77ee686d7d6769fab8cb8f9b17a4609c4e164bb4ed80d9717d9ddad364f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7d925eff-fba6-4b60-a05c-77b1250c0147",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c0abb19b3a72bd2785e8b567e82300423da672a463eefdeda6dd60872ff0e072",
      "pattern": "[file:hashes.'SHA-256' = 'c0abb19b3a72bd2785e8b567e82300423da672a463eefdeda6dd60872ff0e072']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cf855f4f-fa82-42be-b39c-76ae28f8d0ab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: dae8dae748be54ba0d5785ab27b1fdf42b7e66c48ab19177d4981bcc032cfb1c",
      "pattern": "[file:hashes.'SHA-256' = 'dae8dae748be54ba0d5785ab27b1fdf42b7e66c48ab19177d4981bcc032cfb1c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--91c5a4d7-02dd-40de-8d5f-62ad35db13fb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e547306d6dee4b5b2b6ce3e989b9713a5c21ebe3fefa0f5c1a1ea37cec37e20f",
      "pattern": "[file:hashes.'SHA-256' = 'e547306d6dee4b5b2b6ce3e989b9713a5c21ebe3fefa0f5c1a1ea37cec37e20f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f67b0034-b472-43a3-b810-6e7d1565a1f8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ec9e77f1185f644462305184cf8afcf5d12c7eb524a2d3f4090a658a198c20ce",
      "pattern": "[file:hashes.'SHA-256' = 'ec9e77f1185f644462305184cf8afcf5d12c7eb524a2d3f4090a658a198c20ce']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--26371754-9516-46c5-ae9c-b6eafbfe1acf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: efb0153047b08aa1876e1e4e97a082f6cb05af75479e1e9069b77d98473a11f4",
      "pattern": "[file:hashes.'SHA-256' = 'efb0153047b08aa1876e1e4e97a082f6cb05af75479e1e9069b77d98473a11f4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--471db8c1-2884-4542-8749-90bb696ff1e7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-32756",
      "pattern": "[vulnerability:name = 'CVE-2025-32756']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c900c39b-b0b4-4590-8d0d-2d6143f05183",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 156.236.76.90",
      "pattern": "[ipv4-addr:value = '156.236.76.90']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cae6b105-676e-4bf0-922f-847ac1e5f083",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 198.105.127.124",
      "pattern": "[ipv4-addr:value = '198.105.127.124']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--596f3337-281f-42ae-9f77-27415553e8e9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 218.187.69.244",
      "pattern": "[ipv4-addr:value = '218.187.69.244']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--74314c6f-a251-4dc0-8a57-41c586a34e6e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 218.187.69.59",
      "pattern": "[ipv4-addr:value = '218.187.69.59']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c5e31fa4-0483-4706-ba74-2dad3aee802e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 43.228.217.173",
      "pattern": "[ipv4-addr:value = '43.228.217.173']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--27d8c893-4bd5-44c5-83fa-346250db5029",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 43.228.217.82",
      "pattern": "[ipv4-addr:value = '43.228.217.82']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--078e069c-b683-4aa6-a0eb-5f6aa6430574",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 2c8834a52faee8d87cff7cd09c4fb946",
      "pattern": "[file:hashes.MD5 = '2c8834a52faee8d87cff7cd09c4fb946']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d7ce24c9-3ac8-4928-8004-caf9f19c7ac0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 364929c45703a84347064e2d5de45bcd",
      "pattern": "[file:hashes.MD5 = '364929c45703a84347064e2d5de45bcd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a1589b3-339b-473d-b596-09c884a97e84",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 4410352e110f82eabc0bf160bec41d21",
      "pattern": "[file:hashes.MD5 = '4410352e110f82eabc0bf160bec41d21']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--230324ac-5feb-4bca-bb73-03a0270cbecf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 489821c38f429a21e1ea821f8460e590",
      "pattern": "[file:hashes.MD5 = '489821c38f429a21e1ea821f8460e590']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--39cde68b-3823-4add-9b22-8adf609ea225",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: ebce43017d2cb316ea45e08374de7315",
      "pattern": "[file:hashes.MD5 = 'ebce43017d2cb316ea45e08374de7315']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--adecf5f5-de56-423b-ab8f-bfb41059da4e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-30397",
      "pattern": "[vulnerability:name = 'CVE-2025-30397']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-30397 \u2014 Microsoft Windows Scripting Engin",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dbe4fcf1-9a95-45fb-9684-0f2b49ed30ee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-30400",
      "pattern": "[vulnerability:name = 'CVE-2025-30400']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-30400 \u2014 Microsoft Windows DWM Core Librar",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b07aab4c-f48b-465d-b9ba-f0316b555852",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-32701",
      "pattern": "[vulnerability:name = 'CVE-2025-32701']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-32701 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--12095f14-e430-448e-870e-5b463eca8b37",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-32706",
      "pattern": "[vulnerability:name = 'CVE-2025-32706']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-32706 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2fb77add-f021-4fb4-b59a-e6d3b02423b3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-32709",
      "pattern": "[vulnerability:name = 'CVE-2025-32709']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-32709 \u2014 Microsoft Windows Ancillary Funct",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2539069c-6a88-430d-92d4-859b0cd440c7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-47729",
      "pattern": "[vulnerability:name = 'CVE-2025-47729']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-47729 \u2014 TeleMessage TM SGNL Hidden Functi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c72c32a-b0f7-42e7-bf1c-b0974dcee4bf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-10561",
      "pattern": "[vulnerability:name = 'CVE-2018-10561']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Inject",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b5a7d8a-c51c-4550-b0ce-50d81809fb1f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-11120",
      "pattern": "[vulnerability:name = 'CVE-2024-11120']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11120 \u2014 GeoVision Devices OS Command Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--acc43216-d265-46e3-a8ba-9225d2d890d1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-6047",
      "pattern": "[vulnerability:name = 'CVE-2024-6047']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11120 \u2014 GeoVision Devices OS Command Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4609773c-4b8b-48c8-ab2d-9625c427c0de",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: connect.antiwifi.dev",
      "pattern": "[domain-name:value = 'connect.antiwifi.dev']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11120 \u2014 GeoVision Devices OS Command Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eab2a8fe-3752-4c09-80ae-21f5e8d37b42",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 176.65.144.232",
      "pattern": "[ipv4-addr:value = '176.65.144.232']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11120 \u2014 GeoVision Devices OS Command Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--838768fd-bcf6-4393-9592-3dabad7ae58d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 176.65.144.253",
      "pattern": "[ipv4-addr:value = '176.65.144.253']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11120 \u2014 GeoVision Devices OS Command Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--50b8ffc0-fb4b-407a-a10e-47d81685b647",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 198.23.212.246",
      "pattern": "[ipv4-addr:value = '198.23.212.246']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11120 \u2014 GeoVision Devices OS Command Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--36d9d048-1dbb-4c17-93e3-4ff4cb019477",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 209.141.44.28",
      "pattern": "[ipv4-addr:value = '209.141.44.28']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11120 \u2014 GeoVision Devices OS Command Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67d356e6-81e7-4493-9288-70e20434caff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 51.38.137.114",
      "pattern": "[ipv4-addr:value = '51.38.137.114']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11120 \u2014 GeoVision Devices OS Command Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3183d844-22d2-4be0-ae16-30292c9c08fc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 11c0447f524d0fcb3be2cd0fbd23eb2cc2045f374b70c9c029708a9f2f4a4114",
      "pattern": "[file:hashes.'SHA-256' = '11c0447f524d0fcb3be2cd0fbd23eb2cc2045f374b70c9c029708a9f2f4a4114']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11120 \u2014 GeoVision Devices OS Command Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--50817ccf-fc3f-4545-92aa-94ecb77db631",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8df660bd1722a09c45fb213e591d1dab73f24d240c456865fe0e2dc85573d85e",
      "pattern": "[file:hashes.'SHA-256' = '8df660bd1722a09c45fb213e591d1dab73f24d240c456865fe0e2dc85573d85e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c7105c90-8314-40e2-9be2-923253b54c8a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f05247a2322e212513ee08b2e8513f4c764bde7b30831736dfc927097baf6714",
      "pattern": "[file:hashes.'SHA-256' = 'f05247a2322e212513ee08b2e8513f4c764bde7b30831736dfc927097baf6714']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11120 \u2014 GeoVision Devices OS Command Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c19ae8b-5338-419b-a87b-20e13511f2c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-27363",
      "pattern": "[vulnerability:name = 'CVE-2025-27363']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-27363 \u2014 FreeType Out-of-Bounds Write Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b65088e7-8fd8-42f5-b416-6b06156f3b3a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-3248",
      "pattern": "[vulnerability:name = 'CVE-2025-3248']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-3248 \u2014 Langflow Missing Authentication Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fb5ed5ca-9913-47c2-b50c-2194f9922315",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 80.66.75.121",
      "pattern": "[ipv4-addr:value = '80.66.75.121']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-3248 \u2014 Langflow Missing Authentication Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aff92c9e-62ef-4c3e-86d3-97b251275a4f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-4990",
      "pattern": "[vulnerability:name = 'CVE-2024-4990']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-58136 \u2014 Yiiframework Yii Improper Protect",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d891781d-0565-473f-a400-71c431e02443",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-34028",
      "pattern": "[vulnerability:name = 'CVE-2025-34028']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-34028 \u2014 Commvault Command Center Path Tra",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9798eee0-6b5a-47cc-964d-34578947f21d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-44221",
      "pattern": "[vulnerability:name = 'CVE-2023-44221']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38475 \u2014 Apache HTTP Server Improper Escap",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-44221 \u2014 SonicWall SMA100 Appliances OS Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--edc97a36-2428-429e-89d3-c9f596ab40a7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-38475",
      "pattern": "[vulnerability:name = 'CVE-2024-38475']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38475 \u2014 Apache HTTP Server Improper Escap",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-44221 \u2014 SonicWall SMA100 Appliances OS Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d8ef5030-e602-482a-8ae5-19e5f1d8a29d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-40766",
      "pattern": "[vulnerability:name = 'CVE-2024-40766']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-44221 \u2014 SonicWall SMA100 Appliances OS Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f5f30db2-5f4e-425f-867c-7e6907eb1af9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-31324",
      "pattern": "[vulnerability:name = 'CVE-2025-31324']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ded8b3c5-8504-4c04-81b7-accc563e12e4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: aaa.ki6zmfw3ps8q14rfbfczfq5qkhq8e12q.oastify.com",
      "pattern": "[domain-name:value = 'aaa.ki6zmfw3ps8q14rfbfczfq5qkhq8e12q.oastify.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b7463d30-3ded-42ee-beaf-3ff7723eea37",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: d-69b.pages.dev",
      "pattern": "[domain-name:value = 'd-69b.pages.dev']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--15ed978d-2f7a-4415-9206-0c3048afac45",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: data.hs285.top",
      "pattern": "[domain-name:value = 'data.hs285.top']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--45087871-eb77-408f-aa09-99fa8d7186a4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ocr-freespace.oss-cn-beijing.aliyuncs.com",
      "pattern": "[domain-name:value = 'ocr-freespace.oss-cn-beijing.aliyuncs.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b5a9730f-995f-4a8f-ba88-40b72cfdee9d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: overseas-recognized-athens-oakland.trycloudflare.com",
      "pattern": "[domain-name:value = 'overseas-recognized-athens-oakland.trycloudflare.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3cc73854-e5aa-40ae-9990-9abe5cf9fb5d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sentinelones.com",
      "pattern": "[domain-name:value = 'sentinelones.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9a93fb4f-6fa4-4974-a726-f6d4b161a357",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 101.99.91.107",
      "pattern": "[ipv4-addr:value = '101.99.91.107']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32980072-9d67-4d2c-9444-7136e8a889b7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.207.14.195",
      "pattern": "[ipv4-addr:value = '103.207.14.195']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe82d6c6-de44-4fbc-9128-9f16b84b1c22",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.30.76.206",
      "pattern": "[ipv4-addr:value = '103.30.76.206']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3e8b8212-c03c-4bb9-9e19-be8e87fe368b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 107.173.135.116",
      "pattern": "[ipv4-addr:value = '107.173.135.116']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c9beae02-05ad-42af-a10d-2d0dd8ad89ce",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 107.175.77.118",
      "pattern": "[ipv4-addr:value = '107.175.77.118']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cc80f0ad-36a2-4cc4-9538-4eebf2fa3348",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 108.171.195.163",
      "pattern": "[ipv4-addr:value = '108.171.195.163']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4d569d3f-ad5f-40ba-95be-6d22b4352247",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 13.232.191.219",
      "pattern": "[ipv4-addr:value = '13.232.191.219']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c6692ac4-f03c-45c1-a7a6-c80ddd32f916",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 138.197.40.133",
      "pattern": "[ipv4-addr:value = '138.197.40.133']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ddf2a09e-185b-43f1-ae51-b47b76475c1c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 138.68.61.82",
      "pattern": "[ipv4-addr:value = '138.68.61.82']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bd2cfa5c-6e2c-4fd0-944a-cc830702246a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 15.188.246.198",
      "pattern": "[ipv4-addr:value = '15.188.246.198']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e3a010f4-acef-4fc3-9ec1-a466b7c9584f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 15.204.56.106",
      "pattern": "[ipv4-addr:value = '15.204.56.106']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4f3a1fd0-d2aa-422d-9870-9859fa05d8c4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 158.247.224.100",
      "pattern": "[ipv4-addr:value = '158.247.224.100']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--05aab625-9ae8-4344-8096-b0bb0fdd91bc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 159.65.34.242",
      "pattern": "[ipv4-addr:value = '159.65.34.242']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ec678aaa-fbf8-4d16-b38c-56ba406263fa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 188.166.87.88",
      "pattern": "[ipv4-addr:value = '188.166.87.88']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--27571573-0405-4b7e-94d0-0e7f4ec02a57",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.243.115.175",
      "pattern": "[ipv4-addr:value = '192.243.115.175']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c5c89d12-19c5-44bb-9e80-c4d75f472c03",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.3.153.18",
      "pattern": "[ipv4-addr:value = '192.3.153.18']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dbd6b34c-edc6-4564-aac7-ebb8ed017935",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 205.169.39.55",
      "pattern": "[ipv4-addr:value = '205.169.39.55']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3f8de6f3-4934-4bdb-aa14-fcd6cf5fc123",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 206.188.197.52",
      "pattern": "[ipv4-addr:value = '206.188.197.52']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c05a161-e4dd-4ec6-ad99-1426c76e304e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 223.184.254.150",
      "pattern": "[ipv4-addr:value = '223.184.254.150']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--62730317-6834-4a3b-86ed-27c8c8ee65a0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.95.123.5",
      "pattern": "[ipv4-addr:value = '23.95.123.5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3f56c7de-a757-4a30-a9b0-70f44ca5dc37",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 3.125.102.39",
      "pattern": "[ipv4-addr:value = '3.125.102.39']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ef56f1e0-7d18-4b98-ab4b-0276eb730804",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 31.192.107.157",
      "pattern": "[ipv4-addr:value = '31.192.107.157']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1fdd71d8-bd78-4c5f-98b4-2442f5321970",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 43.247.135.53",
      "pattern": "[ipv4-addr:value = '43.247.135.53']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--69dbbc53-40dc-489a-bb90-5b7421f9d153",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.155.222.14",
      "pattern": "[ipv4-addr:value = '45.155.222.14']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--18e24caf-78ac-40e8-97fc-3c23464d1486",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.76.93.60",
      "pattern": "[ipv4-addr:value = '45.76.93.60']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f283590e-3d92-444e-9835-0275118d3005",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 47.97.42.177",
      "pattern": "[ipv4-addr:value = '47.97.42.177']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3c90ca6d-c4ac-4dc5-8cba-d5ff1525a40f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 51.79.66.183",
      "pattern": "[ipv4-addr:value = '51.79.66.183']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2858eb13-59bb-45c0-acc9-b1532879feab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 65.49.235.210",
      "pattern": "[ipv4-addr:value = '65.49.235.210']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a031e74b-2f99-4842-b7ae-135487edbd6a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 85.106.113.168",
      "pattern": "[ipv4-addr:value = '85.106.113.168']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2602a218-314c-4f29-b0fb-3b02407682f7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 00920e109f16fe61092e70fca68a5219ade6d42b427e895202f628b467a3d22e",
      "pattern": "[file:hashes.'SHA-256' = '00920e109f16fe61092e70fca68a5219ade6d42b427e895202f628b467a3d22e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--db5ef73a-a7ca-4524-b41c-41be6123a317",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 0c2c8280701706e0772cb9be83502096e94ad4d9c21d576db0bc627e1e84b579",
      "pattern": "[file:hashes.'SHA-256' = '0c2c8280701706e0772cb9be83502096e94ad4d9c21d576db0bc627e1e84b579']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--90a32293-f4c9-494b-a62b-437b3a0c434e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1abf922a8228fd439a72cfddf1ed08ea09b59eaa4ae5eeba1d322d5f3e3c97e8",
      "pattern": "[file:hashes.'SHA-256' = '1abf922a8228fd439a72cfddf1ed08ea09b59eaa4ae5eeba1d322d5f3e3c97e8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5ef84ba5-b3bf-4729-877b-90b2e14d2714",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2dcbb4138f836bb5d7bc7d8101d3004848c541df6af997246d4b2a252f29d51a",
      "pattern": "[file:hashes.'SHA-256' = '2dcbb4138f836bb5d7bc7d8101d3004848c541df6af997246d4b2a252f29d51a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4beda23e-8d43-4824-baf1-883cf3bb0a4c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2e6f348f8296f4e062c397d2f3708ca6fdeab2c71edfd130b2ca4c935e53c0d3",
      "pattern": "[file:hashes.'SHA-256' = '2e6f348f8296f4e062c397d2f3708ca6fdeab2c71edfd130b2ca4c935e53c0d3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--24a4d312-3c5b-4b73-ab55-dbff7319cc9f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3f14dc65cc9e35989857dc1ec4bb1179ab05457f2238e917b698edb4c57ae7ce",
      "pattern": "[file:hashes.'SHA-256' = '3f14dc65cc9e35989857dc1ec4bb1179ab05457f2238e917b698edb4c57ae7ce']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1d343dad-4271-434d-a276-e960411e870c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3f5fd4b23126cb21d1007b479954af619a16b0963a51f45cc32a8611e8e845b5",
      "pattern": "[file:hashes.'SHA-256' = '3f5fd4b23126cb21d1007b479954af619a16b0963a51f45cc32a8611e8e845b5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--17affe85-85f8-462e-bdc0-aa6647f051ca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 427877aadd89f427e1815007998d9bb88309c548951a92a6e4064df001e327c2",
      "pattern": "[file:hashes.'SHA-256' = '427877aadd89f427e1815007998d9bb88309c548951a92a6e4064df001e327c2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b264f2fe-aaba-44f6-92b0-ac1cc55efc7f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 47ff0ae9220a09bfad2a2fb1e2fa2c8ffe5e9cb0466646e2a940ac2e0cf55d04",
      "pattern": "[file:hashes.'SHA-256' = '47ff0ae9220a09bfad2a2fb1e2fa2c8ffe5e9cb0466646e2a940ac2e0cf55d04']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b9fb76df-0e9e-43a0-8804-397e231f1318",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4b17beee8c2d94cf8e40efc100651d70d046f5c14a027cf97d845dc839e423f9",
      "pattern": "[file:hashes.'SHA-256' = '4b17beee8c2d94cf8e40efc100651d70d046f5c14a027cf97d845dc839e423f9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4ab99451-7f35-404e-8d66-1d1373753cc8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4c9e60cc73e87da4cadc51523690d67549de4902e880974bfacf7f1a8dc40d7d",
      "pattern": "[file:hashes.'SHA-256' = '4c9e60cc73e87da4cadc51523690d67549de4902e880974bfacf7f1a8dc40d7d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--776e9663-8824-4988-893c-af91785cc1f2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5919f2eab8a826d7ba84e6c413626f5d11ed412d7df0d3ab864f31d3a8db3763",
      "pattern": "[file:hashes.'SHA-256' = '5919f2eab8a826d7ba84e6c413626f5d11ed412d7df0d3ab864f31d3a8db3763']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f6ee38a3-45b8-468b-8859-5aec8ceea9a2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 598b38f44564565e0e76aa604f915ad88a20a8d5b5827151e681c8866b7ea8b0",
      "pattern": "[file:hashes.'SHA-256' = '598b38f44564565e0e76aa604f915ad88a20a8d5b5827151e681c8866b7ea8b0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d1992594-f8cf-4091-ac18-fc82af73ca57",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5a8ddc779dcf124fe5692d15be44346fb6d742322acb0eb3c6b4e90f581c5f9e",
      "pattern": "[file:hashes.'SHA-256' = '5a8ddc779dcf124fe5692d15be44346fb6d742322acb0eb3c6b4e90f581c5f9e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--70a6b397-fc1d-4c47-9ffb-c31d25b5fafb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5e24b41a0bd076ec2b4e49e66daac94396c6180d00a45bcd7f4342a385fa1eed",
      "pattern": "[file:hashes.'SHA-256' = '5e24b41a0bd076ec2b4e49e66daac94396c6180d00a45bcd7f4342a385fa1eed']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--028f9649-5b16-4306-af46-4bd767a6dd8e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5f3d1f17033d85b85f3bd5ae55cb720e53b31f1679d52986c8d635fd1ce0c08a",
      "pattern": "[file:hashes.'SHA-256' = '5f3d1f17033d85b85f3bd5ae55cb720e53b31f1679d52986c8d635fd1ce0c08a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fa996b74-08a1-4e9e-a8af-c18c58e2b08a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 63aa0c6890ec5c16b872fb6d070556447cd707dfba185d32a2c10c008dbdbcdd",
      "pattern": "[file:hashes.'SHA-256' = '63aa0c6890ec5c16b872fb6d070556447cd707dfba185d32a2c10c008dbdbcdd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76403405-e6cc-49fb-8113-45c72fbe859b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 69bb809b3fee09ed3ec9138f7566cc867bd6f1e8949b5e3daff21d451c533d75",
      "pattern": "[file:hashes.'SHA-256' = '69bb809b3fee09ed3ec9138f7566cc867bd6f1e8949b5e3daff21d451c533d75']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--09f7b335-ebec-4ef4-84d4-2e4f1ee18625",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6c6c984727dc53af110ed08ec8b15092facb924c8ad62e86ec76b52a00a41a40",
      "pattern": "[file:hashes.'SHA-256' = '6c6c984727dc53af110ed08ec8b15092facb924c8ad62e86ec76b52a00a41a40']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--794e6314-1c7f-4649-9620-e24f5921691e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 888e953538ff668104f838120bc4d801c41adb07027db16281402a62f6ec29ef",
      "pattern": "[file:hashes.'SHA-256' = '888e953538ff668104f838120bc4d801c41adb07027db16281402a62f6ec29ef']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6598b384-e68d-4a69-9288-ed5a52312dc4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 91f66ba1ad49d3062afdcc80e54da0807207d80a1b539edcdbd6e1bf99e7a2ca",
      "pattern": "[file:hashes.'SHA-256' = '91f66ba1ad49d3062afdcc80e54da0807207d80a1b539edcdbd6e1bf99e7a2ca']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d0ec0a26-d0a9-4050-a1e4-2315b453b373",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9fb57a4c6576a98003de6bf441e4306f72c83f783630286758f5b468abaa105d",
      "pattern": "[file:hashes.'SHA-256' = '9fb57a4c6576a98003de6bf441e4306f72c83f783630286758f5b468abaa105d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bf109e6c-5aa4-426c-a7a3-b0b594d57e4a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a114b52c146bd11558cc7c48c3ee679ca5ca55cf2c9cc33616956a6e6229f110",
      "pattern": "[file:hashes.'SHA-256' = 'a114b52c146bd11558cc7c48c3ee679ca5ca55cf2c9cc33616956a6e6229f110']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d698894-cc1d-4fb1-9adf-0470dc5bba97",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b8e56de3792dbd0f4239b54cfaad7ece3bd42affa4fbbdd7668492de548b5df8",
      "pattern": "[file:hashes.'SHA-256' = 'b8e56de3792dbd0f4239b54cfaad7ece3bd42affa4fbbdd7668492de548b5df8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7469c543-cd31-4cf0-bd5c-3e611de24e02",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b9533ce8e428f16f3d0e1946f19a6f756ff11a532d0b7e61ae402837f46c678e",
      "pattern": "[file:hashes.'SHA-256' = 'b9533ce8e428f16f3d0e1946f19a6f756ff11a532d0b7e61ae402837f46c678e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f059a935-5398-42ab-a149-b8305c1b979f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b9ef95ca541d3e05a6285411005f5fee15495251041f78e715234b09d019b92c",
      "pattern": "[file:hashes.'SHA-256' = 'b9ef95ca541d3e05a6285411005f5fee15495251041f78e715234b09d019b92c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc76a423-6576-4fe8-9eae-841ba9a24b4e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c71da1dfea145798f881afd73b597336d87f18f8fd8f9a7f524c6749a5c664e4",
      "pattern": "[file:hashes.'SHA-256' = 'c71da1dfea145798f881afd73b597336d87f18f8fd8f9a7f524c6749a5c664e4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--865d71f8-6fbb-4994-941b-d3c59f41b762",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c7b9ae61046eed01651a72afe7a31de088056f1c1430b368b1acda0b58299e28",
      "pattern": "[file:hashes.'SHA-256' = 'c7b9ae61046eed01651a72afe7a31de088056f1c1430b368b1acda0b58299e28']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a12c1cbb-c13e-4830-a47a-d1b2ad4421ee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: df492597eb412c94155a7f437f593aed89cfec2f1f149eb65174c6201be69049",
      "pattern": "[file:hashes.'SHA-256' = 'df492597eb412c94155a7f437f593aed89cfec2f1f149eb65174c6201be69049']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e171f5e5-62fa-4a6c-b065-1638f3a49317",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f92d0cf4d577c68aa615797d1704f40b14810d98b48834b241dd5c9963e113ec",
      "pattern": "[file:hashes.'SHA-256' = 'f92d0cf4d577c68aa615797d1704f40b14810d98b48834b241dd5c9963e113ec']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f68447c5-fbb3-4927-9396-b345b260aafd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-1976",
      "pattern": "[vulnerability:name = 'CVE-2025-1976']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-1976 \u2014 Broadcom Brocade Fabric OS Code In",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--032d27ad-df7f-462b-9fc2-c78972c705ba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-3928",
      "pattern": "[vulnerability:name = 'CVE-2025-3928']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-3928 \u2014 Commvault Web Server Unspecified V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d66d0b57-5d23-4d3b-92dc-48281522de09",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-42599",
      "pattern": "[vulnerability:name = 'CVE-2025-42599']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-42599 \u2014 Qualitia Active! Mail Stack-Based",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c26808e0-f59e-4736-970b-ed0ef6b92f8a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 108.6.189.53",
      "pattern": "[ipv4-addr:value = '108.6.189.53']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-3928 \u2014 Commvault Web Server Unspecified V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3e2b0eb0-81b3-4e10-a299-b028c17f3df6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 108.69.148.100",
      "pattern": "[ipv4-addr:value = '108.69.148.100']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-3928 \u2014 Commvault Web Server Unspecified V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9e471b93-1edb-4b94-a822-a976cc58677e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 128.92.80.210",
      "pattern": "[ipv4-addr:value = '128.92.80.210']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-3928 \u2014 Commvault Web Server Unspecified V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--72c22a9c-1257-4209-a4cf-a13b6da024ef",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 159.242.42.20",
      "pattern": "[ipv4-addr:value = '159.242.42.20']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-3928 \u2014 Commvault Web Server Unspecified V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4b89ff0a-54b4-482e-9b74-9051757b3c32",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 184.153.42.129",
      "pattern": "[ipv4-addr:value = '184.153.42.129']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-3928 \u2014 Commvault Web Server Unspecified V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bff6e936-662b-450f-9fe2-a11798326f27",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-43451",
      "pattern": "[vulnerability:name = 'CVE-2024-43451']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24054 \u2014 Microsoft Windows NTLM Hash Discl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-43451 \u2014 Microsoft Windows NTLMv2 Hash Dis",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ab7d30e9-8f5c-479e-9314-72c0c094897d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-24054",
      "pattern": "[vulnerability:name = 'CVE-2025-24054']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24054 \u2014 Microsoft Windows NTLM Hash Discl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8bca5f1c-5348-469c-9a9e-ebc9b78cca4b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-31200",
      "pattern": "[vulnerability:name = 'CVE-2025-31200']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31201 \u2014 Apple Multiple Products Arbitrary",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-31200 \u2014 Apple Multiple Products Memory Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ec279d5f-af57-4534-85c2-96895a75c172",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-31201",
      "pattern": "[vulnerability:name = 'CVE-2025-31201']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31201 \u2014 Apple Multiple Products Arbitrary",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-31200 \u2014 Apple Multiple Products Memory Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--43a07b10-09ef-417b-9d41-90ba4ea618a7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 159.196.128.120",
      "pattern": "[ipv4-addr:value = '159.196.128.120']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24054 \u2014 Microsoft Windows NTLM Hash Discl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1e18861c-f116-4423-8598-b07dffa31f3b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.127.179.157",
      "pattern": "[ipv4-addr:value = '194.127.179.157']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24054 \u2014 Microsoft Windows NTLM Hash Discl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--229f85bf-0f48-4b4a-9686-ee0b935b052b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 054784f1a398a35e0c5242cbfa164df0c277da73",
      "pattern": "[file:hashes.'SHA-1' = '054784f1a398a35e0c5242cbfa164df0c277da73']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24054 \u2014 Microsoft Windows NTLM Hash Discl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0294f82-964d-4366-80db-a9c9bd5e742e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 5e42c6d12f6b51364b6bfb170f4306c5ce608b4f",
      "pattern": "[file:hashes.'SHA-1' = '5e42c6d12f6b51364b6bfb170f4306c5ce608b4f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24054 \u2014 Microsoft Windows NTLM Hash Discl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d38b10c4-e0e6-4e65-abcc-9f71e18546f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 76e93c97ffdb5adb509c966bca22e12c4508dcaa",
      "pattern": "[file:hashes.'SHA-1' = '76e93c97ffdb5adb509c966bca22e12c4508dcaa']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24054 \u2014 Microsoft Windows NTLM Hash Discl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6611841b-8ea9-4263-842f-b2429961f29b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 7a43c177a582c777e258246f0ba818f9e73a69ab",
      "pattern": "[file:hashes.'SHA-1' = '7a43c177a582c777e258246f0ba818f9e73a69ab']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24054 \u2014 Microsoft Windows NTLM Hash Discl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e7f99848-0a3b-49b3-a2f8-3eadf3040767",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 7dd0131dd4660be562bc869675772e58a1e3ac8e",
      "pattern": "[file:hashes.'SHA-1' = '7dd0131dd4660be562bc869675772e58a1e3ac8e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24054 \u2014 Microsoft Windows NTLM Hash Discl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--42a01203-47b0-47f3-9fce-409b3dae7e4a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 84132ae00239e15b50c1a20126000eed29388100",
      "pattern": "[file:hashes.'SHA-1' = '84132ae00239e15b50c1a20126000eed29388100']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24054 \u2014 Microsoft Windows NTLM Hash Discl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8b6efb5c-fcfc-4287-b16c-9f01f265de41",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 9ca72d969d7c5494a30e996324c6c0fcb72ae1ae",
      "pattern": "[file:hashes.'SHA-1' = '9ca72d969d7c5494a30e996324c6c0fcb72ae1ae']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24054 \u2014 Microsoft Windows NTLM Hash Discl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2df50e96-a2b9-403f-b075-b8bde4ed6c46",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-20035",
      "pattern": "[vulnerability:name = 'CVE-2021-20035']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8675ab0f-bd74-490c-944d-216b6e50e152",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-20038",
      "pattern": "[vulnerability:name = 'CVE-2021-20038']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-20038 \u2014 SonicWall SMA 100 Appliances Stac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--940ba3f4-d478-4240-b2ea-122613810616",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-20039",
      "pattern": "[vulnerability:name = 'CVE-2021-20039']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8870ffd4-04fc-4a19-8891-03123f47c82b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-32819",
      "pattern": "[vulnerability:name = 'CVE-2025-32819']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--455659fb-5cf1-4caa-a893-dc33ce7d2015",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.149.176.230",
      "pattern": "[ipv4-addr:value = '193.149.176.230']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4f45009f-3c77-454d-9917-cbcab077cd3f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.149.180.50",
      "pattern": "[ipv4-addr:value = '193.149.180.50']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--122f6fbc-34cc-40a2-bdb5-1a1e0ffa42aa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 64.52.80.80",
      "pattern": "[ipv4-addr:value = '64.52.80.80']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe0898e8-fa7e-4e90-b6fd-49c4826ed153",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 6de26d211966262e59359d0e2a67d473",
      "pattern": "[file:hashes.MD5 = '6de26d211966262e59359d0e2a67d473']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3bcc9693-ce27-4194-972a-c2cef7414f37",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: b28d57269fe4cd90d1650bde5e905611",
      "pattern": "[file:hashes.MD5 = 'b28d57269fe4cd90d1650bde5e905611']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da5da737-f21b-4f0c-a638-9482719d4bad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: d5a070acac1debaf0889d0d48c10e149",
      "pattern": "[file:hashes.MD5 = 'd5a070acac1debaf0889d0d48c10e149']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3baf6372-a32f-4763-9eee-8bb935b7fd7f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: f0e0db06ca665907770e2202957d3ecc",
      "pattern": "[file:hashes.MD5 = 'f0e0db06ca665907770e2202957d3ecc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c990a2d-c5fa-4b23-842a-bcf7a183433f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-50302",
      "pattern": "[vulnerability:name = 'CVE-2024-50302']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-53197 \u2014 Linux Kernel Out-of-Bounds Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-50302 \u2014 Linux Kernel Use of Uninitialized",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-53104 \u2014 Linux Kernel Out-of-Bounds Write ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd6974ad-1175-46b9-bf1b-64add2e61339",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-53104",
      "pattern": "[vulnerability:name = 'CVE-2024-53104']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-53197 \u2014 Linux Kernel Out-of-Bounds Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-53104 \u2014 Linux Kernel Out-of-Bounds Write ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a0473ca1-5aa1-40fd-b3bd-b9bccbc4b052",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-53150",
      "pattern": "[vulnerability:name = 'CVE-2024-53150']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-53150 \u2014 Linux Kernel Out-of-Bounds Read V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-53197 \u2014 Linux Kernel Out-of-Bounds Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--712c57b0-1b57-4a10-983a-8423bab5abfb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-53197",
      "pattern": "[vulnerability:name = 'CVE-2024-53197']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-53197 \u2014 Linux Kernel Out-of-Bounds Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-53104 \u2014 Linux Kernel Out-of-Bounds Write ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ac7af091-d6cf-4261-9ee6-e5f613d34905",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-29824",
      "pattern": "[vulnerability:name = 'CVE-2025-29824']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--77eab22a-8d9e-4946-b315-896aed3efc4a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: jbdg4buq6jd7ed3rd6cynqtq5abttuekjnxqrqyvk4xam5i7ld33jvqd.onion",
      "pattern": "[domain-name:value = 'jbdg4buq6jd7ed3rd6cynqtq5abttuekjnxqrqyvk4xam5i7ld33jvqd.onion']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7aa25942-3c87-4153-b03a-d56b7d8ddc56",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: rtb.mftadsrvr.com",
      "pattern": "[domain-name:value = 'rtb.mftadsrvr.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-30406 \u2014 Gladinet CentreStack and Triofox ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ae9d21dd-74e8-4a05-8cda-b8c5497abc6a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: uyhi3ypdkfeymyf5v35pbk3pz7st3zamsbjzf47jiqbcm3zmikpwf3qd.onion",
      "pattern": "[domain-name:value = 'uyhi3ypdkfeymyf5v35pbk3pz7st3zamsbjzf47jiqbcm3zmikpwf3qd.onion']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--38e4adc9-d6c0-4084-aa49-74bb7e8aee25",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.21.16.1",
      "pattern": "[ipv4-addr:value = '104.21.16.1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-30406 \u2014 Gladinet CentreStack and Triofox ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7249824f-abbe-4a1a-9c67-ca0758ee7616",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.21.48.1",
      "pattern": "[ipv4-addr:value = '104.21.48.1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-30406 \u2014 Gladinet CentreStack and Triofox ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--96ab8a57-c801-4475-a4f7-73c3fad8b696",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 165.227.7.206",
      "pattern": "[ipv4-addr:value = '165.227.7.206']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-30406 \u2014 Gladinet CentreStack and Triofox ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e86e182d-f212-4304-a276-65dc262d34a1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 2.58.56.16",
      "pattern": "[ipv4-addr:value = '2.58.56.16']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-30406 \u2014 Gladinet CentreStack and Triofox ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--550c5fd6-2c65-4c42-a29f-5bfa218a2c3a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.84.107.76",
      "pattern": "[ipv4-addr:value = '45.84.107.76']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-30406 \u2014 Gladinet CentreStack and Triofox ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ca170fad-eca3-4725-989b-f983e3e41429",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 293b455b5b7e1c2063a8781f3c169cf8ef2b1d06e6b7a086b7b44f37f55729bd",
      "pattern": "[file:hashes.'SHA-256' = '293b455b5b7e1c2063a8781f3c169cf8ef2b1d06e6b7a086b7b44f37f55729bd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--117e299b-dcdf-4423-8413-def6be59e275",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 30981d4082b58704d12a376c3cbb12fecb8a36c2bce64666315e26aef21e75c2",
      "pattern": "[file:hashes.'SHA-256' = '30981d4082b58704d12a376c3cbb12fecb8a36c2bce64666315e26aef21e75c2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-30406 \u2014 Gladinet CentreStack and Triofox ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b14cec1b-3917-4f36-81aa-dc482e64e7cd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 430d1364d0d0a60facd9b73e674faddf63a8f77649cd10ba855df7e49189980b",
      "pattern": "[file:hashes.'SHA-256' = '430d1364d0d0a60facd9b73e674faddf63a8f77649cd10ba855df7e49189980b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9f0a5e11-43fd-4319-94a0-96b6a88a7e42",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 48b006cb17e75ecdb707dc40dd654f449b94abe49f97a808b35cabca1c5fabbf",
      "pattern": "[file:hashes.'SHA-256' = '48b006cb17e75ecdb707dc40dd654f449b94abe49f97a808b35cabca1c5fabbf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-30406 \u2014 Gladinet CentreStack and Triofox ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3061ffc9-4795-46e2-b8be-6b69a6f0d762",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6030c4381b8b5d5c5734341292316723a89f1bdbd2d10bb67c4d06b1242afd05",
      "pattern": "[file:hashes.'SHA-256' = '6030c4381b8b5d5c5734341292316723a89f1bdbd2d10bb67c4d06b1242afd05']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e02ef2ef-f1b4-42bf-bf82-2a2c3f53c24e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6d7374b4f977f689389c7155192b5db70ee44a7645625ecf8163c00da8828388",
      "pattern": "[file:hashes.'SHA-256' = '6d7374b4f977f689389c7155192b5db70ee44a7645625ecf8163c00da8828388']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2e3cbfb9-2809-4ac5-bc9e-d3b571846f89",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 858efe4f9037e5efebadaaa70aa8ad096f7244c4c4aeade72c51ddad23d05bfe",
      "pattern": "[file:hashes.'SHA-256' = '858efe4f9037e5efebadaaa70aa8ad096f7244c4c4aeade72c51ddad23d05bfe']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--59eef494-4fa7-4fc2-8471-4911c24526bc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9c21adbcb2888daf14ef55c4fa1f41eaa6cbfbe20d85c3e1da61a96a53ba18f9",
      "pattern": "[file:hashes.'SHA-256' = '9c21adbcb2888daf14ef55c4fa1f41eaa6cbfbe20d85c3e1da61a96a53ba18f9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--087054dd-8c3b-4aa4-9f6b-e79aac092f71",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: af260c172baffd0e8b2671fd0c84e607ac9b2c8beb57df43cf5df6e103cbb7ad",
      "pattern": "[file:hashes.'SHA-256' = 'af260c172baffd0e8b2671fd0c84e607ac9b2c8beb57df43cf5df6e103cbb7ad']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c56e114-ffc8-43eb-a92e-765c87dcd899",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b2cba01ae6707ce694073018d948f82340b9c41fb2b2bc49769f9a0be37071e1",
      "pattern": "[file:hashes.'SHA-256' = 'b2cba01ae6707ce694073018d948f82340b9c41fb2b2bc49769f9a0be37071e1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--474653b8-e8de-4db6-b3a6-70bf9fb871a3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b3ee068bf282575ac7eb715dd779254889e0b8a55aba2b7a1700fc8aa4dcb1da",
      "pattern": "[file:hashes.'SHA-256' = 'b3ee068bf282575ac7eb715dd779254889e0b8a55aba2b7a1700fc8aa4dcb1da']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--94246667-d337-4a65-b869-eef489b20d28",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-4040",
      "pattern": "[vulnerability:name = 'CVE-2024-4040']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-4040 \u2014 CrushFTP VFS Sandbox Escape Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ad6e2a11-1f5d-405c-b0a3-0126c4d34eb3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-2825",
      "pattern": "[vulnerability:name = 'CVE-2025-2825']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f9ba3364-5a03-4fd0-a6c1-cd5013f5fb20",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-31161",
      "pattern": "[vulnerability:name = 'CVE-2025-31161']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bfcb3289-297b-4c80-a220-ea13a6f6f65d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 143.244.47.67",
      "pattern": "[ipv4-addr:value = '143.244.47.67']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--31ed86b0-767e-4929-b7fa-dddc005d1355",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 146.70.166.201",
      "pattern": "[ipv4-addr:value = '146.70.166.201']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2d46dd13-4144-452a-9bb8-f71fcc2f13cf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.235.144.67",
      "pattern": "[ipv4-addr:value = '172.235.144.67']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--83a85c3d-0d0d-4454-b7ed-df3cea8ccbd4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 0b8e76eb315bc522af3cec74749a85e8f55cfed720976892d6610cfc89d84f69",
      "pattern": "[file:hashes.'SHA-256' = '0b8e76eb315bc522af3cec74749a85e8f55cfed720976892d6610cfc89d84f69']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1fbe5b54-cb3c-4051-8b03-a0857145addc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 85a1bfebf2a5973ebecd6e5a58c8fab18edfead2c1680ec1e9cce902924c347e",
      "pattern": "[file:hashes.'SHA-256' = '85a1bfebf2a5973ebecd6e5a58c8fab18edfead2c1680ec1e9cce902924c347e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--37835e6a-5960-43b0-b33a-4dba0fd8b5cb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9036c92c3ca73cb6ec2da25035322554319288fd2f6db906413011873ad7e281",
      "pattern": "[file:hashes.'SHA-256' = '9036c92c3ca73cb6ec2da25035322554319288fd2f6db906413011873ad7e281']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--89292760-93a1-4b11-90fb-6218799c7c93",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: be6cb5f80b33b9e97622d278a86a99e67b78ccab0b3e554b8430ae5969bcfc0e",
      "pattern": "[file:hashes.'SHA-256' = 'be6cb5f80b33b9e97622d278a86a99e67b78ccab0b3e554b8430ae5969bcfc0e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ad5fd6cb-264d-4c13-afc1-9783fd1cfca8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ee6d24410a8cf31d672d2a47466b76ad287c7ba016d3711490f0f607b1dc0be3",
      "pattern": "[file:hashes.'SHA-256' = 'ee6d24410a8cf31d672d2a47466b76ad287c7ba016d3711490f0f607b1dc0be3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cdf73f48-044c-4bdc-bec3-6aa145b82a90",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f7c8be827f3bd98b30c5a8d23c1af77f3d0324a9ebcd90104134fc1971751ff7",
      "pattern": "[file:hashes.'SHA-256' = 'f7c8be827f3bd98b30c5a8d23c1af77f3d0324a9ebcd90104134fc1971751ff7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a29ce5cb-7b58-4893-89cf-f641e048392e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-22457",
      "pattern": "[vulnerability:name = 'CVE-2025-22457']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-22457 \u2014 Ivanti Connect Secure, Policy Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--79790e8a-dfe0-4f79-9b89-ee9576798469",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 10659b392e7f5b30b375b94cae4fdca0",
      "pattern": "[file:hashes.MD5 = '10659b392e7f5b30b375b94cae4fdca0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-22457 \u2014 Ivanti Connect Secure, Policy Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6263b4d2-8990-4801-a699-fe9e77189ba2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 4628a501088c31f53b5c9ddf6788e835",
      "pattern": "[file:hashes.MD5 = '4628a501088c31f53b5c9ddf6788e835']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-22457 \u2014 Ivanti Connect Secure, Policy Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--49618495-1371-416a-aa39-e65379d8d258",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 6e01ef1367ea81994578526b3bd331d6",
      "pattern": "[file:hashes.MD5 = '6e01ef1367ea81994578526b3bd331d6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-22457 \u2014 Ivanti Connect Secure, Policy Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3cbb29c3-ca48-4af3-b7bc-8d39a5048f95",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: ce2b6a554ae46b5eb7d79ca5e7f440da",
      "pattern": "[file:hashes.MD5 = 'ce2b6a554ae46b5eb7d79ca5e7f440da']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-22457 \u2014 Ivanti Connect Secure, Policy Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c432413-d6a0-4043-9dca-f8bb91eaff16",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e5192258c27e712c7acf80303e68980b",
      "pattern": "[file:hashes.MD5 = 'e5192258c27e712c7acf80303e68980b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-22457 \u2014 Ivanti Connect Secure, Policy Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4ade62a4-d54e-4e16-aa34-b3d46a7bd2e3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-0305",
      "pattern": "[vulnerability:name = 'CVE-2024-0305']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20439 \u2014 Cisco Smart Licensing Utility Sta",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e320ecd2-8e65-4ea7-8fc2-cf5d81bca159",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-20439",
      "pattern": "[vulnerability:name = 'CVE-2024-20439']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20439 \u2014 Cisco Smart Licensing Utility Sta",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6df1e1d7-a88f-496b-8596-409001f2a54f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-20440",
      "pattern": "[vulnerability:name = 'CVE-2024-20440']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20439 \u2014 Cisco Smart Licensing Utility Sta",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f109eca3-acba-4146-aa7b-7c5ee499eb12",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-6473",
      "pattern": "[vulnerability:name = 'CVE-2024-6473']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escap",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9f0faed3-532e-4985-abaf-896e4fb06dd3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-2783",
      "pattern": "[vulnerability:name = 'CVE-2025-2783']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escap",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1a3b3b65-b31c-46d7-9e34-82cebbe6aa01",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-2857",
      "pattern": "[vulnerability:name = 'CVE-2025-2857']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escap",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--696ad55c-d7a4-4858-99d7-432fe24597fc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: bus-pod-tenant.global.ssl.fastly.net",
      "pattern": "[domain-name:value = 'bus-pod-tenant.global.ssl.fastly.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escap",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2866b8de-9ba3-4807-96e5-6168657191fd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: e-library.wiki",
      "pattern": "[domain-name:value = 'e-library.wiki']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escap",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e1b791e0-d2a8-41bc-96d3-9eca8aad8a60",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: perf-service-clients2.global.ssl.fastly.net",
      "pattern": "[domain-name:value = 'perf-service-clients2.global.ssl.fastly.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escap",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bf9b4dbd-505b-4db0-b37d-fa14cf3f21a2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: status-portal-api.global.ssl.fastly.net",
      "pattern": "[domain-name:value = 'status-portal-api.global.ssl.fastly.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escap",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f428922e-c250-4a97-bf28-f7b5c770951d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 33bb0678af6011481845d7ce9643cedc",
      "pattern": "[file:hashes.MD5 = '33bb0678af6011481845d7ce9643cedc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escap",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7e7e7599-10c5-4a95-bb89-d0c12a97c541",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 35869e8760928407d2789c7f115b7f83",
      "pattern": "[file:hashes.MD5 = '35869e8760928407d2789c7f115b7f83']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escap",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6849e9c5-209e-40d9-ba07-d76f137ceec3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 7d3a30dbf4fd3edaf4dde35ccb5cf926",
      "pattern": "[file:hashes.MD5 = '7d3a30dbf4fd3edaf4dde35ccb5cf926']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escap",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--22147562-881b-45b2-b8cd-ce18e922c18d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 3650c1ac97bd5674e1e3bfa9b26008644edacfed",
      "pattern": "[file:hashes.'SHA-1' = '3650c1ac97bd5674e1e3bfa9b26008644edacfed']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escap",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--250a8cd5-997d-492d-acb3-bd15020904c1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 8390e2ebdd0db5d1a950b2c9984a5f429805d48c",
      "pattern": "[file:hashes.'SHA-1' = '8390e2ebdd0db5d1a950b2c9984a5f429805d48c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escap",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--be7643d4-fa9d-4b0f-ae66-8bae4d43631f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: c25275228c6da54cf578fa72c9f49697e5309694",
      "pattern": "[file:hashes.'SHA-1' = 'c25275228c6da54cf578fa72c9f49697e5309694']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escap",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--05e8642a-76ca-47b7-a914-545ba39671c8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 07d272b607f082305ce7b1987bfa17dc967ab45c8cd89699bcdced34ea94e126",
      "pattern": "[file:hashes.'SHA-256' = '07d272b607f082305ce7b1987bfa17dc967ab45c8cd89699bcdced34ea94e126']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escap",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d92a8260-9730-419f-9c1a-47d946fd9c99",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2e39800df1cafbebfa22b437744d80f1b38111b471fa3eb42f2214a5ac7e1f13",
      "pattern": "[file:hashes.'SHA-256' = '2e39800df1cafbebfa22b437744d80f1b38111b471fa3eb42f2214a5ac7e1f13']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escap",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b8440124-0bbd-4bc7-b227-39f9051b4ea8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 388a8af43039f5f16a0673a6e342fa6ae2402e63ba7569d20d9ba4894dc0ba59",
      "pattern": "[file:hashes.'SHA-256' = '388a8af43039f5f16a0673a6e342fa6ae2402e63ba7569d20d9ba4894dc0ba59']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escap",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3537d818-f44f-4431-9c38-dee7362bc9a1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-9874",
      "pattern": "[vulnerability:name = 'CVE-2019-9874']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-9875 \u2014 Sitecore CMS and Experience Platfo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-9874 \u2014 Sitecore CMS and Experience Platfo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--265f6271-f5ab-43cf-b435-291c878b04c9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-9875",
      "pattern": "[vulnerability:name = 'CVE-2019-9875']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-9875 \u2014 Sitecore CMS and Experience Platfo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-9874 \u2014 Sitecore CMS and Experience Platfo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dbc03273-870b-42f1-b79f-3c102bd9c97e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-30154",
      "pattern": "[vulnerability:name = 'CVE-2025-30154']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-30154 \u2014 reviewdog/action-setup GitHub Act",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-30066 \u2014 tj-actions/changed-files GitHub A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--41be2237-f70b-4c76-8d04-b93487fdcafa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 3c6d5c14e71ff37a0a341c6fdc3e71cefbc85ba0",
      "pattern": "[file:hashes.'SHA-1' = '3c6d5c14e71ff37a0a341c6fdc3e71cefbc85ba0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-30154 \u2014 reviewdog/action-setup GitHub Act",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--51174304-3260-4d38-a2cc-8a69ce59271d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 6e6023c01918b353229af0881232f601a4cc8365",
      "pattern": "[file:hashes.'SHA-1' = '6e6023c01918b353229af0881232f601a4cc8365']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-30154 \u2014 reviewdog/action-setup GitHub Act",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-30066 \u2014 tj-actions/changed-files GitHub A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e359a15d-302b-460a-b3f8-da4a2740beab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: f5434e31b6259b4e08684618a305bae127b6d784",
      "pattern": "[file:hashes.'SHA-1' = 'f5434e31b6259b4e08684618a305bae127b6d784']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-30154 \u2014 reviewdog/action-setup GitHub Act",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-30066 \u2014 tj-actions/changed-files GitHub A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--07587ded-ac22-473f-8a78-ca4f6a77ad99",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-12637",
      "pattern": "[vulnerability:name = 'CVE-2017-12637']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-12637 \u2014 SAP NetWeaver Directory Traversal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a72b7e66-6560-4c86-885e-93f447533b7d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-48248",
      "pattern": "[vulnerability:name = 'CVE-2024-48248']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-48248 \u2014 NAKIVO Backup and Replication Abs",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c74411b1-248c-4124-bf9d-efd097685b01",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-1316",
      "pattern": "[vulnerability:name = 'CVE-2025-1316']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-1316 \u2014 Edimax IC-7100 IP Camera OS Comman",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ce250c1f-7762-4b29-b87b-7fbe322c2a7b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-55591",
      "pattern": "[vulnerability:name = 'CVE-2024-55591']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-55591 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--77a0471a-a2ff-4d48-a738-48e19998be38",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-24472",
      "pattern": "[vulnerability:name = 'CVE-2025-24472']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--475bddc6-c932-4793-879c-b83ee15a075a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 109.248.160.118",
      "pattern": "[ipv4-addr:value = '109.248.160.118']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c59e1195-c388-4d26-b9db-b27baa1dc980",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 149.22.94.37",
      "pattern": "[ipv4-addr:value = '149.22.94.37']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c7ab0bd6-93c7-43fa-a318-cb8ea78db546",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 155.133.4.175",
      "pattern": "[ipv4-addr:value = '155.133.4.175']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-55591 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--91112596-b658-44a0-b09a-e58e2479d198",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 158.255.215.126",
      "pattern": "[ipv4-addr:value = '158.255.215.126']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ad095793-adb8-44d2-9be8-47876b902802",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 170.130.55.164",
      "pattern": "[ipv4-addr:value = '170.130.55.164']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ddf2d237-f301-480a-b55e-df370d90d089",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 176.53.147.5",
      "pattern": "[ipv4-addr:value = '176.53.147.5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cbf1a821-7cae-49ea-84d0-0149920c2d3f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.147.124.10",
      "pattern": "[ipv4-addr:value = '185.147.124.10']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1ec64dde-8240-4099-b6c6-490838baeec0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.147.124.31",
      "pattern": "[ipv4-addr:value = '185.147.124.31']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9e5e9d97-7f30-403f-9fd8-1cd496b9a0d2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.147.124.34",
      "pattern": "[ipv4-addr:value = '185.147.124.34']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--08f286f6-9c7c-4dcf-8d50-426fbf8499a0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.147.124.55",
      "pattern": "[ipv4-addr:value = '185.147.124.55']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0e0d8c39-6ec4-4096-ab64-2f8fdd8b28a5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.224.0.201",
      "pattern": "[ipv4-addr:value = '185.224.0.201']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--33b054ac-6641-4010-a9cd-3ba55fc8f6b1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.95.159.43",
      "pattern": "[ipv4-addr:value = '185.95.159.43']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2e8de111-c3a8-42fe-82c6-ea40b3314a1e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.248.155.218",
      "pattern": "[ipv4-addr:value = '192.248.155.218']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e166057c-704f-4024-b8e9-e11dc9482c1f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.143.1.65",
      "pattern": "[ipv4-addr:value = '193.143.1.65']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--79fdff0e-4144-4074-b16f-1abadab524bc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 213.176.64.114",
      "pattern": "[ipv4-addr:value = '213.176.64.114']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de67c4dd-b043-48fe-b36c-9438bcbda679",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 217.144.189.35",
      "pattern": "[ipv4-addr:value = '217.144.189.35']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c0404579-f1d8-4d58-b74b-24314056e546",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.15.17.67",
      "pattern": "[ipv4-addr:value = '45.15.17.67']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--58f6fc28-bc06-411b-99ef-5f286d9491b3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.55.158.47",
      "pattern": "[ipv4-addr:value = '45.55.158.47']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-55591 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b2383cfc-f845-4dfd-bed4-e56e30c188a5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.181.171.133",
      "pattern": "[ipv4-addr:value = '5.181.171.133']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f545db7b-3779-4188-8729-daf10d43a88d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 57.69.19.70",
      "pattern": "[ipv4-addr:value = '57.69.19.70']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--369a6f8f-fbd8-41b5-90f3-514f2c58fb81",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 80.64.30.237",
      "pattern": "[ipv4-addr:value = '80.64.30.237']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--981651ba-ad65-45f9-ad35-e3442ae375f9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 80.66.88.90",
      "pattern": "[ipv4-addr:value = '80.66.88.90']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--24f5d35c-2d97-44b4-b37c-7e52c30297b2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 87.249.138.47",
      "pattern": "[ipv4-addr:value = '87.249.138.47']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9d610687-8519-41f0-b0f6-2f8fab9b90a8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 89.248.192.55",
      "pattern": "[ipv4-addr:value = '89.248.192.55']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b1d74cb0-897f-43a2-905d-41eb01ea6203",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 94.154.35.208",
      "pattern": "[ipv4-addr:value = '94.154.35.208']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0db51aa7-ef8c-461e-b2d6-0834112435c7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 94.156.177.187",
      "pattern": "[ipv4-addr:value = '94.156.177.187']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5cf3cdd3-237f-418b-82d1-bb82e09cd7c0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 94.156.227.208",
      "pattern": "[ipv4-addr:value = '94.156.227.208']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d8b9a40-bcb8-4ab2-8ae7-f370ebadfad4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 95.179.234.4",
      "pattern": "[ipv4-addr:value = '95.179.234.4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--55b85b1d-1334-4094-a01d-4dc8f781c84b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 95.217.78.122",
      "pattern": "[ipv4-addr:value = '95.217.78.122']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bdb1f08f-3bee-4e62-8e55-430fb62b753c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 96.31.67.39",
      "pattern": "[ipv4-addr:value = '96.31.67.39']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--55c5aaca-c616-4e94-b01d-347e4deb4aff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 782c3c463809cd818dadad736f076c36cdea01d8c4efed094d78661ba0a57045",
      "pattern": "[file:hashes.'SHA-256' = '782c3c463809cd818dadad736f076c36cdea01d8c4efed094d78661ba0a57045']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0259a291-c1d5-4dfd-bcd6-81b49633f32d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 813ad8caa4dcbd814c1ee9ea28040d74338e79e76beae92bedc8a47b402dedc2",
      "pattern": "[file:hashes.'SHA-256' = '813ad8caa4dcbd814c1ee9ea28040d74338e79e76beae92bedc8a47b402dedc2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--69990394-b845-41f8-a553-88270e63fe32",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 917e115cc403e29b4388e0d175cbfac3e7e40ca1742299fbdb353847db2de7c2",
      "pattern": "[file:hashes.'SHA-256' = '917e115cc403e29b4388e0d175cbfac3e7e40ca1742299fbdb353847db2de7c2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7aecd700-378b-4297-a207-6bfc9e4c151f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c994b132b2a264b8cf1d47b2f432fe6bda631b994ec7dcddf5650113f4a5a404",
      "pattern": "[file:hashes.'SHA-256' = 'c994b132b2a264b8cf1d47b2f432fe6bda631b994ec7dcddf5650113f4a5a404']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6070b90e-5272-4ade-b579-cb11528e2814",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d9938ac4346d03a07f8ce8b57436e75ba5e936372b9bfd0386f18f6d56902c88",
      "pattern": "[file:hashes.'SHA-256' = 'd9938ac4346d03a07f8ce8b57436e75ba5e936372b9bfd0386f18f6d56902c88']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9e913706-4cea-44fb-a69e-7d627f8a839c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f383bca7e763b9a76e64489f1e2e54c44e1fd24094e9f3a28d4b45b5ec88b513",
      "pattern": "[file:hashes.'SHA-256' = 'f383bca7e763b9a76e64489f1e2e54c44e1fd24094e9f3a28d4b45b5ec88b513']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--93d0c7e2-d3f7-4599-a229-cff8b8e7de00",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-21590",
      "pattern": "[vulnerability:name = 'CVE-2025-21590']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c5b4549-391d-4b4c-abc6-e2e831923581",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-24201",
      "pattern": "[vulnerability:name = 'CVE-2025-24201']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24201 \u2014 Apple Multiple Products WebKit Ou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--02fd5b0b-59e4-4a2c-856f-3501b9de8876",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 101.100.182.122",
      "pattern": "[ipv4-addr:value = '101.100.182.122']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--22445252-70b5-4c61-aa99-55f8ca52d57d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 116.88.34.184",
      "pattern": "[ipv4-addr:value = '116.88.34.184']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9df687d3-107e-4198-a39e-a5440606e400",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 118.189.188.122",
      "pattern": "[ipv4-addr:value = '118.189.188.122']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eddb93d7-d9c2-498b-a5f4-b73a7a76ea8f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 129.126.109.50",
      "pattern": "[ipv4-addr:value = '129.126.109.50']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--82641f1b-4ad4-4a31-84d1-45e766379e67",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 158.140.135.244",
      "pattern": "[ipv4-addr:value = '158.140.135.244']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b91b39ed-02a4-47ef-b74b-974c0c652e21",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 223.25.78.136",
      "pattern": "[ipv4-addr:value = '223.25.78.136']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--861ef0b5-c322-4aff-92eb-cd10dd68a54f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.77.39.28",
      "pattern": "[ipv4-addr:value = '45.77.39.28']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--305ad7d4-3dbf-437a-9f6f-6bf4a16fed62",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 8.222.225.8",
      "pattern": "[ipv4-addr:value = '8.222.225.8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5ea17787-0ff2-43d5-a75f-3aa3ea226445",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 2c89a18944d3a895bd6432415546635e",
      "pattern": "[file:hashes.MD5 = '2c89a18944d3a895bd6432415546635e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6adb25df-daa3-4b44-a87d-b69f8df5ec68",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 3243e04afe18cc5e1230d49011e19899",
      "pattern": "[file:hashes.MD5 = '3243e04afe18cc5e1230d49011e19899']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3c552f59-9231-4cee-819a-497a05e07720",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 5724d76f832ce8061f74b0e9f1dcad90",
      "pattern": "[file:hashes.MD5 = '5724d76f832ce8061f74b0e9f1dcad90']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6c1600c8-5397-4bd7-9f95-73171519dbf8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 8023d01ffb7a38b582f0d598afb974ee",
      "pattern": "[file:hashes.MD5 = '8023d01ffb7a38b582f0d598afb974ee']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e88e2b8-152b-4c95-830f-413d0336d6fb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: aac5d83d296df81c9259c9a533a8423a",
      "pattern": "[file:hashes.MD5 = 'aac5d83d296df81c9259c9a533a8423a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0d23f0f-31a0-4c4c-80c3-5553df003112",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: b9e4784fa0e6283ce6e2094426a02fce",
      "pattern": "[file:hashes.MD5 = 'b9e4784fa0e6283ce6e2094426a02fce']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b19a479c-be0e-413d-92dc-9f6a8cf9e910",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: bf80c96089d37b8571b5de7cab14dd9f",
      "pattern": "[file:hashes.MD5 = 'bf80c96089d37b8571b5de7cab14dd9f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--347671f2-b309-48f9-9732-bcae4b319ecc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e7622d983d22e749b3658600df00296d",
      "pattern": "[file:hashes.MD5 = 'e7622d983d22e749b3658600df00296d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--82f452fd-c10d-46b0-8ab0-7a94e5f76513",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 01735bb47a933ae9ec470e6be737d8f646a8ec66",
      "pattern": "[file:hashes.'SHA-1' = '01735bb47a933ae9ec470e6be737d8f646a8ec66']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0953785e-01e5-4f45-9999-0bba6ca9092d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 06a1f879da398c00522649171526dc968f769093",
      "pattern": "[file:hashes.'SHA-1' = '06a1f879da398c00522649171526dc968f769093']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ace6b28-2f19-47a6-8b0d-dc8e05fee19c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 1a6d07da7e77a5706dd8af899ebe4daa74bbbe91",
      "pattern": "[file:hashes.'SHA-1' = '1a6d07da7e77a5706dd8af899ebe4daa74bbbe91']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c1558fb-8046-4d69-bd96-ae3c78cc0b19",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 2e9215a203e908483d04dfc0328651d79d35b54f",
      "pattern": "[file:hashes.'SHA-1' = '2e9215a203e908483d04dfc0328651d79d35b54f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6cd73502-dccb-4e39-9140-0688bd2afbbc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 50520639cf77df0c15cc95076fac901e3d04b708",
      "pattern": "[file:hashes.'SHA-1' = '50520639cf77df0c15cc95076fac901e3d04b708']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--071c5e15-4b95-427e-98c7-d1cbfa330699",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: cec327e51b79cf11b3eeffebf1be8ac0d66e9529",
      "pattern": "[file:hashes.'SHA-1' = 'cec327e51b79cf11b3eeffebf1be8ac0d66e9529']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e599c00e-e2a7-4894-b049-cccd7722f577",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: cf7af504ef0796d91207e41815187a793d430d85",
      "pattern": "[file:hashes.'SHA-1' = 'cf7af504ef0796d91207e41815187a793d430d85']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c8abbaa1-d4ed-4952-a819-ef08e09f1564",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: f8697b400059d4d5082eee2d269735aa8ea2df9a",
      "pattern": "[file:hashes.'SHA-1' = 'f8697b400059d4d5082eee2d269735aa8ea2df9a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--86851482-7d07-462b-89ef-2e37f6b74115",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3751997cfcb038e6b658e9180bc7cce28a3c25dbb892b661bcd1065723f11f7e",
      "pattern": "[file:hashes.'SHA-256' = '3751997cfcb038e6b658e9180bc7cce28a3c25dbb892b661bcd1065723f11f7e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c2a30b5f-fbd9-4467-9024-bac185c04088",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5995aaff5a047565c0d7fe3c80fa354c40e7e8c3e7d4df292316c8472d4ac67a",
      "pattern": "[file:hashes.'SHA-256' = '5995aaff5a047565c0d7fe3c80fa354c40e7e8c3e7d4df292316c8472d4ac67a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7524e3d5-674e-4530-9bb2-40172a4394ac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5bef7608d66112315eefff354dae42f49178b7498f994a728ae6203a8a59f5a2",
      "pattern": "[file:hashes.'SHA-256' = '5bef7608d66112315eefff354dae42f49178b7498f994a728ae6203a8a59f5a2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0d591922-6385-44e8-8433-ac52f65d70a7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 905b18d5df58bd6c16930e318d9574a2ad793ec993ad2f68bca813574e3d854b",
      "pattern": "[file:hashes.'SHA-256' = '905b18d5df58bd6c16930e318d9574a2ad793ec993ad2f68bca813574e3d854b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--54064906-4ffc-4550-bae4-30bc73a392aa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 98380ec6bf4e03d3ff490cdc6c48c37714450930e4adf82e6e14d244d8373888",
      "pattern": "[file:hashes.'SHA-256' = '98380ec6bf4e03d3ff490cdc6c48c37714450930e4adf82e6e14d244d8373888']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--924e378e-30b2-467e-bac0-e79ae400373f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c0ec15e08b4fb3730c5695fb7b4a6b85f7fe341282ad469e4e141c40ead310c3",
      "pattern": "[file:hashes.'SHA-256' = 'c0ec15e08b4fb3730c5695fb7b4a6b85f7fe341282ad469e4e141c40ead310c3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f662ec2c-242c-4749-9678-c7f5b5ff2761",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e1de05a2832437ab70d36c4c05b43c4a57f856289224bbd41182deea978400ed",
      "pattern": "[file:hashes.'SHA-256' = 'e1de05a2832437ab70d36c4c05b43c4a57f856289224bbd41182deea978400ed']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--627e7f48-d41d-44c7-a2c7-f39f59ad52b3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-22869",
      "pattern": "[vulnerability:name = 'CVE-2025-22869']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk Helps Secure the Golang Bento Project",
          "url": "https://snyk.io/blog/snyk-helps-secure-the-golang-bento-project/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--688eebe5-0fd7-470c-819f-c0b3565267fb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-24983",
      "pattern": "[vulnerability:name = 'CVE-2025-24983']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24983 \u2014 Microsoft Windows Win32k Use-Afte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c5861928-560e-4303-ba8f-439b088ca255",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-24984",
      "pattern": "[vulnerability:name = 'CVE-2025-24984']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24984 \u2014 Microsoft Windows NTFS Informatio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--41b8b889-3755-43fb-8708-027c49d2333c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-24985",
      "pattern": "[vulnerability:name = 'CVE-2025-24985']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24985 \u2014 Microsoft Windows Fast FAT File S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f5a2328-7c73-4a68-b1c0-70145a1af122",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-24991",
      "pattern": "[vulnerability:name = 'CVE-2025-24991']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24991 \u2014 Microsoft Windows NTFS Out-Of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c41d5fae-e5a0-4404-8007-7b1bdc38dc2c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-24993",
      "pattern": "[vulnerability:name = 'CVE-2025-24993']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24993 \u2014 Microsoft Windows NTFS Heap-Based",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6fdcec50-579b-443b-8242-d21cd100e3b6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-26633",
      "pattern": "[vulnerability:name = 'CVE-2025-26633']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-26633 \u2014 Microsoft Windows Management Cons",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a560ef0d-a968-41f9-b05d-565c7fbc3768",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: belaysolutions.link",
      "pattern": "[domain-name:value = 'belaysolutions.link']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-26633 \u2014 Microsoft Windows Management Cons",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--57817381-080e-42d7-8acc-0c68c2aa163b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.246.147.17",
      "pattern": "[ipv4-addr:value = '103.246.147.17']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-26633 \u2014 Microsoft Windows Management Cons",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cbbb5223-5db5-42c7-9934-73207bbb8363",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 82.115.223.182",
      "pattern": "[ipv4-addr:value = '82.115.223.182']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-26633 \u2014 Microsoft Windows Management Cons",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a7f481c4-b22b-4773-a44d-b89c3c6dde03",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: bad43a1c8ba1dacf3daf82bc30a0673f9bc2675ea6cdedd34624ffc933b959f4",
      "pattern": "[file:hashes.'SHA-256' = 'bad43a1c8ba1dacf3daf82bc30a0673f9bc2675ea6cdedd34624ffc933b959f4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-26633 \u2014 Microsoft Windows Management Cons",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--40778dcb-719f-4285-b793-461f6b8c81b7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-9248",
      "pattern": "[vulnerability:name = 'CVE-2017-9248']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2d379ee4-3997-4e73-8954-60292e75e8f1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-18935",
      "pattern": "[vulnerability:name = 'CVE-2019-18935']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-11357 \u2014 Telerik UI for ASP.NET AJAX Insec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8454a7a0-0c59-41e2-b7c8-a668076d8705",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-10811",
      "pattern": "[vulnerability:name = 'CVE-2024-10811']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-13159 \u2014 Ivanti Endpoint Manager (EPM) Abs",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e208439d-3a46-4da6-badc-d2e157229fb2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-13159",
      "pattern": "[vulnerability:name = 'CVE-2024-13159']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-13159 \u2014 Ivanti Endpoint Manager (EPM) Abs",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e6b69c87-0946-4043-9dcd-f85a5ae6e14e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-13160",
      "pattern": "[vulnerability:name = 'CVE-2024-13160']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-13160 \u2014 Ivanti Endpoint Manager (EPM) Abs",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-13159 \u2014 Ivanti Endpoint Manager (EPM) Abs",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--70b20a71-2d10-423e-a722-20e1fab514c9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-13161",
      "pattern": "[vulnerability:name = 'CVE-2024-13161']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-13161 \u2014 Ivanti Endpoint Manager (EPM) Abs",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-13159 \u2014 Ivanti Endpoint Manager (EPM) Abs",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d904d3f-edcd-463e-afd9-5fb76f40fe36",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-57968",
      "pattern": "[vulnerability:name = 'CVE-2024-57968']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ae79e98e-6da1-44cc-ad70-5836c519c636",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-25181",
      "pattern": "[vulnerability:name = 'CVE-2025-25181']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--532e30b2-770e-428b-972d-c497b67dbd07",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: hivnd.com",
      "pattern": "[domain-name:value = 'hivnd.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--744abc61-cf58-4405-9f68-cf6f1d0d4549",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: object.fm",
      "pattern": "[domain-name:value = 'object.fm']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb97f3a2-ad34-4a63-9e39-d1c86c663840",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: paycashs.com",
      "pattern": "[domain-name:value = 'paycashs.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9f13f7df-a154-488e-a057-e5af9a0fc7c3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sexadult.com",
      "pattern": "[domain-name:value = 'sexadult.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--94deba4a-7c32-40d6-bfc5-5adfe0c79cbe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: xegroups.com",
      "pattern": "[domain-name:value = 'xegroups.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--00ebc62b-906c-46f8-90ea-9a37a3ffde26",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: xework.com",
      "pattern": "[domain-name:value = 'xework.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b059fe66-9146-4bc7-8437-1fcd6100fc73",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 123.20.29.193",
      "pattern": "[ipv4-addr:value = '123.20.29.193']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c250a8d3-6b72-432b-971f-20269639fb20",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 171.227.250.249",
      "pattern": "[ipv4-addr:value = '171.227.250.249']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bdb11779-80a8-4fa3-bf79-defa05bdd2b7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 222.253.102.94",
      "pattern": "[ipv4-addr:value = '222.253.102.94']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e13af1d5-a13f-4df7-a00b-2bcd63bd186c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 339a79457a8cf3504312d394be3ece98",
      "pattern": "[file:hashes.MD5 = '339a79457a8cf3504312d394be3ece98']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a3c9db3e-235f-4c5d-a532-65e47bc5f571",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 457d7e3a708d1b5c6a8d449e52064985",
      "pattern": "[file:hashes.MD5 = '457d7e3a708d1b5c6a8d449e52064985']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cc0d06bc-eb25-4b1e-a8d2-fbeb5da52ccb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 7a9b5c3bb7dab0857ee2c2d71758eca3",
      "pattern": "[file:hashes.MD5 = '7a9b5c3bb7dab0857ee2c2d71758eca3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f448987-e68b-48e3-959d-74362d7b92ca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 7abb73b7844f2308d9c62954e6e8b7fc",
      "pattern": "[file:hashes.MD5 = '7abb73b7844f2308d9c62954e6e8b7fc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ccbe896c-500e-4291-9954-3786465c1afb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 7b5b7d96006fec70c2091e90fbf02b99",
      "pattern": "[file:hashes.MD5 = '7b5b7d96006fec70c2091e90fbf02b99']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2552faa7-5fe1-44f7-9352-56fde466cd6d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 032dd95a1299f37aaa76318945e030eb7da94da9",
      "pattern": "[file:hashes.'SHA-1' = '032dd95a1299f37aaa76318945e030eb7da94da9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--94c405cc-3812-434a-a2f8-8163c8974ea6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 16db01fe25b0c09e18d13f38c88a4ead5d10e323",
      "pattern": "[file:hashes.'SHA-1' = '16db01fe25b0c09e18d13f38c88a4ead5d10e323']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f048e1cf-9c96-42ac-b2b0-8e1ae3e2b217",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 84e7f4ff1f93a4297c2e2c4e54f14edb18396b60",
      "pattern": "[file:hashes.'SHA-1' = '84e7f4ff1f93a4297c2e2c4e54f14edb18396b60']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c270f144-7ada-4af8-8ef7-bf72e267ff8f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 9e928a26aa3c0e6eb8e709fc55ea12dcf7e02ff9",
      "pattern": "[file:hashes.'SHA-1' = '9e928a26aa3c0e6eb8e709fc55ea12dcf7e02ff9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b1ede416-7c3c-4ac4-969d-3f4e847e1364",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: ede5ddb97b98d80440553b23dfc19fdb4adc7499",
      "pattern": "[file:hashes.'SHA-1' = 'ede5ddb97b98d80440553b23dfc19fdb4adc7499']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--80baa27b-d809-4a81-a098-83bc653ec022",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 013ccea1d7fc2aa2d660e900f87a3192f5cb73768710ef2eb9016f81df8e5c70",
      "pattern": "[file:hashes.'SHA-256' = '013ccea1d7fc2aa2d660e900f87a3192f5cb73768710ef2eb9016f81df8e5c70']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--375ff01d-a741-4773-9cac-9d4c0b4ce34b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 322f8cd560d5e10e93af3ea6d3505c8de213f549e6627c3ef4664ed92ba55f56",
      "pattern": "[file:hashes.'SHA-256' = '322f8cd560d5e10e93af3ea6d3505c8de213f549e6627c3ef4664ed92ba55f56']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9cedca1a-8a88-4039-99bb-3a9a03d08efc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 38b2d52dc471587fb65ef99c64cb3f69470ddfdaa184a256aecb26edeff3553a",
      "pattern": "[file:hashes.'SHA-256' = '38b2d52dc471587fb65ef99c64cb3f69470ddfdaa184a256aecb26edeff3553a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4f1f04f3-39f8-47fb-b9bc-c7220c0f41f7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 680b7e8ec8204975c5026bcbaf70f7e9620eacdd7bf72e5476d17266b4a7d316",
      "pattern": "[file:hashes.'SHA-256' = '680b7e8ec8204975c5026bcbaf70f7e9620eacdd7bf72e5476d17266b4a7d316']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b6184e0a-e05b-4c13-9ae7-3c35c62b2d0a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 884c394c7b3eb757ae57050ac2e6a75385a361555e8e4272de1a3cf24746eec7",
      "pattern": "[file:hashes.'SHA-256' = '884c394c7b3eb757ae57050ac2e6a75385a361555e8e4272de1a3cf24746eec7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d7a03314-cc54-4b79-91b0-eb2b40aabe41",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c564acd69efa62a5037931090bf70a6506419fdf59ec52f8d1ab0b15d861cc67",
      "pattern": "[file:hashes.'SHA-256' = 'c564acd69efa62a5037931090bf70a6506419fdf59ec52f8d1ab0b15d861cc67']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a96ac7ec-bcc6-44fc-a2e5-780b3e2ca7aa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-22224",
      "pattern": "[vulnerability:name = 'CVE-2025-22224']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-22225 \u2014 VMware ESXi Arbitrary Write Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-22224 \u2014 VMware ESXi and Workstation TOCTO",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--659ec383-4052-407c-b48e-8dc88dcf34b6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-22225",
      "pattern": "[vulnerability:name = 'CVE-2025-22225']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-22225 \u2014 VMware ESXi Arbitrary Write Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c3b7fd5c-670d-461e-a8c3-acd67757afa5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-22226",
      "pattern": "[vulnerability:name = 'CVE-2025-22226']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-22226 \u2014 VMware ESXi, Workstation, and Fus",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-22225 \u2014 VMware ESXi Arbitrary Write Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4bb9ba11-5441-414c-a06a-31ef533ad952",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2bc5d02774ac1778be22cace51f9e35fe7b53378f8d70143bf646b68d2c0f94c",
      "pattern": "[file:hashes.'SHA-256' = '2bc5d02774ac1778be22cace51f9e35fe7b53378f8d70143bf646b68d2c0f94c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-22224 \u2014 VMware ESXi and Workstation TOCTO",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5ae9081-50d2-44b6-bb0b-d71ce6af8b41",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 37972a232ac6d8c402ac4531430967c1fd458b74a52d6d1990688d88956791a7",
      "pattern": "[file:hashes.'SHA-256' = '37972a232ac6d8c402ac4531430967c1fd458b74a52d6d1990688d88956791a7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-22224 \u2014 VMware ESXi and Workstation TOCTO",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--81fdff57-86cd-44d2-9a4c-7f5a0b1332c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4614346fc1ff74f057d189db45aa7dc25d6e7f3d9b68c287a409a53c86dca25e",
      "pattern": "[file:hashes.'SHA-256' = '4614346fc1ff74f057d189db45aa7dc25d6e7f3d9b68c287a409a53c86dca25e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-22224 \u2014 VMware ESXi and Workstation TOCTO",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--94d57018-b0dc-4fc4-952d-8c9fc4578422",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c3f8da7599468c11782c2332497b9e5013d98a1030034243dfed0cf072469c89",
      "pattern": "[file:hashes.'SHA-256' = 'c3f8da7599468c11782c2332497b9e5013d98a1030034243dfed0cf072469c89']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-22224 \u2014 VMware ESXi and Workstation TOCTO",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f9c27398-1bed-40f4-8fb2-a41c5e467e55",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: dc5b8f7c6a8a6764de3309279e3b6412c23e6af1d7a8631c65b80027444d62bb",
      "pattern": "[file:hashes.'SHA-256' = 'dc5b8f7c6a8a6764de3309279e3b6412c23e6af1d7a8631c65b80027444d62bb']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-22224 \u2014 VMware ESXi and Workstation TOCTO",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1d2bc6f0-3e72-4ea1-8975-e9a636178fa8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-8639",
      "pattern": "[vulnerability:name = 'CVE-2018-8639']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-8639 \u2014 Microsoft Windows Win32k Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--52b147a6-c104-40df-91fa-1156429cb4c9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-43769",
      "pattern": "[vulnerability:name = 'CVE-2022-43769']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-43769 \u2014 Hitachi Vantara Pentaho BA Server",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4246a653-412c-47b3-ae8f-3e78953ce45a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-43939",
      "pattern": "[vulnerability:name = 'CVE-2022-43939']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-43939 \u2014 Hitachi Vantara Pentaho BA Server",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f578b77f-ec98-4670-b0cd-e5ee485f198d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-20118",
      "pattern": "[vulnerability:name = 'CVE-2023-20118']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fccd97bb-3ab2-4bea-8972-d31c9ee5f643",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-4885",
      "pattern": "[vulnerability:name = 'CVE-2024-4885']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4885 \u2014 Progress WhatsUp Gold Path Travers",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6b5a2d1e-81e5-48e5-9ddc-23471761c25d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: aipricadd.top",
      "pattern": "[domain-name:value = 'aipricadd.top']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea213254-59a9-4a84-9bc4-ba9cbc62ed7b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: asustordownload.com",
      "pattern": "[domain-name:value = 'asustordownload.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6eae4791-2976-42f8-9f50-a29085f4163b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: centrequ.cc",
      "pattern": "[domain-name:value = 'centrequ.cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--99186bb3-d76a-430e-83e3-78ceb598deb5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: durianlink.cc",
      "pattern": "[domain-name:value = 'durianlink.cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--824c81b0-2904-4e63-b587-df0841af5bfb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: firebasesafer.top",
      "pattern": "[domain-name:value = 'firebasesafer.top']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1798993f-6b91-4050-ace2-f9ec18f43a26",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: gardensc.cc",
      "pattern": "[domain-name:value = 'gardensc.cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--50053da6-57bb-42d7-960e-3bc77d7f5a02",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: headached.cc",
      "pattern": "[domain-name:value = 'headached.cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--14001784-287d-40b7-8ccc-0d29038c00c3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: hitchil.cc",
      "pattern": "[domain-name:value = 'hitchil.cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f1f4ef97-7560-484a-aa4c-611e4e058cae",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: icecreand.cc",
      "pattern": "[domain-name:value = 'icecreand.cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5198b117-0abb-4ccd-92a6-ad4455eaa934",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: landim.cc",
      "pattern": "[domain-name:value = 'landim.cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2fbbd6b1-3aa9-4e2f-a420-002b68ee4aea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: largeroofs.top",
      "pattern": "[domain-name:value = 'largeroofs.top']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aeb4d435-d956-4c3d-bafe-8f8a97c7166e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: logchim.cc",
      "pattern": "[domain-name:value = 'logchim.cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--74e707e1-02d2-4749-b6a7-8865f3b31031",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: longlog.cc",
      "pattern": "[domain-name:value = 'longlog.cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c2fa7ba1-027d-468d-80e9-e9ad429653ab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: nternetd.cc",
      "pattern": "[domain-name:value = 'nternetd.cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76520a64-87f6-48b2-9012-212be2be4d66",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: siotherlentsearsitech.shop",
      "pattern": "[domain-name:value = 'siotherlentsearsitech.shop']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fc41370d-6aec-46ae-beda-35e996ebee19",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ssofhoseuegsgrfnu.ru",
      "pattern": "[domain-name:value = 'ssofhoseuegsgrfnu.ru']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--34466893-870f-427a-b963-2c0abead51ea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: suiteiol.cc",
      "pattern": "[domain-name:value = 'suiteiol.cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--152f59d0-abb6-47dd-9545-8a26fa066b21",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 101.99.91.239",
      "pattern": "[ipv4-addr:value = '101.99.91.239']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d4d5569-0432-430a-bbb2-7f006a118f6c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 119.8.186.227",
      "pattern": "[ipv4-addr:value = '119.8.186.227']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe3bd347-d1b3-4481-9701-71d3ded503b9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 122.8.183.181",
      "pattern": "[ipv4-addr:value = '122.8.183.181']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a00af15f-0053-4aaf-b0d4-1ddb114bf6fd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 159.138.119.99",
      "pattern": "[ipv4-addr:value = '159.138.119.99']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--711c2190-28d9-49b3-8f7c-56ef975cf907",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 195.123.212.54",
      "pattern": "[ipv4-addr:value = '195.123.212.54']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--65a5de6f-c2a7-46db-b8a8-1af56329fbe1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 43.129.205.244",
      "pattern": "[ipv4-addr:value = '43.129.205.244']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--276c3f2f-caf0-4d1f-abf1-f44db3402989",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 121969d72f8e6f09ad93cf17500c479c452e230e27e7b157d5c9336dff15b6ef",
      "pattern": "[file:hashes.'SHA-256' = '121969d72f8e6f09ad93cf17500c479c452e230e27e7b157d5c9336dff15b6ef']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb85219c-86cd-4de5-bc99-de9b3b7ac5fc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 13cd040a7f488e937b1b234d71a0126b7bc74367bf6538b6961c476f5d620d13",
      "pattern": "[file:hashes.'SHA-256' = '13cd040a7f488e937b1b234d71a0126b7bc74367bf6538b6961c476f5d620d13']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0ebe0315-1b57-48d9-bfa5-8d94a5000884",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1ca7262f91d517853a0551b14abb0306c4e3567e41b1e82a018f0aac718e499e",
      "pattern": "[file:hashes.'SHA-256' = '1ca7262f91d517853a0551b14abb0306c4e3567e41b1e82a018f0aac718e499e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bfd3ecf4-007b-45cd-8e7e-5e6f5da80e2e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 464f29d5f496b4acffc455330f00adb34ab920c66ca1908eee262339d6946bcd",
      "pattern": "[file:hashes.'SHA-256' = '464f29d5f496b4acffc455330f00adb34ab920c66ca1908eee262339d6946bcd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a66311e7-3c0d-4963-909a-32b58141f59a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 932b2545bd6e3ad74b82ca2199944edecf9c92ad3f75fce0d07e04ab084824d5",
      "pattern": "[file:hashes.'SHA-256' = '932b2545bd6e3ad74b82ca2199944edecf9c92ad3f75fce0d07e04ab084824d5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--10756266-84ab-445e-b37c-ad1f179efcf6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: eda7cc5e1781c681afe99bf513fcaf5ae86afbf1d84dfd23aa563b1a043cbba8",
      "pattern": "[file:hashes.'SHA-256' = 'eda7cc5e1781c681afe99bf513fcaf5ae86afbf1d84dfd23aa563b1a043cbba8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe526b61-8b48-4854-8489-09699da86b0c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-34192",
      "pattern": "[vulnerability:name = 'CVE-2023-34192']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-34192 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--83f461b6-782f-49a4-95c4-f1ca8d596652",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-49035",
      "pattern": "[vulnerability:name = 'CVE-2024-49035']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49035 \u2014 Microsoft Partner Center Improper",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--43d9f8cc-55fe-4687-98f9-9844a079116a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-3066",
      "pattern": "[vulnerability:name = 'CVE-2017-3066']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-3066 \u2014 Adobe ColdFusion Deserialization V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1cd4a6bf-d0fd-484d-84a0-ff5a0bb26ae9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-20953",
      "pattern": "[vulnerability:name = 'CVE-2024-20953']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20953 \u2014 Oracle Agile Product Lifecycle Ma",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b11cd714-d463-471a-95b6-5a29abfb003b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-24989",
      "pattern": "[vulnerability:name = 'CVE-2025-24989']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24989 \u2014 Microsoft Power Pages Improper Ac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--77d4496b-944f-410a-adee-6a331baef7ab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-24439",
      "pattern": "[vulnerability:name = 'CVE-2022-24439']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk\u2019s Fetch the Flag CTF is More Than Just a CTF",
          "url": "https://snyk.io/blog/snyks-fetch-the-flag-ctf/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e4d3b0ec-7dce-47eb-84cd-013cd7049c90",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-33891",
      "pattern": "[vulnerability:name = 'CVE-2022-33891']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk\u2019s Fetch the Flag CTF is More Than Just a CTF",
          "url": "https://snyk.io/blog/snyks-fetch-the-flag-ctf/"
        },
        {
          "source_name": "CISA KEV: CVE-2022-33891 \u2014 Apache Spark Command Injection Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0367b6d9-dd68-4387-aea7-c14a2470acf7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-40267",
      "pattern": "[vulnerability:name = 'CVE-2023-40267']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk\u2019s Fetch the Flag CTF is More Than Just a CTF",
          "url": "https://snyk.io/blog/snyks-fetch-the-flag-ctf/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--912c5298-4e1f-413e-b06f-616dfb38e505",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-9474",
      "pattern": "[vulnerability:name = 'CVE-2024-9474']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0111 \u2014 Palo Alto Networks PAN-OS File Rea",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-0108 \u2014 Palo Alto Networks PAN-OS Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--90a362f2-2139-4ea8-93ae-a10fdd82ff72",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-0108",
      "pattern": "[vulnerability:name = 'CVE-2025-0108']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0111 \u2014 Palo Alto Networks PAN-OS File Rea",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-0108 \u2014 Palo Alto Networks PAN-OS Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f19e6021-d6c0-4b84-9ef8-fd39bc375745",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-0111",
      "pattern": "[vulnerability:name = 'CVE-2025-0111']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0111 \u2014 Palo Alto Networks PAN-OS File Rea",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-0108 \u2014 Palo Alto Networks PAN-OS Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b00f9623-cd96-4c46-aa52-4073a1fed9e4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-23209",
      "pattern": "[vulnerability:name = 'CVE-2025-23209']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-23209 \u2014 Craft CMS Code Injection Vulnerab",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb6cbb26-7475-41a1-8754-dd30f25bce73",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-53704",
      "pattern": "[vulnerability:name = 'CVE-2024-53704']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-53704 \u2014 SonicWall SonicOS SSLVPN Improper",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7af47d01-d0b5-4ee8-81a1-6b3f36514edb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-57727",
      "pattern": "[vulnerability:name = 'CVE-2024-57727']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-57727 \u2014 SimpleHelp Path Traversal Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0db9ec5-849d-43b3-9758-6a31c0508de7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-10562",
      "pattern": "[vulnerability:name = 'CVE-2018-10562']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Inject",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--917daee1-c193-4564-83d8-11cd5eea8ef9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-17532",
      "pattern": "[vulnerability:name = 'CVE-2018-17532']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9d33804f-cf3f-48a7-a32a-a59381bcedb7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-31137",
      "pattern": "[vulnerability:name = 'CVE-2022-31137']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5829c489-e60e-4dc8-9e25-39d5833e77e7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-26801",
      "pattern": "[vulnerability:name = 'CVE-2023-26801']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fcf58846-7baf-496d-a02d-a948fc08c117",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-41710",
      "pattern": "[vulnerability:name = 'CVE-2024-41710']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd62da37-47fa-4323-a1f9-1b4250af2aa4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-24200",
      "pattern": "[vulnerability:name = 'CVE-2025-24200']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24200 \u2014 Apple iOS and iPadOS Incorrect Au",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1b639b77-f43f-4b6b-9d08-99f2f807c3cc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: GO-2025-3451",
      "pattern": "[vulnerability:name = 'GO-2025-3451']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Do not pass GO - Malicious Package Alert",
          "url": "https://snyk.io/blog/go-malicious-package-alert/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5eb0ba83-5ea7-4c20-b7d9-8174bfd441b8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cardiacpure.ru",
      "pattern": "[domain-name:value = 'cardiacpure.ru']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd0fb960-7e48-4131-bdf0-32b468f72270",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: eye-network.ru",
      "pattern": "[domain-name:value = 'eye-network.ru']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--38ca7e00-d50a-454c-8351-4935963aaa3c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: fuerer-net.ru",
      "pattern": "[domain-name:value = 'fuerer-net.ru']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4f03eb52-b9d5-414f-b578-f3aa1b195d45",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: github.com/boltdb-go/bolt",
      "pattern": "[domain-name:value = 'github.com/boltdb-go/bolt']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Do not pass GO - Malicious Package Alert",
          "url": "https://snyk.io/blog/go-malicious-package-alert/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0a8177a7-2aad-47a0-9d0f-1bdb317ca140",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: intenseapi.com",
      "pattern": "[domain-name:value = 'intenseapi.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bea84d26-1390-4e9f-be73-1b2a85ff2e33",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 49.12.198.231",
      "pattern": "[ipv4-addr:value = '49.12.198.231']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Do not pass GO - Malicious Package Alert",
          "url": "https://snyk.io/blog/go-malicious-package-alert/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c109bf1-74db-4abd-a9f2-a41653e465b6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 91.92.243.233",
      "pattern": "[ipv4-addr:value = '91.92.243.233']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f47c4db2-5eb1-4d98-b0ab-3ab53b58947b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e06c3f5c32aaa422e66056290eb566065afe2ce611fe019f3ba804af939ac1a3",
      "pattern": "[file:hashes.'SHA-256' = 'e06c3f5c32aaa422e66056290eb566065afe2ce611fe019f3ba804af939ac1a3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--482cbc29-124a-43e5-8b1a-bd8a78221a96",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-40890",
      "pattern": "[vulnerability:name = 'CVE-2024-40890']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40891 \u2014 Zyxel DSL CPE OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-40890 \u2014 Zyxel DSL CPE OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--65e17965-ee35-423b-9148-ed97b0fdec69",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-40891",
      "pattern": "[vulnerability:name = 'CVE-2024-40891']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40891 \u2014 Zyxel DSL CPE OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-40890 \u2014 Zyxel DSL CPE OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fa420464-a1b6-4409-8990-c7db2d0c91f1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-0890",
      "pattern": "[vulnerability:name = 'CVE-2025-0890']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40891 \u2014 Zyxel DSL CPE OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-40890 \u2014 Zyxel DSL CPE OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a227d76-1516-4a33-ae35-5c1c3faf6530",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-21391",
      "pattern": "[vulnerability:name = 'CVE-2025-21391']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21391 \u2014 Microsoft Windows Storage Link Fo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de72fb63-e0df-43c9-8711-3e031039ac17",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-21418",
      "pattern": "[vulnerability:name = 'CVE-2025-21418']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21418 \u2014 Microsoft Windows Ancillary Funct",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b23b6f39-e898-493d-bbbd-d091b6820876",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-0994",
      "pattern": "[vulnerability:name = 'CVE-2025-0994']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0994 \u2014 Trimble Cityworks Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9fa373d9-dee5-40a6-a6d0-c54956ede5f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cdn.lgaircon.xyz",
      "pattern": "[domain-name:value = 'cdn.lgaircon.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0994 \u2014 Trimble Cityworks Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--adaacd88-ee49-454d-a4f3-ab936162def5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cdn.phototagx.com",
      "pattern": "[domain-name:value = 'cdn.phototagx.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0994 \u2014 Trimble Cityworks Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1e533f0b-9424-44fa-807d-b8afc2c3fb0c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: lgaircon.xyz",
      "pattern": "[domain-name:value = 'lgaircon.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0994 \u2014 Trimble Cityworks Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--415d009d-d906-48e9-bd9e-c67d5d1fc3d8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: www.roomako.com",
      "pattern": "[domain-name:value = 'www.roomako.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0994 \u2014 Trimble Cityworks Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--33d70d23-00e3-402c-bfbc-6e3146187344",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.210.239.172",
      "pattern": "[ipv4-addr:value = '192.210.239.172']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0994 \u2014 Trimble Cityworks Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--680a3854-b2ba-4ff8-98b6-a089ff952179",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 14ed3878b6623c287283a8a80020f68e1cb6bfc37b236f33a95f3a64c4f4611f",
      "pattern": "[file:hashes.'SHA-256' = '14ed3878b6623c287283a8a80020f68e1cb6bfc37b236f33a95f3a64c4f4611f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0994 \u2014 Trimble Cityworks Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9b3bc850-12e8-4532-9754-881c5bf73135",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1c38e3cda8ac6d79d9da40834367697a209c6b07e6b3ab93b3a4f375b161a901",
      "pattern": "[file:hashes.'SHA-256' = '1c38e3cda8ac6d79d9da40834367697a209c6b07e6b3ab93b3a4f375b161a901']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0994 \u2014 Trimble Cityworks Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3503f8e0-e80b-4e60-99b4-77454ef2b8f8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1de72c03927bcd2810ce98205ff871ef1ebf4344fba187e126e50caa1e43250b",
      "pattern": "[file:hashes.'SHA-256' = '1de72c03927bcd2810ce98205ff871ef1ebf4344fba187e126e50caa1e43250b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0994 \u2014 Trimble Cityworks Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--11521f71-d1dd-4d61-97fa-5f7bf923970b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4ffc33bdc8527a2e8cb87e49cdc16c3b1480dfc135e507d552f581a67d1850a9",
      "pattern": "[file:hashes.'SHA-256' = '4ffc33bdc8527a2e8cb87e49cdc16c3b1480dfc135e507d552f581a67d1850a9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0994 \u2014 Trimble Cityworks Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9a4192a8-f0fe-4ef2-8f11-7bbd87cd405f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c02d50d0eb3974818091b8dd91a8bbb8cdefd94d4568a4aea8e1dcdd8869f738",
      "pattern": "[file:hashes.'SHA-256' = 'c02d50d0eb3974818091b8dd91a8bbb8cdefd94d4568a4aea8e1dcdd8869f738']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0994 \u2014 Trimble Cityworks Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a4fdc0b4-cc97-49a1-9e3b-b9c08ffede3a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-15069",
      "pattern": "[vulnerability:name = 'CVE-2020-15069']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-15069 \u2014 Sophos XG Firewall Buffer Overflo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--437e512a-d582-4596-a6fb-30495ae24dfc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-29574",
      "pattern": "[vulnerability:name = 'CVE-2020-29574']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-29574 \u2014 CyberoamOS (CROS) SQL Injection V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2e015884-d74b-40fd-8824-faa4f1821876",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-23748",
      "pattern": "[vulnerability:name = 'CVE-2022-23748']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-23748 \u2014 Dante Discovery Process Control V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3a114073-0241-44d4-9a7e-1a0aec022add",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-21413",
      "pattern": "[vulnerability:name = 'CVE-2024-21413']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-21413 \u2014 Microsoft Outlook Improper Input ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--572de7ac-7d6d-45f3-97d9-3f72cb38af4e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-0411",
      "pattern": "[vulnerability:name = 'CVE-2025-0411']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0411 \u2014 7-Zip Mark of the Web Bypass Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--35fb4d69-e7f5-4c42-92a8-e9dcbefec320",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7786501e3666c1a5071c9c5e5a019e2bc86a1f169d469cc4bfef2fe339aaf384",
      "pattern": "[file:hashes.'SHA-256' = '7786501e3666c1a5071c9c5e5a019e2bc86a1f169d469cc4bfef2fe339aaf384']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0411 \u2014 7-Zip Mark of the Web Bypass Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--236ecd17-daad-4184-a47a-ccc62f2345b0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 84ab6c3e1f2dc98cf4d5b8b739237570416bb82e2edaf078e9868663553c5412",
      "pattern": "[file:hashes.'SHA-256' = '84ab6c3e1f2dc98cf4d5b8b739237570416bb82e2edaf078e9868663553c5412']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0411 \u2014 7-Zip Mark of the Web Bypass Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b7b98505-617e-49c9-8009-da9bacc50495",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-19410",
      "pattern": "[vulnerability:name = 'CVE-2018-19410']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-19410 \u2014 Paessler PRTG Network Monitor Loc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--97297fea-61a9-413e-9373-6567370d6586",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-9276",
      "pattern": "[vulnerability:name = 'CVE-2018-9276']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-9276 \u2014 Paessler PRTG Network Monitor OS C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d627b71-7477-4377-b28d-353bba4a780e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-29059",
      "pattern": "[vulnerability:name = 'CVE-2024-29059']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-29059 \u2014 Microsoft .NET Framework Informat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--866677ca-e867-491a-a8bc-173d8782ff67",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-45195",
      "pattern": "[vulnerability:name = 'CVE-2024-45195']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-45195 \u2014 Apache OFBiz Forced Browsing Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aa0b19b6-3ebe-4822-b83e-21226c780050",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-24085",
      "pattern": "[vulnerability:name = 'CVE-2025-24085']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-24085 \u2014 Apple Multiple Products Use-After",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--74602489-1738-40fd-9db6-6c56befc89e1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-23006",
      "pattern": "[vulnerability:name = 'CVE-2025-23006']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-23006 \u2014 SonicWall SMA1000 Appliances Dese",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--13a08cd4-b6c4-4e1e-8858-232662b13ea4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-11023",
      "pattern": "[vulnerability:name = 'CVE-2020-11023']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-11023 \u2014 JQuery Cross-Site Scripting (XSS)",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b993ddd1-1d22-41f5-ae7d-b38bcf0c9cac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-50603",
      "pattern": "[vulnerability:name = 'CVE-2024-50603']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e37bbb54-92a2-4d11-b8cd-34304c7fc909",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 107.172.43.186",
      "pattern": "[ipv4-addr:value = '107.172.43.186']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e36871d5-894b-4ea7-9f35-9856bef2cd9a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.104.60.176",
      "pattern": "[ipv4-addr:value = '172.104.60.176']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--361eeb1b-4bf9-4188-8b06-6e0f9df01742",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 83.222.191.91",
      "pattern": "[ipv4-addr:value = '83.222.191.91']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a61a7512-0df2-41d2-90be-0a7427d3c612",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 91.188.254.21",
      "pattern": "[ipv4-addr:value = '91.188.254.21']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1314549c-9af2-49e6-8442-03cd749fd22b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 1ce0c293f2042b677cd55a393913ec052eded4b9",
      "pattern": "[file:hashes.'SHA-1' = '1ce0c293f2042b677cd55a393913ec052eded4b9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5e4bbf35-4642-46e5-9ba5-ecc85b6fa583",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 41d589a077038048c4b120494719c905e71485ba",
      "pattern": "[file:hashes.'SHA-1' = '41d589a077038048c4b120494719c905e71485ba']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c12db0e7-f660-43d4-a206-32bdaa9efb56",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 68d88d1918676c87dcd39c7581c3910a9eb94882",
      "pattern": "[file:hashes.'SHA-1' = '68d88d1918676c87dcd39c7581c3910a9eb94882']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1baef478-abe5-4b10-aa51-e17eff806e96",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: c4f63a3a6cb6b8aae133bd4c5ac6f2fc9020c349",
      "pattern": "[file:hashes.'SHA-1' = 'c4f63a3a6cb6b8aae133bd4c5ac6f2fc9020c349']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d9031b0-24ed-44e6-90bc-6c21fb472178",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: c63f646edfddb4232afa5618e3fac4eee1b4b115",
      "pattern": "[file:hashes.'SHA-1' = 'c63f646edfddb4232afa5618e3fac4eee1b4b115']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cc0a832d-0ee2-4930-97dc-265e3ce36277",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: e10e750115bf2ae29a8ce8f9fa14e09e66534a15",
      "pattern": "[file:hashes.'SHA-1' = 'e10e750115bf2ae29a8ce8f9fa14e09e66534a15']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5bb36d7d-67d9-42ae-90f8-dd303d33a56a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-21333",
      "pattern": "[vulnerability:name = 'CVE-2025-21333']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21335 \u2014 Microsoft Windows Hyper-V NT Kern",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21334 \u2014 Microsoft Windows Hyper-V NT Kern",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21333 \u2014 Microsoft Windows Hyper-V NT Kern",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--92d4d97c-7206-4409-9181-42e09a52bba7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-21334",
      "pattern": "[vulnerability:name = 'CVE-2025-21334']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21335 \u2014 Microsoft Windows Hyper-V NT Kern",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21334 \u2014 Microsoft Windows Hyper-V NT Kern",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f057ff3c-e0b7-41fd-a5a6-d48f61f6621f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-21335",
      "pattern": "[vulnerability:name = 'CVE-2025-21335']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-21335 \u2014 Microsoft Windows Hyper-V NT Kern",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2025-21334 \u2014 Microsoft Windows Hyper-V NT Kern",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--557da418-6e09-469d-9f1e-1b94788637f8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 137.184.65.71",
      "pattern": "[ipv4-addr:value = '137.184.65.71']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55591 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a11bfac4-e364-4f42-aa4c-bb5895153095",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 157.245.3.251",
      "pattern": "[ipv4-addr:value = '157.245.3.251']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55591 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b493b327-beb1-4ffd-a3b7-95a6f3e98c5d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 167.71.245.10",
      "pattern": "[ipv4-addr:value = '167.71.245.10']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55591 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--39925998-8c69-4401-846a-a730cb989efa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.27.140.65",
      "pattern": "[ipv4-addr:value = '23.27.140.65']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55591 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc2fd132-c017-4984-b712-f6387f70133c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 31.192.107.165",
      "pattern": "[ipv4-addr:value = '31.192.107.165']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55591 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2889f64-da1e-40b7-9d88-2a34f9892699",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 37.19.196.65",
      "pattern": "[ipv4-addr:value = '37.19.196.65']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55591 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc3b4a2a-1f02-4733-aba8-4d6f2a03d206",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 64.190.113.25",
      "pattern": "[ipv4-addr:value = '64.190.113.25']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55591 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--29297172-8759-4962-bb6d-bc9339f20993",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 66.135.27.178",
      "pattern": "[ipv4-addr:value = '66.135.27.178']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55591 \u2014 Fortinet FortiOS and FortiProxy A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f9796d36-5f43-4526-a93f-2032f85e4e42",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-41265",
      "pattern": "[vulnerability:name = 'CVE-2023-41265']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-48365 \u2014 Qlik Sense HTTP Tunneling Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41266 \u2014 Qlik Sense Path Traversal Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41265 \u2014 Qlik Sense HTTP Tunneling Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6c95c0de-51ba-4c29-a433-874dace1727e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-41266",
      "pattern": "[vulnerability:name = 'CVE-2023-41266']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-48365 \u2014 Qlik Sense HTTP Tunneling Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41266 \u2014 Qlik Sense Path Traversal Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41265 \u2014 Qlik Sense HTTP Tunneling Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b7f8b4a-42c3-48f9-bb9b-1b15b49c9238",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-48365",
      "pattern": "[vulnerability:name = 'CVE-2023-48365']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-48365 \u2014 Qlik Sense HTTP Tunneling Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41266 \u2014 Qlik Sense Path Traversal Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41265 \u2014 Qlik Sense HTTP Tunneling Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--81f4ccd7-c324-4a53-a75a-ac1558e04dcb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-12356",
      "pattern": "[vulnerability:name = 'CVE-2024-12356']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12686 \u2014 BeyondTrust Privileged Remote Acc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-12356 \u2014 BeyondTrust Privileged Remote Acc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7db98f17-2946-4e12-a5cb-d99ba587a996",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-12686",
      "pattern": "[vulnerability:name = 'CVE-2024-12686']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-12686 \u2014 BeyondTrust Privileged Remote Acc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-12356 \u2014 BeyondTrust Privileged Remote Acc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--812c267d-2315-4478-926a-5e166f32bb37",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: q983.requestcatcher.com",
      "pattern": "[domain-name:value = 'q983.requestcatcher.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-48365 \u2014 Qlik Sense HTTP Tunneling Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--61c48eb7-d67b-4413-b7a1-32fedda06560",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: zohoservice.net",
      "pattern": "[domain-name:value = 'zohoservice.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-48365 \u2014 Qlik Sense HTTP Tunneling Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41266 \u2014 Qlik Sense Path Traversal Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41265 \u2014 Qlik Sense HTTP Tunneling Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--33062fd9-dcfc-4990-863f-2a594c4a993e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 144.172.122.30",
      "pattern": "[ipv4-addr:value = '144.172.122.30']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-48365 \u2014 Qlik Sense HTTP Tunneling Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41266 \u2014 Qlik Sense Path Traversal Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41265 \u2014 Qlik Sense HTTP Tunneling Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--763dbe86-c2d5-440a-ae9d-1399154cc0fc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 216.107.136.46",
      "pattern": "[ipv4-addr:value = '216.107.136.46']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-48365 \u2014 Qlik Sense HTTP Tunneling Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41266 \u2014 Qlik Sense Path Traversal Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41265 \u2014 Qlik Sense HTTP Tunneling Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--056ef0ce-3f94-4b7b-8fb6-51232eb49ee3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.61.147.176",
      "pattern": "[ipv4-addr:value = '45.61.147.176']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-48365 \u2014 Qlik Sense HTTP Tunneling Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41266 \u2014 Qlik Sense Path Traversal Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41265 \u2014 Qlik Sense HTTP Tunneling Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--60b2c2ca-781b-4784-a68b-6d440b29e505",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 94.156.71.115",
      "pattern": "[ipv4-addr:value = '94.156.71.115']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-48365 \u2014 Qlik Sense HTTP Tunneling Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--42bc34f2-221d-483c-ba55-0bef9cf608c8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-0282",
      "pattern": "[vulnerability:name = 'CVE-2025-0282']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0282 \u2014 Ivanti Connect Secure, Policy Secu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--41e3f490-cd5f-4498-b7da-13511cac4c4f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2025-0283",
      "pattern": "[vulnerability:name = 'CVE-2025-0283']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0282 \u2014 Ivanti Connect Secure, Policy Secu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8a01d2ce-72a3-45b0-96d6-ab2c367ef3eb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 61bb586dc4e047ab081ef6ca65684e48",
      "pattern": "[file:hashes.MD5 = '61bb586dc4e047ab081ef6ca65684e48']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0282 \u2014 Ivanti Connect Secure, Policy Secu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--903eec64-f016-49bc-a81b-df96247aaea6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: a638fd203ddb540d0484d8e00490df06",
      "pattern": "[file:hashes.MD5 = 'a638fd203ddb540d0484d8e00490df06']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0282 \u2014 Ivanti Connect Secure, Policy Secu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e5c0dcaf-0bc8-4072-a09f-0d2f78751cb6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: d18e5425ecd9608ecb992606b974e15d",
      "pattern": "[file:hashes.MD5 = 'd18e5425ecd9608ecb992606b974e15d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0282 \u2014 Ivanti Connect Secure, Policy Secu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--89710300-dd97-4eb0-92cd-de30daf6935b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e7d24813535f74187db31d4114f607a1",
      "pattern": "[file:hashes.MD5 = 'e7d24813535f74187db31d4114f607a1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2025-0282 \u2014 Ivanti Connect Secure, Policy Secu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5eadecaa-3cd8-45a7-bbf3-582a2dd377d5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-2555",
      "pattern": "[vulnerability:name = 'CVE-2020-2555']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-2883 \u2014 Oracle WebLogic Server Unspecified",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-2555 \u2014 Oracle Multiple Products Remote Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7349c2ae-1d2d-4ab8-9bed-e302ef8fac29",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-2883",
      "pattern": "[vulnerability:name = 'CVE-2020-2883']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-2883 \u2014 Oracle WebLogic Server Unspecified",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--03f7ad30-4efa-4758-b556-602710ede058",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-41713",
      "pattern": "[vulnerability:name = 'CVE-2024-41713']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55550 \u2014 Mitel MiCollab Path Traversal Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--edc43e1b-1d60-4f18-884e-09d43f5bbb9c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-55550",
      "pattern": "[vulnerability:name = 'CVE-2024-55550']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55550 \u2014 Mitel MiCollab Path Traversal Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aee4b626-1422-4a61-911a-edb9181f2687",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-3393",
      "pattern": "[vulnerability:name = 'CVE-2024-3393']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3393 \u2014 Palo Alto Networks PAN-OS Maliciou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--881547a2-8a56-489b-9b15-a647d4d9881b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-0688",
      "pattern": "[vulnerability:name = 'CVE-2020-0688']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-0688 \u2014 Microsoft Exchange Server Validati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--21c8d12a-c2bb-4a83-b5d1-849f11bdc322",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-44207",
      "pattern": "[vulnerability:name = 'CVE-2021-44207']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--170da382-7c8a-4954-b642-f9bc2d70dfa2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-44228",
      "pattern": "[vulnerability:name = 'CVE-2021-44228']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "The persistent threat: Why major vulnerabilities like Log4Sh",
          "url": "https://snyk.io/blog/log4shell-spring4shell-threat/"
        },
        {
          "source_name": "CISA KEV: CVE-2021-45046 \u2014 Apache Log4j2 Deserialization of ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4969d09f-8f20-452d-b27a-2b4e02a55431",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: afdentry.workstation.eu.org",
      "pattern": "[domain-name:value = 'afdentry.workstation.eu.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--49bf0f19-ca64-43ec-b4e4-a091f26d7725",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cdn.ns.time12.cf",
      "pattern": "[domain-name:value = 'cdn.ns.time12.cf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7f06b0c9-c0f5-4026-b2bf-03eb6d29b0a6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: east.winsproxy.com",
      "pattern": "[domain-name:value = 'east.winsproxy.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9671a543-2410-44cd-ba62-37c7c16ad7d1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ns1.entrydns.eu.org",
      "pattern": "[domain-name:value = 'ns1.entrydns.eu.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--562c89bf-6331-42c6-b623-7a9c90315921",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: subnet.milli-seconds.com",
      "pattern": "[domain-name:value = 'subnet.milli-seconds.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1bb2cfc0-d4ae-4aad-8095-a92a175435e6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: work.queryip.cf",
      "pattern": "[domain-name:value = 'work.queryip.cf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8074c49c-62ee-4392-b2ab-25a1036483d8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: work.viewdns.ml",
      "pattern": "[domain-name:value = 'work.viewdns.ml']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8320c5ee-8c96-4edd-92e1-9b06f496600a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 107.172.210.69",
      "pattern": "[ipv4-addr:value = '107.172.210.69']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cdc06f08-0823-414b-b17b-2eccfe35e488",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 149.28.15.152",
      "pattern": "[ipv4-addr:value = '149.28.15.152']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3fcb3bbf-410d-4616-87b7-b5e57a9e8ea2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.104.206.48",
      "pattern": "[ipv4-addr:value = '172.104.206.48']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--31269f16-2dff-4c26-9282-72c4d5847bc2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 18.118.56.237",
      "pattern": "[ipv4-addr:value = '18.118.56.237']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2fb8ec3e-03e7-4de7-ac73-ff96c31267b8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.118.167.40",
      "pattern": "[ipv4-addr:value = '185.118.167.40']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2253b127-9e5e-4b95-a38a-c187b3c3cd20",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.156.98.12",
      "pattern": "[ipv4-addr:value = '194.156.98.12']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9cc7c24d-93d0-4c16-acad-d2c436507927",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.195.125.121",
      "pattern": "[ipv4-addr:value = '194.195.125.121']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9455a6a8-d8dd-4af7-afb4-ec0b70d7b92b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 20.121.42.11",
      "pattern": "[ipv4-addr:value = '20.121.42.11']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--21f16e6c-5f71-49ee-a3bd-d62d2a8462f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 34.139.13.46",
      "pattern": "[ipv4-addr:value = '34.139.13.46']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--41ffe7df-e426-45b1-8eab-bfbef6fb76d3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.153.231.31",
      "pattern": "[ipv4-addr:value = '45.153.231.31']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6b1123e0-de5c-4ff2-8e69-3c8222057a6c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.84.1.181",
      "pattern": "[ipv4-addr:value = '45.84.1.181']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bd66b12e-c836-46d7-a75f-df9a1babd0c6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 54.248.110.45",
      "pattern": "[ipv4-addr:value = '54.248.110.45']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d26373f-8fee-4cca-929c-4483d995961f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 54.80.67.241",
      "pattern": "[ipv4-addr:value = '54.80.67.241']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--42410f25-857d-4f1e-aabf-39d34d170e6c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 67.205.132.162",
      "pattern": "[ipv4-addr:value = '67.205.132.162']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8dd26293-da70-4c7f-9ae6-3b4fd12a8307",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 143278845a3f5276a1dd5860e7488313",
      "pattern": "[file:hashes.MD5 = '143278845a3f5276a1dd5860e7488313']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fd463a61-0af4-4af8-9c57-0212a4fc1a81",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 49f1daea8a115dd6fce51a1328d863cf",
      "pattern": "[file:hashes.MD5 = '49f1daea8a115dd6fce51a1328d863cf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c13ecf7-9b0e-461c-b77f-44deabe7c922",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 900ca3ee85dfc109baeed4888ccb5d39",
      "pattern": "[file:hashes.MD5 = '900ca3ee85dfc109baeed4888ccb5d39']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1dd0b2be-b28c-4dc2-8c56-5a9c916f0c1d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: b108b28138b93ec4822e165b82e41c7a",
      "pattern": "[file:hashes.MD5 = 'b108b28138b93ec4822e165b82e41c7a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--68557bd2-6fc8-4c6a-bcc8-e1d92dd1c5ff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: b82456963d04f44e83442b6393face47",
      "pattern": "[file:hashes.MD5 = 'b82456963d04f44e83442b6393face47']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d95e453f-805d-44a2-8b63-854633422261",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 355b3ff61db44d18003537be8496eb03536e300f",
      "pattern": "[file:hashes.'SHA-1' = '355b3ff61db44d18003537be8496eb03536e300f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8edb6e1e-094c-4d89-8d5d-b1a4b73a22c6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 6f6b51e6c88e5252a2a117ca1cfb57934930166b",
      "pattern": "[file:hashes.'SHA-1' = '6f6b51e6c88e5252a2a117ca1cfb57934930166b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f494ba21-a543-4252-80d9-171bc15bba79",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 7056b044f97e3e349e3e0183311bb44b0bc3464f",
      "pattern": "[file:hashes.'SHA-1' = '7056b044f97e3e349e3e0183311bb44b0bc3464f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5404c079-5ab0-4b76-bff7-a366412d2870",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 996aa691bbc1250b571a2f5423a5d5e2da8317e6",
      "pattern": "[file:hashes.'SHA-1' = '996aa691bbc1250b571a2f5423a5d5e2da8317e6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--595e663b-804c-4485-9256-344c891c7c06",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: e85427af661fe5e853c8c9398dc46ddde50e2241",
      "pattern": "[file:hashes.'SHA-1' = 'e85427af661fe5e853c8c9398dc46ddde50e2241']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--35a124a6-466d-4d09-9b13-fbf3c42cf8d0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 062a7399100454c7a523a938293bef7ddb0bc10636fd402be5f9797d8cc3c57e",
      "pattern": "[file:hashes.'SHA-256' = '062a7399100454c7a523a938293bef7ddb0bc10636fd402be5f9797d8cc3c57e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e887111b-5904-4159-bc11-b9c5815389e9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a4647fcb35c79f26354c34452e4a03a1e4e338a80b2c29db97bba4088a208ad0",
      "pattern": "[file:hashes.'SHA-256' = 'a4647fcb35c79f26354c34452e4a03a1e4e338a80b2c29db97bba4088a208ad0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4fe3d026-9c76-4be1-b957-c12c0235e2cd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d7e8cc6c19ceebf0e125c9f18b50167c0ee65294b3fce179fdab560e3e8e0192",
      "pattern": "[file:hashes.'SHA-256' = 'd7e8cc6c19ceebf0e125c9f18b50167c0ee65294b3fce179fdab560e3e8e0192']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--94495069-c359-43ff-8cca-bb19bd5a7fad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e024ccc4c72eb5813cc2b6db7975e4750337a1cc619d7339b21fdbb32d93fd85",
      "pattern": "[file:hashes.'SHA-256' = 'e024ccc4c72eb5813cc2b6db7975e4750337a1cc619d7339b21fdbb32d93fd85']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--75f9ebad-1d54-41aa-bd22-9cc82521700e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ebf28e56ae5873102b51da2cc49cbbe43192ca2f318c4dfc874448d9b85ebd00",
      "pattern": "[file:hashes.'SHA-256' = 'ebf28e56ae5873102b51da2cc49cbbe43192ca2f318c4dfc874448d9b85ebd00']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of H",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e066452-17c9-4fa7-bbf0-97c8f2f86fc8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2011-5325",
      "pattern": "[vulnerability:name = 'CVE-2011-5325']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-23227 \u2014 NUUO NVRmini2 Devices Missing Aut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8fe47452-5204-46ef-a838-e370f343c7d5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-14933",
      "pattern": "[vulnerability:name = 'CVE-2018-14933']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-14933 \u2014 NUUO NVRmini Devices OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e114a812-da04-4af6-b04a-49d667625e25",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-11001",
      "pattern": "[vulnerability:name = 'CVE-2019-11001']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11001 \u2014 Reolink Multiple IP Cameras OS Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--abf3fd13-bf35-46b2-a0d3-eb4381468793",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-40407",
      "pattern": "[vulnerability:name = 'CVE-2021-40407']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-40407 \u2014 Reolink RLC-410W IP Camera OS Com",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aa7b9dc8-1fc2-41e2-8f65-a6b9b95524dd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-23227",
      "pattern": "[vulnerability:name = 'CVE-2022-23227']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-23227 \u2014 NUUO NVRmini2 Devices Missing Aut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67101cae-d16b-4a70-a7e2-80fca7bc50a5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-50623",
      "pattern": "[vulnerability:name = 'CVE-2024-50623']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestrict",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--60ec785e-f8f3-42e2-a075-bd3c9e344f65",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-55956",
      "pattern": "[vulnerability:name = 'CVE-2024-55956']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestrict",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--23a9ea97-7dae-4a42-ab52-8558edf6f387",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 176.123.10.115",
      "pattern": "[ipv4-addr:value = '176.123.10.115']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestrict",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--676cd6d1-828a-46c5-87e1-8a8f9ed40b4c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 176.123.5.126",
      "pattern": "[ipv4-addr:value = '176.123.5.126']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestrict",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--be3c3a66-5c79-42ff-abfb-ba13b0586062",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 181.214.147.164",
      "pattern": "[ipv4-addr:value = '181.214.147.164']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestrict",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b04d0807-d6ad-4763-bd65-873a00f10ba4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.162.128.133",
      "pattern": "[ipv4-addr:value = '185.162.128.133']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestrict",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5cf1b743-9e10-44ed-8435-aee637bb1083",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.163.204.137",
      "pattern": "[ipv4-addr:value = '185.163.204.137']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestrict",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ebb3c5d2-a5ee-4f32-a16c-523dd1de0a2b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.181.230.103",
      "pattern": "[ipv4-addr:value = '185.181.230.103']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestrict",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--49d47238-fab9-4368-8e96-15411ce2b0ca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.119.99.42",
      "pattern": "[ipv4-addr:value = '192.119.99.42']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestrict",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--57ecf8f1-060c-4064-9e8f-121eac9bca1d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 209.127.12.38",
      "pattern": "[ipv4-addr:value = '209.127.12.38']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestrict",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--63c7f652-0129-48b6-873e-e77b70b4a0f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.182.189.102",
      "pattern": "[ipv4-addr:value = '45.182.189.102']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestrict",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c300080c-f6fd-4869-aaa7-81c46fb38148",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.149.249.226",
      "pattern": "[ipv4-addr:value = '5.149.249.226']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestrict",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--34125511-2815-482b-95ed-8f5d3a1cc379",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 89.248.172.139",
      "pattern": "[ipv4-addr:value = '89.248.172.139']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestrict",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--12c3b590-28a0-449e-9888-b46ada126ba6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-26347",
      "pattern": "[vulnerability:name = 'CVE-2023-26347']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3e44ff84-ff02-4e5a-93be-a712724cf7b7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-26359",
      "pattern": "[vulnerability:name = 'CVE-2023-26359']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-26359 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--59a787b3-59f3-4435-87c3-983f2e40feee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-29298",
      "pattern": "[vulnerability:name = 'CVE-2023-29298']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-29300 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--14de0203-2f23-46a0-9fc3-be6a90e14176",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-29300",
      "pattern": "[vulnerability:name = 'CVE-2023-29300']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-29300 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5b283074-5e5b-45af-94a8-ae127d5647ce",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-38203",
      "pattern": "[vulnerability:name = 'CVE-2023-38203']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-29300 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0cefc865-9f51-4db3-8a20-894708dda98e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-38204",
      "pattern": "[vulnerability:name = 'CVE-2023-38204']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f15bc6f-bdcd-40be-96f8-4b375de2df55",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-38205",
      "pattern": "[vulnerability:name = 'CVE-2023-38205']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-38205 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc2bac97-39b6-4561-84b1-b80908fd8e16",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-44352",
      "pattern": "[vulnerability:name = 'CVE-2023-44352']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0062e9d9-3206-4518-a1de-8aad6dafb298",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-44353",
      "pattern": "[vulnerability:name = 'CVE-2023-44353']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--72609168-0528-43a9-97fe-a76ef175f3c7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-20767",
      "pattern": "[vulnerability:name = 'CVE-2024-20767']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ecef69a5-7fac-45a5-bd9e-60e5429cf77e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-35250",
      "pattern": "[vulnerability:name = 'CVE-2024-35250']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-35250 \u2014 Microsoft Windows Kernel-Mode Dri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--37aeea52-f510-45b2-8249-f745cb91f7b9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: oast.fun",
      "pattern": "[domain-name:value = 'oast.fun']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b00ab619-5ebb-4119-b111-117c92be8b71",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: oast.live",
      "pattern": "[domain-name:value = 'oast.live']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a4d29556-a296-41ba-bc89-de3f7d818132",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: oast.me",
      "pattern": "[domain-name:value = 'oast.me']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ef09be1-d9b5-4aa9-b450-df80de7a265a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: oast.online",
      "pattern": "[domain-name:value = 'oast.online']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--61956598-bdf2-4f49-b859-2dbcac850814",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: oast.pro",
      "pattern": "[domain-name:value = 'oast.pro']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--36465edd-c08f-42bb-8b58-4219803af53e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: oast.site",
      "pattern": "[domain-name:value = 'oast.site']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--afa5fee6-a4b6-44c2-aac6-00cdb40a7024",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 134.122.136.119",
      "pattern": "[ipv4-addr:value = '134.122.136.119']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6517c523-fa26-4fe6-975e-3ab17b957af8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 134.122.136.96",
      "pattern": "[ipv4-addr:value = '134.122.136.96']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--086616fe-0fbe-4b7d-b42b-de3c3d16ab1c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.81.132.99",
      "pattern": "[ipv4-addr:value = '172.81.132.99']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8878e84d-744f-45e6-855a-331b29d652c6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.234.85.20",
      "pattern": "[ipv4-addr:value = '23.234.85.20']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--88021b0c-0b08-4676-a041-1ed9705503ac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.225.206.87",
      "pattern": "[ipv4-addr:value = '38.225.206.87']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--78df4411-9178-4d46-8a6f-93b234e2a4be",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.225.206.88",
      "pattern": "[ipv4-addr:value = '38.225.206.88']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c3d35a32-f80e-4576-ac64-7710c677b142",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: connect.consrensys.com",
      "pattern": "[domain-name:value = 'connect.consrensys.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Ultralytics AI Pwn Request Supply Chain Attack",
          "url": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7bf6f6e4-282c-47ca-b21b-f15a517ce4a4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: webhook.site/1e6c12e8-aaeb-4349-98ad-a7196e632c5a",
      "pattern": "[domain-name:value = 'webhook.site/1e6c12e8-aaeb-4349-98ad-a7196e632c5a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Ultralytics AI Pwn Request Supply Chain Attack",
          "url": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--39b36a3d-9421-4501-a87b-5f5eb5a1c74a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: webhook.site/ecd706a0-f207-4df2-b639-d326ef3c2fe1",
      "pattern": "[domain-name:value = 'webhook.site/ecd706a0-f207-4df2-b639-d326ef3c2fe1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Ultralytics AI Pwn Request Supply Chain Attack",
          "url": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2bc21bc3-890e-4ca7-a8a0-67f67a1c0c45",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 059beed5bcdfea16c05b4d45560c97abfd4af3de",
      "pattern": "[file:hashes.'SHA-1' = '059beed5bcdfea16c05b4d45560c97abfd4af3de']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Ultralytics AI Pwn Request Supply Chain Attack",
          "url": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e3b86e0a-e233-414d-9cb1-88c678385e7a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 62b6532384bdd9b96af5ac684d87f52efb48f7de",
      "pattern": "[file:hashes.'SHA-1' = '62b6532384bdd9b96af5ac684d87f52efb48f7de']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Ultralytics AI Pwn Request Supply Chain Attack",
          "url": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff8943af-1d39-41d8-8bd7-fba2461d7f47",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 7c6136cf4e857582c2f086673359be94e7e4b702",
      "pattern": "[file:hashes.'SHA-1' = '7c6136cf4e857582c2f086673359be94e7e4b702']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Ultralytics AI Pwn Request Supply Chain Attack",
          "url": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--59242e4d-3268-455b-b077-b0b2eaad506c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 96f496ac5c64f3c884676dd99d6edbe7fa596255",
      "pattern": "[file:hashes.'SHA-1' = '96f496ac5c64f3c884676dd99d6edbe7fa596255']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Ultralytics AI Pwn Request Supply Chain Attack",
          "url": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e1d7abf8-0f59-4c08-bcc4-f1484e6de558",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: a1f1e3ede7c7e6ae650a294630214ce7fa596255",
      "pattern": "[file:hashes.'SHA-1' = 'a1f1e3ede7c7e6ae650a294630214ce7fa596255']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Ultralytics AI Pwn Request Supply Chain Attack",
          "url": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--07488a5a-1f05-4c42-8fb6-97a22517d9fd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: bea3060707e6f3fec47aa2af64ea2e774b56e9f5",
      "pattern": "[file:hashes.'SHA-1' = 'bea3060707e6f3fec47aa2af64ea2e774b56e9f5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Ultralytics AI Pwn Request Supply Chain Attack",
          "url": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dda8f0f7-fd3a-4535-b860-8bb262b125dc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: dd0577b10e73792f2b2315af63b872fe4123ec9c",
      "pattern": "[file:hashes.'SHA-1' = 'dd0577b10e73792f2b2315af63b872fe4123ec9c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Ultralytics AI Pwn Request Supply Chain Attack",
          "url": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff189020-147d-4ef5-aea6-b695c6d8803c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: ee304a92a9e68e7923d7a37a370c7556ac596250",
      "pattern": "[file:hashes.'SHA-1' = 'ee304a92a9e68e7923d7a37a370c7556ac596250']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Ultralytics AI Pwn Request Supply Chain Attack",
          "url": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67775223-7454-4222-9042-c398cc9c93ef",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 15bcffd83cda47082acb081eaf7270a38c497b3a2bc6e917582bda8a5b0f7bab",
      "pattern": "[file:hashes.'SHA-256' = '15bcffd83cda47082acb081eaf7270a38c497b3a2bc6e917582bda8a5b0f7bab']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Ultralytics AI Pwn Request Supply Chain Attack",
          "url": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32962806-3cd7-4d5e-8521-0732bef6eb32",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4347625838a5cb0e9d29f3ec76ed8365b31b281103b716952bf64d37cf309785",
      "pattern": "[file:hashes.'SHA-256' = '4347625838a5cb0e9d29f3ec76ed8365b31b281103b716952bf64d37cf309785']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Ultralytics AI Pwn Request Supply Chain Attack",
          "url": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--db3e9d05-dfcd-4346-a08d-7a92af814be5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6a9d121f538cad60cabd9369a951ec4405a081c664311a90537f0a7a61b0f3e5",
      "pattern": "[file:hashes.'SHA-256' = '6a9d121f538cad60cabd9369a951ec4405a081c664311a90537f0a7a61b0f3e5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Ultralytics AI Pwn Request Supply Chain Attack",
          "url": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b2067481-2539-4909-a2fd-74623d1f5e58",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b0e1ae6d73d656b203514f498b59cbcf29f067edf6fbd3803a3de7d21960848d",
      "pattern": "[file:hashes.'SHA-256' = 'b0e1ae6d73d656b203514f498b59cbcf29f067edf6fbd3803a3de7d21960848d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Ultralytics AI Pwn Request Supply Chain Attack",
          "url": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--31f1a241-01ec-4b0d-912f-3f571a6ac136",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b6ea1681855ec2f73c643ea2acfcf7ae084a9648f888d4bd1e3e119ec15c3495",
      "pattern": "[file:hashes.'SHA-256' = 'b6ea1681855ec2f73c643ea2acfcf7ae084a9648f888d4bd1e3e119ec15c3495']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Ultralytics AI Pwn Request Supply Chain Attack",
          "url": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--af9e135f-6981-42ad-8847-b1ed5f2fa36c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c9c3401536fd9a0b6012aec9169d2c1fc1368b7073503384cfc0b38c47b1d7e1",
      "pattern": "[file:hashes.'SHA-256' = 'c9c3401536fd9a0b6012aec9169d2c1fc1368b7073503384cfc0b38c47b1d7e1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Ultralytics AI Pwn Request Supply Chain Attack",
          "url": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--02bc1969-2244-4498-8ab0-022046717852",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e9d538203ac43e9df11b68803470c116b7bb02881cd06175b0edfc4438d4d1a2",
      "pattern": "[file:hashes.'SHA-256' = 'e9d538203ac43e9df11b68803470c116b7bb02881cd06175b0edfc4438d4d1a2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Ultralytics AI Pwn Request Supply Chain Attack",
          "url": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--10b54235-2a84-4eef-9271-b3664144b528",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ec12cd32729e8abea5258478731e70ccc5a7c6c4847dde78488b8dd0b91b8555",
      "pattern": "[file:hashes.'SHA-256' = 'ec12cd32729e8abea5258478731e70ccc5a7c6c4847dde78488b8dd0b91b8555']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Ultralytics AI Pwn Request Supply Chain Attack",
          "url": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dff7c661-04d7-4bef-9030-05d0c09432ad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f08d47cb3e1e848b5607ac44baedf1754b201b6b90dfc527d6cefab1dd2d2c23",
      "pattern": "[file:hashes.'SHA-256' = 'f08d47cb3e1e848b5607ac44baedf1754b201b6b90dfc527d6cefab1dd2d2c23']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Ultralytics AI Pwn Request Supply Chain Attack",
          "url": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3cc497ac-2c71-439e-88a0-b13097a365c1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-49138",
      "pattern": "[vulnerability:name = 'CVE-2024-49138']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49138 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3ac7c488-9d35-404f-995d-31663f12e2dc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-51378",
      "pattern": "[vulnerability:name = 'CVE-2024-51378']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-51378 \u2014 CyberPanel Incorrect Default Perm",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-51567 \u2014 CyberPanel Incorrect Default Perm",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d173a926-8b27-40f3-bc1a-1310dc69d003",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-28461",
      "pattern": "[vulnerability:name = 'CVE-2023-28461']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-45727 \u2014 North Grid Proself Improper Restr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-28461 \u2014 Array Networks AG and vxAG ArrayO",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--195f7d54-b346-40ea-83dd-af35b7676335",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-45727",
      "pattern": "[vulnerability:name = 'CVE-2023-45727']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-45727 \u2014 North Grid Proself Improper Restr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a7b2b6de-b622-4ca9-a930-066a09ae5b62",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-11667",
      "pattern": "[vulnerability:name = 'CVE-2024-11667']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Tra",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9e1d796c-6f6b-4a8f-b9a8-8dddb3290da7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-11680",
      "pattern": "[vulnerability:name = 'CVE-2024-11680']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11680 \u2014 ProjectSend Improper Authenticati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3a664dc7-3075-4c24-8f66-0bfefd7e82ae",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-42057",
      "pattern": "[vulnerability:name = 'CVE-2024-42057']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Tra",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--43761857-80bd-4203-8f87-ef9975d352e5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 0bfe25de8c46834e9a7c216f99057d855e272eafafdfef98a6012cecbbdcfabf",
      "pattern": "[file:hashes.'SHA-256' = '0bfe25de8c46834e9a7c216f99057d855e272eafafdfef98a6012cecbbdcfabf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Tra",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--286405fd-cd62-4dbd-9d3e-63f6c2d1fb7d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2621c5c7e1c12560c6062fdf2eeeb815de4ce3856376022a1a9f8421b4bae8e1",
      "pattern": "[file:hashes.'SHA-256' = '2621c5c7e1c12560c6062fdf2eeeb815de4ce3856376022a1a9f8421b4bae8e1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Tra",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dee09cd9-4781-4bcb-8310-a785caaa2c06",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2b15e09b98bc2835a4430c4560d3f5b25011141c9efa4331f66e9a707e2a23c0",
      "pattern": "[file:hashes.'SHA-256' = '2b15e09b98bc2835a4430c4560d3f5b25011141c9efa4331f66e9a707e2a23c0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Tra",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bf56f283-eda3-4034-b01e-ee426001f3a5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3e3fad9888856ce195c9c239ad014074f687ba288c78ef26660be93ddd97289e",
      "pattern": "[file:hashes.'SHA-256' = '3e3fad9888856ce195c9c239ad014074f687ba288c78ef26660be93ddd97289e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Tra",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0aa0f93d-26f3-4fe3-b0a6-398122f6241c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 47635e2cf9d41cab4b73f2a37e6a59a7de29428b75a7b4481205aee4330d4d19",
      "pattern": "[file:hashes.'SHA-256' = '47635e2cf9d41cab4b73f2a37e6a59a7de29428b75a7b4481205aee4330d4d19']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Tra",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--48f06673-00a8-439e-bdba-f0180bcfae0b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 67aea3de7ab23b72e02347cbf6514f28fb726d313e62934b5de6d154215ee733",
      "pattern": "[file:hashes.'SHA-256' = '67aea3de7ab23b72e02347cbf6514f28fb726d313e62934b5de6d154215ee733']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Tra",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a72c9a6d-9246-4eeb-ba10-d243dcc91483",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6ef9a0b6301d737763f6c59ae6d5b3be4cf38941a69517be0f069d0a35f394dd",
      "pattern": "[file:hashes.'SHA-256' = '6ef9a0b6301d737763f6c59ae6d5b3be4cf38941a69517be0f069d0a35f394dd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Tra",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a64a74f-4314-4e76-b0ab-c16d21d0cada",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7731d73e048a351205615821b90ed4f2507abc65acf4d6fe30ecdb211f0b0872",
      "pattern": "[file:hashes.'SHA-256' = '7731d73e048a351205615821b90ed4f2507abc65acf4d6fe30ecdb211f0b0872']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Tra",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d757402a-06d9-4f0e-95b7-15a639a72919",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7cd7c04c62d2a8b4697ceebbe7dd95c910d687e4a6989c1d839117e55c1cafd7",
      "pattern": "[file:hashes.'SHA-256' = '7cd7c04c62d2a8b4697ceebbe7dd95c910d687e4a6989c1d839117e55c1cafd7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Tra",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f78b4d3-031f-4c6a-8983-8d4c16de86dd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9ab19741ac36e198fb2fd912620bf320aa7fdeeeb8d4a9e956f3eb3d2092c92c",
      "pattern": "[file:hashes.'SHA-256' = '9ab19741ac36e198fb2fd912620bf320aa7fdeeeb8d4a9e956f3eb3d2092c92c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Tra",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f5a75e1b-dc03-4862-bde0-5e1cc2166c93",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: cb48e4298b216ae532cfd3c89c8f2cbd1e32bb402866d2c81682c6671aa4f8ea",
      "pattern": "[file:hashes.'SHA-256' = 'cb48e4298b216ae532cfd3c89c8f2cbd1e32bb402866d2c81682c6671aa4f8ea']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Tra",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--01c45000-9ce2-44ac-8e0c-9ba740039fb4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ccd78d3eba6c53959835c6407d81262d3094e8d06bf2712fefa4b04baadd4bfe",
      "pattern": "[file:hashes.'SHA-256' = 'ccd78d3eba6c53959835c6407d81262d3094e8d06bf2712fefa4b04baadd4bfe']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Tra",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--25e09fc1-d4ab-463b-8aad-f511abafa80b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-21287",
      "pattern": "[vulnerability:name = 'CVE-2024-21287']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-21287 \u2014 Oracle Agile Product Lifecycle Ma",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9723a949-9ed4-4aa7-b847-99e490f2f209",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-44308",
      "pattern": "[vulnerability:name = 'CVE-2024-44308']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-44309 \u2014 Apple Multiple Products Cross-Sit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-44308 \u2014 Apple Multiple Products Code Exec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c8a0468-8548-44a8-915b-467090409e71",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-44309",
      "pattern": "[vulnerability:name = 'CVE-2024-44309']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-44309 \u2014 Apple Multiple Products Cross-Sit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-44308 \u2014 Apple Multiple Products Code Exec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76804cca-5728-4cce-a562-8657f8f8fd73",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-38812",
      "pattern": "[vulnerability:name = 'CVE-2024-38812']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38813 \u2014 VMware vCenter Server Privilege E",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-38812 \u2014 VMware vCenter Server Heap-Based ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--730775c3-5076-4971-9784-9b0b89dbf389",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-38813",
      "pattern": "[vulnerability:name = 'CVE-2024-38813']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38813 \u2014 VMware vCenter Server Privilege E",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e566c040-b44b-4a3f-ac6c-82389e3edd09",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-0012",
      "pattern": "[vulnerability:name = 'CVE-2024-0012']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--74a2737c-3308-4f20-94aa-b49b633f83ba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-1212",
      "pattern": "[vulnerability:name = 'CVE-2024-1212']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1212 \u2014 Progress Kemp LoadMaster OS Comman",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ae9697cf-a373-4483-b629-fa56d0f9d6fb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.112.106.17",
      "pattern": "[ipv4-addr:value = '103.112.106.17']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f5d044ed-ffc8-4760-a637-c6585f94182b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.28.208.123",
      "pattern": "[ipv4-addr:value = '104.28.208.123']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ffcbd6ba-5850-49e6-b1dd-6149ed56ef61",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.28.240.123",
      "pattern": "[ipv4-addr:value = '104.28.240.123']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--655d41cd-4a64-40d4-a91f-d75897e994b7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 136.144.17.146",
      "pattern": "[ipv4-addr:value = '136.144.17.146']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b321f23a-5fa7-4a8a-a26d-42fb8121144e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 136.144.17.149",
      "pattern": "[ipv4-addr:value = '136.144.17.149']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1a7de027-cd02-4190-9132-b1f13d46553f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 136.144.17.154",
      "pattern": "[ipv4-addr:value = '136.144.17.154']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0636b5d3-7103-4dca-a3b5-c3d4278a60ca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 136.144.17.158",
      "pattern": "[ipv4-addr:value = '136.144.17.158']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67972b47-b37b-4eca-8275-f07f097916d0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 136.144.17.161",
      "pattern": "[ipv4-addr:value = '136.144.17.161']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ac5a15bd-2c9e-4e03-9d02-4026dbced23a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 136.144.17.164",
      "pattern": "[ipv4-addr:value = '136.144.17.164']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4e140a3-b339-4c18-82f4-76c84aa99ab6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 136.144.17.166",
      "pattern": "[ipv4-addr:value = '136.144.17.166']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--94697f2d-b7ee-4f57-99bd-67697147e222",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 136.144.17.167",
      "pattern": "[ipv4-addr:value = '136.144.17.167']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87768c20-535b-4bd2-b8e9-88cc7cfd64bd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 136.144.17.170",
      "pattern": "[ipv4-addr:value = '136.144.17.170']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--901d1662-16a5-4d91-ba02-faa105fc9d93",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 136.144.17.176",
      "pattern": "[ipv4-addr:value = '136.144.17.176']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aa83b33a-d233-4b00-8909-d82aadadd407",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 136.144.17.177",
      "pattern": "[ipv4-addr:value = '136.144.17.177']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1cd47ef2-95a0-4c75-940a-e967943d32e1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 136.144.17.178",
      "pattern": "[ipv4-addr:value = '136.144.17.178']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7f4640fd-6ad9-4ff6-913d-f69498acf646",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 136.144.17.180",
      "pattern": "[ipv4-addr:value = '136.144.17.180']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc820f62-8e7a-429f-822d-ff4c40f05d24",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 15.235.189.144",
      "pattern": "[ipv4-addr:value = '15.235.189.144']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6a2fd5bc-2e76-4d3c-a822-f6f16ba706ed",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 15.235.189.145",
      "pattern": "[ipv4-addr:value = '15.235.189.145']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--099499c3-c99e-422b-bcc3-194b70344938",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 15.235.189.146",
      "pattern": "[ipv4-addr:value = '15.235.189.146']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5de62347-17fc-44e6-ae3f-2f4c0ca4e772",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 15.235.189.147",
      "pattern": "[ipv4-addr:value = '15.235.189.147']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5bb8b88f-1177-4b3d-b689-1323746d1a1c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 15.235.189.148",
      "pattern": "[ipv4-addr:value = '15.235.189.148']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c45d9b3b-850e-4c15-9efc-7bf243e1a079",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 15.235.189.149",
      "pattern": "[ipv4-addr:value = '15.235.189.149']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cfe56b4a-51eb-485c-bab8-ea9e44455279",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 15.235.189.150",
      "pattern": "[ipv4-addr:value = '15.235.189.150']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2c97e803-4ee9-4354-83a5-96b80b701dd3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 173.239.218.248",
      "pattern": "[ipv4-addr:value = '173.239.218.248']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cd55195a-0497-4faf-87dc-a0159fe020c7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 173.239.218.251",
      "pattern": "[ipv4-addr:value = '173.239.218.251']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a437b4ff-3554-4ead-90f1-fed3e95388c4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 182.78.17.137",
      "pattern": "[ipv4-addr:value = '182.78.17.137']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f81a83b9-0ecd-45c7-943b-362347f36d47",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 209.200.246.173",
      "pattern": "[ipv4-addr:value = '209.200.246.173']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--502d514b-c2c7-42a0-a512-bb0728c221a6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 209.200.246.184",
      "pattern": "[ipv4-addr:value = '209.200.246.184']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c8d85b4c-a1fa-44e6-976f-7e5c56db4ec0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 216.73.160.186",
      "pattern": "[ipv4-addr:value = '216.73.160.186']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2f782813-1f78-4ba3-b546-52b002572449",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 216.73.162.69",
      "pattern": "[ipv4-addr:value = '216.73.162.69']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f7ed6b0-6e7e-4be3-bac7-daa75b1787c5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 216.73.162.71",
      "pattern": "[ipv4-addr:value = '216.73.162.71']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--426d5bb9-4fb3-4683-9e11-c3850fb2e6aa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 216.73.162.73",
      "pattern": "[ipv4-addr:value = '216.73.162.73']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3ad39b34-f955-47bf-bb9b-dea38ddd4267",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 216.73.162.74",
      "pattern": "[ipv4-addr:value = '216.73.162.74']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76599eb0-4f2a-48e2-8af2-4df831f59c23",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.32.110.123",
      "pattern": "[ipv4-addr:value = '45.32.110.123']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0470078a-b885-4aa1-a4d9-aa91dbe33803",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 91.208.197.167",
      "pattern": "[ipv4-addr:value = '91.208.197.167']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--effb24c5-8f00-4fcb-ac8d-27de8d4211e9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3c5f9034c86cb1952aa5bb07b4f77ce7d8bb5cc9fe5c029a32c72adc7e814668",
      "pattern": "[file:hashes.'SHA-256' = '3c5f9034c86cb1952aa5bb07b4f77ce7d8bb5cc9fe5c029a32c72adc7e814668']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--849ddfa9-8c6e-4fe0-9d4f-9e1785aeb0c6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-5910",
      "pattern": "[vulnerability:name = 'CVE-2024-5910']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9465 \u2014 Palo Alto Networks Expedition SQL ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-5910 \u2014 Palo Alto Networks Expedition Miss",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--636a7270-5dd7-4d89-bdc2-fb3ee385a83b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-9463",
      "pattern": "[vulnerability:name = 'CVE-2024-9463']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9465 \u2014 Palo Alto Networks Expedition SQL ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9463 \u2014 Palo Alto Networks Expedition OS C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e6829eca-8e16-41b4-b2ff-753541ae224d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-9464",
      "pattern": "[vulnerability:name = 'CVE-2024-9464']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9465 \u2014 Palo Alto Networks Expedition SQL ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-5910 \u2014 Palo Alto Networks Expedition Miss",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6d074fc-2c53-4518-a55e-818f1fe80983",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-9465",
      "pattern": "[vulnerability:name = 'CVE-2024-9465']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9465 \u2014 Palo Alto Networks Expedition SQL ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-5910 \u2014 Palo Alto Networks Expedition Miss",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7967d777-a431-42a8-9f7c-429a943f12f9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-9466",
      "pattern": "[vulnerability:name = 'CVE-2024-9466']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9465 \u2014 Palo Alto Networks Expedition SQL ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-5910 \u2014 Palo Alto Networks Expedition Miss",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff34d8ed-1b98-4489-9cab-57e332b8ac58",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-9467",
      "pattern": "[vulnerability:name = 'CVE-2024-9467']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9465 \u2014 Palo Alto Networks Expedition SQL ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fc01e401-2508-4e8a-a9cf-d175fbbef955",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-2120",
      "pattern": "[vulnerability:name = 'CVE-2014-2120']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-2120 \u2014 Cisco Adaptive Security Appliance ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0cb09477-3352-4693-b464-b0ec7da38aac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-26086",
      "pattern": "[vulnerability:name = 'CVE-2021-26086']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26086 \u2014 Atlassian Jira Server and Data Ce",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c2658f9a-f009-4700-87e3-adc41296c534",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-41277",
      "pattern": "[vulnerability:name = 'CVE-2021-41277']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-41277 \u2014 Metabase GeoJSON API Local File I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f2749774-00c6-4f6b-8d8b-f19f07edf25b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-49039",
      "pattern": "[vulnerability:name = 'CVE-2024-49039']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f415e71f-66f8-4709-8699-f8d0b700ca95",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-9680",
      "pattern": "[vulnerability:name = 'CVE-2024-9680']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6f885c36-f010-4463-9c1d-d3445b0efc4b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: 1drv.us.com",
      "pattern": "[domain-name:value = '1drv.us.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--93add361-eb9b-4dea-9fbc-1fcb1a021a09",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: correctiv.sbs",
      "pattern": "[domain-name:value = 'correctiv.sbs']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0e3472e-0099-431f-b2a0-390e42453ad7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cwise.store",
      "pattern": "[domain-name:value = 'cwise.store']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff7ac555-3dd5-44ac-97f3-5fb6322a387a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: devolredir.com",
      "pattern": "[domain-name:value = 'devolredir.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd4f84a5-8af0-4582-8e7a-10ba20ff1687",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: doc.osvita-kp.gov.ua",
      "pattern": "[domain-name:value = 'doc.osvita-kp.gov.ua']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-43451 \u2014 Microsoft Windows NTLMv2 Hash Dis",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--82f23036-632b-41a4-bed8-2822e8b193f8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: economistjournal.cloud",
      "pattern": "[domain-name:value = 'economistjournal.cloud']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9eded91f-a770-4767-a134-f9304fa836e6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: journalctd.live",
      "pattern": "[domain-name:value = 'journalctd.live']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--90393d03-0a79-4bc0-a6a8-ad7b982c7cf3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: osvita-kp.gov.ua",
      "pattern": "[domain-name:value = 'osvita-kp.gov.ua']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-43451 \u2014 Microsoft Windows NTLMv2 Hash Dis",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cc276949-13c0-471e-a338-2d4ebc3e4858",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: redirconnectwise.cloud",
      "pattern": "[domain-name:value = 'redirconnectwise.cloud']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b41cb27b-e63c-4952-a39c-11337967a860",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: redircorrectiv.com",
      "pattern": "[domain-name:value = 'redircorrectiv.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--08cb3cbb-99fe-4833-a11a-209e671678c1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: redjournal.cloud",
      "pattern": "[domain-name:value = 'redjournal.cloud']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5907c01c-044b-49e9-bb58-6a81631827a0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 147.45.78.102",
      "pattern": "[ipv4-addr:value = '147.45.78.102']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0a21fe3e-5a7c-4b0e-a3d0-6f4b5e54b651",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 176.124.206.88",
      "pattern": "[ipv4-addr:value = '176.124.206.88']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b03a53bc-c73d-43ba-a4d2-2b781b282abd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 178.236.246.241",
      "pattern": "[ipv4-addr:value = '178.236.246.241']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7bda360e-dd9f-4d3f-8b6f-6f432f0bf005",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.87.189.171",
      "pattern": "[ipv4-addr:value = '194.87.189.171']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff7ff02a-bf82-4bb4-8d97-ed7c80a2f6ab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.87.189.19",
      "pattern": "[ipv4-addr:value = '194.87.189.19']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b3eaab66-9b8c-4322-8d3d-a61ee11a6a16",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.138.74.238",
      "pattern": "[ipv4-addr:value = '45.138.74.238']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1490d55e-9151-47b2-8580-1352ab305c9a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 46.226.163.67",
      "pattern": "[ipv4-addr:value = '46.226.163.67']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0705b18a-790f-4629-91a5-8dc8d4d71193",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 62.60.237.116",
      "pattern": "[ipv4-addr:value = '62.60.237.116']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--80782175-8fba-4a85-b9b7-f0935d2ac70e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 62.60.237.38",
      "pattern": "[ipv4-addr:value = '62.60.237.38']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--160be3b3-d8f8-4f27-b772-0052489dfc6b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 62.60.238.81",
      "pattern": "[ipv4-addr:value = '62.60.238.81']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c0d2bb8-25c1-410e-9f4f-59812b4eb9d6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 92.42.96.30",
      "pattern": "[ipv4-addr:value = '92.42.96.30']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-43451 \u2014 Microsoft Windows NTLMv2 Hash Dis",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f7c0d148-d039-4c52-a5a7-91198f185183",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 21918cfd17b378eb4152910f1246d2446f9b5b11",
      "pattern": "[file:hashes.'SHA-1' = '21918cfd17b378eb4152910f1246d2446f9b5b11']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--34fca1ce-b7d9-47c0-bcf3-e765e2cedc03",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 703a25f053e356eb6ece4d16a048344c55dc89fd",
      "pattern": "[file:hashes.'SHA-1' = '703a25f053e356eb6ece4d16a048344c55dc89fd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9ccda30d-e734-4581-bb28-ccae9479d616",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: a4aad0e2ac1ee0c8dd25968fa4631805689757b6",
      "pattern": "[file:hashes.'SHA-1' = 'a4aad0e2ac1ee0c8dd25968fa4631805689757b6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ad41a98c-b64f-4bb9-9eee-631577165c37",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: a9d445b77f6f4e90c29e385264d4b1b95947add5",
      "pattern": "[file:hashes.'SHA-1' = 'a9d445b77f6f4e90c29e385264d4b1b95947add5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b639575d-9842-4bf3-9c1e-b953101b3065",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: abb54c4751f97a9fc1c9598fed1ec9fb9e6b1db6",
      "pattern": "[file:hashes.'SHA-1' = 'abb54c4751f97a9fc1c9598fed1ec9fb9e6b1db6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--913cf8bd-01cf-447b-96ab-8d3554dc4a44",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: ca6f8966a3b2640f49b19434ba8c21832e77a031",
      "pattern": "[file:hashes.'SHA-1' = 'ca6f8966a3b2640f49b19434ba8c21832e77a031']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--61a410df-2440-4335-9e87-43ac48dd4b52",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-16278",
      "pattern": "[vulnerability:name = 'CVE-2019-16278']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16278 \u2014 Nostromo nhttpd Directory Travers",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3de9da66-642b-4fe3-b4c1-8d02a3f2e136",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-43093",
      "pattern": "[vulnerability:name = 'CVE-2024-43093']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-43093 \u2014 Android Framework Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b26c0178-ff22-4d2d-8106-de6cd12731e2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-51567",
      "pattern": "[vulnerability:name = 'CVE-2024-51567']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-51567 \u2014 CyberPanel Incorrect Default Perm",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a510ecde-8a5f-41e0-a514-a93d572334fb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-51568",
      "pattern": "[vulnerability:name = 'CVE-2024-51568']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-51567 \u2014 CyberPanel Incorrect Default Perm",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--72ec2ece-496e-4d99-9fe5-f8134b6b3634",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-8956",
      "pattern": "[vulnerability:name = 'CVE-2024-8956']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-8956 \u2014 PTZOptics PT30X-SDI/NDI Cameras Au",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a9850a49-bc9c-4066-9872-66d2d5a2579a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-8957",
      "pattern": "[vulnerability:name = 'CVE-2024-8957']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-8956 \u2014 PTZOptics PT30X-SDI/NDI Cameras Au",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--48a8f1b4-d002-47f6-9f48-d9ee0c7531c6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 209.141.35.56",
      "pattern": "[ipv4-addr:value = '209.141.35.56']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-8956 \u2014 PTZOptics PT30X-SDI/NDI Cameras Au",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ddf6dc51-ea75-4ebb-9b8f-80e094179d1b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.128.232.229",
      "pattern": "[ipv4-addr:value = '45.128.232.229']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-8956 \u2014 PTZOptics PT30X-SDI/NDI Cameras Au",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e5cb09c1-fd0f-4c25-a4ef-60505c63b982",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-20481",
      "pattern": "[vulnerability:name = 'CVE-2024-20481']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20481 \u2014 Cisco ASA and FTD Denial-of-Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--180a55f8-63cf-4906-98d4-6f5680225987",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-37383",
      "pattern": "[vulnerability:name = 'CVE-2024-37383']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-37383 \u2014 RoundCube Webmail Cross-Site Scri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2d845c4-32b5-46d1-b3b7-fe2fc7d63696",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: libcdn.org",
      "pattern": "[domain-name:value = 'libcdn.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-37383 \u2014 RoundCube Webmail Cross-Site Scri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b5479a18-208a-4071-921a-c8cc2ae9766a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: rcm.codes",
      "pattern": "[domain-name:value = 'rcm.codes']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-37383 \u2014 RoundCube Webmail Cross-Site Scri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32158b48-bfcd-48e6-a758-2599124e8167",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-47575",
      "pattern": "[vulnerability:name = 'CVE-2024-47575']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-47575 \u2014 Fortinet FortiManager Missing Aut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-23113 \u2014 Fortinet Multiple Products Format",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4fc6e153-723b-4fd8-982e-6d46d29b3bcc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.238.141.143",
      "pattern": "[ipv4-addr:value = '104.238.141.143']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-47575 \u2014 Fortinet FortiManager Missing Aut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-23113 \u2014 Fortinet Multiple Products Format",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0c827f7-7000-4ebd-be07-aafdec681f99",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 142.93.177.233",
      "pattern": "[ipv4-addr:value = '142.93.177.233']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-47575 \u2014 Fortinet FortiManager Missing Aut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--41ee9f58-85fe-4e8f-8780-25c87626fec6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 158.247.199.37",
      "pattern": "[ipv4-addr:value = '158.247.199.37']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-47575 \u2014 Fortinet FortiManager Missing Aut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-23113 \u2014 Fortinet Multiple Products Format",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8761f1b4-2bdc-41cb-992b-2e1f6f4085d7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.232.167.68",
      "pattern": "[ipv4-addr:value = '172.232.167.68']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-47575 \u2014 Fortinet FortiManager Missing Aut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9f269754-0033-4a03-badb-ca2247efc21e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 195.85.114.78",
      "pattern": "[ipv4-addr:value = '195.85.114.78']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-47575 \u2014 Fortinet FortiManager Missing Aut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-23113 \u2014 Fortinet Multiple Products Format",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--78b9c4ea-fd2d-4658-be4e-bcf41fbfeb67",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 198.199.122.22",
      "pattern": "[ipv4-addr:value = '198.199.122.22']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-47575 \u2014 Fortinet FortiManager Missing Aut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--20bb6335-f75d-4e4f-b55a-7ef4ef05cb1a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.32.41.202",
      "pattern": "[ipv4-addr:value = '45.32.41.202']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-47575 \u2014 Fortinet FortiManager Missing Aut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-23113 \u2014 Fortinet Multiple Products Format",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--96abf0d1-1c58-4e5d-a813-0e5c47284654",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.32.63.2",
      "pattern": "[ipv4-addr:value = '45.32.63.2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-47575 \u2014 Fortinet FortiManager Missing Aut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--26c03e70-c2ba-4fe6-be1f-fb10cd43e281",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 80.66.196.199",
      "pattern": "[ipv4-addr:value = '80.66.196.199']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-47575 \u2014 Fortinet FortiManager Missing Aut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--111f4421-acba-4525-bdba-df6405ff56b6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 9dcfab171580b52deae8703157012674",
      "pattern": "[file:hashes.MD5 = '9dcfab171580b52deae8703157012674']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-47575 \u2014 Fortinet FortiManager Missing Aut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f9096f84-5db0-4380-a5ec-553de4576015",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-38094",
      "pattern": "[vulnerability:name = 'CVE-2024-38094']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7a7a1e22-76b2-4c09-9178-767cb14dbeba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 18.195.61.200",
      "pattern": "[ipv4-addr:value = '18.195.61.200']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--141a8b14-05a1-42f4-9f73-f82ff24935bf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 54.255.89.118",
      "pattern": "[ipv4-addr:value = '54.255.89.118']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--902fb0ee-bf8d-41d4-8288-c9c8aed9ff03",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1beec8cecd28fdf9f7e0fc5fb9226b360934086ded84f69e3d542d1362e3fdf3",
      "pattern": "[file:hashes.'SHA-256' = '1beec8cecd28fdf9f7e0fc5fb9226b360934086ded84f69e3d542d1362e3fdf3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c5bde7fb-6e76-46dc-8991-af49105e9865",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 61c0810a23580cf492a6ba4f7654566108331e7a4134c968c2d6a05261b2d8a1",
      "pattern": "[file:hashes.'SHA-256' = '61c0810a23580cf492a6ba4f7654566108331e7a4134c968c2d6a05261b2d8a1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2334c041-594d-431a-b1c2-f81e044de7c8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6ce228240458563d73c1c3cbbd04ef15cb7c5badacc78ce331848f5431b406cc",
      "pattern": "[file:hashes.'SHA-256' = '6ce228240458563d73c1c3cbbd04ef15cb7c5badacc78ce331848f5431b406cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de631c8f-c942-4b9e-b838-5ae797412266",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 95cc0b082fcfc366a7de8030a6325c099d8012533a3234edbdf555df082413c7",
      "pattern": "[file:hashes.'SHA-256' = '95cc0b082fcfc366a7de8030a6325c099d8012533a3234edbdf555df082413c7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8194d488-63e3-4cf3-a9a7-038f297a0397",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: acb5de5a69c06b7501f86c0522d10fefa9c34776c7535e937e946c6abfc9bbc6",
      "pattern": "[file:hashes.'SHA-256' = 'acb5de5a69c06b7501f86c0522d10fefa9c34776c7535e937e946c6abfc9bbc6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--298841e5-5baa-4035-ad25-0fac9e17d659",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d18aa84b7bf0efde9c6b5db2a38ab1ec9484c59c5284c0bd080f5197bf9388b0",
      "pattern": "[file:hashes.'SHA-256' = 'd18aa84b7bf0efde9c6b5db2a38ab1ec9484c59c5284c0bd080f5197bf9388b0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a12bab49-c336-4bb3-ba67-fd50380f18d9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d3a6ed07bd3b52c62411132d060560f9c0c88ce183851f16b632a99b4d4e7581",
      "pattern": "[file:hashes.'SHA-256' = 'd3a6ed07bd3b52c62411132d060560f9c0c88ce183851f16b632a99b4d4e7581']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c242d68f-4d57-4d86-a53f-3e1b8761a429",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e451287843b3927c6046eaabd3e22b929bc1f445eec23a73b1398b115d02e4fb",
      "pattern": "[file:hashes.'SHA-256' = 'e451287843b3927c6046eaabd3e22b929bc1f445eec23a73b1398b115d02e4fb']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--596b103b-d80b-4fe3-8737-b3122b27bb65",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f618b09c0908119399d14f80fc868b002b987006f7c76adbcec1ac11b9208940",
      "pattern": "[file:hashes.'SHA-256' = 'f618b09c0908119399d14f80fc868b002b987006f7c76adbcec1ac11b9208940']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--14e5f019-1b1b-4958-8bbf-f2fd0e2c5fe6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-9537",
      "pattern": "[vulnerability:name = 'CVE-2024-9537']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9537 \u2014 ScienceLogic SL1 Unspecified Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7a6ec834-f65b-4ba1-98ff-5d514baa85f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-40711",
      "pattern": "[vulnerability:name = 'CVE-2024-40711']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40711 \u2014 Veeam Backup and Replication Dese",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1928e873-d9b9-44c3-9417-e77d9e2df5f2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-35232",
      "pattern": "[vulnerability:name = 'CVE-2021-35232']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-28987 \u2014 SolarWinds Web Help Desk Hardcode",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb131c77-45c2-4ff9-87c4-7dcb47d5755d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-28987",
      "pattern": "[vulnerability:name = 'CVE-2024-28987']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-28987 \u2014 SolarWinds Web Help Desk Hardcode",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d79636d3-1163-4ab8-a680-4464b518e01f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-30088",
      "pattern": "[vulnerability:name = 'CVE-2024-30088']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-30088 \u2014 Microsoft Windows Kernel TOCTOU R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4e7fd3c2-616e-4239-921c-9d6caaff018b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-23113",
      "pattern": "[vulnerability:name = 'CVE-2024-23113']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-23113 \u2014 Fortinet Multiple Products Format",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--36e721c5-666d-4cd4-af2f-12b00d3d1c22",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-29824",
      "pattern": "[vulnerability:name = 'CVE-2024-29824']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-29824 \u2014 Ivanti Endpoint Manager (EPM) SQL",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a939931e-62c0-4564-bfa5-e82f90b133c5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-8190",
      "pattern": "[vulnerability:name = 'CVE-2024-8190']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9379 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0a1e3f0c-d6a5-45ae-8486-aaa42ab1bf89",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-8963",
      "pattern": "[vulnerability:name = 'CVE-2024-8963']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9379 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c46dfac-4c6a-47e4-b183-459f0135d80e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-9379",
      "pattern": "[vulnerability:name = 'CVE-2024-9379']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9379 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--89a91702-d194-42c0-952b-d833f0d57833",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-9380",
      "pattern": "[vulnerability:name = 'CVE-2024-9380']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-9379 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c02903eb-a57b-40c6-9a8a-cf125faa2651",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: 189f31ed7d.ipv6.bypass.eu.org",
      "pattern": "[domain-name:value = '189f31ed7d.ipv6.bypass.eu.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c8202d9-7478-433c-bf02-c26b0211514e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: apiv5.serverbks.xyz",
      "pattern": "[domain-name:value = 'apiv5.serverbks.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--805c2186-2b5b-4340-91ca-34e1dd297021",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: c67f045c2f.ipv6.1433.eu.org",
      "pattern": "[domain-name:value = 'c67f045c2f.ipv6.1433.eu.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--80b9b7ad-8583-4e3c-91b0-50d0d611cf26",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: iowxuintgredogzgblrsmr2cx2e471bor.oast.fun",
      "pattern": "[domain-name:value = 'iowxuintgredogzgblrsmr2cx2e471bor.oast.fun']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4fffa823-56e9-435b-a0c8-00fb8ef3ac38",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 156.234.193.18",
      "pattern": "[ipv4-addr:value = '156.234.193.18']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2ff658a-1f9c-4aad-aab3-0afc942ae727",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.189.100.197",
      "pattern": "[ipv4-addr:value = '193.189.100.197']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--68e6f6e7-f090-4af6-b81e-cb4de906258f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 206.189.156.69",
      "pattern": "[ipv4-addr:value = '206.189.156.69']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ae3755ef-5e0c-4647-a8fe-9c9ef361c9c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 208.105.190.170",
      "pattern": "[ipv4-addr:value = '208.105.190.170']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--58c9f42e-622b-4673-8209-4857e81bfc26",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 216.131.75.52",
      "pattern": "[ipv4-addr:value = '216.131.75.52']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7510f79a-f2b3-4333-870a-665f2e184a14",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.236.66.97",
      "pattern": "[ipv4-addr:value = '23.236.66.97']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--beee7b94-59ff-41e2-ab31-8a16bcfb79c6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 24.166.100.255",
      "pattern": "[ipv4-addr:value = '24.166.100.255']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--284c4988-a976-408e-b063-0cb9ad9726a5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 3.248.33.252",
      "pattern": "[ipv4-addr:value = '3.248.33.252']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9f447fc1-1fd2-4dfe-9ea8-d7161e6461d0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.207.159.76",
      "pattern": "[ipv4-addr:value = '38.207.159.76']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d0cf4b7b-212f-402b-b365-a4007032e909",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.61.136.189",
      "pattern": "[ipv4-addr:value = '45.61.136.189']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--edab7e77-21aa-4185-a5cc-eb8a8c826e87",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 51.91.79.17",
      "pattern": "[ipv4-addr:value = '51.91.79.17']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--195bdcb0-6620-4c76-85ca-a20b1f11027f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 67.217.228.92",
      "pattern": "[ipv4-addr:value = '67.217.228.92']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e4b147af-5fed-4ad2-9180-235f20ef03b8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 69.49.88.235",
      "pattern": "[ipv4-addr:value = '69.49.88.235']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--49def043-cd7e-4bea-9a1c-f855726f23fd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 74.62.81.162",
      "pattern": "[ipv4-addr:value = '74.62.81.162']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f54cb2cb-4552-4c8c-85ad-57e47b1f7980",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 64efc1aad330ea9d98c0c705e16cd4b3af7e74f8",
      "pattern": "[file:hashes.'SHA-1' = '64efc1aad330ea9d98c0c705e16cd4b3af7e74f8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d53ee001-54bf-47e6-ad4c-94f2c4d344cb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: beb723a5f20a1a2c4375f9aa250d968d55155689",
      "pattern": "[file:hashes.'SHA-1' = 'beb723a5f20a1a2c4375f9aa250d968d55155689']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0d8f5f1c-83d7-449f-aa52-e511ae18fe14",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6edd7b3123de985846a805931ca8ee5f6f7ed7b160144aa0e066967bc7c0423a",
      "pattern": "[file:hashes.'SHA-256' = '6edd7b3123de985846a805931ca8ee5f6f7ed7b160144aa0e066967bc7c0423a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--08300a18-3379-446b-9b2d-d988dfe80eab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8d016d02f8fbe25dce76481a90dd0b48630ce9e74e8c31ba007cf133e48b8526",
      "pattern": "[file:hashes.'SHA-256' = '8d016d02f8fbe25dce76481a90dd0b48630ce9e74e8c31ba007cf133e48b8526']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b438853-7a26-48f5-88d5-ecd7ebd15cb2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d57a2cac394a778e19ce9b926f2e0a71936510798f30d20f207f2a49b49ce7b1",
      "pattern": "[file:hashes.'SHA-256' = 'd57a2cac394a778e19ce9b926f2e0a71936510798f30d20f207f2a49b49ce7b1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a10bb584-15d6-4742-a55d-adff7e6d69b6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-38112",
      "pattern": "[vulnerability:name = 'CVE-2024-38112']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-43573 \u2014 Microsoft Windows MSHTML Platform",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-43461 \u2014 Microsoft Windows MSHTML Platform",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-38112 \u2014 Microsoft Windows MSHTML Platform",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4bd50347-b911-4eb3-9a4d-d08d43ab5a24",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-43047",
      "pattern": "[vulnerability:name = 'CVE-2024-43047']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-43047 \u2014 Qualcomm Multiple Chipsets Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd17bf54-9803-4d86-99e5-569a722d8c5b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-43461",
      "pattern": "[vulnerability:name = 'CVE-2024-43461']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-43573 \u2014 Microsoft Windows MSHTML Platform",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-43461 \u2014 Microsoft Windows MSHTML Platform",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0c757b9b-6986-4f4e-8448-18f799546118",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-43572",
      "pattern": "[vulnerability:name = 'CVE-2024-43572']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-43572 \u2014 Microsoft Windows Management Cons",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--be47534b-b8ce-4d4a-9b1a-125a91f2009b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-43573",
      "pattern": "[vulnerability:name = 'CVE-2024-43573']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-43573 \u2014 Microsoft Windows MSHTML Platform",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f5b43193-2874-4b71-a17a-084c7ade7998",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-45519",
      "pattern": "[vulnerability:name = 'CVE-2024-45519']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-45519 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6c0c4f1-85d3-4f10-b71c-acc099a40db0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 79.124.49.86",
      "pattern": "[ipv4-addr:value = '79.124.49.86']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-45519 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c293c7c0-94b7-4e06-a15e-2c72f6a0bd3f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-0344",
      "pattern": "[vulnerability:name = 'CVE-2019-0344']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-0344 \u2014 SAP Commerce Cloud Deserialization",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eaa2e38e-8ff0-4119-b087-61226f11ad50",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-14472",
      "pattern": "[vulnerability:name = 'CVE-2020-14472']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-15415 \u2014 DrayTek Multiple Vigor Routers OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c8064fe-46c0-40fd-911d-1e9b3f92082a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-14993",
      "pattern": "[vulnerability:name = 'CVE-2020-14993']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-15415 \u2014 DrayTek Multiple Vigor Routers OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ee9803bc-1b60-4baf-95cb-e4ed50c14a57",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-15415",
      "pattern": "[vulnerability:name = 'CVE-2020-15415']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-15415 \u2014 DrayTek Multiple Vigor Routers OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--96d27d94-2aef-4215-875e-273f1dd30097",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-19664",
      "pattern": "[vulnerability:name = 'CVE-2020-19664']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-15415 \u2014 DrayTek Multiple Vigor Routers OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c525eef-a10c-4533-9533-e5711eae3771",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-8515",
      "pattern": "[vulnerability:name = 'CVE-2020-8515']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-15415 \u2014 DrayTek Multiple Vigor Routers OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-8515 \u2014 Multiple DrayTek Vigor Routers Web",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7ee9917a-c018-401f-9a78-1921a7730002",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-42911",
      "pattern": "[vulnerability:name = 'CVE-2021-42911']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-15415 \u2014 DrayTek Multiple Vigor Routers OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c33746e0-020c-4988-ac29-b2880d38c82b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-43118",
      "pattern": "[vulnerability:name = 'CVE-2021-43118']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-15415 \u2014 DrayTek Multiple Vigor Routers OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--55ff9509-3723-44b2-9a91-fce27e4b6014",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-1162",
      "pattern": "[vulnerability:name = 'CVE-2023-1162']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-15415 \u2014 DrayTek Multiple Vigor Routers OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a60b07b6-f410-449f-b52d-6d5e17771a2d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-24229",
      "pattern": "[vulnerability:name = 'CVE-2023-24229']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-15415 \u2014 DrayTek Multiple Vigor Routers OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d14f96f3-b57b-4542-b5eb-0e5fcfbe0839",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-25280",
      "pattern": "[vulnerability:name = 'CVE-2023-25280']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ac4af108-c25a-43ca-82ab-dfb1e39c6232",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-41592",
      "pattern": "[vulnerability:name = 'CVE-2024-41592']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-15415 \u2014 DrayTek Multiple Vigor Routers OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--302dd819-ed6e-42ec-8e38-e631b8fd7e73",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: zvub.us",
      "pattern": "[domain-name:value = 'zvub.us']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--99951173-d5ff-4b9c-8ba2-24d1083e6ebf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.225.74.251",
      "pattern": "[ipv4-addr:value = '185.225.74.251']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f8b0873-a55e-440b-9d75-6a101605c0dd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.44.81.114",
      "pattern": "[ipv4-addr:value = '185.44.81.114']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8bc3eab9-d823-4c2a-a9b2-a71e447795bf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.32.162.189",
      "pattern": "[ipv4-addr:value = '193.32.162.189']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b11be9ca-0c19-4d82-963e-9983516f5857",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 0d404a27c2f511ea7f4adb8aa150f787b2b1ff36c1b67923d6d1c90179033915",
      "pattern": "[file:hashes.'SHA-256' = '0d404a27c2f511ea7f4adb8aa150f787b2b1ff36c1b67923d6d1c90179033915']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c17ec671-8dd3-4eaf-a0b8-c20fb2729c9e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2d0c8ab6c71743af8667c7318a6d8e16c144ace8df59a681a0a7d48affc05599",
      "pattern": "[file:hashes.'SHA-256' = '2d0c8ab6c71743af8667c7318a6d8e16c144ace8df59a681a0a7d48affc05599']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5dfd75a8-6a61-4a6b-bbfc-a25f29a12918",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 366ddbaa36791cdb99cf7104b0914a258f0c373a94f6cf869f946c7799d5e2c6",
      "pattern": "[file:hashes.'SHA-256' = '366ddbaa36791cdb99cf7104b0914a258f0c373a94f6cf869f946c7799d5e2c6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de2adb9b-208d-44d2-8968-c9188b945145",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3f427eda4d4e18fb192d585fca1490389a1b5f796f88e7ebf3eceec51018ef4d",
      "pattern": "[file:hashes.'SHA-256' = '3f427eda4d4e18fb192d585fca1490389a1b5f796f88e7ebf3eceec51018ef4d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6908a2d-e6f4-4238-85e8-bf7680ccacdd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 413e977ae7d359e2ea7fe32db73fa007ee97ee1e9e3c3f0b4163b100b3ec87c2",
      "pattern": "[file:hashes.'SHA-256' = '413e977ae7d359e2ea7fe32db73fa007ee97ee1e9e3c3f0b4163b100b3ec87c2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6feb3027-1a78-40bf-abb4-494e0c9fd523",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 461f59a84ccb4805c4bbd37093df6e8791cdf1151b2746c46678dfe9f89ac79d",
      "pattern": "[file:hashes.'SHA-256' = '461f59a84ccb4805c4bbd37093df6e8791cdf1151b2746c46678dfe9f89ac79d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cdb9d95d-6c6a-4efd-b974-b13bb73f75c1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4cb8c90d1e1b2d725c2c1366700f11584f5697c9ef50d79e00f7dd2008e989a0",
      "pattern": "[file:hashes.'SHA-256' = '4cb8c90d1e1b2d725c2c1366700f11584f5697c9ef50d79e00f7dd2008e989a0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--205805d6-7fc3-4847-8f42-3a10175dbf79",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4f53eb7fbfa5b68cad3a0850b570cbbcb2d4864e62b5bf0492b54bde2bdbe44b",
      "pattern": "[file:hashes.'SHA-256' = '4f53eb7fbfa5b68cad3a0850b570cbbcb2d4864e62b5bf0492b54bde2bdbe44b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2f30b67e-7d29-4140-a825-7c4648e21757",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 888f4a852642ce70197f77e213456ea2b3cfca4a592b94647827ca45adf2a5b8",
      "pattern": "[file:hashes.'SHA-256' = '888f4a852642ce70197f77e213456ea2b3cfca4a592b94647827ca45adf2a5b8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0ac06500-3eb4-4359-af06-b5214918270b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: aaf446e4e7bfc05a33c8d9e5acf56b1c7e95f2d919b98151ff2db327c333f089",
      "pattern": "[file:hashes.'SHA-256' = 'aaf446e4e7bfc05a33c8d9e5acf56b1c7e95f2d919b98151ff2db327c333f089']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8b3bbbd5-c733-4fc7-baa5-ba1a63758886",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: aed078d3e65b5ff4dd4067ae30da5f3a96c87ec23ec5be44fc85b543c179b777",
      "pattern": "[file:hashes.'SHA-256' = 'aed078d3e65b5ff4dd4067ae30da5f3a96c87ec23ec5be44fc85b543c179b777']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--387ed3cf-896c-4308-844b-fa2e16493fa2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b43a8a56c10ba17ddd6fa9a8ce10ab264c6495b82a38620e9d54d66ec8677b0c",
      "pattern": "[file:hashes.'SHA-256' = 'b43a8a56c10ba17ddd6fa9a8ce10ab264c6495b82a38620e9d54d66ec8677b0c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1d274296-e4d5-43f8-9f87-cf66472d5279",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b45142a2d59d16991a38ea0a112078a6ce42c9e2ee28a74fb2ce7e1edf15dce3",
      "pattern": "[file:hashes.'SHA-256' = 'b45142a2d59d16991a38ea0a112078a6ce42c9e2ee28a74fb2ce7e1edf15dce3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--649a1172-ce04-49f7-9e99-601464ad80af",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: eca42235a41dbd60615d91d564c91933b9903af2ef3f8356ec4cfff2880a2f19",
      "pattern": "[file:hashes.'SHA-256' = 'eca42235a41dbd60615d91d564c91933b9903af2ef3f8356ec4cfff2880a2f19']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--649b3ae3-2df8-4de8-9826-1d9926e1b76e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-47076",
      "pattern": "[vulnerability:name = 'CVE-2024-47076']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Zero-day RCE vulnerability found in CUPS - Common UNIX Print",
          "url": "https://snyk.io/blog/zero-day-rce-in-cups-vulnerability-sept-2024/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ca5c7559-5dc9-4b03-97e6-5e9fe23b1f74",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-47175",
      "pattern": "[vulnerability:name = 'CVE-2024-47175']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Zero-day RCE vulnerability found in CUPS - Common UNIX Print",
          "url": "https://snyk.io/blog/zero-day-rce-in-cups-vulnerability-sept-2024/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5e3375a-ebc2-4714-98c6-7e9fc23af38d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-47176",
      "pattern": "[vulnerability:name = 'CVE-2024-47176']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Zero-day RCE vulnerability found in CUPS - Common UNIX Print",
          "url": "https://snyk.io/blog/zero-day-rce-in-cups-vulnerability-sept-2024/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--57c66931-5632-4f9f-a9ea-1299fc775ad0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-47177",
      "pattern": "[vulnerability:name = 'CVE-2024-47177']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Zero-day RCE vulnerability found in CUPS - Common UNIX Print",
          "url": "https://snyk.io/blog/zero-day-rce-in-cups-vulnerability-sept-2024/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8e093c20-ce1b-418d-9449-64770d3bbba6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-7593",
      "pattern": "[vulnerability:name = 'CVE-2024-7593']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-7593 \u2014 Ivanti Virtual Traffic Manager Aut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--77422c1a-ce30-4e64-9e37-15126c1c53ee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: test.vip8025.mom",
      "pattern": "[domain-name:value = 'test.vip8025.mom']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1bc89d66-9126-4fab-a6f1-df4d7341e320",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: vip8806.mom",
      "pattern": "[domain-name:value = 'vip8806.mom']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e3b3b09e-3544-4db9-900e-098315e59277",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: www.vip8025.mom",
      "pattern": "[domain-name:value = 'www.vip8025.mom']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--04875794-fefc-40c1-aca2-de0eff67af70",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 156.251.172.80",
      "pattern": "[ipv4-addr:value = '156.251.172.80']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c5a146b3-2319-43a3-a0ab-7727594bfef9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 195.133.52.87",
      "pattern": "[ipv4-addr:value = '195.133.52.87']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1899ea2c-746a-49ca-b226-1827d8ee7a4d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 8.218.239.22",
      "pattern": "[ipv4-addr:value = '8.218.239.22']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bbab8100-44e8-4281-ab15-825e4bf476d1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 074739c7ccdee5baef649b7f7cb53668109be8f7e016294b66a5d1469803e42b",
      "pattern": "[file:hashes.'SHA-256' = '074739c7ccdee5baef649b7f7cb53668109be8f7e016294b66a5d1469803e42b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--686032b9-58d9-49b6-a819-4ceb4d5c6ea4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4c86e8c21451074a52cc8d60a262c683aaf4cb6b2634fea8efdd866ea2dbd3aa",
      "pattern": "[file:hashes.'SHA-256' = '4c86e8c21451074a52cc8d60a262c683aaf4cb6b2634fea8efdd866ea2dbd3aa']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--706c84a9-5fe2-48e8-8a01-ec618b1ce07b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 61928ff36c5d8983853ec2f411860b97231729f047527434d3b2db8bf0b42d25",
      "pattern": "[file:hashes.'SHA-256' = '61928ff36c5d8983853ec2f411860b97231729f047527434d3b2db8bf0b42d25']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2bd3c212-847e-43ea-b534-8ce2f11beea3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7798b45ffc488356f7253805dc9c8d2210552bee39db9082f772185430360574",
      "pattern": "[file:hashes.'SHA-256' = '7798b45ffc488356f7253805dc9c8d2210552bee39db9082f772185430360574']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e107a362-a11d-426d-b3b0-c1922d5ac245",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9f97997581f513166aae47b3664ca23c4f4ea90c24916874ff82891e2cd6e01e",
      "pattern": "[file:hashes.'SHA-256' = '9f97997581f513166aae47b3664ca23c4f4ea90c24916874ff82891e2cd6e01e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--abc92c4f-22e5-4167-a9ad-3cea69d3046f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: af3f4ece0d98999077cef265c1af9610b96cb7cf3264c115cc6c210cdd9636fe",
      "pattern": "[file:hashes.'SHA-256' = 'af3f4ece0d98999077cef265c1af9610b96cb7cf3264c115cc6c210cdd9636fe']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--141c4aa4-3832-47bf-a3d5-7ddab018ec44",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c64bd109100aac96eba627ca94c1161c8329378e3e8c75a1763c26b70c921891",
      "pattern": "[file:hashes.'SHA-256' = 'c64bd109100aac96eba627ca94c1161c8329378e3e8c75a1763c26b70c921891']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7729597e-c943-4fa7-bb44-e962f8d3af70",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: cae96b72244855a3d98a42bb3f65daab1cd06e9be638553e2ebf1f8a66b5cc8a",
      "pattern": "[file:hashes.'SHA-256' = 'cae96b72244855a3d98a42bb3f65daab1cd06e9be638553e2ebf1f8a66b5cc8a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f6c5323e-c002-4163-836e-2c84add4ff77",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-0618",
      "pattern": "[vulnerability:name = 'CVE-2020-0618']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-0618 \u2014 Microsoft SQL Server Reporting Ser",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ad0aceff-e4fb-48bd-93f6-22d97a46bf7c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-14644",
      "pattern": "[vulnerability:name = 'CVE-2020-14644']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-14644 \u2014 Oracle WebLogic Server Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-21445 \u2014 Oracle ADF Faces Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--faba8cbb-80bd-4ed0-817d-aee7c7682ee8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-21445",
      "pattern": "[vulnerability:name = 'CVE-2022-21445']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-21445 \u2014 Oracle ADF Faces Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5ca93b0-186a-4404-bef6-d4b0d904c51e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-21497",
      "pattern": "[vulnerability:name = 'CVE-2022-21497']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-21445 \u2014 Oracle ADF Faces Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53dfd3f4-2feb-44a9-a624-cea5f911f692",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-27348",
      "pattern": "[vulnerability:name = 'CVE-2024-27348']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27348 \u2014 Apache HugeGraph-Server Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3314b0d2-3cef-4d88-8b25-deb3dd64c522",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-0643",
      "pattern": "[vulnerability:name = 'CVE-2013-0643']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0643 \u2014 Adobe Flash Player Incorrect Defau",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--abd7767c-c70c-45af-a410-56b3820d88c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-0648",
      "pattern": "[vulnerability:name = 'CVE-2013-0648']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0648 \u2014 Adobe Flash Player Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2013-0643 \u2014 Adobe Flash Player Incorrect Defau",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--832ba2e2-3174-41b4-af61-9e529a251a37",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-0502",
      "pattern": "[vulnerability:name = 'CVE-2014-0502']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-0502 \u2014 Adobe Flash Player Double Free Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underfl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--00e5786f-df0e-4825-a124-517d0a83385a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: adservice.no-ip.org",
      "pattern": "[domain-name:value = 'adservice.no-ip.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underfl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2f3db194-985e-4d5e-a1ff-711c2cfdc886",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: giftserv.hopto.org",
      "pattern": "[domain-name:value = 'giftserv.hopto.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underfl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--08874d71-f4f8-4624-82ce-5cb560103510",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ids.ns01.us",
      "pattern": "[domain-name:value = 'ids.ns01.us']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underfl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4d63614a-7983-49eb-88fb-04bdbd8110b7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: java.ns1.name",
      "pattern": "[domain-name:value = 'java.ns1.name']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underfl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aa328d67-1ff4-423d-bac1-c6b51d6c2217",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: static.5ljob.net",
      "pattern": "[domain-name:value = 'static.5ljob.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underfl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--98597da7-6c72-45a0-b818-4698cdd4c625",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: wmi.ns01.us",
      "pattern": "[domain-name:value = 'wmi.ns01.us']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underfl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5796d53f-eb2a-4663-8206-ac0df7a2938d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.246.246.103",
      "pattern": "[ipv4-addr:value = '103.246.246.103']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underfl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c920581f-2678-4441-b8e8-fa9304c34f3a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.74.246.219",
      "pattern": "[ipv4-addr:value = '192.74.246.219']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underfl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c26a19f-117b-4cd5-98ce-0ca95621a3c3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.183.224.75",
      "pattern": "[ipv4-addr:value = '194.183.224.75']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underfl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7d2a109e-8dd4-4c36-b497-8908925377d7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 74.126.177.68",
      "pattern": "[ipv4-addr:value = '74.126.177.68']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underfl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc1e1e3f-4a0a-4281-9a5f-41d7c16b11a5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9d4a89cdefc71e9bfadc7566d2d9d9d2bdf7dc2847df4fcbf01e0a342ab5eead",
      "pattern": "[file:hashes.'SHA-256' = '9d4a89cdefc71e9bfadc7566d2d9d9d2bdf7dc2847df4fcbf01e0a342ab5eead']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underfl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6023a346-e231-4bab-8a20-d0b04de4a307",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-6670",
      "pattern": "[vulnerability:name = 'CVE-2024-6670']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-6670 \u2014 Progress WhatsUp Gold SQL Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--02d63b28-87cc-4333-873c-541998339919",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-6671",
      "pattern": "[vulnerability:name = 'CVE-2024-6671']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-6670 \u2014 Progress WhatsUp Gold SQL Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ee7b94c4-b72d-4a87-9373-9bfa9af3eaac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 8c69830a50fb85d8a794fa46643493b2",
      "pattern": "[file:hashes.MD5 = '8c69830a50fb85d8a794fa46643493b2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-6670 \u2014 Progress WhatsUp Gold SQL Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--20717c56-821b-4d4a-ab63-5a22dc02033f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: bbcf7a68f4164a9f5f5cb2d9f30d9790",
      "pattern": "[file:hashes.MD5 = 'bbcf7a68f4164a9f5f5cb2d9f30d9790']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-6670 \u2014 Progress WhatsUp Gold SQL Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ac44869f-d796-449b-b300-a05c149c676a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c67b03c0a91eaefffd2f2c79b5c26a2648b8d3c19a22cadf35453455ff08ead0",
      "pattern": "[file:hashes.'SHA-256' = 'c67b03c0a91eaefffd2f2c79b5c26a2648b8d3c19a22cadf35453455ff08ead0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-6670 \u2014 Progress WhatsUp Gold SQL Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bdbac9bc-c042-4fc1-8f35-d07063495f67",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6edd7b3123de985846a805931ca8ee5f5f7ed7b160144aa0e066967bc7c0423a",
      "pattern": "[file:hashes.'SHA-256' = '6edd7b3123de985846a805931ca8ee5f5f7ed7b160144aa0e066967bc7c0423a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8789aee2-0053-40c1-a2f6-efad32788137",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-38014",
      "pattern": "[vulnerability:name = 'CVE-2024-38014']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38014 \u2014 Microsoft Windows Installer Impro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9e077062-c96a-41a2-87dd-768c2bb9a12c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-38217",
      "pattern": "[vulnerability:name = 'CVE-2024-38217']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38217 \u2014 Microsoft Windows Mark of the Web",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8dbdb28c-c6b9-4689-8ae0-8c3a245ff9dc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-38226",
      "pattern": "[vulnerability:name = 'CVE-2024-38226']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38226 \u2014 Microsoft Publisher Protection Me",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--13000401-5124-4757-a833-24676ba7574c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 11dadc71018027c7e005a70c306532e5ea7abdc389964cbc85cf3b79f97f6b44",
      "pattern": "[file:hashes.'SHA-256' = '11dadc71018027c7e005a70c306532e5ea7abdc389964cbc85cf3b79f97f6b44']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38217 \u2014 Microsoft Windows Mark of the Web",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d3925761-5d38-4bee-b939-2fbf8ef17aee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4e213bd0a127f1bb24c4c0d971c2727097b04eed9c6e62a57110d168ccc3ba10",
      "pattern": "[file:hashes.'SHA-256' = '4e213bd0a127f1bb24c4c0d971c2727097b04eed9c6e62a57110d168ccc3ba10']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38217 \u2014 Microsoft Windows Mark of the Web",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--26ba40b2-07ba-4796-bc78-4c0aaf961cdb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ba35b8b4346b79b8bb4f97360025cb6befaf501b03149a3b5fef8f07bdf265c7",
      "pattern": "[file:hashes.'SHA-256' = 'ba35b8b4346b79b8bb4f97360025cb6befaf501b03149a3b5fef8f07bdf265c7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38217 \u2014 Microsoft Windows Mark of the Web",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9db7160f-2211-4ccf-bde9-3f7f180bca9e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-3714",
      "pattern": "[vulnerability:name = 'CVE-2016-3714']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-3714 \u2014 ImageMagick Improper Input Validat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "How I was hacking docker containers by exploiting ImageMagic",
          "url": "https://snyk.io/blog/hacking-docker-containers-by-exploiting-base-image-vulnerabilities/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4ee70aba-7a3f-4c19-9a10-c4ccef21b021",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-1000253",
      "pattern": "[vulnerability:name = 'CVE-2017-1000253']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-1000253 \u2014 Linux Kernel PIE Stack Buffer C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7f23a7dd-e335-4a13-b192-10378326df04",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.194.11.34",
      "pattern": "[ipv4-addr:value = '104.194.11.34']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--27ecbcea-8b61-4240-9293-dff82dcfdc9b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 107.155.93.154",
      "pattern": "[ipv4-addr:value = '107.155.93.154']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2697cc87-cb5e-4dc5-a120-f33cc2537a77",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 107.175.102.58",
      "pattern": "[ipv4-addr:value = '107.175.102.58']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8b6daa09-0103-486a-95f3-2d76119715a1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 144.168.41.74",
      "pattern": "[ipv4-addr:value = '144.168.41.74']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c1301e86-d623-46bf-b5bd-070ebda5d472",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 155.117.117.34",
      "pattern": "[ipv4-addr:value = '155.117.117.34']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d53a5950-5852-4304-9897-ad8b34ed8c02",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 162.210.196.101",
      "pattern": "[ipv4-addr:value = '162.210.196.101']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--576dbf6c-c6d3-4571-8a32-361cb0c82926",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.174.100.199",
      "pattern": "[ipv4-addr:value = '185.174.100.199']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1d8e24c8-3bfc-4141-9306-270ba065876a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.181.230.108",
      "pattern": "[ipv4-addr:value = '185.181.230.108']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc659494-d669-4868-8bef-04e1ed2e0a2c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.33.86.2",
      "pattern": "[ipv4-addr:value = '185.33.86.2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d9701820-199a-42f4-bff6-afd6fec78548",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.163.194.7",
      "pattern": "[ipv4-addr:value = '193.163.194.7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d6a84ab-6443-450a-9548-19cf4fca1516",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.239.236.149",
      "pattern": "[ipv4-addr:value = '193.239.236.149']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e64e3aed-1531-4145-b568-c59e3905c5b6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.29.63.226",
      "pattern": "[ipv4-addr:value = '193.29.63.226']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--96b5655e-77de-4416-b7df-0ace1033673b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.33.45.194",
      "pattern": "[ipv4-addr:value = '194.33.45.194']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b20c87e3-d666-42a9-a7d2-231cad5e2ba8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 206.168.190.143",
      "pattern": "[ipv4-addr:value = '206.168.190.143']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--74d4e5cd-c0ed-4861-b512-5230c8ba9ad7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 207.188.6.17",
      "pattern": "[ipv4-addr:value = '207.188.6.17']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a26ef09b-0563-44b5-b82a-3bada131a6ae",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.94.54.125",
      "pattern": "[ipv4-addr:value = '23.94.54.125']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9a6235c6-f02d-40fe-9093-b5793f9db06f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 31.222.247.64",
      "pattern": "[ipv4-addr:value = '31.222.247.64']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--69fbec40-a803-48dc-9b5a-5db620300631",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.114.123.167",
      "pattern": "[ipv4-addr:value = '38.114.123.167']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6a729eb5-a642-4ea2-88d2-4f8279aaedff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.114.123.229",
      "pattern": "[ipv4-addr:value = '38.114.123.229']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--24d17911-ad08-47a5-b7bb-ca741b0a1dd2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.55.76.210",
      "pattern": "[ipv4-addr:value = '45.55.76.210']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--706c1e31-c167-4da1-a9d1-2e489d7fc5e0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.56.163.58",
      "pattern": "[ipv4-addr:value = '45.56.163.58']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--639288d9-b629-46fd-a452-3adf05d533a3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.66.249.93",
      "pattern": "[ipv4-addr:value = '45.66.249.93']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1bb23344-27d2-4779-92da-222142210a13",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 62.76.147.106",
      "pattern": "[ipv4-addr:value = '62.76.147.106']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3538312d-32b1-4c53-af7a-ff48e9cf2cc3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 77.247.126.239",
      "pattern": "[ipv4-addr:value = '77.247.126.239']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3539e783-635f-414f-b7fe-37ecefaf8ca2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 79.141.160.33",
      "pattern": "[ipv4-addr:value = '79.141.160.33']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f87b3388-933f-4cb3-9707-c126875b562e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 79.141.173.235",
      "pattern": "[ipv4-addr:value = '79.141.173.235']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c8c9c864-291d-4ea3-a386-f699a4fc2924",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 83.229.17.123",
      "pattern": "[ipv4-addr:value = '83.229.17.123']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--031f01f4-5adb-472a-8d4b-866614c4e443",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 83.229.17.135",
      "pattern": "[ipv4-addr:value = '83.229.17.135']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--26d80708-0298-4128-bc81-37b267de99b2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 83.229.17.148",
      "pattern": "[ipv4-addr:value = '83.229.17.148']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fb954b38-2f0e-486a-b72d-ad68f9538938",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 91.191.214.170",
      "pattern": "[ipv4-addr:value = '91.191.214.170']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2c2a1aa-e02e-4165-be90-e4a3d4fbaabc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-0568",
      "pattern": "[vulnerability:name = 'CVE-2023-0568']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "What you should know about PHP code security",
          "url": "https://snyk.io/blog/php-code-security/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb81a02f-bf0f-4106-b3bc-717493c10e4b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-0662",
      "pattern": "[vulnerability:name = 'CVE-2023-0662']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "What you should know about PHP code security",
          "url": "https://snyk.io/blog/php-code-security/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--90ac3f08-5f16-4528-a7fc-0b65bb1668da",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-3823",
      "pattern": "[vulnerability:name = 'CVE-2023-3823']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "What you should know about PHP code security",
          "url": "https://snyk.io/blog/php-code-security/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c75b5314-11e3-4968-9351-c085f148f0ff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-20123",
      "pattern": "[vulnerability:name = 'CVE-2021-20123']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-20123 \u2014 Draytek VigorConnect Path Travers",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--58adb719-f979-47b5-a1ef-fea2dff4cc3c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-20124",
      "pattern": "[vulnerability:name = 'CVE-2021-20124']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-20124 \u2014 Draytek VigorConnect Path Travers",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e2a72b18-c37e-4088-ad51-289486af0ba5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-7262",
      "pattern": "[vulnerability:name = 'CVE-2024-7262']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-7262 \u2014 Kingsoft WPS Office Path Traversal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--84439c86-51a4-4ae0-83d3-34bd748d7385",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-7263",
      "pattern": "[vulnerability:name = 'CVE-2024-7263']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-7262 \u2014 Kingsoft WPS Office Path Traversal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f32595a-487f-46c1-a335-fbe5924a80f7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: rammenale.com",
      "pattern": "[domain-name:value = 'rammenale.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-7262 \u2014 Kingsoft WPS Office Path Traversal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d1ad845f-2910-4617-bc1b-8692ff412f96",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 131.153.206.231",
      "pattern": "[ipv4-addr:value = '131.153.206.231']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-7262 \u2014 Kingsoft WPS Office Path Traversal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d5f5ee9-cbcf-4cb8-bb7a-82ad56b65c97",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 162.222.214.48",
      "pattern": "[ipv4-addr:value = '162.222.214.48']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-7262 \u2014 Kingsoft WPS Office Path Traversal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3af02d33-f824-4313-897f-be5db790f796",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 9f88234068d7abad65979eb1df63efb5",
      "pattern": "[file:hashes.MD5 = '9f88234068d7abad65979eb1df63efb5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-7262 \u2014 Kingsoft WPS Office Path Traversal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4fc036fa-935d-4a02-b990-e67c131893ee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: b14ef85a60ac71c669cc960bdf580144",
      "pattern": "[file:hashes.MD5 = 'b14ef85a60ac71c669cc960bdf580144']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-7262 \u2014 Kingsoft WPS Office Path Traversal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--97cf6edf-722a-40aa-9d21-67888134f625",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 08906644b0ef1ee6478c45a6e0dd28533a9efc29",
      "pattern": "[file:hashes.'SHA-1' = '08906644b0ef1ee6478c45a6e0dd28533a9efc29']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-7262 \u2014 Kingsoft WPS Office Path Traversal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--27461014-bd83-4e6e-b0e9-653d0ea591d7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 7509b4c506c01627c1a4c396161d07277f044ac6",
      "pattern": "[file:hashes.'SHA-1' = '7509b4c506c01627c1a4c396161d07277f044ac6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-7262 \u2014 Kingsoft WPS Office Path Traversal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--33dc9a3d-d42c-4040-b85f-45c8fd628788",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6174276f94219bc386bdc628ca18eaec261998b7bd03077562fe93c268b42446",
      "pattern": "[file:hashes.'SHA-256' = '6174276f94219bc386bdc628ca18eaec261998b7bd03077562fe93c268b42446']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-7262 \u2014 Kingsoft WPS Office Path Traversal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--74a8b74d-07d7-426f-8272-a42eba1cbbb2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 861911e953e6fd0a015b3a91a7528a388a535c83f4b9a5cf7366b8209d2f00c3",
      "pattern": "[file:hashes.'SHA-256' = '861911e953e6fd0a015b3a91a7528a388a535c83f4b9a5cf7366b8209d2f00c3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-7262 \u2014 Kingsoft WPS Office Path Traversal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f3c271fc-a3b3-406d-abd6-fcbefce16e8d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-22965",
      "pattern": "[vulnerability:name = 'CVE-2022-22965']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The persistent threat: Why major vulnerabilities like Log4Sh",
          "url": "https://snyk.io/blog/log4shell-spring4shell-threat/"
        },
        {
          "source_name": "Controlling your server with a reverse shell attack",
          "url": "https://snyk.io/blog/reverse-shell-attack/"
        },
        {
          "source_name": "Spring4Shell extends to Glassfish and Payara: same vulnerabi",
          "url": "https://snyk.io/blog/spring4shell-rce-vulnerability-glassfish-payara/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9777ab73-8662-4923-80ff-db742b2eaa0e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-7965",
      "pattern": "[vulnerability:name = 'CVE-2024-7965']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-7965 \u2014 Google Chromium V8 Inappropriate I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--adc15798-9dd6-401b-b666-55e668943b36",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-32113",
      "pattern": "[vulnerability:name = 'CVE-2024-32113']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38856 \u2014 Apache OFBiz Incorrect Authorizat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-32113 \u2014 Apache OFBiz Path Traversal Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--00ff9464-113c-4361-8320-b50c17826b4b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-36104",
      "pattern": "[vulnerability:name = 'CVE-2024-36104']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38856 \u2014 Apache OFBiz Incorrect Authorizat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c10d4a9-3689-4f3a-a057-2cfa44c212d0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-38856",
      "pattern": "[vulnerability:name = 'CVE-2024-38856']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38856 \u2014 Apache OFBiz Incorrect Authorizat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f67254e8-cd9e-4668-b62e-505d2e482e1b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-21338",
      "pattern": "[vulnerability:name = 'CVE-2024-21338']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-7971 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-38193 \u2014 Microsoft Windows Ancillary Funct",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-21338 \u2014 Microsoft Windows Kernel Exposed ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e6d3a205-a04d-47d2-bdfa-3a9eec9859d8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-38106",
      "pattern": "[vulnerability:name = 'CVE-2024-38106']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-7971 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d50ad786-cb6d-47a7-afb1-b73e2d46f6ea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-38193",
      "pattern": "[vulnerability:name = 'CVE-2024-38193']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-7971 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-38193 \u2014 Microsoft Windows Ancillary Funct",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ae7b25b5-30b9-433b-959a-9e77eefa70cd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-7971",
      "pattern": "[vulnerability:name = 'CVE-2024-7971']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-7971 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--91390c2e-7185-48ca-828a-52cd0a3ff563",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: voyagorclub.space",
      "pattern": "[domain-name:value = 'voyagorclub.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-7971 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--17bd2fca-711c-49f9-bf82-cb245ad7e746",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: weinsteinfrog.com",
      "pattern": "[domain-name:value = 'weinsteinfrog.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-7971 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6fb12467-6ed2-4a4d-a405-35f7989c83bd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-39717",
      "pattern": "[vulnerability:name = 'CVE-2024-39717']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-39717 \u2014 Versa Director Dangerous File Typ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da00ffc3-7f43-48a4-9e80-9ac5f21cf5a9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4bcedac20a75e8f8833f4725adfc87577c32990c3783bf6c743f14599a176c37",
      "pattern": "[file:hashes.'SHA-256' = '4bcedac20a75e8f8833f4725adfc87577c32990c3783bf6c743f14599a176c37']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-39717 \u2014 Versa Director Dangerous File Typ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2a6b75f9-6f35-418c-983f-6344bc3bc913",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-31196",
      "pattern": "[vulnerability:name = 'CVE-2021-31196']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31196 \u2014 Microsoft Exchange Server Informa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--403c122f-c96f-4a54-82cd-23e19e5e3f15",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-33045",
      "pattern": "[vulnerability:name = 'CVE-2021-33045']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-33045 \u2014 Dahua IP Camera Authentication By",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-33044 \u2014 Dahua IP Camera Authentication By",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f6d6d50f-03e6-4ed0-89f0-06c83df24240",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-0185",
      "pattern": "[vulnerability:name = 'CVE-2022-0185']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0185 \u2014 Linux Kernel Heap-Based Buffer Ove",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d29c3f40-c99b-42ae-a2cc-85a6d29c0f80",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-23897",
      "pattern": "[vulnerability:name = 'CVE-2024-23897']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-23897 \u2014 Jenkins Command Line Interface (C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1b9a5916-e271-40be-bfdb-7055246522af",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-28986",
      "pattern": "[vulnerability:name = 'CVE-2024-28986']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-28986 \u2014 SolarWinds Web Help Desk Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f7125b05-5ac0-47e5-bae1-277dbd82790d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-1380",
      "pattern": "[vulnerability:name = 'CVE-2020-1380']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38178 \u2014 Microsoft Windows Scripting Engin",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-0986 \u2014 Microsoft Windows Kernel Privilege",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-1380 \u2014 Microsoft Internet Explorer Script",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2986def1-c708-4e64-9fb2-c27a00002cab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-41128",
      "pattern": "[vulnerability:name = 'CVE-2022-41128']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38178 \u2014 Microsoft Windows Scripting Engin",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Langu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9a165651-dc53-4d9d-bb66-b93ef8439081",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-36025",
      "pattern": "[vulnerability:name = 'CVE-2023-36025']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38213 \u2014 Microsoft Windows SmartScreen Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-29988 \u2014 Microsoft SmartScreen Prompt Secu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-21351 \u2014 Microsoft Windows SmartScreen Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--78796b10-e162-445a-882d-71313c64b9ef",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-21412",
      "pattern": "[vulnerability:name = 'CVE-2024-21412']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38213 \u2014 Microsoft Windows SmartScreen Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-29988 \u2014 Microsoft SmartScreen Prompt Secu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-21412 \u2014 Microsoft Windows Internet Shortc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3bb491e1-ebcf-4a03-ba40-7d1855914551",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-29988",
      "pattern": "[vulnerability:name = 'CVE-2024-29988']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38213 \u2014 Microsoft Windows SmartScreen Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-29988 \u2014 Microsoft SmartScreen Prompt Secu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c676143b-ff3c-4af7-b4ec-90e861359c97",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-38107",
      "pattern": "[vulnerability:name = 'CVE-2024-38107']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38107 \u2014 Microsoft Windows Power Dependenc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-38106 \u2014 Microsoft Windows Kernel Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0d2755a-875b-40a7-a2e0-40a0227f477b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-38178",
      "pattern": "[vulnerability:name = 'CVE-2024-38178']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38178 \u2014 Microsoft Windows Scripting Engin",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7faf91c2-87bc-4555-9d03-4795302634c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-38189",
      "pattern": "[vulnerability:name = 'CVE-2024-38189']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38189 \u2014 Microsoft Project Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d4729488-36b7-4771-826b-9fd3f727d09c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-38213",
      "pattern": "[vulnerability:name = 'CVE-2024-38213']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38213 \u2014 Microsoft Windows SmartScreen Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-29988 \u2014 Microsoft SmartScreen Prompt Secu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9a60304e-9d96-446b-b498-28ee514c2781",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e11bb2478930d0b5f6c473464f2a2b6e",
      "pattern": "[file:hashes.MD5 = 'e11bb2478930d0b5f6c473464f2a2b6e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38178 \u2014 Microsoft Windows Scripting Engin",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--081ede92-cc3b-45d6-b74f-59cbebfe35d3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1277b7f12af65d3590f7e06672413698255214dfab3bdf7668d5846577c00368",
      "pattern": "[file:hashes.'SHA-256' = '1277b7f12af65d3590f7e06672413698255214dfab3bdf7668d5846577c00368']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38213 \u2014 Microsoft Windows SmartScreen Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--61ce8394-334e-4a2b-ad4d-62ee92028c23",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 49bef5b4b64221297f90380092f6eba6014d81f6f517e82e42f4906087b20d19",
      "pattern": "[file:hashes.'SHA-256' = '49bef5b4b64221297f90380092f6eba6014d81f6f517e82e42f4906087b20d19']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38213 \u2014 Microsoft Windows SmartScreen Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aeeac14e-a150-432b-9fe2-2bc40ac540ed",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 736092b71a9686fde43d3c4abd941a6774721b90b17d946c9d05af19c84df0a4",
      "pattern": "[file:hashes.'SHA-256' = '736092b71a9686fde43d3c4abd941a6774721b90b17d946c9d05af19c84df0a4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38178 \u2014 Microsoft Windows Scripting Engin",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1df74727-81cb-4fd5-ac29-045138c3ed94",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: bb2f8dff11bd99bcfbc0544d29a5e690701fc242c8188e68192371768bec6f7d",
      "pattern": "[file:hashes.'SHA-256' = 'bb2f8dff11bd99bcfbc0544d29a5e690701fc242c8188e68192371768bec6f7d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38213 \u2014 Microsoft Windows SmartScreen Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--385641b3-e342-42b0-9862-49dc829ee927",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-36971",
      "pattern": "[vulnerability:name = 'CVE-2024-36971']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36971 \u2014 Android Kernel Remote Code Execut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c0b1f0ad-9c87-4e0f-af0d-d1db45376e3e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-0824",
      "pattern": "[vulnerability:name = 'CVE-2018-0824']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--18a9772a-d52b-4b8d-ab07-f9ff1c9818fe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: w2.chatgptsfit.com",
      "pattern": "[domain-name:value = 'w2.chatgptsfit.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1cd15de9-f9f0-483a-89bb-a06beab911f7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.56.114.69",
      "pattern": "[ipv4-addr:value = '103.56.114.69']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--981eca4e-d24e-4f14-936d-57e7f934d21f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.96.131.84",
      "pattern": "[ipv4-addr:value = '103.96.131.84']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--01ceeb90-df5f-4ec2-bac3-00d3f364ef54",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.85.76.10",
      "pattern": "[ipv4-addr:value = '45.85.76.10']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0df53156-f383-4988-949c-41c9495a866a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.85.76.18",
      "pattern": "[ipv4-addr:value = '45.85.76.18']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ad75b15f-cbbc-4d9a-aec1-3802c653a0bc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 58.64.204.145",
      "pattern": "[ipv4-addr:value = '58.64.204.145']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f99235d1-f51b-40e5-a2a6-ca263ee77608",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 027443e516eabfc15ebf76a954c2c61e",
      "pattern": "[file:hashes.MD5 = '027443e516eabfc15ebf76a954c2c61e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f5eaf633-6283-4266-b94c-5956277ca185",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 1647a2c92fc799bd83b0ee33c98ad187",
      "pattern": "[file:hashes.MD5 = '1647a2c92fc799bd83b0ee33c98ad187']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--98bd1475-07b6-40ab-812e-6b202a9a2d6a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 2c66bf055c6349408bf00ec3925cb678",
      "pattern": "[file:hashes.MD5 = '2c66bf055c6349408bf00ec3925cb678']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--20d22468-6d0a-42fa-bbd5-78b3b787f9d7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 549d5b936e77f1067feb4e395f6f7b61",
      "pattern": "[file:hashes.MD5 = '549d5b936e77f1067feb4e395f6f7b61']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c45713fb-c33b-4cb7-bbc6-dfb50aabd997",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 623ac8801fb147ddc30c563f743441e0",
      "pattern": "[file:hashes.MD5 = '623ac8801fb147ddc30c563f743441e0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--615a6afe-2cc0-4354-b894-6dab87c5229a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 9ccb2f877777f3db8b1cb58440168ebd",
      "pattern": "[file:hashes.MD5 = '9ccb2f877777f3db8b1cb58440168ebd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc0460a0-ddbd-4c98-8c9d-79428a72dbc8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: b39d28b5dc1770ece081b96a561511a0",
      "pattern": "[file:hashes.MD5 = 'b39d28b5dc1770ece081b96a561511a0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--099345e0-43f5-4bca-8a40-2ea71cef0fac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: ccdcad8c74aac5c706cbad7e7ce085d1",
      "pattern": "[file:hashes.MD5 = 'ccdcad8c74aac5c706cbad7e7ce085d1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--95e01c8d-05b1-4d11-a81d-c96d17816d6a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 03501f7b4f398c682d1de2dc0c503e17f0212afe",
      "pattern": "[file:hashes.'SHA-1' = '03501f7b4f398c682d1de2dc0c503e17f0212afe']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--18c5b199-bc8d-42c6-9206-2761d159afe1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 2634e0eec33e7fbf734f1a13b023ab8952fe6f03",
      "pattern": "[file:hashes.'SHA-1' = '2634e0eec33e7fbf734f1a13b023ab8952fe6f03']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7654184d-6cce-48e3-ba3c-f721ddd0c7c7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 2adc28beb14583064d63819b3619794d58734d69",
      "pattern": "[file:hashes.'SHA-1' = '2adc28beb14583064d63819b3619794d58734d69']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b4a4b70-1bb1-4a45-b7e6-ef4c43b15c17",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 4826fe7edbbfe546253c168e0f652e1500bb70bc",
      "pattern": "[file:hashes.'SHA-1' = '4826fe7edbbfe546253c168e0f652e1500bb70bc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d6d5ed6-b004-4a5e-a371-f271daf20c6c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 884c36c7f146a4ac8941b8227a150daaf9b95dc7",
      "pattern": "[file:hashes.'SHA-1' = '884c36c7f146a4ac8941b8227a150daaf9b95dc7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ae5e1228-2741-4e39-849e-69f0499c9bd6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: d594fb3a164a8adc678086c52d2422e7c9272ebe",
      "pattern": "[file:hashes.'SHA-1' = 'd594fb3a164a8adc678086c52d2422e7c9272ebe']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3c739007-7488-4792-b9b6-a5dd467be523",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: d8d7922a550db6afd661b74eaa97c8f59c76cf21",
      "pattern": "[file:hashes.'SHA-1' = 'd8d7922a550db6afd661b74eaa97c8f59c76cf21']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9e3f4e71-29f2-49ae-bf73-823d8906b962",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: f6aae5d8deaa50cbec0503e8219ea5ba0f26db8b",
      "pattern": "[file:hashes.'SHA-1' = 'f6aae5d8deaa50cbec0503e8219ea5ba0f26db8b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a0458f49-5d32-4b04-9e10-29f3de15f5a1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 087c475a1b5b36b7939f5ff12dc711ba591dd2c4227ccaa28d322425ef4d0d4c",
      "pattern": "[file:hashes.'SHA-256' = '087c475a1b5b36b7939f5ff12dc711ba591dd2c4227ccaa28d322425ef4d0d4c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--18892c59-bec0-4e6d-ad87-c122e81fd536",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 0ff80e4db32d1d45a0c2afdfd7a1be961c0fbd9d43613a22a989f9024cc1b1e9",
      "pattern": "[file:hashes.'SHA-256' = '0ff80e4db32d1d45a0c2afdfd7a1be961c0fbd9d43613a22a989f9024cc1b1e9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b59fb355-1b87-47ff-9666-6219d9dec1b1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2149d481b863bec2240ffb64c68f7fb437458885c903a7b0c21aa44f88a69d86",
      "pattern": "[file:hashes.'SHA-256' = '2149d481b863bec2240ffb64c68f7fb437458885c903a7b0c21aa44f88a69d86']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e5bad71e-c814-474c-afe9-2d351ab1276b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2e46fcadacfe9e2a63cfc18d95d5870de8b3414462bf14ba9e7c517678f235c9",
      "pattern": "[file:hashes.'SHA-256' = '2e46fcadacfe9e2a63cfc18d95d5870de8b3414462bf14ba9e7c517678f235c9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--30ed7138-b7a2-45bd-b9c9-9121c09a0575",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 386eb7aa33c76ce671d6685f79512597f1fab28ea46c8ec7d89e58340081e2bd",
      "pattern": "[file:hashes.'SHA-256' = '386eb7aa33c76ce671d6685f79512597f1fab28ea46c8ec7d89e58340081e2bd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f57a92f0-dd55-44af-99db-ffefa2ec8c0f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 756ceb563d9283df1fd03252aee9e9621cd2cc7ddb45f596e16660fed1dd6442",
      "pattern": "[file:hashes.'SHA-256' = '756ceb563d9283df1fd03252aee9e9621cd2cc7ddb45f596e16660fed1dd6442']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4ae73f6a-503f-41c6-b715-83b88c689529",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9dc827fb1c2e3c12ee39aa5ccf3b31f64051e0cdda9d2ac54caee6b235f52640",
      "pattern": "[file:hashes.'SHA-256' = '9dc827fb1c2e3c12ee39aa5ccf3b31f64051e0cdda9d2ac54caee6b235f52640']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--06551375-c840-427b-995c-43f6e31502c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: abb2fe1f67a48b931258e47531884ca5502cec73996e686ca82eeba536258f67",
      "pattern": "[file:hashes.'SHA-256' = 'abb2fe1f67a48b931258e47531884ca5502cec73996e686ca82eeba536258f67']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--508f1764-3a08-4472-b169-c56816a4c569",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: eba3138d0f3d2385b55b08d8886b1018834d194440691d33d612402ba8a11d28",
      "pattern": "[file:hashes.'SHA-256' = 'eba3138d0f3d2385b55b08d8886b1018834d194440691d33d612402ba8a11d28']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4e994199-8d51-4d13-afcb-1b3eff9a8280",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-24762",
      "pattern": "[vulnerability:name = 'CVE-2024-24762']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "A denial of service Regex breaks FastAPI security",
          "url": "https://snyk.io/blog/dos-regex-breaks-fastapi-security/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c502381-d6af-4ee0-91a5-e835e2347be6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-28252",
      "pattern": "[vulnerability:name = 'CVE-2023-28252']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-37085 \u2014 VMware ESXi Authentication Bypass",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-28252 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b595170b-1b1f-4e62-8c06-c75f89112252",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-37085",
      "pattern": "[vulnerability:name = 'CVE-2024-37085']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-37085 \u2014 VMware ESXi Authentication Bypass",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fc2106dc-9a98-4218-92db-835212f909e2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-45249",
      "pattern": "[vulnerability:name = 'CVE-2023-45249']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-45249 \u2014 Acronis Cyber Infrastructure (ACI",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c086df87-986a-45ef-9822-33a8e2ed1603",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-4879",
      "pattern": "[vulnerability:name = 'CVE-2024-4879']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-5217 \u2014 ServiceNow Incomplete List of Disa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-4879 \u2014 ServiceNow Improper Input Validati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f1c7e5b-889e-4771-b51c-25ef3cb3937f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-5178",
      "pattern": "[vulnerability:name = 'CVE-2024-5178']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-5217 \u2014 ServiceNow Incomplete List of Disa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-4879 \u2014 ServiceNow Improper Input Validati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ef5d1474-76ed-4bf8-95ec-689c546721de",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-5217",
      "pattern": "[vulnerability:name = 'CVE-2024-5217']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-5217 \u2014 ServiceNow Incomplete List of Disa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-4879 \u2014 ServiceNow Improper Input Validati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ad7ff5cb-78e4-45fd-a424-553335782622",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-4792",
      "pattern": "[vulnerability:name = 'CVE-2012-4792']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-4792 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32e2254c-0cdb-4074-b4de-4ac75a1d33e9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-39891",
      "pattern": "[vulnerability:name = 'CVE-2024-39891']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-39891 \u2014 Twilio Authy Information Disclosu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--570ebf1b-0f98-42d1-bf5a-69ae74835d94",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 48d56ec320ecf6c54a87a7540cf21340",
      "pattern": "[file:hashes.MD5 = '48d56ec320ecf6c54a87a7540cf21340']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-4792 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2c5aeaa-4f39-4e86-9c37-90ff197bbbf2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 2b9f1a858bb8cc18dc1e2184a872c183c327d3d4",
      "pattern": "[file:hashes.'SHA-1' = '2b9f1a858bb8cc18dc1e2184a872c183c327d3d4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-4792 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--adf3c541-47f4-4dd9-8577-a67943caab34",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ac335a4894485859d2cfd24b816f6929831c1e844164ceb2f90cbab5fa671965",
      "pattern": "[file:hashes.'SHA-256' = 'ac335a4894485859d2cfd24b816f6929831c1e844164ceb2f90cbab5fa671965']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-4792 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d0fd6af-346a-470c-885a-cdaef69c05d6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-22948",
      "pattern": "[vulnerability:name = 'CVE-2022-22948']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22948 \u2014 VMware vCenter Server Incorrect D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32b0e4b9-5c55-41ca-849a-b77e28b124cd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-20867",
      "pattern": "[vulnerability:name = 'CVE-2023-20867']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22948 \u2014 VMware vCenter Server Incorrect D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-34048 \u2014 VMware vCenter Server Out-of-Boun",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-20867 \u2014 VMware Tools Authentication Bypas",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6a459634-64eb-4447-9694-7a86679662f9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-28995",
      "pattern": "[vulnerability:name = 'CVE-2024-28995']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-28995 \u2014 SolarWinds Serv-U Path Traversal ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--500dd2ed-7429-429a-aa67-65f1333637eb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-2961",
      "pattern": "[vulnerability:name = 'CVE-2024-2961']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--858f0b9f-2b82-4d4a-8828-6da9673e38ab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-34102",
      "pattern": "[vulnerability:name = 'CVE-2024-34102']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--27e37321-9d2f-4e51-89ec-61746a53ef0b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: analytisgroup.com",
      "pattern": "[domain-name:value = 'analytisgroup.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--03a2a7f5-a4ac-4720-8b36-d7c5e947b258",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: analytisweb.com",
      "pattern": "[domain-name:value = 'analytisweb.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--189936fb-c62a-46f8-90c3-c97843acb0f2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: bingforce.org",
      "pattern": "[domain-name:value = 'bingforce.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--187fa65f-f44b-4bfc-b0e9-fbcf463ea118",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: bystats.io",
      "pattern": "[domain-name:value = 'bystats.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1585cf94-bf8d-4ef0-be97-4ff56a005332",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cdnstatics.net",
      "pattern": "[domain-name:value = 'cdnstatics.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--47a3afe8-37e8-4435-a16c-e722783166ba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: chartismart.com",
      "pattern": "[domain-name:value = 'chartismart.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--898d602e-ad1e-4520-8ff0-f084acab244f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: codecarawan.com",
      "pattern": "[domain-name:value = 'codecarawan.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--09f73d3b-3664-466f-a830-3d7f1997f312",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: creativeslim.com",
      "pattern": "[domain-name:value = 'creativeslim.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f337f03-095e-4d65-8552-432c7f64da2f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: creatls.com",
      "pattern": "[domain-name:value = 'creatls.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--caa15edd-241c-4fcf-90f3-7b53906e680a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: desynlabtech.com",
      "pattern": "[domain-name:value = 'desynlabtech.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9bff9224-43a8-429f-807e-2f057addedeb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: easttrack.net",
      "pattern": "[domain-name:value = 'easttrack.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76e6e1fc-c0ec-42a8-84ac-a1f665eef6d9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: foptimize.net",
      "pattern": "[domain-name:value = 'foptimize.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c67cfa59-e371-4ca1-bd61-a298be18e667",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: gearplace.net",
      "pattern": "[domain-name:value = 'gearplace.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9621b422-89c6-47b0-a619-75325cef8099",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: getstylify.com",
      "pattern": "[domain-name:value = 'getstylify.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fb35380a-f717-49d5-bb6c-dc5ffa78f8d0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: graphiqsw.com",
      "pattern": "[domain-name:value = 'graphiqsw.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a573b8ce-a6cf-4afc-b507-cfeb3f0c975b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: happyllfe.online",
      "pattern": "[domain-name:value = 'happyllfe.online']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f49aeb3c-10c1-436c-8ea7-7e416071b3cc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: horlzonhub.com",
      "pattern": "[domain-name:value = 'horlzonhub.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d603ac4b-24d5-410e-95dd-ea29a6c0b65a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: iconstaff.top",
      "pattern": "[domain-name:value = 'iconstaff.top']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1a2907ba-56d7-438c-8553-facf235d1808",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: infiniboosts.com",
      "pattern": "[domain-name:value = 'infiniboosts.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5e6801bc-f603-4a9a-9d27-f77e19ac19fc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: jquerypackageus.com",
      "pattern": "[domain-name:value = 'jquerypackageus.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87d692ef-f114-4f48-b3c1-32f2f6ac0a03",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: jstatic201.com",
      "pattern": "[domain-name:value = 'jstatic201.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3618836e-d705-4d2a-96b5-96f1723b1651",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: marketiqhub.com",
      "pattern": "[domain-name:value = 'marketiqhub.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--78f526b1-0b82-4030-94be-edabfb6a2b85",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: novastraem.com",
      "pattern": "[domain-name:value = 'novastraem.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c31caf00-84fa-4dcd-89fb-94e5bfca5263",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: quantunnquest.com",
      "pattern": "[domain-name:value = 'quantunnquest.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ad1b903-38d7-4959-ab80-21ba831d83ae",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: radlantroots.com",
      "pattern": "[domain-name:value = 'radlantroots.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--968e5a02-e516-4c8e-9aff-cd0d4b6ad4bf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sellerstat.site",
      "pattern": "[domain-name:value = 'sellerstat.site']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a19d41d6-cc57-4253-b47a-6349997e7061",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sellifypro.com",
      "pattern": "[domain-name:value = 'sellifypro.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a7282bcf-808e-4a5e-9c8b-aa5b74cbcbd4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: statspots.com",
      "pattern": "[domain-name:value = 'statspots.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--69d7352a-c7ef-43cb-8eca-621ae90a99cd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: techtnee.com",
      "pattern": "[domain-name:value = 'techtnee.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3ae6659b-46c6-490c-bd18-2322f78b9f34",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: trendgurupro.com",
      "pattern": "[domain-name:value = 'trendgurupro.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c8d782d9-8820-4789-8732-81caba1a836f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.36.229.32",
      "pattern": "[ipv4-addr:value = '104.36.229.32']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6f8211f0-bf25-4c51-9a39-12348afc7c53",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 106.14.40.200",
      "pattern": "[ipv4-addr:value = '106.14.40.200']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c0e267ef-9613-4080-9434-e8e57fe075e1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 120.245.64.189",
      "pattern": "[ipv4-addr:value = '120.245.64.189']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-28995 \u2014 SolarWinds Serv-U Path Traversal ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2b18623d-67fe-41c1-bf14-52a5486b2570",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 141.98.81.24",
      "pattern": "[ipv4-addr:value = '141.98.81.24']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--61219efc-d3d8-4c5d-9579-6e397c0be436",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 141.98.82.3",
      "pattern": "[ipv4-addr:value = '141.98.82.3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--083df6b2-3256-4f87-abfc-e3a59f8459cd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 146.190.165.100",
      "pattern": "[ipv4-addr:value = '146.190.165.100']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--99991d07-391c-4a6e-a40f-d878f15b90fe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 15.204.207.175",
      "pattern": "[ipv4-addr:value = '15.204.207.175']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c477c9e9-3848-4bb2-9e27-d49670748b31",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 157.230.230.193",
      "pattern": "[ipv4-addr:value = '157.230.230.193']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe432455-d351-4a54-9bfd-24548a5e037c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 159.223.136.255",
      "pattern": "[ipv4-addr:value = '159.223.136.255']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--833fcd44-e27e-453b-934e-ae2218c68dfc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.104.28.240",
      "pattern": "[ipv4-addr:value = '172.104.28.240']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cf236c4f-e260-47bf-b53f-8b25e80d70fc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 173.255.242.28",
      "pattern": "[ipv4-addr:value = '173.255.242.28']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ecc9526b-b4bc-4691-9fd2-56d61c26b9a9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 184.31.15.39",
      "pattern": "[ipv4-addr:value = '184.31.15.39']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a560811f-da67-4657-80b3-05c7b3d9c047",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 184.31.15.70",
      "pattern": "[ipv4-addr:value = '184.31.15.70']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--44b61a39-1b68-4418-b3df-9587898c1115",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.175.225.116",
      "pattern": "[ipv4-addr:value = '185.175.225.116']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--43857ef3-9956-4f0f-b632-6bcf83932673",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.193.126.86",
      "pattern": "[ipv4-addr:value = '185.193.126.86']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--07eb3610-da8d-44b3-b90d-60f9fe7b8948",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.196.10.2",
      "pattern": "[ipv4-addr:value = '185.196.10.2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-28995 \u2014 SolarWinds Serv-U Path Traversal ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6cb5ce2d-667f-47a1-ba4e-52f63ea42c16",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.233.128.167",
      "pattern": "[ipv4-addr:value = '193.233.128.167']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c20064e3-8c40-48df-81ce-581ba961d498",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.233.129.150",
      "pattern": "[ipv4-addr:value = '193.233.129.150']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b16054c9-f2db-45d3-9b4c-bb4aee0cfc3c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.233.130.84",
      "pattern": "[ipv4-addr:value = '193.233.130.84']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a52cc2fa-6da6-4ef2-a72c-fd41b03040b5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.233.216.201",
      "pattern": "[ipv4-addr:value = '193.233.216.201']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b742986-adc1-41a7-ab54-251b75a8af94",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.233.217.12",
      "pattern": "[ipv4-addr:value = '193.233.217.12']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2f0cde40-8bdd-4bce-987f-068cc2d3972f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 217.182.199.126",
      "pattern": "[ipv4-addr:value = '217.182.199.126']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ace49424-7bb6-4115-bdba-d0f48ed6cfa9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 221.4.215.215",
      "pattern": "[ipv4-addr:value = '221.4.215.215']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-28995 \u2014 SolarWinds Serv-U Path Traversal ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4bc7cde-9453-4c2d-93bc-e3bf96a3f97f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 31.134.11.12",
      "pattern": "[ipv4-addr:value = '31.134.11.12']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d3106e2f-db7c-48d9-8267-b9beea0e52db",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 31.134.11.69",
      "pattern": "[ipv4-addr:value = '31.134.11.69']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3c786362-d9be-4ad2-a155-3d7a840277aa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 31.134.13.106",
      "pattern": "[ipv4-addr:value = '31.134.13.106']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d20e7329-3991-4e67-ad25-dc5a5c28fb62",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 37.9.41.91",
      "pattern": "[ipv4-addr:value = '37.9.41.91']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--41812827-5b51-440c-9cd3-38f05a21f818",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 37.9.42.158",
      "pattern": "[ipv4-addr:value = '37.9.42.158']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--25176f33-551a-4c30-9ea5-460c619307a4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 85.239.43.38",
      "pattern": "[ipv4-addr:value = '85.239.43.38']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c202c758-c2d9-42a0-af16-4a3da6e4cfab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 89.110.84.168",
      "pattern": "[ipv4-addr:value = '89.110.84.168']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c6508d17-9cb4-46c1-8aac-b288527ff42b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 91.92.243.104",
      "pattern": "[ipv4-addr:value = '91.92.243.104']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8799cab3-0336-4497-b901-1fc7d14fab62",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 91.92.247.205",
      "pattern": "[ipv4-addr:value = '91.92.247.205']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--90e7ebb4-c38f-4771-b915-74e31e7b538d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 92.112.184.102",
      "pattern": "[ipv4-addr:value = '92.112.184.102']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--baa04b2d-1a46-4275-9d83-7af1fb1d590d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-36401",
      "pattern": "[vulnerability:name = 'CVE-2024-36401']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--726a21d7-9850-443f-a5f7-947041ba0f70",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: 1.download765.online",
      "pattern": "[domain-name:value = '1.download765.online']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b1e7f0d8-cdac-4931-9e6a-7c449b6fc7de",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: 9527527.xyz",
      "pattern": "[domain-name:value = '9527527.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bfd9d325-a987-4c81-9c02-301d99b1c31e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: bots.gxz.me",
      "pattern": "[domain-name:value = 'bots.gxz.me']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--544694fe-4850-4897-b50e-c37bcf706715",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: gsdasdfadfs.9527527.xyz",
      "pattern": "[domain-name:value = 'gsdasdfadfs.9527527.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5b012f9f-91b8-42bf-8a8f-c1c22a1c2398",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: oss.17ww.vip",
      "pattern": "[domain-name:value = 'oss.17ww.vip']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--29a4274a-8e63-42f8-ada5-b85f64cf8e7d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: repositorylinux.com",
      "pattern": "[domain-name:value = 'repositorylinux.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2398ec18-efb5-4b8f-aa55-54981819e1c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sdfasdfsf.9527527.xyz",
      "pattern": "[domain-name:value = 'sdfasdfsf.9527527.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--83ceb216-88ce-487b-b0b7-82fe1ae25116",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: secure.systemupdatecdn.de",
      "pattern": "[domain-name:value = 'secure.systemupdatecdn.de']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2b8bf596-dbfa-4b38-a840-940cf8fe3079",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: trcpay.xyz",
      "pattern": "[domain-name:value = 'trcpay.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7391b074-1536-4cc9-82b6-01fa9a936df1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 112.133.194.254",
      "pattern": "[ipv4-addr:value = '112.133.194.254']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--61340d6e-0195-455d-b74c-563def11a00c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 181.214.58.14",
      "pattern": "[ipv4-addr:value = '181.214.58.14']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2cdf0e86-d181-4755-a7a9-082aa83ae6fc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 188.214.27.50",
      "pattern": "[ipv4-addr:value = '188.214.27.50']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e03c3f73-f296-4eb9-a25f-3e36a0f0463d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 209.146.124.181",
      "pattern": "[ipv4-addr:value = '209.146.124.181']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9dc86291-0d07-46bf-8338-9a0480e23163",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 47.253.46.11",
      "pattern": "[ipv4-addr:value = '47.253.46.11']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--31ec103c-cb40-470e-90b0-fed0fdd5eb52",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 95.85.93.196",
      "pattern": "[ipv4-addr:value = '95.85.93.196']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5966239f-ede7-4c71-b8f0-5184493fc5e2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1588bee7db42495ba7e6e34d217e6b82c5ab93f27c1eea68435cbb9e7792f9be",
      "pattern": "[file:hashes.'SHA-256' = '1588bee7db42495ba7e6e34d217e6b82c5ab93f27c1eea68435cbb9e7792f9be']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--416a70dd-db82-4905-9e35-fe111b3ff904",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1af8e068aa7377f0055640af581a412aa9d7288c912a93dd0d739657af0079fb",
      "pattern": "[file:hashes.'SHA-256' = '1af8e068aa7377f0055640af581a412aa9d7288c912a93dd0d739657af0079fb']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c67648e-7373-4101-a263-2e516c50bc43",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 20d97f144bf7b1662a13ac537715126b9b2f68eff46a4a09234743ae236f0177",
      "pattern": "[file:hashes.'SHA-256' = '20d97f144bf7b1662a13ac537715126b9b2f68eff46a4a09234743ae236f0177']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da3d9830-2db4-4ea7-b8fb-d29ae1686172",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3c73ebc7a85accc65c9ee5bf151f70b990e5a12f27a843ca21c0f9d9a10fd17d",
      "pattern": "[file:hashes.'SHA-256' = '3c73ebc7a85accc65c9ee5bf151f70b990e5a12f27a843ca21c0f9d9a10fd17d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ec1ebdc3-1874-49c2-be3b-2e8b84185a22",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 50b7e615b8cdc45486b6ed1c1c081c7a92c262edb84318fa864531dcab753f82",
      "pattern": "[file:hashes.'SHA-256' = '50b7e615b8cdc45486b6ed1c1c081c7a92c262edb84318fa864531dcab753f82']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6b44d9a2-d3d5-443e-9c75-150d518d1142",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 53994a35a57970dea48e97009f65ad045b69a83234b771b106446211376a6866",
      "pattern": "[file:hashes.'SHA-256' = '53994a35a57970dea48e97009f65ad045b69a83234b771b106446211376a6866']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6a89c3df-2938-4b3b-a2a0-8d0d150cf1e5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5cc7e35254347f705422800bfb7fe29c6002e2537f6bac0ff996a720dfb5f48e",
      "pattern": "[file:hashes.'SHA-256' = '5cc7e35254347f705422800bfb7fe29c6002e2537f6bac0ff996a720dfb5f48e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--23edb1cc-cc9c-4dcc-9d7b-f3991fb23ede",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7194ec436231c2a383ffc7c75eef4f5b5a952c18fa176ffd0830667835a80533",
      "pattern": "[file:hashes.'SHA-256' = '7194ec436231c2a383ffc7c75eef4f5b5a952c18fa176ffd0830667835a80533']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32cd0879-5e91-40c7-ac67-65fd3eebbf86",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 79c9532fb6ef2742e207498bfe2b2ee09aa9773376ac0e56085083aab17b98be",
      "pattern": "[file:hashes.'SHA-256' = '79c9532fb6ef2742e207498bfe2b2ee09aa9773376ac0e56085083aab17b98be']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--387b6946-755c-412f-8067-e8288d9c92a0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 83fb74bb852bbd722e6ebc4e249e49cb4bb4194493a26d62d4bfcdfca2998412",
      "pattern": "[file:hashes.'SHA-256' = '83fb74bb852bbd722e6ebc4e249e49cb4bb4194493a26d62d4bfcdfca2998412']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a9ea27bc-e8c4-4393-b050-2b2bd5ba2dd5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8d3440301bc94ed83cdafb69e4b0166d3a0020eb4f38e9fa159c2f13f14b2d29",
      "pattern": "[file:hashes.'SHA-256' = '8d3440301bc94ed83cdafb69e4b0166d3a0020eb4f38e9fa159c2f13f14b2d29']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--630a7058-f5d0-4b3b-b3ba-4c24d0da2950",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 96cf27a66b629d2b19708c6887441a8422b40dc0e9e7c5c0f2212efe0b6b3323",
      "pattern": "[file:hashes.'SHA-256' = '96cf27a66b629d2b19708c6887441a8422b40dc0e9e7c5c0f2212efe0b6b3323']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8e1d09d-a364-4574-8d2d-ea14541b406a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 994b924b00fb56e12a6a987c4cdf65dd05a221c47b5fc0a7a2babf1f05c2ed38",
      "pattern": "[file:hashes.'SHA-256' = '994b924b00fb56e12a6a987c4cdf65dd05a221c47b5fc0a7a2babf1f05c2ed38']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a0028ec8-d6b1-4da3-8b81-acfa8da4117f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9bf642a7e14f0a0b0a784f00a0d1cf590ac60ae5ae378d29d435519f4d9dbf2b",
      "pattern": "[file:hashes.'SHA-256' = '9bf642a7e14f0a0b0a784f00a0d1cf590ac60ae5ae378d29d435519f4d9dbf2b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea995e6e-be42-40e7-a589-1d5e50ba3f78",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a13a979f4ca57450528bb6cd7aa2bf47d2eea211053eb1a14b8c4a44fd661831",
      "pattern": "[file:hashes.'SHA-256' = 'a13a979f4ca57450528bb6cd7aa2bf47d2eea211053eb1a14b8c4a44fd661831']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b5684df4-0eb3-456e-bf82-84eaa994260e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a9e7b5284182d3881c865895ee6e0fb03273eec3dcbf4bfc82dd2b069245beae",
      "pattern": "[file:hashes.'SHA-256' = 'a9e7b5284182d3881c865895ee6e0fb03273eec3dcbf4bfc82dd2b069245beae']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fa2b0da1-b75a-4cad-9182-a745dc24d794",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: addccd0ecb643251af2e79e878b19a8e9c8f1c87302e732ef057cdba821f4b30",
      "pattern": "[file:hashes.'SHA-256' = 'addccd0ecb643251af2e79e878b19a8e9c8f1c87302e732ef057cdba821f4b30']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe99b90d-d36e-43a5-8ae5-4c30ab719062",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b3a015b6650ec9800fa878ff9a5f732013806c8dcb0e7069515dae0dd380fda4",
      "pattern": "[file:hashes.'SHA-256' = 'b3a015b6650ec9800fa878ff9a5f732013806c8dcb0e7069515dae0dd380fda4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3f50dbd2-27d2-49c0-ace9-e679b1039872",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b60d7fb66caf103a04e81fb89dbb05111b4b0ef513f3769c8e0a8106ab01a075",
      "pattern": "[file:hashes.'SHA-256' = 'b60d7fb66caf103a04e81fb89dbb05111b4b0ef513f3769c8e0a8106ab01a075']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--88d7fc53-0c48-45b9-83e1-832c56fc321e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b67ab1b9b66fdc2c4ed1689698a54a347c2bdd6eaff87039ae337675243670d8",
      "pattern": "[file:hashes.'SHA-256' = 'b67ab1b9b66fdc2c4ed1689698a54a347c2bdd6eaff87039ae337675243670d8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c9918c7-c4bd-4f7f-bac2-aef3c9e2cead",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b80e9466b7bb42959c29546b8c052e67fcaa0f591857617457d5d28348bd8860",
      "pattern": "[file:hashes.'SHA-256' = 'b80e9466b7bb42959c29546b8c052e67fcaa0f591857617457d5d28348bd8860']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--08bb0192-ede2-4af2-ace1-d5f4d83c2ba9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c226744b40e8f5d2cf95b4fb2537ff00e222ecc2d24c5096ecfadb14b4a47f97",
      "pattern": "[file:hashes.'SHA-256' = 'c226744b40e8f5d2cf95b4fb2537ff00e222ecc2d24c5096ecfadb14b4a47f97']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--86724f9d-1384-4e72-84bb-f73171f21d64",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c3101b0b74d76a95ba91b6cc4945657e928d2dac8fdf926ffbf09031d46e9186",
      "pattern": "[file:hashes.'SHA-256' = 'c3101b0b74d76a95ba91b6cc4945657e928d2dac8fdf926ffbf09031d46e9186']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--41510c68-873f-4ca2-ac0d-86cad03f9fb0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d9dfe98b5fba09e17dbe29dfeb8deb7d777d4a3b0d670914691ed360b916116a",
      "pattern": "[file:hashes.'SHA-256' = 'd9dfe98b5fba09e17dbe29dfeb8deb7d777d4a3b0d670914691ed360b916116a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6c16690d-e74a-4e86-a74d-1d172a94143c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d9e8b390f8e2e8a6c2308c723a6a812f59c055ecad4e9098a120e5c4c65d3905",
      "pattern": "[file:hashes.'SHA-256' = 'd9e8b390f8e2e8a6c2308c723a6a812f59c055ecad4e9098a120e5c4c65d3905']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6eb70fe-88df-412a-abe4-4b18b79d1e51",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e8b0f5a952f07c83c4d67809ac0715c7164d518323d8038542e84aab8456db43",
      "pattern": "[file:hashes.'SHA-256' = 'e8b0f5a952f07c83c4d67809ac0715c7164d518323d8038542e84aab8456db43']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1548f813-467b-403c-9651-d3d4ef372816",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f3d3572ef96c9c59e137425ca6804e1b86b7f8b57210a3724d567017460774de",
      "pattern": "[file:hashes.'SHA-256' = 'f3d3572ef96c9c59e137425ca6804e1b86b7f8b57210a3724d567017460774de']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0d09be01-e41c-4985-b2c3-430db3f081d7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f7b97677b6387c1f02d429e98868bf6973a8dec14dfee2516a27e885d6b1c780",
      "pattern": "[file:hashes.'SHA-256' = 'f7b97677b6387c1f02d429e98868bf6973a8dec14dfee2516a27e885d6b1c780']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4581a29-2688-48ee-b1f1-2e86e20a6b86",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: fabbb4611fb9df5d8f208d9353be0b73c3942fe78903da096cbfe2f47c9e3566",
      "pattern": "[file:hashes.'SHA-256' = 'fabbb4611fb9df5d8f208d9353be0b73c3942fe78903da096cbfe2f47c9e3566']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b2330de-e3a6-4201-8c9f-344f8d114d2a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-23692",
      "pattern": "[vulnerability:name = 'CVE-2024-23692']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-23692 \u2014 Rejetto HTTP File Server Improper",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2a07c91c-a467-4290-af6c-dc331698868a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-38080",
      "pattern": "[vulnerability:name = 'CVE-2024-38080']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-38080 \u2014 Microsoft Windows Hyper-V Privile",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c20463ee-5972-4c09-a7ec-6ae0886711ca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-20399",
      "pattern": "[vulnerability:name = 'CVE-2024-20399']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20399 \u2014 Cisco NX-OS Command Injection Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8220743-2f05-4543-a566-60729b36ae71",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-13965",
      "pattern": "[vulnerability:name = 'CVE-2020-13965']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-13965 \u2014 Roundcube Webmail Cross-Site Scri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c0fd6f4a-fce0-49bd-8cd2-ed6f4a076954",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-24816",
      "pattern": "[vulnerability:name = 'CVE-2022-24816']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24816 \u2014 OSGeo GeoServer JAI-EXT Code Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8fb67ca9-68b6-4157-b0d8-cf0726dfd116",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-2586",
      "pattern": "[vulnerability:name = 'CVE-2022-2586']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-2586 \u2014 Linux Kernel Use-After-Free Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ea4174a-e529-4423-be48-427387f78612",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-38526",
      "pattern": "[vulnerability:name = 'CVE-2024-38526']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Polyfill supply chain attack embeds malware in JavaScript CD",
          "url": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ffb5d065-be24-4283-8d82-1725e8ba84a0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: 5f52353c.u.fn03.vip",
      "pattern": "[domain-name:value = '5f52353c.u.fn03.vip']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Polyfill supply chain attack embeds malware in JavaScript CD",
          "url": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--00821b95-5b34-475a-ad41-27c04f94e34a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: bootcdn.net",
      "pattern": "[domain-name:value = 'bootcdn.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Polyfill supply chain attack embeds malware in JavaScript CD",
          "url": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--905fb6ba-3505-4846-a068-5d4114d41093",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: bootcss.com",
      "pattern": "[domain-name:value = 'bootcss.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Polyfill supply chain attack embeds malware in JavaScript CD",
          "url": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--26311c48-a1a0-4469-9247-a88ffe12ab84",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cdn.polyfill.io",
      "pattern": "[domain-name:value = 'cdn.polyfill.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Polyfill supply chain attack embeds malware in JavaScript CD",
          "url": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4e89c46e-a2ff-43bb-9f27-2445e46782f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cdn.polyfill.io.bsclink.cn",
      "pattern": "[domain-name:value = 'cdn.polyfill.io.bsclink.cn']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Polyfill supply chain attack embeds malware in JavaScript CD",
          "url": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4ef181c6-91c1-47b4-92e4-7d84c970d697",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: googie-anaiytics.com",
      "pattern": "[domain-name:value = 'googie-anaiytics.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Polyfill supply chain attack embeds malware in JavaScript CD",
          "url": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--31f25e89-466e-4e29-a4e7-b030ca995ee8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: kuurza.com",
      "pattern": "[domain-name:value = 'kuurza.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Polyfill supply chain attack embeds malware in JavaScript CD",
          "url": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e2d6c406-5b5f-4af1-bd96-0dac37273daf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: newcrbpc.com",
      "pattern": "[domain-name:value = 'newcrbpc.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Polyfill supply chain attack embeds malware in JavaScript CD",
          "url": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e9fbc101-d28d-4565-836d-e5c42022748f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: polyfill.com",
      "pattern": "[domain-name:value = 'polyfill.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Polyfill supply chain attack embeds malware in JavaScript CD",
          "url": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--898ed796-083d-419c-b490-8662d5777a48",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: polyfill.io",
      "pattern": "[domain-name:value = 'polyfill.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Polyfill supply chain attack embeds malware in JavaScript CD",
          "url": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9dc3298a-52e0-461f-8337-7dbf6c6e8e5b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: polyfill.io.bsclink.cn",
      "pattern": "[domain-name:value = 'polyfill.io.bsclink.cn']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Polyfill supply chain attack embeds malware in JavaScript CD",
          "url": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1595b43f-2c9f-4073-abe8-8493d162c57b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: polyfill.site",
      "pattern": "[domain-name:value = 'polyfill.site']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Polyfill supply chain attack embeds malware in JavaScript CD",
          "url": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7d110b42-311f-4015-a03f-02da4e384379",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: polyfillcache.com",
      "pattern": "[domain-name:value = 'polyfillcache.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Polyfill supply chain attack embeds malware in JavaScript CD",
          "url": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dcae51cf-f318-4676-9313-78f489209deb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: staticfile.net",
      "pattern": "[domain-name:value = 'staticfile.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Polyfill supply chain attack embeds malware in JavaScript CD",
          "url": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2f4733a9-ab81-4e9c-8691-6e10ee34e871",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: staticfile.org",
      "pattern": "[domain-name:value = 'staticfile.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Polyfill supply chain attack embeds malware in JavaScript CD",
          "url": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b84303b7-ffef-4892-8ef4-7faa25036896",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: union.macoms.la",
      "pattern": "[domain-name:value = 'union.macoms.la']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Polyfill supply chain attack embeds malware in JavaScript CD",
          "url": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--39ea9fa8-40c4-4c30-87a1-fa460f7cb7ca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: unionadjs.com",
      "pattern": "[domain-name:value = 'unionadjs.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Polyfill supply chain attack embeds malware in JavaScript CD",
          "url": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7d326281-7d2d-4b45-ad40-7e7d4af905ef",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: w9.vty70.net",
      "pattern": "[domain-name:value = 'w9.vty70.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Polyfill supply chain attack embeds malware in JavaScript CD",
          "url": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e3d8a8d1-0e8b-4a83-8bcb-4f1e1dbccaf6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: wildcard.polyfill.io.bsclink.cn",
      "pattern": "[domain-name:value = 'wildcard.polyfill.io.bsclink.cn']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Polyfill supply chain attack embeds malware in JavaScript CD",
          "url": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--424ddeb5-dd54-412c-afac-6ce461707e9f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: xhsbpza.com",
      "pattern": "[domain-name:value = 'xhsbpza.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Polyfill supply chain attack embeds malware in JavaScript CD",
          "url": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2eca45e5-7b9a-4cb8-84b9-446bfd72a934",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-1800",
      "pattern": "[vulnerability:name = 'CVE-2024-1800']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4358 \u2014 Progress Telerik Report Server Aut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--636ba453-de8e-4fda-907a-51b61ac7dcb6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-26169",
      "pattern": "[vulnerability:name = 'CVE-2024-26169']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ad441f9-4b98-490e-a5e6-e252705e005e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-32896",
      "pattern": "[vulnerability:name = 'CVE-2024-32896']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-32896 \u2014 Android Pixel Privilege Escalatio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--17b34b48-1d60-47f6-aba8-9418ded86d3b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-4358",
      "pattern": "[vulnerability:name = 'CVE-2024-4358']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4358 \u2014 Progress Telerik Report Server Aut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd60aca6-594e-4db8-bb03-aad404390ee7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 1984cd0bf7b20c5bef58338f80e4e65e",
      "pattern": "[file:hashes.MD5 = '1984cd0bf7b20c5bef58338f80e4e65e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f617bd2f-b830-4636-b7f4-cae40fc5959c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: acaf01f83da439915027c3e2e900c8dd",
      "pattern": "[file:hashes.MD5 = 'acaf01f83da439915027c3e2e900c8dd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c593b24a-5d19-4e54-b86f-d19bdde51969",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: f17918862a190afd4649b2a6b4a34b5c",
      "pattern": "[file:hashes.MD5 = 'f17918862a190afd4649b2a6b4a34b5c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a92adbf9-da29-4266-be1c-ae26c9bbd92a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: ff217dab57393592c6767de1c6a999eb",
      "pattern": "[file:hashes.MD5 = 'ff217dab57393592c6767de1c6a999eb']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cd4fb866-8894-4504-9516-70300f81bfdf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 2861b4e463fa89e05f2d7d629fae5140cef49843",
      "pattern": "[file:hashes.'SHA-1' = '2861b4e463fa89e05f2d7d629fae5140cef49843']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--91f6be18-b476-4361-8394-9031287b5f72",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 4ea121b4b45bab1e17fae11c8cce30241f5f8a75",
      "pattern": "[file:hashes.'SHA-1' = '4ea121b4b45bab1e17fae11c8cce30241f5f8a75']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--feedb3a4-c28c-44a1-8ff2-35d0c77064f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: b4b5963c62c07c2adcee093571afd0e9e765de3b",
      "pattern": "[file:hashes.'SHA-1' = 'b4b5963c62c07c2adcee093571afd0e9e765de3b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--00e02158-f3b9-4a8e-8598-33b9f0422ead",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: cc580c52f4263803255d65dfb6ab208be7f4a534",
      "pattern": "[file:hashes.'SHA-1' = 'cc580c52f4263803255d65dfb6ab208be7f4a534']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1174c4c1-7aeb-448b-a693-1fe1fc5cf131",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2408be22f6184cdccec7a34e2e79711ff4957e42f1ed7b7ad63f914d37dba625",
      "pattern": "[file:hashes.'SHA-256' = '2408be22f6184cdccec7a34e2e79711ff4957e42f1ed7b7ad63f914d37dba625']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4d52c642-65e0-4489-b94d-ff8e483e6684",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3b3bd81232f517ba6d65c7838c205b301b0f27572fcfef9e5b86dd30a1d55a0d",
      "pattern": "[file:hashes.'SHA-256' = '3b3bd81232f517ba6d65c7838c205b301b0f27572fcfef9e5b86dd30a1d55a0d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d72f02e8-3957-4755-92fe-fcfdc45203a0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4aae231fb5357c0647483181aeae47956ac66e42b6b134f5b90da76d8ec0ac63",
      "pattern": "[file:hashes.'SHA-256' = '4aae231fb5357c0647483181aeae47956ac66e42b6b134f5b90da76d8ec0ac63']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e4101f90-772c-4d51-bbd2-4dd19852aa1f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a31e075bd5a2652917f91714fea4d272816c028d7734b36c84899cd583181b3d",
      "pattern": "[file:hashes.'SHA-256' = 'a31e075bd5a2652917f91714fea4d272816c028d7734b36c84899cd583181b3d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--16eeb56a-d401-4df7-a442-ca34aa372022",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b0903921e666ca3ffd45100a38c11d7e5c53ab38646715eafc6d1851ad41b92e",
      "pattern": "[file:hashes.'SHA-256' = 'b0903921e666ca3ffd45100a38c11d7e5c53ab38646715eafc6d1851ad41b92e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--08e03832-8c9c-4e8e-92d9-2c54d509fa58",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b73a7e25d224778172e394426c98b86215087d815296c71a3f76f738c720c1b0",
      "pattern": "[file:hashes.'SHA-256' = 'b73a7e25d224778172e394426c98b86215087d815296c71a3f76f738c720c1b0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b4dbb6c2-15ca-4abf-a745-8b36a25fb70c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-1823",
      "pattern": "[vulnerability:name = 'CVE-2012-1823']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4577 \u2014 PHP-CGI OS Command Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2012-1823 \u2014 PHP-CGI Query String Parameter Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6893258f-ccfe-4e82-bb5a-7cfc7f95cf54",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-4610",
      "pattern": "[vulnerability:name = 'CVE-2024-4610']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4610 \u2014 Arm Mali GPU Kernel Driver Use-Aft",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a1727373-63ab-477c-b66d-28babf85ce13",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 178.16.55.224",
      "pattern": "[ipv4-addr:value = '178.16.55.224']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4577 \u2014 PHP-CGI OS Command Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d3133bbf-e27e-44e6-9358-eabfa468f0f2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 88.218.76.13",
      "pattern": "[ipv4-addr:value = '88.218.76.13']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4577 \u2014 PHP-CGI OS Command Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--65537390-a7dd-45a1-8e04-14316be5ed2e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5a2b9ddddea96f21d905036761ab27627bd6db4f5973b006f1e39d4acb04a618",
      "pattern": "[file:hashes.'SHA-256' = '5a2b9ddddea96f21d905036761ab27627bd6db4f5973b006f1e39d4acb04a618']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4577 \u2014 PHP-CGI OS Command Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4709e92f-bd89-4d5e-86be-3963be76e067",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 95279881525d4ed4ce25777bb967ab87659e7f72235b76f9530456b48a00bac3",
      "pattern": "[file:hashes.'SHA-256' = '95279881525d4ed4ce25777bb967ab87659e7f72235b76f9530456b48a00bac3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4577 \u2014 PHP-CGI OS Command Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d353b1ed-f73a-42a2-b648-870d412921ba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9562ad2c173b107a2baa7a4986825b52e881a935deb4356bf8b80b1ec6d41c53",
      "pattern": "[file:hashes.'SHA-256' = '9562ad2c173b107a2baa7a4986825b52e881a935deb4356bf8b80b1ec6d41c53']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4577 \u2014 PHP-CGI OS Command Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--45ad9b66-2e3b-449e-8f5d-3c9f0f87dcae",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-10271",
      "pattern": "[vulnerability:name = 'CVE-2017-10271']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7eaeb145-cc5f-4a9d-9dac-abd83917f786",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-3506",
      "pattern": "[vulnerability:name = 'CVE-2017-3506']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--357bffb4-bcab-4659-9b05-c5dddcfcb4f2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-21839",
      "pattern": "[vulnerability:name = 'CVE-2023-21839']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-21839 \u2014 Oracle WebLogic Server Unspecifie",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--288420a6-7b1c-40be-ba3c-ec2001082934",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: su-94.letmaker.top",
      "pattern": "[domain-name:value = 'su-94.letmaker.top']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b8f2208d-5280-4e7e-b1c3-db4b3a1cb0fc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: work.letmaker.top",
      "pattern": "[domain-name:value = 'work.letmaker.top']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--97b5eb78-3952-4b62-92dd-e168a8c83245",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 179.43.155.202",
      "pattern": "[ipv4-addr:value = '179.43.155.202']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3f1853c6-1b20-4ae1-9ef1-1e4107d0a922",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 217.182.205.238",
      "pattern": "[ipv4-addr:value = '217.182.205.238']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--abb6e316-3e9d-4e18-9c50-3d9313add3cf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 79.110.49.232",
      "pattern": "[ipv4-addr:value = '79.110.49.232']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bf2aa3d9-5dfc-4019-a277-682bc6a70fbc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 87.121.105.232",
      "pattern": "[ipv4-addr:value = '87.121.105.232']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--157d0fe4-ab21-49b8-9886-e40f63b73b82",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 89.169.52.37",
      "pattern": "[ipv4-addr:value = '89.169.52.37']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ba985da5-2121-477d-aeb8-98e14a249af2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 89.185.85.102",
      "pattern": "[ipv4-addr:value = '89.185.85.102']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e845745b-b72b-4c87-a36a-6a6906f00564",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 0bf87b0e65713bf35c8cf54c9fa0015fa629624fd590cb4ba941cd7cdeda8050",
      "pattern": "[file:hashes.'SHA-256' = '0bf87b0e65713bf35c8cf54c9fa0015fa629624fd590cb4ba941cd7cdeda8050']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f051dd0c-c577-4cd2-acc7-132a36e6fe52",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2e32c5cea00f8e4c808eae806b14585e8672385df7449d2f6575927537ce8884",
      "pattern": "[file:hashes.'SHA-256' = '2e32c5cea00f8e4c808eae806b14585e8672385df7449d2f6575927537ce8884']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4414c5df-da21-47ed-9973-e0a74917e677",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b380b771c7f5c2c26750e281101873772e10c8c1a0d2a2ff0aff1912b569ab93",
      "pattern": "[file:hashes.'SHA-256' = 'b380b771c7f5c2c26750e281101873772e10c8c1a0d2a2ff0aff1912b569ab93']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--afd73ebf-5e1a-4550-9ebd-36f1643c50cd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e6e69e85962a402a35cbc5b75571dab3739c0b2f3861ba5853dbd140bae4e4da",
      "pattern": "[file:hashes.'SHA-256' = 'e6e69e85962a402a35cbc5b75571dab3739c0b2f3861ba5853dbd140bae4e4da']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--25fa0810-afd7-40c1-8f78-19b24619ba94",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f4d11b36a844a68bf9718cf720984468583efa6664fc99966115a44b9a20aa33",
      "pattern": "[file:hashes.'SHA-256' = 'f4d11b36a844a68bf9718cf720984468583efa6664fc99966115a44b9a20aa33']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7e6649c4-83e5-41a8-9ef3-8d57cb1a5176",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-1086",
      "pattern": "[vulnerability:name = 'CVE-2024-1086']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1086 \u2014 Linux Kernel Use-After-Free Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f84d9722-8ece-4fe2-9590-28d05fbc4871",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-24919",
      "pattern": "[vulnerability:name = 'CVE-2024-24919']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-24919 \u2014 Check Point Quantum Security Gate",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--40c837ef-42d0-4673-9b91-761ef2fc7b5f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 125.229.221.55",
      "pattern": "[ipv4-addr:value = '125.229.221.55']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-24919 \u2014 Check Point Quantum Security Gate",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--757c3e33-986e-44db-82f8-6420efe4d7b7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.88.91.78",
      "pattern": "[ipv4-addr:value = '45.88.91.78']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-24919 \u2014 Check Point Quantum Security Gate",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a181cdc2-9ba8-475d-8478-7cb330166411",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d1e32373f9a5dab0cc79f785f8533d784e06e3205243ab4e85123158f023abee",
      "pattern": "[file:hashes.'SHA-256' = 'd1e32373f9a5dab0cc79f785f8533d784e06e3205243ab4e85123158f023abee']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1086 \u2014 Linux Kernel Use-After-Free Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--261ba610-da52-4a6c-a8f7-e227b413b896",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-4978",
      "pattern": "[vulnerability:name = 'CVE-2024-4978']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4978 \u2014 Justice AV Solutions (JAVS) Viewer",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c5afefa-6d8a-4e79-981a-ff56c2a68802",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.120.177.178",
      "pattern": "[ipv4-addr:value = '45.120.177.178']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4978 \u2014 Justice AV Solutions (JAVS) Viewer",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--99f8fcfd-64f8-4c83-90fe-9fafc6478fdb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2183c102c107d11ae8aa1e9c0f2af3dc8fa462d0683a033d62a982364a0100d0",
      "pattern": "[file:hashes.'SHA-256' = '2183c102c107d11ae8aa1e9c0f2af3dc8fa462d0683a033d62a982364a0100d0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4978 \u2014 Justice AV Solutions (JAVS) Viewer",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dfcbf63c-ff03-47de-8b2f-ad89fa47c197",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4150452d8041a6ec73c447cbe3b1422203fffdfbf5c845dbac1bed74b33a5e09",
      "pattern": "[file:hashes.'SHA-256' = '4150452d8041a6ec73c447cbe3b1422203fffdfbf5c845dbac1bed74b33a5e09']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4978 \u2014 Justice AV Solutions (JAVS) Viewer",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--950b7447-9369-4cac-9b14-a3d2125f7dc6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 421a4ad2615941b177b6ec4ab5e239c14e62af2ab07c6df1741e2a62223223c4",
      "pattern": "[file:hashes.'SHA-256' = '421a4ad2615941b177b6ec4ab5e239c14e62af2ab07c6df1741e2a62223223c4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4978 \u2014 Justice AV Solutions (JAVS) Viewer",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7299ef0c-c398-4308-8783-6d1b73070c03",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4f0ca76987edfe00022c8b9c48ad239229ea88532e2b7a7cd6811ae353cd1eda",
      "pattern": "[file:hashes.'SHA-256' = '4f0ca76987edfe00022c8b9c48ad239229ea88532e2b7a7cd6811ae353cd1eda']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4978 \u2014 Justice AV Solutions (JAVS) Viewer",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e7de0300-0ae7-458a-ab00-b36435f78c19",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a5e24c10d595969858af422c6dff6bed5f9c6c49dc9622d694327323d8a57d72",
      "pattern": "[file:hashes.'SHA-256' = 'a5e24c10d595969858af422c6dff6bed5f9c6c49dc9622d694327323d8a57d72']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4978 \u2014 Justice AV Solutions (JAVS) Viewer",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e0fff7c4-992f-4dc6-a551-ffb1915a89e2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c65ee0f73f53b287654b6446ffe7264e0d93b24302e7f0036f5e7db3748749b9",
      "pattern": "[file:hashes.'SHA-256' = 'c65ee0f73f53b287654b6446ffe7264e0d93b24302e7f0036f5e7db3748749b9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4978 \u2014 Justice AV Solutions (JAVS) Viewer",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--29ad2ac1-f693-4c61-b3a2-050d90fc6c6c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d8def4437bd76279ec6351b65156d670ec0fed24d904e6648de536fed1061671",
      "pattern": "[file:hashes.'SHA-256' = 'd8def4437bd76279ec6351b65156d670ec0fed24d904e6648de536fed1061671']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4978 \u2014 Justice AV Solutions (JAVS) Viewer",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1db3741e-0fea-4bcf-a1a6-6f8225dd559b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f8a734d5e7a7b99b29182dddf804d5daa9d876bf39ce7a04721794367a73da51",
      "pattern": "[file:hashes.'SHA-256' = 'f8a734d5e7a7b99b29182dddf804d5daa9d876bf39ce7a04721794367a73da51']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4978 \u2014 Justice AV Solutions (JAVS) Viewer",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dea13e32-1299-41ae-a2a1-afb0daba4bb4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: fe408e2df48237b11cb724fa51b6d5e9c74c8f5d5b2955c22962095c7ed70b2c",
      "pattern": "[file:hashes.'SHA-256' = 'fe408e2df48237b11cb724fa51b6d5e9c74c8f5d5b2955c22962095c7ed70b2c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4978 \u2014 Justice AV Solutions (JAVS) Viewer",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--974d05bb-fae3-4f82-8abc-c79f621a8548",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-5274",
      "pattern": "[vulnerability:name = 'CVE-2024-5274']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-5274 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--65fce94f-06ab-45f0-a476-477dad5fa169",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-17519",
      "pattern": "[vulnerability:name = 'CVE-2020-17519']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-17519 \u2014 Apache Flink Improper Access Cont",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5e278313-44c8-4bc8-ba5f-3fa51254e116",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-37679",
      "pattern": "[vulnerability:name = 'CVE-2023-37679']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-43208 \u2014 NextGen Healthcare Mirth Connect ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1b08b03e-c60f-4e5a-aa53-fdb2ab81ac9d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-43208",
      "pattern": "[vulnerability:name = 'CVE-2023-43208']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-43208 \u2014 NextGen Healthcare Mirth Connect ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e7e58301-7f0c-4256-87d2-874edb3202d2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-4947",
      "pattern": "[vulnerability:name = 'CVE-2024-4947']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4947 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--03ef7e66-f485-4c79-b465-a576f771d65c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: api.detankzone.com",
      "pattern": "[domain-name:value = 'api.detankzone.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4947 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--89c60d19-f273-4a55-886c-5afb0cf86cac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ccwaterfall.com",
      "pattern": "[domain-name:value = 'ccwaterfall.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4947 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cac021c5-7300-40ad-a25e-d706ae7b911a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: detankzone.com",
      "pattern": "[domain-name:value = 'detankzone.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4947 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fa25c101-0dda-4e99-9d13-f1a8356876df",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 8312e556c4eec999204368d69ba91bf4",
      "pattern": "[file:hashes.MD5 = '8312e556c4eec999204368d69ba91bf4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4947 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8a545139-5d59-4491-b9d6-492554604d8e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: b2dc7aec2c6d2ffa28219ac288e4750c",
      "pattern": "[file:hashes.MD5 = 'b2dc7aec2c6d2ffa28219ac288e4750c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4947 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7af13e86-1a7c-48f3-9235-8d7772f17f87",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 7f28ad5ee9966410b15ca85b7facb70088a17c5f",
      "pattern": "[file:hashes.'SHA-1' = '7f28ad5ee9966410b15ca85b7facb70088a17c5f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4947 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--27d49367-601d-495f-b87b-ac31e024fbe2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: e5da4ab6366c5690dfd1bb386c7fe0c78f6ed54f",
      "pattern": "[file:hashes.'SHA-1' = 'e5da4ab6366c5690dfd1bb386c7fe0c78f6ed54f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4947 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b8f7b7a-08bf-4935-858a-f30bfba5f9e5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 59a37d7d2bf4cffe31407edd286a811d9600b68fe757829e30da4394ab65a4cc",
      "pattern": "[file:hashes.'SHA-256' = '59a37d7d2bf4cffe31407edd286a811d9600b68fe757829e30da4394ab65a4cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4947 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ee27a5db-32d0-4207-bf58-099d9030602c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7353ab9670133468081305bd442f7691cf2f2c1136f09d9508400546c417833a",
      "pattern": "[file:hashes.'SHA-256' = '7353ab9670133468081305bd442f7691cf2f2c1136f09d9508400546c417833a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4947 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a5bab967-edbc-48d8-b3b1-e23728db6ba1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-100005",
      "pattern": "[vulnerability:name = 'CVE-2014-100005']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-100005 \u2014 D-Link DIR-600 Router Cross-Site",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--450440bd-a5ed-48c9-ac1d-75033870798d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-40655",
      "pattern": "[vulnerability:name = 'CVE-2021-40655']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-40655 \u2014 D-Link DIR-605 Router Information",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f7351bb7-199c-4e06-8f57-f948575f6441",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-4761",
      "pattern": "[vulnerability:name = 'CVE-2024-4761']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4761 \u2014 Google Chromium V8 Out-of-Bounds M",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--45390582-f2f7-49aa-8eb9-bee9f59b1f54",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-30040",
      "pattern": "[vulnerability:name = 'CVE-2024-30040']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-30040 \u2014 Microsoft Windows MSHTML Platform",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c4fcac11-ee04-4faa-8318-6c3fe1ac2766",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-30051",
      "pattern": "[vulnerability:name = 'CVE-2024-30051']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-30051 \u2014  Microsoft DWM Core Library Privi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ecdee6e3-7476-476c-b4a4-cd783c2c2516",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-4671",
      "pattern": "[vulnerability:name = 'CVE-2024-4671']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-4671 \u2014 Google Chromium Visuals Use-After-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bf875d32-09f9-4be7-a43d-311e5c857730",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-7028",
      "pattern": "[vulnerability:name = 'CVE-2023-7028']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7028 \u2014 GitLab Community and Enterprise Ed",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--51a5ab8e-cfce-435f-998d-92ed61baae94",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-20353",
      "pattern": "[vulnerability:name = 'CVE-2024-20353']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--049b1ca8-588f-4604-b4cc-c69d8b6c04f0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-20358",
      "pattern": "[vulnerability:name = 'CVE-2024-20358']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53374343-70be-4d11-9c67-e19aa0bd6482",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-20359",
      "pattern": "[vulnerability:name = 'CVE-2024-20359']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9f6b0ad3-1fc9-4aa4-841b-f8f3a7f71ff8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.114.200.230",
      "pattern": "[ipv4-addr:value = '103.114.200.230']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1431829d-32e6-4fdf-8ed4-f3f912278d35",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 121.227.168.69",
      "pattern": "[ipv4-addr:value = '121.227.168.69']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--29399a06-843a-441e-894a-bd78e870fdfe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 131.196.252.148",
      "pattern": "[ipv4-addr:value = '131.196.252.148']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9675f482-41e7-4b83-b092-7d740c0f47c6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.105.90.154",
      "pattern": "[ipv4-addr:value = '172.105.90.154']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b7549256-ed68-4543-bc77-9d250d4bf5e4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.105.94.93",
      "pattern": "[ipv4-addr:value = '172.105.94.93']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1ffe683c-cee2-4091-b347-367e36d6bdfa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 176.31.18.153",
      "pattern": "[ipv4-addr:value = '176.31.18.153']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1368768e-4e7d-406d-b0dd-3af5b01d3a90",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.167.60.85",
      "pattern": "[ipv4-addr:value = '185.167.60.85']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e1461281-ea94-4019-be8b-4caac64c052a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.227.111.17",
      "pattern": "[ipv4-addr:value = '185.227.111.17']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--73230fc1-a580-472a-8964-8cf5721b1823",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.244.210.120",
      "pattern": "[ipv4-addr:value = '185.244.210.120']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9baa5dd1-1856-4283-9f56-04d9a116b126",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.244.210.65",
      "pattern": "[ipv4-addr:value = '185.244.210.65']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--250fe157-19d8-44af-a089-dba4d628be66",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.36.57.181",
      "pattern": "[ipv4-addr:value = '192.36.57.181']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5466defb-0c17-4a79-b5bf-69f64633dd13",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.4.49.6",
      "pattern": "[ipv4-addr:value = '194.4.49.6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bac474ed-7ffa-48af-8018-8405cd21f569",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 212.193.2.48",
      "pattern": "[ipv4-addr:value = '212.193.2.48']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a23803e0-14ec-4071-8682-e2cab7e5924e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 213.156.138.68",
      "pattern": "[ipv4-addr:value = '213.156.138.68']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b986dc6-813f-438d-8671-f84545c198fe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 213.156.138.77",
      "pattern": "[ipv4-addr:value = '213.156.138.77']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2abd6a39-32fa-4d09-99e7-2653d0a19150",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 213.156.138.78",
      "pattern": "[ipv4-addr:value = '213.156.138.78']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4b376ef-9b33-4832-ab2f-13ef57706eff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 216.238.75.155",
      "pattern": "[ipv4-addr:value = '216.238.75.155']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67dca334-95f0-42db-92ea-d2248ce63139",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.77.52.253",
      "pattern": "[ipv4-addr:value = '45.77.52.253']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ed4ebbf1-8a6b-40db-abed-57769460a81e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.86.163.224",
      "pattern": "[ipv4-addr:value = '45.86.163.224']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7f3aefe2-7909-4f14-8871-f69bff493a28",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 51.15.145.37",
      "pattern": "[ipv4-addr:value = '51.15.145.37']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b16ddc22-0b2c-4122-9f1d-4b81c9e5663a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 89.44.198.189",
      "pattern": "[ipv4-addr:value = '89.44.198.189']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2a6b5434-1328-4701-adff-27441d7b602f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 89.44.198.196",
      "pattern": "[ipv4-addr:value = '89.44.198.196']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8825fbbe-a06c-4d16-ad55-bc8633cecfaa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-38028",
      "pattern": "[vulnerability:name = 'CVE-2022-38028']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-38028 \u2014 Microsoft Windows Print Spooler P",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0feb117f-4d4f-478d-876a-0ad46f210e9b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-3400",
      "pattern": "[vulnerability:name = 'CVE-2024-3400']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b4d20395-6579-4397-9d3a-ad2e74ed4529",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 110.47.250.103",
      "pattern": "[ipv4-addr:value = '110.47.250.103']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3528a505-1fb3-4def-b98c-05918be1fa78",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 126.227.76.24",
      "pattern": "[ipv4-addr:value = '126.227.76.24']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ef16680d-a156-453d-8504-c7634569186e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 144.172.79.92",
      "pattern": "[ipv4-addr:value = '144.172.79.92']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2f1444fa-2fbf-4eb7-88a3-a9a856e53a28",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 146.70.192.174",
      "pattern": "[ipv4-addr:value = '146.70.192.174']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b6f671f-c604-4392-a7ac-2258f5460f6e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 147.45.70.100",
      "pattern": "[ipv4-addr:value = '147.45.70.100']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cd0ead5e-408e-4de8-9813-b2a17074958b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 149.28.194.95",
      "pattern": "[ipv4-addr:value = '149.28.194.95']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c484af35-84d1-4563-8ae7-ef6f8689d4b8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 149.88.27.212",
      "pattern": "[ipv4-addr:value = '149.88.27.212']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff1e01a0-c9f4-4efd-8598-534803d193aa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 154.223.16.34",
      "pattern": "[ipv4-addr:value = '154.223.16.34']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b2d557d1-638a-4ac1-8dc1-3e61b007f265",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.233.228.93",
      "pattern": "[ipv4-addr:value = '172.233.228.93']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--091da33c-a8a7-4dd0-81c2-1b1a339d66b4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 173.255.223.159",
      "pattern": "[ipv4-addr:value = '173.255.223.159']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--88450109-1cc2-4219-94f8-a5cfdd026326",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.108.105.110",
      "pattern": "[ipv4-addr:value = '185.108.105.110']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--21bd8b41-9ff8-4fdb-907f-5c9c0f20c53e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 199.119.206.28",
      "pattern": "[ipv4-addr:value = '199.119.206.28']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6f888eef-6971-41ea-b489-185012826e81",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 203.160.86.91",
      "pattern": "[ipv4-addr:value = '203.160.86.91']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cdd9abce-3bf6-4bb8-b826-da19cfee84d0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.180.106.167",
      "pattern": "[ipv4-addr:value = '38.180.106.167']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c7582c15-1524-42c2-b456-32f0e5fdd97d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.180.128.159",
      "pattern": "[ipv4-addr:value = '38.180.128.159']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--daa43e0d-da79-41e0-b559-d6082e72119e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.180.41.251",
      "pattern": "[ipv4-addr:value = '38.180.41.251']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--73027e77-7608-4963-a3bb-7b6b2295bcb5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.181.70.3",
      "pattern": "[ipv4-addr:value = '38.181.70.3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ddef680-57dd-4333-b55d-ebb01b232b9d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.207.148.123",
      "pattern": "[ipv4-addr:value = '38.207.148.123']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--03980805-b22e-422e-ba1a-97727f052933",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.60.218.153",
      "pattern": "[ipv4-addr:value = '38.60.218.153']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7125be59-2d5f-4f9e-8fda-be857eb6eaf3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.121.51.2",
      "pattern": "[ipv4-addr:value = '45.121.51.2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ed95cb41-bbab-4db5-a418-afb70a878f23",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 64.176.226.203",
      "pattern": "[ipv4-addr:value = '64.176.226.203']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4ab24355-e3a7-47ad-81ef-0f7ab7f0be54",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 66.235.168.222",
      "pattern": "[ipv4-addr:value = '66.235.168.222']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6b144b5c-6802-4baf-8bf0-47abec34c9c5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 78.141.232.174",
      "pattern": "[ipv4-addr:value = '78.141.232.174']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--14a739ec-6ef0-4d31-a81f-a68ad0513b68",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 089801d87998fa193377b9bfe98e87ff",
      "pattern": "[file:hashes.MD5 = '089801d87998fa193377b9bfe98e87ff']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--23082488-6a8f-499b-8f5e-c120c97f276b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 0c1554888ce9ed0da1583dbdf7b31651",
      "pattern": "[file:hashes.MD5 = '0c1554888ce9ed0da1583dbdf7b31651']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a3047d3-d1f0-4735-98d9-57c0572e0961",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 427258462c745481c1ae47327182acd3",
      "pattern": "[file:hashes.MD5 = '427258462c745481c1ae47327182acd3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5eaf5327-216f-436a-a296-4f049dbca216",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: d31ec83a5a79451a46e980ebffb6e0e8",
      "pattern": "[file:hashes.MD5 = 'd31ec83a5a79451a46e980ebffb6e0e8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--68a77a20-0ab8-435f-af3b-9be1e095a65a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 988fc0d23e6e30c2c46ccec9bbff50b7453b8ba9",
      "pattern": "[file:hashes.'SHA-1' = '988fc0d23e6e30c2c46ccec9bbff50b7453b8ba9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8418cde8-fbe9-41db-a6f6-babec150ec4e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: a7c6f264b00d13808ceb76b3277ee5461ae1354e",
      "pattern": "[file:hashes.'SHA-1' = 'a7c6f264b00d13808ceb76b3277ee5461ae1354e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--efdc4577-a611-41a0-9a68-7d5d174143f2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 161fd76c83e557269bee39a57baa2ccbbac679f59d9adff1e1b73b0f4bb277a6",
      "pattern": "[file:hashes.'SHA-256' = '161fd76c83e557269bee39a57baa2ccbbac679f59d9adff1e1b73b0f4bb277a6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cf779757-c2d7-4d37-b6a4-5e1c23340504",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 35a5f8ac03b0e3865b3177892420cb34233c55240f452f00f9004e274a85703c",
      "pattern": "[file:hashes.'SHA-256' = '35a5f8ac03b0e3865b3177892420cb34233c55240f452f00f9004e274a85703c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--95498aa2-ddbe-4569-a87d-4e580282d0f0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3de2a4392b8715bad070b2ae12243f166ead37830f7c6d24e778985927f9caac",
      "pattern": "[file:hashes.'SHA-256' = '3de2a4392b8715bad070b2ae12243f166ead37830f7c6d24e778985927f9caac']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4a451ff2-5a1f-4f36-9b73-77c1a0842c99",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 448fbd7b3389fe2aa421de224d065cea7064de0869a036610e5363c931df5b7c",
      "pattern": "[file:hashes.'SHA-256' = '448fbd7b3389fe2aa421de224d065cea7064de0869a036610e5363c931df5b7c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b48c9b69-1951-44f2-8d66-277a1a653952",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5460b51da26c060727d128f3b3d6415d1a4c25af6a29fef4cc6b867ad3659078",
      "pattern": "[file:hashes.'SHA-256' = '5460b51da26c060727d128f3b3d6415d1a4c25af6a29fef4cc6b867ad3659078']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--98de3813-e641-4418-826b-a1041bb7f697",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 755f5b8bd67d226f24329dc960f59e11cb5735b930b4ed30b2df77572efb32e8",
      "pattern": "[file:hashes.'SHA-256' = '755f5b8bd67d226f24329dc960f59e11cb5735b930b4ed30b2df77572efb32e8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--09acd182-7e27-4c16-9049-f4888dc29b5e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 96dbec24ac64e7dd5fef6e2c26214c8fe5be3486d5c92d21d5dcb4f6c4e365b9",
      "pattern": "[file:hashes.'SHA-256' = '96dbec24ac64e7dd5fef6e2c26214c8fe5be3486d5c92d21d5dcb4f6c4e365b9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ecf8f0e9-17e2-4267-b301-61ca7b61dc8e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: adba167a9df482aa991faaa0e0cde1182fb9acfbb0dc8d19148ce634608bab87",
      "pattern": "[file:hashes.'SHA-256' = 'adba167a9df482aa991faaa0e0cde1182fb9acfbb0dc8d19148ce634608bab87']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0bfb185c-9475-4377-9954-0d07939b8b02",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e315907415eb8cfcf3b6a4cd6602b392a3fe8ee0f79a2d51a81a928dbce950f8",
      "pattern": "[file:hashes.'SHA-256' = 'e315907415eb8cfcf3b6a4cd6602b392a3fe8ee0f79a2d51a81a928dbce950f8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cdbfc608-c934-4d36-b82a-fdd6bba5391d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: fe07ca449e99827265ca95f9f56ec6543a4c5b712ed50038a9a153199e95a0b7",
      "pattern": "[file:hashes.'SHA-256' = 'fe07ca449e99827265ca95f9f56ec6543a4c5b712ed50038a9a153199e95a0b7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ae163ae9-7b83-47d5-8a54-7f40d0734ad1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-3272",
      "pattern": "[vulnerability:name = 'CVE-2024-3272']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3273 \u2014 D-Link Multiple NAS Devices Comman",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c6770ae9-1b9b-4306-80a8-f1d5d1e00fe4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-3273",
      "pattern": "[vulnerability:name = 'CVE-2024-3273']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3273 \u2014 D-Link Multiple NAS Devices Comman",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6c28f27e-a3af-45c8-b808-865407d2a300",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.6.224.248",
      "pattern": "[ipv4-addr:value = '38.6.224.248']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3273 \u2014 D-Link Multiple NAS Devices Comman",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8cf3593e-2428-4132-b9f2-b05ac73e8b65",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 859e679f8e8be4a4c895139fb7fb1b177627bbe712e1ed4c316ec85008426db8",
      "pattern": "[file:hashes.'SHA-256' = '859e679f8e8be4a4c895139fb7fb1b177627bbe712e1ed4c316ec85008426db8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-3273 \u2014 D-Link Multiple NAS Devices Comman",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ad9bebc0-edfd-4f5b-8f92-85f659b3d7fc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-45288",
      "pattern": "[vulnerability:name = 'CVE-2023-45288']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Exploiting HTTP/2 CONTINUATION frames for DoS attacks",
          "url": "https://snyk.io/blog/exploiting-http-2-continuation-frames-dos-attacks/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f2dde77-c3c0-4107-8f42-0ec47222a128",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-24549",
      "pattern": "[vulnerability:name = 'CVE-2024-24549']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Exploiting HTTP/2 CONTINUATION frames for DoS attacks",
          "url": "https://snyk.io/blog/exploiting-http-2-continuation-frames-dos-attacks/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--13470558-6cda-499e-bb2b-3b84a37396a7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-2653",
      "pattern": "[vulnerability:name = 'CVE-2024-2653']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Exploiting HTTP/2 CONTINUATION frames for DoS attacks",
          "url": "https://snyk.io/blog/exploiting-http-2-continuation-frames-dos-attacks/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e89f7772-4b54-42c7-99cc-2be59cba0e22",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-27316",
      "pattern": "[vulnerability:name = 'CVE-2024-27316']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Exploiting HTTP/2 CONTINUATION frames for DoS attacks",
          "url": "https://snyk.io/blog/exploiting-http-2-continuation-frames-dos-attacks/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--51d11d48-1217-45d4-89b1-a01a63c05792",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-2758",
      "pattern": "[vulnerability:name = 'CVE-2024-2758']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Exploiting HTTP/2 CONTINUATION frames for DoS attacks",
          "url": "https://snyk.io/blog/exploiting-http-2-continuation-frames-dos-attacks/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--df2dc83b-a988-49ec-aa3e-66f77cac3260",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-27919",
      "pattern": "[vulnerability:name = 'CVE-2024-27919']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Exploiting HTTP/2 CONTINUATION frames for DoS attacks",
          "url": "https://snyk.io/blog/exploiting-http-2-continuation-frames-dos-attacks/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--486ff510-aa9d-4b47-a44e-81e5fd93ece6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-27983",
      "pattern": "[vulnerability:name = 'CVE-2024-27983']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Exploiting HTTP/2 CONTINUATION frames for DoS attacks",
          "url": "https://snyk.io/blog/exploiting-http-2-continuation-frames-dos-attacks/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c65ea911-67b0-4d26-8c2f-01b1792e990a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-28182",
      "pattern": "[vulnerability:name = 'CVE-2024-28182']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Exploiting HTTP/2 CONTINUATION frames for DoS attacks",
          "url": "https://snyk.io/blog/exploiting-http-2-continuation-frames-dos-attacks/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bf182e55-1a5a-4a35-97a3-87dbb5ade88b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-30255",
      "pattern": "[vulnerability:name = 'CVE-2024-30255']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Exploiting HTTP/2 CONTINUATION frames for DoS attacks",
          "url": "https://snyk.io/blog/exploiting-http-2-continuation-frames-dos-attacks/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6f48798d-9557-4ea7-96d9-dbda7c9b0467",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-31309",
      "pattern": "[vulnerability:name = 'CVE-2024-31309']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Exploiting HTTP/2 CONTINUATION frames for DoS attacks",
          "url": "https://snyk.io/blog/exploiting-http-2-continuation-frames-dos-attacks/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c0e7c41f-02ae-434e-87a5-f1a6b4f6454a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-29745",
      "pattern": "[vulnerability:name = 'CVE-2024-29745']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-29745 \u2014 Android Pixel Information Disclos",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--799a372a-2b95-4d67-b6b7-62f2f9a446fe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-29748",
      "pattern": "[vulnerability:name = 'CVE-2024-29748']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-29748 \u2014 Android Pixel Privilege Escalatio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--54f65d45-7a5c-4730-a7c7-4231d68c7909",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-24955",
      "pattern": "[vulnerability:name = 'CVE-2023-24955']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-24955 \u2014 Microsoft SharePoint Server Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-29357 \u2014 Microsoft SharePoint Server Privi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--19ee7502-7f77-4dd2-841c-f5d071565b85",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-29357",
      "pattern": "[vulnerability:name = 'CVE-2023-29357']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-24955 \u2014 Microsoft SharePoint Server Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-29357 \u2014 Microsoft SharePoint Server Privi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--407122a3-ad64-4856-8beb-f19859de4f57",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-7256",
      "pattern": "[vulnerability:name = 'CVE-2019-7256']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-7256 \u2014 Nice Linear eMerge E3-Series OS Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--94fef359-08fd-49c0-b832-52e3f00eb96d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-44529",
      "pattern": "[vulnerability:name = 'CVE-2021-44529']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44529 \u2014 Ivanti Endpoint Manager Cloud Ser",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b145ae0c-550c-4a6a-aca8-530eea07df68",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-48788",
      "pattern": "[vulnerability:name = 'CVE-2023-48788']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-48788 \u2014 Fortinet FortiClient EMS SQL Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b3246725-341f-445c-9e53-93781cb56d0b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: api.playanext.com",
      "pattern": "[domain-name:value = 'api.playanext.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-48788 \u2014 Fortinet FortiClient EMS SQL Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e77087f3-e14c-40eb-a9e8-d81b8d2dc2b1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: azure-documents.com",
      "pattern": "[domain-name:value = 'azure-documents.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-48788 \u2014 Fortinet FortiClient EMS SQL Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c39fe477-d38c-417d-b716-895ae0bdf206",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.168.140.84",
      "pattern": "[ipv4-addr:value = '104.168.140.84']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-48788 \u2014 Fortinet FortiClient EMS SQL Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f8f61d71-e38b-48d2-a92e-26abdc2039af",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 128.199.207.131",
      "pattern": "[ipv4-addr:value = '128.199.207.131']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-48788 \u2014 Fortinet FortiClient EMS SQL Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--23c729a7-2506-47a0-8c69-5648030be074",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.56.83.82",
      "pattern": "[ipv4-addr:value = '185.56.83.82']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-48788 \u2014 Fortinet FortiClient EMS SQL Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4ffd9ea4-1415-44f5-8843-bbceef078a8a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 212.113.106.100",
      "pattern": "[ipv4-addr:value = '212.113.106.100']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-48788 \u2014 Fortinet FortiClient EMS SQL Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--36f8f44b-4cde-41fc-b42a-701a540096fe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 212.32.243.25",
      "pattern": "[ipv4-addr:value = '212.32.243.25']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-48788 \u2014 Fortinet FortiClient EMS SQL Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--17f760fd-ede0-42ca-82a7-38d5c9c6a60a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 77.246.103.110",
      "pattern": "[ipv4-addr:value = '77.246.103.110']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-48788 \u2014 Fortinet FortiClient EMS SQL Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2aab835b-de67-485a-b8cf-0c36590c23b9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 89.149.200.91",
      "pattern": "[ipv4-addr:value = '89.149.200.91']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-48788 \u2014 Fortinet FortiClient EMS SQL Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--afc87618-e17b-4623-9dd2-be2d1d43900f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 95.181.173.172",
      "pattern": "[ipv4-addr:value = '95.181.173.172']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-48788 \u2014 Fortinet FortiClient EMS SQL Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ff8e55e-4ae7-4043-9ae1-f0ae78b1a17e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-1597",
      "pattern": "[vulnerability:name = 'CVE-2024-1597']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk users don't have to worry about NVD delays",
          "url": "https://snyk.io/blog/snyk-users-dont-have-to-worry-about-nvd-delays/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c04eef1-4b9a-41a4-9847-413f51d739bc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-22243",
      "pattern": "[vulnerability:name = 'CVE-2024-22243']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk users don't have to worry about NVD delays",
          "url": "https://snyk.io/blog/snyk-users-dont-have-to-worry-about-nvd-delays/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd52bec7-4d3c-4bc8-9a9a-b9e710e3e153",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-27198",
      "pattern": "[vulnerability:name = 'CVE-2024-27198']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-27198 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dab45096-b579-4835-8731-b7af8a0df0dc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-23225",
      "pattern": "[vulnerability:name = 'CVE-2024-23225']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-23225 \u2014 Apple Multiple Products Memory Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9d7e007c-5be8-4fac-85b0-1a3a6cd1414b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-23296",
      "pattern": "[vulnerability:name = 'CVE-2024-23296']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-23296 \u2014 Apple Multiple Products Memory Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aec67bbf-1b75-48b8-8290-23e024141bad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-36380",
      "pattern": "[vulnerability:name = 'CVE-2021-36380']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-36380 \u2014 Sunhillo SureLine OS Command Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e47c2234-2836-41db-930b-27ab8787cf90",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-21237",
      "pattern": "[vulnerability:name = 'CVE-2023-21237']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-21237 \u2014 Android Pixel Information Disclos",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1568740b-5812-4146-a05a-905881a84d10",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-29360",
      "pattern": "[vulnerability:name = 'CVE-2023-29360']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-29360 \u2014 Microsoft Streaming Service Untru",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6b5a87c6-03de-4b47-84a2-dae2de04c7c8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-1709",
      "pattern": "[vulnerability:name = 'CVE-2024-1709']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a167c02d-38d0-4c96-a557-8d053fd32f31",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 116.0.56.101",
      "pattern": "[ipv4-addr:value = '116.0.56.101']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--56cdd63f-98d2-4900-bc36-751ee19e3f75",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 118.69.65.60",
      "pattern": "[ipv4-addr:value = '118.69.65.60']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7e20d2b2-70b7-4b2c-b1e9-aa3f1d2a5e9b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 119.3.12.54",
      "pattern": "[ipv4-addr:value = '119.3.12.54']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ed4f9082-50e9-4657-b58e-a8f4682a11eb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 155.133.5.14",
      "pattern": "[ipv4-addr:value = '155.133.5.14']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9485d75c-fef7-430a-942a-483b66bf5e50",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 155.133.5.15",
      "pattern": "[ipv4-addr:value = '155.133.5.15']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5201f568-927e-45ba-ab75-5497010c4ebd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 159.65.130.146",
      "pattern": "[ipv4-addr:value = '159.65.130.146']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4218fa3b-266b-4a9c-a573-86e40d1ecdf4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.232.92.32",
      "pattern": "[ipv4-addr:value = '185.232.92.32']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c8c7a21d-2bef-4b46-a674-89571b89b9e4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 207.246.74.189",
      "pattern": "[ipv4-addr:value = '207.246.74.189']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0c5e9c1-9b85-4695-97bb-aecdea77c26d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.26.137.225",
      "pattern": "[ipv4-addr:value = '23.26.137.225']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--61570d17-fe12-4369-999d-68b133df21f2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 91.238.181.238",
      "pattern": "[ipv4-addr:value = '91.238.181.238']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--177e39ff-f397-4bd1-b361-611395c66051",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 0d185ea3b0a49c2fa65bfd2757c9d0705657f0639fd36f196ac394fcd38c361d",
      "pattern": "[file:hashes.'SHA-256' = '0d185ea3b0a49c2fa65bfd2757c9d0705657f0639fd36f196ac394fcd38c361d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--815328df-03a5-4d8e-b0c4-48041a3a9a4f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 11d2dde6c51e977ed6e3f3d3e256c78062ae41fe780aefecfba1627e66daf771",
      "pattern": "[file:hashes.'SHA-256' = '11d2dde6c51e977ed6e3f3d3e256c78062ae41fe780aefecfba1627e66daf771']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--354da2a7-f0a2-4e94-958c-86151147df96",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1362e6d43b068005f5d7c755e997e6202775430ac15a794014aa9a7a03a974e7",
      "pattern": "[file:hashes.'SHA-256' = '1362e6d43b068005f5d7c755e997e6202775430ac15a794014aa9a7a03a974e7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3283ab4c-97a0-419e-b191-e5d5bdc4c533",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 19fc383683b34ba31ed055dc2e546a64eecbe06d79b6cc346773478c84f25f92",
      "pattern": "[file:hashes.'SHA-256' = '19fc383683b34ba31ed055dc2e546a64eecbe06d79b6cc346773478c84f25f92']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--399eca57-ad08-45ab-9de8-0b833820d9e0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 254714b7028005596fd56bdbe30bfc77f02bbe274048d0982118d93966e79331",
      "pattern": "[file:hashes.'SHA-256' = '254714b7028005596fd56bdbe30bfc77f02bbe274048d0982118d93966e79331']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2c7ea06e-7af9-4bb0-bd34-06aec4563c1c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2da975fee507060baa1042fb45e8467579abf3f348f1fd37b86bb742db63438a",
      "pattern": "[file:hashes.'SHA-256' = '2da975fee507060baa1042fb45e8467579abf3f348f1fd37b86bb742db63438a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--16acdb42-335d-4295-8073-2cbd62377560",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3818bb7adf60f8c2aeb5fe8c59b81fc7eb7f1471a80932610dc9a294ba7ba543",
      "pattern": "[file:hashes.'SHA-256' = '3818bb7adf60f8c2aeb5fe8c59b81fc7eb7f1471a80932610dc9a294ba7ba543']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b548094e-46af-4db1-8bfc-1703c99a714b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 444338339260d884070de53554543785acc3c9772e92c5af1dff96e60e67c195",
      "pattern": "[file:hashes.'SHA-256' = '444338339260d884070de53554543785acc3c9772e92c5af1dff96e60e67c195']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--098359f2-988c-4330-b04d-3af5158126e3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 55e4ce3fe726043070ecd7de5a74b2459ea8bed19ef2a36ce7884b2ab0863047",
      "pattern": "[file:hashes.'SHA-256' = '55e4ce3fe726043070ecd7de5a74b2459ea8bed19ef2a36ce7884b2ab0863047']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b603ac1-ab87-49c5-94c2-5774a97e032e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 858ddfe6530fb00adb467f26e2c8f119fef284e1e9b6c92f0634f403ee3e7913",
      "pattern": "[file:hashes.'SHA-256' = '858ddfe6530fb00adb467f26e2c8f119fef284e1e9b6c92f0634f403ee3e7913']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a7e931e7-0752-45fe-bcf0-439b49c41c6f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 86b5d7dd88b46a3e7c2fb58c01fbeb11dc7ad350370abfe648dbfad45edb8132",
      "pattern": "[file:hashes.'SHA-256' = '86b5d7dd88b46a3e7c2fb58c01fbeb11dc7ad350370abfe648dbfad45edb8132']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8010779c-5d90-4ee7-bfd7-fc51273ae5c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8c2d246bf93bf84f6d4376cd46d8fcc3cb9c96d9bef7d42c23ff222d8f66eeaf",
      "pattern": "[file:hashes.'SHA-256' = '8c2d246bf93bf84f6d4376cd46d8fcc3cb9c96d9bef7d42c23ff222d8f66eeaf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--497c302e-eb90-4200-b175-acce23048f4b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8e51de4774d27ad31a83d5df060ba008148665ab9caf6bc889a5e3fba4d7e600",
      "pattern": "[file:hashes.'SHA-256' = '8e51de4774d27ad31a83d5df060ba008148665ab9caf6bc889a5e3fba4d7e600']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3155ca01-6dd4-4e90-b134-a27160f0464d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9b3327f9ea7c02c6909a472a3c1abb562b19ae72d733a8e2e990e975b5f8a5d0",
      "pattern": "[file:hashes.'SHA-256' = '9b3327f9ea7c02c6909a472a3c1abb562b19ae72d733a8e2e990e975b5f8a5d0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bdac45b1-1018-4b8f-b910-5c4b43a64ae9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a39d9b1b41157510d16e41e7c877b35452f201d02a05afa328f1bcd53d8ee016",
      "pattern": "[file:hashes.'SHA-256' = 'a39d9b1b41157510d16e41e7c877b35452f201d02a05afa328f1bcd53d8ee016']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e0eaa21c-cc1d-4671-ba77-94d4ddf66f4c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a50d9954c0a50e5804065a8165b18571048160200249766bfa2f75d03c8cb6d0",
      "pattern": "[file:hashes.'SHA-256' = 'a50d9954c0a50e5804065a8165b18571048160200249766bfa2f75d03c8cb6d0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--47de7ae8-bd55-41c4-bf38-745ec835c344",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b423d100e7aa2e576c8f21586f1d8924b34c3e9ed4cfdba40d121e21c3618445",
      "pattern": "[file:hashes.'SHA-256' = 'b423d100e7aa2e576c8f21586f1d8924b34c3e9ed4cfdba40d121e21c3618445']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f39c0cb8-63e8-48d7-88ba-887e28b1fc25",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c94038781c56ab85d2f110db4f45b86ccf269e77a3ff4b9133b96745ff97d25f",
      "pattern": "[file:hashes.'SHA-256' = 'c94038781c56ab85d2f110db4f45b86ccf269e77a3ff4b9133b96745ff97d25f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b239d168-b963-415e-9b53-b9abdb273586",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: de42bd53cb0944da8bc33107796ecf296d00968725eed1763a8143cef90e2297",
      "pattern": "[file:hashes.'SHA-256' = 'de42bd53cb0944da8bc33107796ecf296d00968725eed1763a8143cef90e2297']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--30ffc2a8-4180-4a39-8ac5-db6852bfcc7c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f1c7045badec0b9771da4a0f067eac99587d235d1ede35190080cd051d923da6",
      "pattern": "[file:hashes.'SHA-256' = 'f1c7045badec0b9771da4a0f067eac99587d235d1ede35190080cd051d923da6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4f97d26b-b7a4-457b-9f16-612b65d68a71",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f3f5d3595559cad6019406d41f96fa88c69d693326cdf608c5fc4941fdf6a8ec",
      "pattern": "[file:hashes.'SHA-256' = 'f3f5d3595559cad6019406d41f96fa88c69d693326cdf608c5fc4941fdf6a8ec']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--82f54341-7b8f-48df-9dc0-e6f50daed001",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-3259",
      "pattern": "[vulnerability:name = 'CVE-2020-3259']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-3259 \u2014 Cisco ASA and FTD Information Disc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7118f764-09c8-4a03-9778-99f855a95fab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-21410",
      "pattern": "[vulnerability:name = 'CVE-2024-21410']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-21410 \u2014 Microsoft Exchange Server Privile",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cf80588b-5a49-4b6a-a880-df0878abf206",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-21351",
      "pattern": "[vulnerability:name = 'CVE-2024-21351']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-21351 \u2014 Microsoft Windows SmartScreen Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d4c50d17-fa42-43f5-bbff-36220c38be7e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: 21centuryart.com",
      "pattern": "[domain-name:value = '21centuryart.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-21351 \u2014 Microsoft Windows SmartScreen Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5e7b884d-2b95-4d24-b08d-4090ac2da7b9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: fxbulls.ru",
      "pattern": "[domain-name:value = 'fxbulls.ru']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-21351 \u2014 Microsoft Windows SmartScreen Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e242b8c8-f6e5-4aa8-b8e5-6d7c11429068",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-4762",
      "pattern": "[vulnerability:name = 'CVE-2023-4762']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-4762 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e5270f60-1219-4df5-b584-6859e349bc25",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-48618",
      "pattern": "[vulnerability:name = 'CVE-2022-48618']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-48618 \u2014 Apple Multiple Products Memory Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cc40f732-a16a-4e31-8468-1a1100aef2d2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-21893",
      "pattern": "[vulnerability:name = 'CVE-2024-21893']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-21893 \u2014 Ivanti Connect Secure, Policy Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--152a9d81-36a2-4dc0-89ec-75a0004e97af",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-22527",
      "pattern": "[vulnerability:name = 'CVE-2023-22527']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--afc11714-f15b-4013-b465-1ca58cdc0287",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.228.162.76",
      "pattern": "[ipv4-addr:value = '103.228.162.76']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f719cf54-8cd1-40ad-af92-f4836a1c1c82",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 111.26.72.177",
      "pattern": "[ipv4-addr:value = '111.26.72.177']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f69d1507-3443-48af-bb5a-a2139185daab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 114.242.99.122",
      "pattern": "[ipv4-addr:value = '114.242.99.122']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eef2f2a5-5bfa-4b44-b4c1-2f076966f832",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 120.237.168.25",
      "pattern": "[ipv4-addr:value = '120.237.168.25']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--510a97bf-8fa9-458c-806e-064b6a16e0b5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 125.76.87.134",
      "pattern": "[ipv4-addr:value = '125.76.87.134']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b2c0e232-6060-499e-9e98-3eab5b7a4ec1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 128.199.150.109",
      "pattern": "[ipv4-addr:value = '128.199.150.109']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--96bc50bb-d6a6-43f2-a3e0-1ba7016be52f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 14.225.53.158",
      "pattern": "[ipv4-addr:value = '14.225.53.158']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7a4a4b32-df6b-496e-96b3-ce4c50b58c14",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 14.225.53.21",
      "pattern": "[ipv4-addr:value = '14.225.53.21']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc026dac-a670-4874-bc15-70a43b3f67ea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 14.225.53.68",
      "pattern": "[ipv4-addr:value = '14.225.53.68']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cbae94be-598d-4316-b107-ff5300778070",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 161.97.172.232",
      "pattern": "[ipv4-addr:value = '161.97.172.232']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4f2c1f33-ed78-4904-bb84-82aad8c9ef40",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 177.185.117.136",
      "pattern": "[ipv4-addr:value = '177.185.117.136']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--36ad8047-e88d-413c-9cc1-5e23222a0216",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 179.0.190.32",
      "pattern": "[ipv4-addr:value = '179.0.190.32']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--79e1e597-b931-4771-a396-493b48bf34ce",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 183.196.214.38",
      "pattern": "[ipv4-addr:value = '183.196.214.38']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4b84de68-b761-4994-8d12-a747ba3dcf16",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 183.57.45.194",
      "pattern": "[ipv4-addr:value = '183.57.45.194']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--546ad702-38bc-46cc-9d5c-2c6e7691a1ea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.29.12.182",
      "pattern": "[ipv4-addr:value = '193.29.12.182']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8da6f921-bd43-4ed6-8407-f34a2d0d5e7d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.8.172.178",
      "pattern": "[ipv4-addr:value = '193.8.172.178']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9026cd37-27f7-43fd-afba-56b7d51523a5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.113.236.177",
      "pattern": "[ipv4-addr:value = '194.113.236.177']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9529f03c-49c0-4c3d-a2a3-37aeb81a6e0b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 202.142.95.131",
      "pattern": "[ipv4-addr:value = '202.142.95.131']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--318b7151-06e1-4908-b715-bae5994550d7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 217.112.83.246",
      "pattern": "[ipv4-addr:value = '217.112.83.246']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5b1b287f-a4e5-43c9-9235-847778903aa2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 219.139.101.136",
      "pattern": "[ipv4-addr:value = '219.139.101.136']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--afa986c7-408c-4cdb-bc43-664555940e78",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 222.216.206.99",
      "pattern": "[ipv4-addr:value = '222.216.206.99']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b950993f-c39e-478e-97ae-a680e47897b6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 222.217.86.135",
      "pattern": "[ipv4-addr:value = '222.217.86.135']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f1ad0507-86c9-42fd-bbfc-fa4a035024fe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 39.103.211.146",
      "pattern": "[ipv4-addr:value = '39.103.211.146']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--751aec7f-a6de-44be-9412-74af5991392a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 39.98.218.14",
      "pattern": "[ipv4-addr:value = '39.98.218.14']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ffe97ddb-2eb7-4bd7-a66d-abde1ff2e530",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 47.236.124.26",
      "pattern": "[ipv4-addr:value = '47.236.124.26']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e097e4fd-5c7a-4665-8787-6bf59a9075a6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 47.93.204.111",
      "pattern": "[ipv4-addr:value = '47.93.204.111']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c8d7d67-3669-44cf-ba1a-7834bfd50b60",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 49.232.119.187",
      "pattern": "[ipv4-addr:value = '49.232.119.187']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d6b076f-27b5-49a5-a52b-8d3234c88bdd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.157.38.50",
      "pattern": "[ipv4-addr:value = '5.157.38.50']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--096a060d-7d1c-4b75-8d3f-9aae172f3709",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 60.235.233.170",
      "pattern": "[ipv4-addr:value = '60.235.233.170']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7e8be895-2213-45be-9af7-9a36ad430c1e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 64.190.113.197",
      "pattern": "[ipv4-addr:value = '64.190.113.197']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--767cb86b-633e-40d6-a26d-dd2feab38619",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-34048",
      "pattern": "[vulnerability:name = 'CVE-2023-34048']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-34048 \u2014 VMware vCenter Server Out-of-Boun",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-20867 \u2014 VMware Tools Authentication Bypas",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8cde0a8c-9db9-40e5-8750-1464aac69462",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-35078",
      "pattern": "[vulnerability:name = 'CVE-2023-35078']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-35082 \u2014 Ivanti Endpoint Manager Mobile (E",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-38035 \u2014 Ivanti Sentry Authentication Bypa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-35081 \u2014 Ivanti Endpoint Manager Mobile (E",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6cb740e4-7a37-4bb6-97d2-93d8989b5d66",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-35081",
      "pattern": "[vulnerability:name = 'CVE-2023-35081']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-35082 \u2014 Ivanti Endpoint Manager Mobile (E",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-38035 \u2014 Ivanti Sentry Authentication Bypa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-35081 \u2014 Ivanti Endpoint Manager Mobile (E",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da4210ce-5c5a-4349-b8d2-4970d3e1d814",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-35082",
      "pattern": "[vulnerability:name = 'CVE-2023-35082']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-35082 \u2014 Ivanti Endpoint Manager Mobile (E",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ae67dd04-8013-4535-b4e6-58256ab5709b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-22195",
      "pattern": "[vulnerability:name = 'CVE-2024-22195']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Understanding and mitigating the Jinja2 XSS vulnerability (C",
          "url": "https://snyk.io/blog/jinja2-xss-vulnerability/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5b39b403-dbd7-45f9-954e-49665c8e7020",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-6548",
      "pattern": "[vulnerability:name = 'CVE-2023-6548']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-6548 \u2014 Citrix NetScaler ADC and NetScaler",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--69d07dd6-d98b-4bed-b6d3-63198fea9ad4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-6549",
      "pattern": "[vulnerability:name = 'CVE-2023-6549']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-6549 \u2014 Citrix NetScaler ADC and NetScaler",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-6548 \u2014 Citrix NetScaler ADC and NetScaler",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe0485a7-a67b-433b-9d2e-a6894edfe1b1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-0519",
      "pattern": "[vulnerability:name = 'CVE-2024-0519']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2024-0519 \u2014 Google Chromium V8 Out-of-Bounds M",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c5084d1c-bc0e-4071-9178-ecf6c9e5ac6e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-15133",
      "pattern": "[vulnerability:name = 'CVE-2018-15133']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-15133 \u2014 Laravel Deserialization of Untrus",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c78e89db-5e69-48fe-92d9-a93978d7dc20",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: mc.rockylinux.si",
      "pattern": "[domain-name:value = 'mc.rockylinux.si']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-15133 \u2014 Laravel Deserialization of Untrus",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--326055f7-855a-4839-ac53-601884378140",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-46805",
      "pattern": "[vulnerability:name = 'CVE-2023-46805']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c86a31c-0425-421f-a663-c6c47072930e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-21887",
      "pattern": "[vulnerability:name = 'CVE-2024-21887']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a774de86-e111-4ace-b3b3-697693395dd9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2024-21888",
      "pattern": "[vulnerability:name = 'CVE-2024-21888']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b1141c5-617e-4c08-b772-5a22e8b0826c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: api.d-n-s.name",
      "pattern": "[domain-name:value = 'api.d-n-s.name']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c71d2dc-3382-4387-af48-5e29aa801ded",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: areekaweb.com",
      "pattern": "[domain-name:value = 'areekaweb.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2ccfae6c-5026-471b-b6cf-ac742059c60e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: clickcom.click",
      "pattern": "[domain-name:value = 'clickcom.click']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4291469a-055e-4921-89e5-1b9685602775",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: clicko.click",
      "pattern": "[domain-name:value = 'clicko.click']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e184a380-bf7b-4099-a021-2935c755bf8f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cpanel.netbar.org",
      "pattern": "[domain-name:value = 'cpanel.netbar.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ddbfd6d7-ae16-4aa4-8f4d-0d6c8cba7f21",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: duorhytm.fun",
      "pattern": "[domain-name:value = 'duorhytm.fun']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--790c249b-c4f8-4284-b8f9-a557cba57603",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ehangmun.com",
      "pattern": "[domain-name:value = 'ehangmun.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff55bbe4-cd74-4ccc-9aac-98d749616307",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: entraide-internationale.fr",
      "pattern": "[domain-name:value = 'entraide-internationale.fr']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de5629e9-fb72-4f56-bcdd-da9dab82b5b7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: gpoaccess.com",
      "pattern": "[domain-name:value = 'gpoaccess.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--317519c9-0f6c-457d-a81f-04611b5c48a0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: line-api.com",
      "pattern": "[domain-name:value = 'line-api.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b53ba8b4-8bde-4d9e-938f-aec8859f4b10",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: miltonhouse.nl",
      "pattern": "[domain-name:value = 'miltonhouse.nl']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7ce61914-0d3d-4d22-b8c7-2e83eb57d16f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: secure-cama.com",
      "pattern": "[domain-name:value = 'secure-cama.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--75f632b4-ffb2-4f9b-b395-43a3fd688975",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: symantke.com",
      "pattern": "[domain-name:value = 'symantke.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f21fabfb-b979-43a9-9452-6c255c603887",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: webb-institute.com",
      "pattern": "[domain-name:value = 'webb-institute.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2d839571-bb15-4b9c-9e2b-68c92ee11a9b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 146.0.228.66",
      "pattern": "[ipv4-addr:value = '146.0.228.66']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b4d9b499-e00e-4eb7-9de3-d55aa7a29e16",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 173.220.106.166",
      "pattern": "[ipv4-addr:value = '173.220.106.166']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b55f4e86-df4b-4bbf-8da6-aff5189d5acb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 173.53.43.7",
      "pattern": "[ipv4-addr:value = '173.53.43.7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f41418b3-f6cd-4fff-9dda-e77af1ef746f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 186.179.39.235",
      "pattern": "[ipv4-addr:value = '186.179.39.235']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5b895c1d-5af0-41ea-a7bf-57dd43c5584d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 206.189.208.156",
      "pattern": "[ipv4-addr:value = '206.189.208.156']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4bbe32a9-5ae2-47a9-8648-a7c6d12fd340",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.61.136.14",
      "pattern": "[ipv4-addr:value = '45.61.136.14']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cd745581-e3d8-41de-b903-1c2517a09cd9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 47.207.9.89",
      "pattern": "[ipv4-addr:value = '47.207.9.89']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4f9d4c8b-3387-4694-82f5-6486030a5d0b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 50.213.208.89",
      "pattern": "[ipv4-addr:value = '50.213.208.89']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eda53e92-f54a-4c3b-86f2-2e8a3e5045e8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 50.215.39.49",
      "pattern": "[ipv4-addr:value = '50.215.39.49']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6692ea96-0dc0-4836-b861-bb8e58a4766f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 50.243.177.161",
      "pattern": "[ipv4-addr:value = '50.243.177.161']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7afd613a-9101-4b02-91d8-dfbee6ef1d71",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 64.24.179.210",
      "pattern": "[ipv4-addr:value = '64.24.179.210']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9d1f720c-f2a0-4086-8ac7-39df93dc2fc3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 71.127.149.194",
      "pattern": "[ipv4-addr:value = '71.127.149.194']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--504c270d-06bf-4aec-b897-8a3535b8aa9c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 73.128.178.221",
      "pattern": "[ipv4-addr:value = '73.128.178.221']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2a38a05f-2e29-4f2f-9efd-47332bad086f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 75.145.224.109",
      "pattern": "[ipv4-addr:value = '75.145.224.109']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0a91a2fb-dc46-490f-bae2-8d5995e6174d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 75.145.243.85",
      "pattern": "[ipv4-addr:value = '75.145.243.85']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc64a3bc-22ce-47aa-ad1c-0684e89c4366",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 8.137.112.245",
      "pattern": "[ipv4-addr:value = '8.137.112.245']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7116ef49-c438-49af-8993-2643388c70c1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 91.92.254.14",
      "pattern": "[ipv4-addr:value = '91.92.254.14']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--10466014-adfa-4fdc-b4e9-1fe01cbf5d0e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 98.160.48.170",
      "pattern": "[ipv4-addr:value = '98.160.48.170']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1530cdc8-a614-45dc-b77f-ae20b56733d0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 2ec505088b942c234f39a37188e80d7a",
      "pattern": "[file:hashes.MD5 = '2ec505088b942c234f39a37188e80d7a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7a1851ed-ab6a-4b45-96cb-0179eacf237b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 3045f5b3d355a9ab26ab6f44cc831a83",
      "pattern": "[file:hashes.MD5 = '3045f5b3d355a9ab26ab6f44cc831a83']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3c5e4399-1fe0-4c59-8d5f-e500912d2780",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 3d97f55a03ceb4f71671aa2ecf5b24e9",
      "pattern": "[file:hashes.MD5 = '3d97f55a03ceb4f71671aa2ecf5b24e9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b72b9e70-4d51-4923-8b45-e49851a25019",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 465600cece80861497e8c1c86a07a23e",
      "pattern": "[file:hashes.MD5 = '465600cece80861497e8c1c86a07a23e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4a0b2733-8e9f-4f0c-a48a-05f2aa00a8de",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 8eb042da6ba683ef1bae460af103cc44",
      "pattern": "[file:hashes.MD5 = '8eb042da6ba683ef1bae460af103cc44']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c4cedc83-03bd-4ea6-ac87-7b7fd908e6e4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: a739bd4c2b9f3679f43579711448786f",
      "pattern": "[file:hashes.MD5 = 'a739bd4c2b9f3679f43579711448786f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff3538ee-0d4a-4718-a4d0-13055c7ceace",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: a81813f70151a022ea1065b7f4d6b5ab",
      "pattern": "[file:hashes.MD5 = 'a81813f70151a022ea1065b7f4d6b5ab']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c10f2ae2-ec75-457d-b331-f3f2378ea4bb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: d0c7a334a4d9dcd3c6335ae13bee59ea",
      "pattern": "[file:hashes.MD5 = 'd0c7a334a4d9dcd3c6335ae13bee59ea']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--04e58056-d860-45ff-8ba1-5a7305d96670",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e8489983d73ed30a4240a14b1f161254",
      "pattern": "[file:hashes.MD5 = 'e8489983d73ed30a4240a14b1f161254']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e81c3076-9543-46be-a6d3-95bfd58a5eed",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-20017",
      "pattern": "[vulnerability:name = 'CVE-2016-20017']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-20017 \u2014 D-Link DSL-2750B Devices Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--82e8aeed-f8fa-4313-b8a1-7b6fcc57d2dd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-23752",
      "pattern": "[vulnerability:name = 'CVE-2023-23752']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-23752 \u2014 Joomla! Improper Access Control V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d3ec166f-54b0-47dd-b01c-132ac377f136",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-27524",
      "pattern": "[vulnerability:name = 'CVE-2023-27524']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27524 \u2014 Apache Superset Insecure Default ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0a4ad933-bf7e-4043-a427-f4e203d97831",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-32434",
      "pattern": "[vulnerability:name = 'CVE-2023-32434']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41990 \u2014 Apple Multiple Products Code Exec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-38606 \u2014 Apple Multiple Products Kernel Un",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-32434 \u2014 Apple Multiple Products Integer O",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--774da786-489c-479d-8834-7c4946cf6638",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-32435",
      "pattern": "[vulnerability:name = 'CVE-2023-32435']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41990 \u2014 Apple Multiple Products Code Exec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-38606 \u2014 Apple Multiple Products Kernel Un",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-32434 \u2014 Apple Multiple Products Integer O",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--254ef6af-a386-4b06-8b54-433a13a8ee41",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-38606",
      "pattern": "[vulnerability:name = 'CVE-2023-38606']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41990 \u2014 Apple Multiple Products Code Exec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-38606 \u2014 Apple Multiple Products Kernel Un",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-32434 \u2014 Apple Multiple Products Integer O",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1e22336f-3e4a-42c8-9311-894a49a446e0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-41990",
      "pattern": "[vulnerability:name = 'CVE-2023-41990']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41990 \u2014 Apple Multiple Products Code Exec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-38606 \u2014 Apple Multiple Products Kernel Un",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-32434 \u2014 Apple Multiple Products Integer O",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--55687aeb-d470-4a7e-a917-a17804a1068a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: h4ck4fun.xyz",
      "pattern": "[domain-name:value = 'h4ck4fun.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f02f0014-40cd-4823-8b35-0e01388daee6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: mooo-ng.com",
      "pattern": "[domain-name:value = 'mooo-ng.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f799126a-d8f3-4b26-beef-4474b14067e9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: redteam.tf",
      "pattern": "[domain-name:value = 'redteam.tf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a18cfd13-670a-4d32-afc5-c2b29d62b98f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.255.177.55",
      "pattern": "[ipv4-addr:value = '103.255.177.55']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ab21b6af-a442-4a61-ae2a-e2e61a724589",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 113.141.91.61",
      "pattern": "[ipv4-addr:value = '113.141.91.61']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-29300 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aeee23cf-2037-4929-9864-6bfae61e2f6f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 81.68.197.3",
      "pattern": "[ipv4-addr:value = '81.68.197.3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--48e180d6-62b8-4c0f-a7da-a9983b41a5e6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 81.68.214.122",
      "pattern": "[ipv4-addr:value = '81.68.214.122']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6c757962-33e9-44f1-a2a8-fd14ff82c6ba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 82.156.147.183",
      "pattern": "[ipv4-addr:value = '82.156.147.183']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--571c73d3-0407-41ba-afa4-5867ea2b8e52",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4f22fea4d0fadd2e01139021f98f04d3cae678e6526feb61fa8a6eceda13296a",
      "pattern": "[file:hashes.'SHA-256' = '4f22fea4d0fadd2e01139021f98f04d3cae678e6526feb61fa8a6eceda13296a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7e134e61-6595-4530-8ab5-cb54757e5412",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 590d3088ed566cb3d85d48f4914cc657ee49b7d33e85c72167e7c72d81d4cb6c",
      "pattern": "[file:hashes.'SHA-256' = '590d3088ed566cb3d85d48f4914cc657ee49b7d33e85c72167e7c72d81d4cb6c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--07ca5e29-a4e2-494a-8556-eaef8d135093",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7c6f0bae1e588821bd5d66cd98f52b7005e054279748c2c851647097fa2ae2df",
      "pattern": "[file:hashes.'SHA-256' = '7c6f0bae1e588821bd5d66cd98f52b7005e054279748c2c851647097fa2ae2df']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--645e7dc4-1fd2-46d4-a844-d0435a9eaf7e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 808f0f85aee6be3d3f3dd4bb827f556401c4d69a642ba4b1cb3645368954622e",
      "pattern": "[file:hashes.'SHA-256' = '808f0f85aee6be3d3f3dd4bb827f556401c4d69a642ba4b1cb3645368954622e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1db84bf0-ca6e-48dc-ba51-8640e7afb067",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: cb493680d1a8ee7a70a2d339ece0b190db02fba4ba6af3b2c26a6b4841902d52",
      "pattern": "[file:hashes.'SHA-256' = 'cb493680d1a8ee7a70a2d339ece0b190db02fba4ba6af3b2c26a6b4841902d52']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-29300 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e2452b82-2891-4299-85b7-d418668a7afe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d6910571564cc4c61b1277334701c612fd3a25b96b63b267d64fcf48a5998254",
      "pattern": "[file:hashes.'SHA-256' = 'd6910571564cc4c61b1277334701c612fd3a25b96b63b267d64fcf48a5998254']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-29300 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ed71be24-e837-459b-aa4d-d0dcce6c1332",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-2868",
      "pattern": "[vulnerability:name = 'CVE-2023-2868']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--73f04ee4-5d52-4849-8caa-69c5244c22ac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-50164",
      "pattern": "[vulnerability:name = 'CVE-2023-50164']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Krampus delivers an end-of-year Struts vulnerability",
          "url": "https://snyk.io/blog/struts-path-traversal-vulnerability/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--09e70dd7-0d3c-432c-ae45-8ce1c6551395",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-7024",
      "pattern": "[vulnerability:name = 'CVE-2023-7024']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7024 \u2014 Google Chromium WebRTC Heap Buffer",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--54058fb6-c501-430d-8941-8f021ee22f9c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-7101",
      "pattern": "[vulnerability:name = 'CVE-2023-7101']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc0d4eef-ac6b-4c68-8991-1432a3b706f7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-7102",
      "pattern": "[vulnerability:name = 'CVE-2023-7102']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f3e137d1-4339-4bd7-97b9-c4199ddc8b6d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: bestfindthetruth.com",
      "pattern": "[domain-name:value = 'bestfindthetruth.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0303bfe3-3a0f-4a80-9eee-5c3e26d5e0e7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: fessionalwork.com",
      "pattern": "[domain-name:value = 'fessionalwork.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--558b47ad-435e-459a-803c-5c9453747383",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: gesturefavour.com",
      "pattern": "[domain-name:value = 'gesturefavour.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6344c090-131d-4267-a0ca-d9652c9f9d5f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: goldenunder.com",
      "pattern": "[domain-name:value = 'goldenunder.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--37d59ab0-85a9-4c7f-b3fc-e1e344a9ab6b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: singamofing.com",
      "pattern": "[domain-name:value = 'singamofing.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e7c6dd14-fcdb-4ac7-87ed-5f2303937e48",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: singnode.com",
      "pattern": "[domain-name:value = 'singnode.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--46d24d7b-d46e-40ef-ae0a-84d5f6b26ec9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: togetheroffway.com",
      "pattern": "[domain-name:value = 'togetheroffway.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb23e9a3-bfcc-4a52-8047-6802d0c922f1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: troublendsef.com",
      "pattern": "[domain-name:value = 'troublendsef.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ed41756c-86af-4057-91f7-b090595429d0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 107.148.41.146",
      "pattern": "[ipv4-addr:value = '107.148.41.146']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0e52b36-7ae8-4853-8db3-0f33a4a36c50",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.224.99.242",
      "pattern": "[ipv4-addr:value = '23.224.99.242']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--06e298a1-c244-4d87-80b4-46a8ce1ef5e8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.224.99.243",
      "pattern": "[ipv4-addr:value = '23.224.99.243']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d1ea8ac7-0985-4ab2-b21c-ba9d2f57c964",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.224.99.244",
      "pattern": "[ipv4-addr:value = '23.224.99.244']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc222793-8d28-40d4-adb3-d54613c88bd4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.224.99.245",
      "pattern": "[ipv4-addr:value = '23.224.99.245']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f145dc45-eb49-4e7f-a4f5-819a6b03db18",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.224.99.246",
      "pattern": "[ipv4-addr:value = '23.224.99.246']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cab3703e-daa9-40f7-9e00-7df763f3adac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.225.35.234",
      "pattern": "[ipv4-addr:value = '23.225.35.234']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--abde9f4d-2f7b-49ee-b9fc-8d39bf7236fb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.225.35.235",
      "pattern": "[ipv4-addr:value = '23.225.35.235']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d3db718-002b-4106-9165-3531e4aa5b94",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.225.35.236",
      "pattern": "[ipv4-addr:value = '23.225.35.236']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b974c01d-dbae-45f8-abac-ed693a1c1b3e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.225.35.237",
      "pattern": "[ipv4-addr:value = '23.225.35.237']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5ba8b5e6-65ce-4fff-b3d9-11448bfe3658",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.225.35.238",
      "pattern": "[ipv4-addr:value = '23.225.35.238']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--79a7842a-7f08-48f8-ad4c-0cc4fa00d4bc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 2b172fe3329260611a9022e71acdebca",
      "pattern": "[file:hashes.MD5 = '2b172fe3329260611a9022e71acdebca']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--875359ee-3f86-484b-a7e4-746419464686",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 7b83e4bd880bb9d7904e8f553c2736e3",
      "pattern": "[file:hashes.MD5 = '7b83e4bd880bb9d7904e8f553c2736e3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ee8e6ce5-c5b2-49b1-8976-ff5f4f4fc6e3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: d493aab1319f10c633f6d223da232a27",
      "pattern": "[file:hashes.MD5 = 'd493aab1319f10c633f6d223da232a27']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fb8843b3-7027-4659-b33e-9232cfe42aa7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e7842edc7868c8c5cf0480dd98bcfe76",
      "pattern": "[file:hashes.MD5 = 'e7842edc7868c8c5cf0480dd98bcfe76']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d87e835a-948e-4212-9a00-bbb3d47f550a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 118fad9e1f03b8b1abe00529c61dc3edfda043b787c9084180d83535b4d177b7",
      "pattern": "[file:hashes.'SHA-256' = '118fad9e1f03b8b1abe00529c61dc3edfda043b787c9084180d83535b4d177b7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8b34c62b-ba33-4886-8117-aae73dde0fc4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 34494ecb02a1cccadda1c7693c45666e1fe3928cc83576f8f07380801b07d8ba",
      "pattern": "[file:hashes.'SHA-256' = '34494ecb02a1cccadda1c7693c45666e1fe3928cc83576f8f07380801b07d8ba']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67942b45-e40e-4ba6-ab25-8ebf3e25a647",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 803cb5a7de1fe0067a9eeb220dfc24ca56f3f571a986180e146b6cf387855bdd",
      "pattern": "[file:hashes.'SHA-256' = '803cb5a7de1fe0067a9eeb220dfc24ca56f3f571a986180e146b6cf387855bdd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--391f1abe-0405-43b9-a647-e577bb06f0a5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 952c5f45d203d8f1a7532e5b59af8e3306b5c1c53a30624b6733e0176d8d1acd",
      "pattern": "[file:hashes.'SHA-256' = '952c5f45d203d8f1a7532e5b59af8e3306b5c1c53a30624b6733e0176d8d1acd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c4f88bf-440d-4e3c-bc69-de3b24c98de4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-47565",
      "pattern": "[vulnerability:name = 'CVE-2023-47565']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--121f2ffb-adcf-4099-a040-0110f92ffbf1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-49897",
      "pattern": "[vulnerability:name = 'CVE-2023-49897']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f67e2ce-a9cf-416f-93c2-e2554c3e5c29",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: chinkona.buzz",
      "pattern": "[domain-name:value = 'chinkona.buzz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fb32eed5-9d82-4e07-9a4b-176cb4b5dcfa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: dfvzfvd.help",
      "pattern": "[domain-name:value = 'dfvzfvd.help']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--17e6437c-813b-4bd5-992f-dfdd8b467ca4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: dogeating.monster",
      "pattern": "[domain-name:value = 'dogeating.monster']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1093f0f1-7802-433f-b2fb-a36e83684668",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: dogeatingchink.uno",
      "pattern": "[domain-name:value = 'dogeatingchink.uno']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--19d37538-1898-4903-bdc5-d1a163875d19",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: homehitter.tk",
      "pattern": "[domain-name:value = 'homehitter.tk']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5fc07646-be30-4970-93f9-8d2369110a8e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: hujunxa.cc",
      "pattern": "[domain-name:value = 'hujunxa.cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--60fc8fba-f04b-4c06-8bf7-cb829a629b32",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: husd8uasd9.online",
      "pattern": "[domain-name:value = 'husd8uasd9.online']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--838c0955-7c4f-4562-8fb0-7126c3ae5edb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: iaxtpa.parody",
      "pattern": "[domain-name:value = 'iaxtpa.parody']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c1eef066-c0e8-4cff-8663-86b6dc0ae1c7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: infectedchink.cat",
      "pattern": "[domain-name:value = 'infectedchink.cat']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c7302f09-96cb-4178-93ab-0e4183ca89b5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: infectedchink.online",
      "pattern": "[domain-name:value = 'infectedchink.online']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4016d734-c81b-4508-a171-73b7b36575e5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: opewu.homes",
      "pattern": "[domain-name:value = 'opewu.homes']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ef6c046f-df86-491a-bdcb-ce1fad6af8df",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: pqahzam.ink",
      "pattern": "[domain-name:value = 'pqahzam.ink']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--14ee80d0-6e5c-41e5-8fe8-31bb934b956a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: skid.uno",
      "pattern": "[domain-name:value = 'skid.uno']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--13ddb155-3f3a-4f23-a9c7-8c6384e19d75",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: wu.qwewu.site",
      "pattern": "[domain-name:value = 'wu.qwewu.site']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b17f1fe-0e1b-4b8b-be04-8e07dc6efa6b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 162.220.166.114",
      "pattern": "[ipv4-addr:value = '162.220.166.114']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bfb97fea-80a8-4f90-8cd2-32347e0bd9bc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 162.246.20.236",
      "pattern": "[ipv4-addr:value = '162.246.20.236']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ca84808-4c47-4070-878e-5ce41f0d4458",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.150.26.226",
      "pattern": "[ipv4-addr:value = '185.150.26.226']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fb61c6a3-2b3a-4aa8-913a-8f8b45e1e018",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.225.74.161",
      "pattern": "[ipv4-addr:value = '185.225.74.161']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--47e9bc68-7294-42ab-849c-123d76c61401",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.153.216.164",
      "pattern": "[ipv4-addr:value = '194.153.216.164']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--39341f7d-5d74-471e-8adc-0dd65de3fa74",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.180.48.202",
      "pattern": "[ipv4-addr:value = '194.180.48.202']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9a122171-ac31-462f-b367-69b7fa0f5760",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.38.21.42",
      "pattern": "[ipv4-addr:value = '194.38.21.42']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c8264548-2c7e-4573-9fd7-efefb92baa12",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.139.105.145",
      "pattern": "[ipv4-addr:value = '45.139.105.145']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--78e05467-0fac-4e05-b926-360659980ce7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.142.182.96",
      "pattern": "[ipv4-addr:value = '45.142.182.96']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4ef93d8-10ae-440c-89c3-d5ab96e55b4d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.95.147.226",
      "pattern": "[ipv4-addr:value = '45.95.147.226']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bbe6dd98-71e1-4c08-a831-25ad3a2ede84",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.181.80.102",
      "pattern": "[ipv4-addr:value = '5.181.80.102']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9f719e02-d353-439b-b689-5daabeb2a23c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.181.80.126",
      "pattern": "[ipv4-addr:value = '5.181.80.126']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c0239316-3d54-475e-8c5a-ad20040075d2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.181.80.127",
      "pattern": "[ipv4-addr:value = '5.181.80.127']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--96914848-9fb4-47a5-bf1d-1a44f5795470",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.181.80.53",
      "pattern": "[ipv4-addr:value = '5.181.80.53']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--07471648-b6bd-4774-b1db-0edffd6a34a9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.181.80.54",
      "pattern": "[ipv4-addr:value = '5.181.80.54']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--41c33f6d-5b96-44fb-93b7-e309ae8c4504",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.181.80.55",
      "pattern": "[ipv4-addr:value = '5.181.80.55']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a28b57a8-71b5-419f-8213-f75f31b3f591",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.181.80.59",
      "pattern": "[ipv4-addr:value = '5.181.80.59']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c906f4e5-e245-4d4e-a25e-a04fae224b53",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.181.80.72",
      "pattern": "[ipv4-addr:value = '5.181.80.72']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d7791c44-32fe-4fad-bd54-0b4892bd692a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.181.80.77",
      "pattern": "[ipv4-addr:value = '5.181.80.77']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b77aa1c6-f0e5-42ac-a729-d3b308048f7c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.181.80.81",
      "pattern": "[ipv4-addr:value = '5.181.80.81']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9677f99b-5478-43c8-9140-3db8fd4040bf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 62.113.113.168",
      "pattern": "[ipv4-addr:value = '62.113.113.168']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d3dcb544-137d-4b33-a9fe-0ce2c8d236c4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 85.217.144.207",
      "pattern": "[ipv4-addr:value = '85.217.144.207']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f92a1292-f743-49bc-b9d0-0b1c83dcb5b6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 89.190.156.145",
      "pattern": "[ipv4-addr:value = '89.190.156.145']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--638831d6-50cd-44e6-b7a3-5b7c981536a7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 91.92.254.4",
      "pattern": "[ipv4-addr:value = '91.92.254.4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--508b25b3-c7c1-4526-9102-8ce1a856834b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 95.214.27.10",
      "pattern": "[ipv4-addr:value = '95.214.27.10']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--23a15fc7-9ced-4d60-b075-d32f03f2e74c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 29f11b5d4dbd6d06d4906b9035f5787e16f9e23134a2cc43dfc1165127c89bff",
      "pattern": "[file:hashes.'SHA-256' = '29f11b5d4dbd6d06d4906b9035f5787e16f9e23134a2cc43dfc1165127c89bff']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1d8e01a9-bd81-4557-9831-7aacc542c57e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 35fcc2058ae3a0af68c5ed7452e57ff286abe6ded68bf59078abd9e7b11ea90a",
      "pattern": "[file:hashes.'SHA-256' = '35fcc2058ae3a0af68c5ed7452e57ff286abe6ded68bf59078abd9e7b11ea90a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d6a2552-3e26-4900-af2d-1184e9e4a5af",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3f3c2e779f8e3d7f2cc81536ef72d96dd1c7b7691b6e613f5f76c3d02909edd8",
      "pattern": "[file:hashes.'SHA-256' = '3f3c2e779f8e3d7f2cc81536ef72d96dd1c7b7691b6e613f5f76c3d02909edd8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--05d4c6f2-0315-4da8-8c41-bccea708c87a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 75ef686859010d6164bcd6a4d6cf8a590754ccc3ea45c47ace420b02649ec380",
      "pattern": "[file:hashes.'SHA-256' = '75ef686859010d6164bcd6a4d6cf8a590754ccc3ea45c47ace420b02649ec380']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7ee9b20a-1eb2-44de-ab9d-6574028a5811",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7cc62a1bb2db82e76183eb06e4ca84e07a78cfb71241f21212afd1e01cb308b2",
      "pattern": "[file:hashes.'SHA-256' = '7cc62a1bb2db82e76183eb06e4ca84e07a78cfb71241f21212afd1e01cb308b2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5478b9e9-9225-42a7-a942-eaf08d55eafe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8777f9af3564b109b43cbcf1fd1a24180f5cf424965050594ce73d754a4e1099",
      "pattern": "[file:hashes.'SHA-256' = '8777f9af3564b109b43cbcf1fd1a24180f5cf424965050594ce73d754a4e1099']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f3aa2898-a8df-4ba9-9d73-db3317aef334",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8e64de3ac6818b4271d3de5d8e4a5d166d13d12804da01ce1cdb7510d8922cc6",
      "pattern": "[file:hashes.'SHA-256' = '8e64de3ac6818b4271d3de5d8e4a5d166d13d12804da01ce1cdb7510d8922cc6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1094e977-1546-492b-b593-95ace87b0d7b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a3b78818bbef4fd55f704c96c203765b5ab37723bc87aac6aa7ebfcc76dfa06d",
      "pattern": "[file:hashes.'SHA-256' = 'a3b78818bbef4fd55f704c96c203765b5ab37723bc87aac6aa7ebfcc76dfa06d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4771c372-c06d-44af-af15-243f3452048a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a4975366f0c5b5b52fb371ff2cb034006955b3e3ae064e5700cc5365f27a1d26",
      "pattern": "[file:hashes.'SHA-256' = 'a4975366f0c5b5b52fb371ff2cb034006955b3e3ae064e5700cc5365f27a1d26']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de73e0d2-9258-4002-80fb-f440c7429860",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ac43c52b42b123e2530538273dfb12e3b70178aa1dee6d4fd5198c08bfeb4dc1",
      "pattern": "[file:hashes.'SHA-256' = 'ac43c52b42b123e2530538273dfb12e3b70178aa1dee6d4fd5198c08bfeb4dc1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--97bb74d5-404f-4157-a26e-ef5d26b605d0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: cd93264637cd3bf19b706afc19944dfb88cd27969aaf0077559e56842d9a0f87",
      "pattern": "[file:hashes.'SHA-256' = 'cd93264637cd3bf19b706afc19944dfb88cd27969aaf0077559e56842d9a0f87']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--504caaaa-a647-4c3b-a475-e43f9d494fa9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: cfbcbb876064c2cf671bdae61544649fa13debbbe58b72cf8c630b5bfc0649f9",
      "pattern": "[file:hashes.'SHA-256' = 'cfbcbb876064c2cf671bdae61544649fa13debbbe58b72cf8c630b5bfc0649f9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d4dd9877-e68f-48a3-91fb-c1f8d1eff39d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: dabdd4b5a3a70c64c031126fad36a4c45feb69a45e1028d79da6b443291addb8",
      "pattern": "[file:hashes.'SHA-256' = 'dabdd4b5a3a70c64c031126fad36a4c45feb69a45e1028d79da6b443291addb8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5b4a75c2-1d33-44f3-95e7-f428e95b35fa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f8abf9fb17f59cbd7381aa9f5f2e1952628897cee368defd6baa6885d74f3ecc",
      "pattern": "[file:hashes.'SHA-256' = 'f8abf9fb17f59cbd7381aa9f5f2e1952628897cee368defd6baa6885d74f3ecc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b2eb948-2938-4796-a767-1aa376868912",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-21708",
      "pattern": "[vulnerability:name = 'CVE-2021-21708']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Vulnerability disclosure: Which comes first, the security bu",
          "url": "https://snyk.io/blog/vulnerability-disclosure-php-use-after-free/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--016b2c79-c781-4b4c-83c0-6e0e6e45491f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-28368",
      "pattern": "[vulnerability:name = 'CVE-2022-28368']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Vulnerability disclosure: Which comes first, the security bu",
          "url": "https://snyk.io/blog/vulnerability-disclosure-php-use-after-free/"
        },
        {
          "source_name": "dompdf security alert: RCE vulnerability found in popular PH",
          "url": "https://snyk.io/blog/security-alert-php-pdf-library-dompdf-rce/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c47fa7f2-d262-451b-bc9b-784f942f8849",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-6448",
      "pattern": "[vulnerability:name = 'CVE-2023-6448']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-6448 \u2014 Unitronics Vision PLC and HMI Inse",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cf18542f-90b7-4b7f-95f6-f4bd4940adde",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3ac8308a7378dfe047eacd393c861d32df34bb47535972eb0a35631ab964d14d",
      "pattern": "[file:hashes.'SHA-256' = '3ac8308a7378dfe047eacd393c861d32df34bb47535972eb0a35631ab964d14d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41266 \u2014 Qlik Sense Path Traversal Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41265 \u2014 Qlik Sense HTTP Tunneling Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4d3938a5-f0cd-4f31-8497-c6fef7ba551b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6cb87cad36f56aefcefbe754605c00ac92e640857fd7ca5faab7b9542ef80c96",
      "pattern": "[file:hashes.'SHA-256' = '6cb87cad36f56aefcefbe754605c00ac92e640857fd7ca5faab7b9542ef80c96']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41266 \u2014 Qlik Sense Path Traversal Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41265 \u2014 Qlik Sense HTTP Tunneling Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cf08edf1-aa4d-452e-b30d-c57581e211da",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 828e81aa16b2851561fff6d3127663ea2d1d68571f06cbd732fdf5672086924d",
      "pattern": "[file:hashes.'SHA-256' = '828e81aa16b2851561fff6d3127663ea2d1d68571f06cbd732fdf5672086924d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41266 \u2014 Qlik Sense Path Traversal Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41265 \u2014 Qlik Sense HTTP Tunneling Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--29728457-3185-4f46-a3b7-544c83aab6c0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 90b009b15eb1b5bc4a990ecdd86375fa25eaa67a8515ae6c6b3b58815d46fa82",
      "pattern": "[file:hashes.'SHA-256' = '90b009b15eb1b5bc4a990ecdd86375fa25eaa67a8515ae6c6b3b58815d46fa82']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41266 \u2014 Qlik Sense Path Traversal Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41265 \u2014 Qlik Sense HTTP Tunneling Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--607b50b9-a2b5-48cf-a268-c23252eaafbb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-11261",
      "pattern": "[vulnerability:name = 'CVE-2020-11261']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33107 \u2014 Qualcomm Multiple Chipsets Intege",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-11261 \u2014 Qualcomm Multiple Chipsets Improp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b88d60e3-6310-4e1f-b449-5cff9932247e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-22071",
      "pattern": "[vulnerability:name = 'CVE-2022-22071']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33107 \u2014 Qualcomm Multiple Chipsets Intege",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-33106 \u2014 Qualcomm Multiple Chipsets Use of",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-22071 \u2014 Qualcomm Multiple Chipsets Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dbfada57-a86f-4dea-b32b-a75299f7db8c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-33063",
      "pattern": "[vulnerability:name = 'CVE-2023-33063']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33107 \u2014 Qualcomm Multiple Chipsets Intege",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-33106 \u2014 Qualcomm Multiple Chipsets Use of",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-33063 \u2014 Qualcomm Multiple Chipsets Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb047029-5509-4c66-9d55-df0eab05825d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-33106",
      "pattern": "[vulnerability:name = 'CVE-2023-33106']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33107 \u2014 Qualcomm Multiple Chipsets Intege",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-33106 \u2014 Qualcomm Multiple Chipsets Use of",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-33063 \u2014 Qualcomm Multiple Chipsets Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--82988e44-4985-4f59-b4e9-b89a39c5e40d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-33107",
      "pattern": "[vulnerability:name = 'CVE-2023-33107']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33107 \u2014 Qualcomm Multiple Chipsets Intege",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-33106 \u2014 Qualcomm Multiple Chipsets Use of",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-33063 \u2014 Qualcomm Multiple Chipsets Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--44e8bd4e-a157-4631-9a4b-c2ba16695944",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-42916",
      "pattern": "[vulnerability:name = 'CVE-2023-42916']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42916 \u2014 Apple Multiple Products WebKit Ou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e08d5ea-188c-4b1e-9828-d9e58ffb94e7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-42917",
      "pattern": "[vulnerability:name = 'CVE-2023-42917']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42917 \u2014 Apple Multiple Products WebKit Me",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fdcdb520-8b80-438f-b361-fbbf8b342678",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-49103",
      "pattern": "[vulnerability:name = 'CVE-2023-49103']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-49103 \u2014 ownCloud graphapi Information Dis",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--38f802e3-ec9b-47fd-86c6-277ea1f7ff9d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-6345",
      "pattern": "[vulnerability:name = 'CVE-2023-6345']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-6345 \u2014 Google Skia Integer Overflow Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c87c2908-e666-48d3-9911-0a0f77a9a854",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-5654",
      "pattern": "[vulnerability:name = 'CVE-2023-5654']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Exploring WebExtension security vulnerabilities in React Dev",
          "url": "https://snyk.io/blog/webextension-security-vulnerabilities-react-developer-tools-vue-js/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cd723a11-2062-423b-8eb6-9278d3921a01",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-5718",
      "pattern": "[vulnerability:name = 'CVE-2023-5718']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Exploring WebExtension security vulnerabilities in React Dev",
          "url": "https://snyk.io/blog/webextension-security-vulnerabilities-react-developer-tools-vue-js/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b234d3d4-58d3-4ab7-9790-39c0f8d21cc5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-9841",
      "pattern": "[vulnerability:name = 'CVE-2017-9841']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-4911 \u2014 GNU C Library Buffer Overflow Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-9841 \u2014 PHPUnit Command Injection Vulnerab",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e62ccfbd-40db-451c-9c46-d56ccc2b95dc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-4911",
      "pattern": "[vulnerability:name = 'CVE-2023-4911']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-4911 \u2014 GNU C Library Buffer Overflow Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7ed7570c-f2aa-44f1-be29-4e5fc3013348",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: haxx.in",
      "pattern": "[domain-name:value = 'haxx.in']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-4911 \u2014 GNU C Library Buffer Overflow Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3157ef8b-36c6-4940-9ff0-bff2f7d52fc6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.233.65.92",
      "pattern": "[ipv4-addr:value = '194.233.65.92']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-4911 \u2014 GNU C Library Buffer Overflow Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bfe23dc9-3f14-4fbf-8f9c-5b5f8310a182",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 5d3c00b79be956d4175d0d5fd1d4f1f9",
      "pattern": "[file:hashes.MD5 = '5d3c00b79be956d4175d0d5fd1d4f1f9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-4911 \u2014 GNU C Library Buffer Overflow Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b596c9a1-5ab3-4fd8-8b73-dfceab975b00",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 5dce322f5284213912012e7ba2440da0",
      "pattern": "[file:hashes.MD5 = '5dce322f5284213912012e7ba2440da0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-4911 \u2014 GNU C Library Buffer Overflow Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--31fe697d-4cc9-4294-907e-5dac32a21f52",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 9a868bb2456bcde27cde7985145ef6fc",
      "pattern": "[file:hashes.MD5 = '9a868bb2456bcde27cde7985145ef6fc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-4911 \u2014 GNU C Library Buffer Overflow Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--613983d8-9736-4553-a37d-18c55b624c3f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: ea685e738adedc02ca1a63ebe8ed939e",
      "pattern": "[file:hashes.MD5 = 'ea685e738adedc02ca1a63ebe8ed939e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-4911 \u2014 GNU C Library Buffer Overflow Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b770c605-dbf1-4f25-9e1e-eb620a2c752c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-2551",
      "pattern": "[vulnerability:name = 'CVE-2020-2551']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-2551 \u2014 Oracle Fusion Middleware Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--30c7e89e-f66e-4385-a101-ee58e8914a56",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-1671",
      "pattern": "[vulnerability:name = 'CVE-2023-1671']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-1671 \u2014 Sophos Web Appliance Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b28d801-030a-4150-a349-9121f25b2011",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-36584",
      "pattern": "[vulnerability:name = 'CVE-2023-36584']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-36584 \u2014 Microsoft Windows Mark of the Web",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-36884 \u2014 Microsoft Windows Search Remote C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--70ec7299-bf01-47b4-82fa-0b5048eb2764",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-36884",
      "pattern": "[vulnerability:name = 'CVE-2023-36884']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-36584 \u2014 Microsoft Windows Mark of the Web",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-36884 \u2014 Microsoft Windows Search Remote C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1500233b-1a4e-40a1-8bdd-a8d484518e14",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-21896",
      "pattern": "[vulnerability:name = 'CVE-2022-21896']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-36033 \u2014 Microsoft Windows Desktop Window ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2d70f4b2-d9b1-4c56-97c2-75fa2fd622ba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-21902",
      "pattern": "[vulnerability:name = 'CVE-2022-21902']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-36033 \u2014 Microsoft Windows Desktop Window ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fd43a66b-1527-4747-b5af-6400f4949c5c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-36033",
      "pattern": "[vulnerability:name = 'CVE-2023-36033']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-36033 \u2014 Microsoft Windows Desktop Window ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4fadf779-f2e7-4889-a957-be7cb9fd1776",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-36036",
      "pattern": "[vulnerability:name = 'CVE-2023-36036']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-36036 \u2014 Microsoft Windows Cloud Files Min",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e6a5c5c6-f60e-4a8a-aedb-429248536474",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3a3feea7ededb728efce89a6d74a823d700e2fe9994bc8791e132bf548473e93",
      "pattern": "[file:hashes.'SHA-256' = '3a3feea7ededb728efce89a6d74a823d700e2fe9994bc8791e132bf548473e93']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-36033 \u2014 Microsoft Windows Desktop Window ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7730dc6f-52db-4cdf-9b99-d13b6ba81dda",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 97cf4e82a902de6a1530499af32afdcf6f79253a10f51b89f92e84ae503f89c3",
      "pattern": "[file:hashes.'SHA-256' = '97cf4e82a902de6a1530499af32afdcf6f79253a10f51b89f92e84ae503f89c3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-36033 \u2014 Microsoft Windows Desktop Window ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d3298e33-430a-4bb8-8c84-a87a25aff2d0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-36844",
      "pattern": "[vulnerability:name = 'CVE-2023-36844']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-36844 \u2014 Juniper Junos OS EX Series PHP Ex",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-36846 \u2014 Juniper Junos OS SRX Series Missi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-36847 \u2014 Juniper Junos OS EX Series Missin",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--658bfe56-0621-4ef8-8f09-2fa136141580",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-36845",
      "pattern": "[vulnerability:name = 'CVE-2023-36845']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-36844 \u2014 Juniper Junos OS EX Series PHP Ex",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-36845 \u2014 Juniper Junos OS EX Series and SR",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-36846 \u2014 Juniper Junos OS SRX Series Missi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--73951ec6-0633-4faa-a704-92eee5ef63f7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-36846",
      "pattern": "[vulnerability:name = 'CVE-2023-36846']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-36844 \u2014 Juniper Junos OS EX Series PHP Ex",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-36846 \u2014 Juniper Junos OS SRX Series Missi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-36847 \u2014 Juniper Junos OS EX Series Missin",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ffd7ba8-44bc-4c02-992f-c1c65f6e6981",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-36847",
      "pattern": "[vulnerability:name = 'CVE-2023-36847']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-36844 \u2014 Juniper Junos OS EX Series PHP Ex",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-36846 \u2014 Juniper Junos OS SRX Series Missi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-36847 \u2014 Juniper Junos OS EX Series Missin",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4b61683-0041-45ae-b6b3-cc8fbbb17afe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-36851",
      "pattern": "[vulnerability:name = 'CVE-2023-36851']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-36851 \u2014 Juniper Junos OS SRX Series Missi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2fefb826-89f0-4c4b-866f-2b96900fb6ae",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-47246",
      "pattern": "[vulnerability:name = 'CVE-2023-47246']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-47246 \u2014 SysAid Server Path Traversal Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--def365db-3da9-4500-b039-e02ccdecd4a6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 179.60.150.34",
      "pattern": "[ipv4-addr:value = '179.60.150.34']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-47246 \u2014 SysAid Server Path Traversal Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f7078f7d-c0fe-421d-ad9d-79a028e579cc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.155.37.105",
      "pattern": "[ipv4-addr:value = '45.155.37.105']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-47246 \u2014 SysAid Server Path Traversal Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--358030c5-e474-43d9-96af-dbf58790b0ee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.182.189.100",
      "pattern": "[ipv4-addr:value = '45.182.189.100']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-47246 \u2014 SysAid Server Path Traversal Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--58e97da1-e06e-4878-b5f8-654cd92777ad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 81.19.138.52",
      "pattern": "[ipv4-addr:value = '81.19.138.52']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-47246 \u2014 SysAid Server Path Traversal Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f52ed969-d5c8-495f-a4e6-4deb95aab595",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 98d4184379fb6cf08a57f2bc937887965ae3e9c977a87a5c6443bf5c055bfd18",
      "pattern": "[file:hashes.'SHA-256' = '98d4184379fb6cf08a57f2bc937887965ae3e9c977a87a5c6443bf5c055bfd18']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-47246 \u2014 SysAid Server Path Traversal Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f8f578bc-160d-4e12-b553-d2fc08fd9127",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b5acf14cdac40be590318dee95425d0746e85b1b7b1cbd14da66f21f2522bf4d",
      "pattern": "[file:hashes.'SHA-256' = 'b5acf14cdac40be590318dee95425d0746e85b1b7b1cbd14da66f21f2522bf4d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-47246 \u2014 SysAid Server Path Traversal Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d8c22ed6-93e5-4357-859e-1645bbdb7f6c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: be4334ce0be2683878c5b9fb911a4fb9beaaa09845028215134081268621df38",
      "pattern": "[file:hashes.'SHA-256' = 'be4334ce0be2683878c5b9fb911a4fb9beaaa09845028215134081268621df38']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-47246 \u2014 SysAid Server Path Traversal Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fd63ac5e-5809-4397-ad2e-744ad7435b79",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f0fb710ee7b2a7f07acdf87cba7b79331ead0eda74276150fde8413b7793fcd7",
      "pattern": "[file:hashes.'SHA-256' = 'f0fb710ee7b2a7f07acdf87cba7b79331ead0eda74276150fde8413b7793fcd7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-47246 \u2014 SysAid Server Path Traversal Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--db648864-74d2-4f4b-8581-14f5c5b4732e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: us-east-2.compute.internal",
      "pattern": "[domain-name:value = 'us-east-2.compute.internal']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Real-time threat protection with Snyk and SentinelOne",
          "url": "https://snyk.io/blog/snyk-sentinelone-built-time-runtime-solution/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--45ef66d1-203e-46f5-be7c-6ade9ef5579a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 8656c04d40b0b3900721ddf26ea43c5f5f646b7b",
      "pattern": "[file:hashes.'SHA-1' = '8656c04d40b0b3900721ddf26ea43c5f5f646b7b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Real-time threat protection with Snyk and SentinelOne",
          "url": "https://snyk.io/blog/snyk-sentinelone-built-time-runtime-solution/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe6aed47-5b8b-4857-875d-4067b0864730",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-29552",
      "pattern": "[vulnerability:name = 'CVE-2023-29552']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-29552 \u2014 Service Location Protocol (SLP) D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8a29671-d302-4b4d-8108-0083e17e8ba0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-22515",
      "pattern": "[vulnerability:name = 'CVE-2023-22515']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-22515 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--249f69dd-9cf0-4492-8a55-53ce904ee13d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-22518",
      "pattern": "[vulnerability:name = 'CVE-2023-22518']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--83e9ecf8-8b9b-4888-b76c-a4ea913e5e08",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: j3qxmk6g5sk3zw62i2yhjnwmhm55rfz47fdyfkhaithlpelfjdokdxad.onion",
      "pattern": "[domain-name:value = 'j3qxmk6g5sk3zw62i2yhjnwmhm55rfz47fdyfkhaithlpelfjdokdxad.onion']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e937e40b-6219-40bd-b676-980f194e2555",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.176.179.41",
      "pattern": "[ipv4-addr:value = '193.176.179.41']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a7a8c928-08b9-4b80-a28b-0609e48043d4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.187.172.73",
      "pattern": "[ipv4-addr:value = '193.187.172.73']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6054b3fb-679e-492b-acd2-b1711ea12e43",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.43.72.11",
      "pattern": "[ipv4-addr:value = '193.43.72.11']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--94526232-41bd-46bd-a446-b2a7eb98f98e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.145.6.112",
      "pattern": "[ipv4-addr:value = '45.145.6.112']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--81b0b237-53ca-447d-9651-1a53a636bc18",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 81b760d4057c7c704f18c3f6b3e6b2c4",
      "pattern": "[file:hashes.MD5 = '81b760d4057c7c704f18c3f6b3e6b2c4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1b80019a-087e-4d43-8184-cb008c070b8e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 1243e256f9e806652ba8e719273494f84795bbfe",
      "pattern": "[file:hashes.'SHA-1' = '1243e256f9e806652ba8e719273494f84795bbfe']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--93da69db-9c1d-4506-8b1d-22ea4853a2e4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 2c3b2a6e741cb5d3be7299de007983f1f86c0ef5",
      "pattern": "[file:hashes.'SHA-1' = '2c3b2a6e741cb5d3be7299de007983f1f86c0ef5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--103faabc-ef88-4052-b01d-a37378a26336",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 47c6fdf51760c13d2602909ddbbb84ef8e33f992",
      "pattern": "[file:hashes.'SHA-1' = '47c6fdf51760c13d2602909ddbbb84ef8e33f992']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ffbd89b2-1726-476d-a5eb-3adf68be257f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 8988ef7abd931496d7bbdf7db1a67c9def0641d9",
      "pattern": "[file:hashes.'SHA-1' = '8988ef7abd931496d7bbdf7db1a67c9def0641d9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f4b8a71-f3b7-4242-86db-4aa0501f79c1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: ada7160c49cb22f569265fe3719fa2713a24dcf1",
      "pattern": "[file:hashes.'SHA-1' = 'ada7160c49cb22f569265fe3719fa2713a24dcf1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c174d61d-7915-43be-a07c-b763500a7f1a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: f4384ca1c2250d58a17e692ce2a8efd7dcc97a73",
      "pattern": "[file:hashes.'SHA-1' = 'f4384ca1c2250d58a17e692ce2a8efd7dcc97a73']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--16e52454-df96-493a-8ef5-d5eb46f67e84",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4ed46b98d047f5ed26553c6f4fded7209933ca9632b998d265870e3557a5cdfe",
      "pattern": "[file:hashes.'SHA-256' = '4ed46b98d047f5ed26553c6f4fded7209933ca9632b998d265870e3557a5cdfe']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f42a92d8-592b-44f6-8c80-ce93f8ba412e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-46604",
      "pattern": "[vulnerability:name = 'CVE-2023-46604']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46604 \u2014 Apache ActiveMQ Deserialization o",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--343c194a-1bbe-4c0c-9f8b-8d2e20670833",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: hellokittycat.online",
      "pattern": "[domain-name:value = 'hellokittycat.online']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46604 \u2014 Apache ActiveMQ Deserialization o",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd1aa023-f118-4a27-b8a4-84979de02ed0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 166.62.100.62",
      "pattern": "[ipv4-addr:value = '166.62.100.62']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46604 \u2014 Apache ActiveMQ Deserialization o",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb395556-b054-466e-bdaa-b5d639c22c7a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.245.16.125",
      "pattern": "[ipv4-addr:value = '172.245.16.125']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46604 \u2014 Apache ActiveMQ Deserialization o",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--54e92c90-93db-4c51-be25-6d61c20bb5b3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-46747",
      "pattern": "[vulnerability:name = 'CVE-2023-46747']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46748 \u2014 F5 BIG-IP Configuration Utility S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4f1443ec-3b57-41e4-b64e-0663c1351250",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-46748",
      "pattern": "[vulnerability:name = 'CVE-2023-46748']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-46748 \u2014 F5 BIG-IP Configuration Utility S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--974bbd92-2b25-4693-b3fa-1043446d3bc2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-5631",
      "pattern": "[vulnerability:name = 'CVE-2023-5631']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-5631 \u2014 Roundcube Webmail Persistent Cross",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--858ab268-c6f9-4458-807b-f7ff670b45dc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: recsecas.com",
      "pattern": "[domain-name:value = 'recsecas.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-5631 \u2014 Roundcube Webmail Persistent Cross",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0afced2-92be-4bb1-acd6-9c852efbdc64",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.180.76.31",
      "pattern": "[ipv4-addr:value = '38.180.76.31']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-5631 \u2014 Roundcube Webmail Persistent Cross",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--98c2c0ce-3862-419c-b2d0-ee6a1c58c8f6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 8BF7FCC70F6CE032217D9210EF30314DDD6B8135",
      "pattern": "[file:hashes.'SHA-1' = '8BF7FCC70F6CE032217D9210EF30314DDD6B8135']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-5631 \u2014 Roundcube Webmail Persistent Cross",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--89bce72c-f37c-44ca-bc21-678bf571a8a0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 97ED594EF2B5755F0549C6C5758377C0B87CFAE0",
      "pattern": "[file:hashes.'SHA-1' = '97ED594EF2B5755F0549C6C5758377C0B87CFAE0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-5631 \u2014 Roundcube Webmail Persistent Cross",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4151a90a-037a-4456-bc7a-7b68b7ef0288",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-46133",
      "pattern": "[vulnerability:name = 'CVE-2023-46133']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Weak Hash vulnerability discovered in crypto-js and crypto-e",
          "url": "https://snyk.io/blog/weak-hash-vulnerability-crypto-js-crypto-es/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--083a8995-79f8-4a4d-9d4b-ba3e2001c343",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-46233",
      "pattern": "[vulnerability:name = 'CVE-2023-46233']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Weak Hash vulnerability discovered in crypto-js and crypto-e",
          "url": "https://snyk.io/blog/weak-hash-vulnerability-crypto-js-crypto-es/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9117880e-6980-4fe3-95a6-07b6ad7325f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-23369",
      "pattern": "[vulnerability:name = 'CVE-2021-23369']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Adding Snyk security to Jira and Bitbucket Cloud",
          "url": "https://snyk.io/blog/adding-snyk-security-jira-bitbucket-cloud/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--629c5699-77c5-43f8-a672-f5887bdcf3e6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-20198",
      "pattern": "[vulnerability:name = 'CVE-2023-20198']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20273 \u2014 Cisco IOS XE Web UI Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-20198 \u2014 Cisco IOS XE Web UI Privilege Esc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2a7f6b52-753e-4ee2-9473-4d9023a94f34",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-20273",
      "pattern": "[vulnerability:name = 'CVE-2023-20273']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20273 \u2014 Cisco IOS XE Web UI Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-20198 \u2014 Cisco IOS XE Web UI Privilege Esc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4dd6466a-63ac-4866-b6df-aa860c077c67",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 154.53.56.231",
      "pattern": "[ipv4-addr:value = '154.53.56.231']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20273 \u2014 Cisco IOS XE Web UI Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-20198 \u2014 Cisco IOS XE Web UI Privilege Esc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f52c418f-e078-4619-9aba-23a20ec9a87e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.149.249.74",
      "pattern": "[ipv4-addr:value = '5.149.249.74']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20273 \u2014 Cisco IOS XE Web UI Command Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-20198 \u2014 Cisco IOS XE Web UI Privilege Esc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e0ef0021-1884-49e9-b45c-f647eea57b09",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-4966",
      "pattern": "[vulnerability:name = 'CVE-2023-4966']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-4966 \u2014 Citrix NetScaler ADC and NetScaler",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--672acd22-53af-4cee-8cbc-a894eed17dbf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 154.53.63.93",
      "pattern": "[ipv4-addr:value = '154.53.63.93']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20198 \u2014 Cisco IOS XE Web UI Privilege Esc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--be0ebab8-ad35-40c1-a0c1-57457f6210d1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-44487",
      "pattern": "[vulnerability:name = 'CVE-2023-44487']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Find and fix HTTP/2 rapid reset zero-day vulnerability CVE-2",
          "url": "https://snyk.io/blog/find-fix-http-2-rapid-reset-zero-day-vulnerability-cve-2023-44487/"
        },
        {
          "source_name": "CISA KEV: CVE-2023-44487 \u2014 HTTP/2 Rapid Reset Attack Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53eaac6e-3a07-4a7d-b987-37229e2683fc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-20109",
      "pattern": "[vulnerability:name = 'CVE-2023-20109']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20109 \u2014 Cisco IOS and IOS XE Group Encryp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--864cf466-3bbd-4168-95f1-99de1699a7da",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-21608",
      "pattern": "[vulnerability:name = 'CVE-2023-21608']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-21608 \u2014 Adobe Acrobat and Reader Use-Afte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--afc58d8e-b233-43a9-9757-7f73db3e7eeb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-36563",
      "pattern": "[vulnerability:name = 'CVE-2023-36563']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-36563 \u2014 Microsoft WordPad Information Dis",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--05aadcdf-92c3-4684-84eb-7e72eab423a5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-41763",
      "pattern": "[vulnerability:name = 'CVE-2023-41763']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41763 \u2014 Microsoft Skype for Business Priv",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9774ffba-5087-48cd-95f1-e864b46d80ad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-40044",
      "pattern": "[vulnerability:name = 'CVE-2023-40044']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-40044 \u2014 Progress WS_FTP Server Deserializ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f5c224e4-f5bc-4a42-92be-234809786e74",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-42657",
      "pattern": "[vulnerability:name = 'CVE-2023-42657']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-40044 \u2014 Progress WS_FTP Server Deserializ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--050869ac-b370-4ae2-ac96-61f7e4447405",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-42824",
      "pattern": "[vulnerability:name = 'CVE-2023-42824']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42824 \u2014 Apple iOS and iPadOS Kernel Privi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b1aebab-10e5-4cbf-a23b-0c0af9c254f9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: 2adc9m0bc70noboyvgt357r5gwmnady2.oastify.com",
      "pattern": "[domain-name:value = '2adc9m0bc70noboyvgt357r5gwmnady2.oastify.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-40044 \u2014 Progress WS_FTP Server Deserializ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1d545858-1216-4980-84a1-04576082d96b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: realtime-v1.backendapi-fe4.workers.dev",
      "pattern": "[domain-name:value = 'realtime-v1.backendapi-fe4.workers.dev']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-40044 \u2014 Progress WS_FTP Server Deserializ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d4ccf7f1-ca91-42a2-ba43-7c3975935fc1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: status.backendapi-fe4.workers.dev",
      "pattern": "[domain-name:value = 'status.backendapi-fe4.workers.dev']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-40044 \u2014 Progress WS_FTP Server Deserializ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ce86e2e6-0edd-4f20-90af-83e52829f8d4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.163.187.12",
      "pattern": "[ipv4-addr:value = '103.163.187.12']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-40044 \u2014 Progress WS_FTP Server Deserializ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2287d15-0c9a-44d3-8901-8bdf4d16bf06",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.128.89.92",
      "pattern": "[ipv4-addr:value = '104.128.89.92']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22515 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--49e3e37f-093c-4651-8b8b-1d468a5d4099",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 161.35.27.144",
      "pattern": "[ipv4-addr:value = '161.35.27.144']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-40044 \u2014 Progress WS_FTP Server Deserializ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--710bb167-119b-4197-a827-d0b3cae509fb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 162.243.161.105",
      "pattern": "[ipv4-addr:value = '162.243.161.105']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-40044 \u2014 Progress WS_FTP Server Deserializ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e615de3d-74a7-4e51-bbeb-ce65e52ac735",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.245.213.135",
      "pattern": "[ipv4-addr:value = '172.245.213.135']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-40044 \u2014 Progress WS_FTP Server Deserializ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--68442ca5-ea94-4c5e-bb56-051f714439cc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.69.90.31",
      "pattern": "[ipv4-addr:value = '192.69.90.31']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22515 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7d3fb77d-deb1-44b7-b372-533996f7920b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 199.193.127.231",
      "pattern": "[ipv4-addr:value = '199.193.127.231']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22515 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--81bdaf86-5b8f-4aa5-9248-4d393822be17",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 23.105.208.154",
      "pattern": "[ipv4-addr:value = '23.105.208.154']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22515 \u2014 Atlassian Confluence Data Center ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4445de38-87df-49a8-aa5c-bfae411c054f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 64.227.126.135",
      "pattern": "[ipv4-addr:value = '64.227.126.135']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-40044 \u2014 Progress WS_FTP Server Deserializ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b70198a8-b9e9-4146-894b-3f88d31df183",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 86.48.3.172",
      "pattern": "[ipv4-addr:value = '86.48.3.172']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-40044 \u2014 Progress WS_FTP Server Deserializ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c1efcbd-5180-42b7-b25d-32c3bb6812b5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-28229",
      "pattern": "[vulnerability:name = 'CVE-2023-28229']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-28229 \u2014 Microsoft Windows CNG Key Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--03782606-c661-4257-953d-40cd03c6e322",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-42793",
      "pattern": "[vulnerability:name = 'CVE-2023-42793']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e84a8c28-d0ec-4450-bafc-d97adfe02a1b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: 3dkit.org",
      "pattern": "[domain-name:value = '3dkit.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb5e642f-7a97-4a34-a901-5f12f150e788",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: aeon-petro.com",
      "pattern": "[domain-name:value = 'aeon-petro.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2898cd41-1011-4680-97ec-815a23531c39",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: bandarpowder.com",
      "pattern": "[domain-name:value = 'bandarpowder.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--898e3a51-c136-4676-a111-53dbe6b08bfa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: commune-fraita.ma",
      "pattern": "[domain-name:value = 'commune-fraita.ma']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--44dfe4bf-3655-480c-af74-aefb4c316c66",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: dersmarketim.com",
      "pattern": "[domain-name:value = 'dersmarketim.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb667f29-4b51-4eb3-817c-400c3d95953c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: fisheries-states-codes-camps.trycloudflare.com",
      "pattern": "[domain-name:value = 'fisheries-states-codes-camps.trycloudflare.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e9c87618-6562-4080-82ca-1cf27428c03e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: galerielamy.com",
      "pattern": "[domain-name:value = 'galerielamy.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3da4793b-0eca-4971-b4d0-f6d3c1701cff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: mge.sn",
      "pattern": "[domain-name:value = 'mge.sn']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dfb0f1ac-fc7c-4018-a03a-7376e06b79c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: olidhealth.com",
      "pattern": "[domain-name:value = 'olidhealth.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--49d0f15a-7eda-41ac-aee6-584813414eda",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ultasrv.com",
      "pattern": "[domain-name:value = 'ultasrv.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4598ff30-c4fc-43a9-a7f9-b6373e735569",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: vadtalmandir.org",
      "pattern": "[domain-name:value = 'vadtalmandir.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--07ef303e-1b7c-4d39-90df-5121355993eb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.76.128.34",
      "pattern": "[ipv4-addr:value = '103.76.128.34']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87a74a3c-8778-4281-8405-7417a680272f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 147.78.149.201",
      "pattern": "[ipv4-addr:value = '147.78.149.201']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0817f446-ad6e-4204-a8ba-b2619b845f01",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 162.19.71.175",
      "pattern": "[ipv4-addr:value = '162.19.71.175']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--89aa627d-bb1d-4cf2-939c-e4c7d34904ee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 167.114.3.69",
      "pattern": "[ipv4-addr:value = '167.114.3.69']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--86f0cb07-3a05-4de6-b43d-f7f098bc9277",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.133.7.124",
      "pattern": "[ipv4-addr:value = '45.133.7.124']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4cb2faaf-3745-456d-ac31-6cb412c60f70",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.133.7.129",
      "pattern": "[ipv4-addr:value = '45.133.7.129']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c73d7f0-6973-4929-8a5a-4faf4df07a18",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.133.7.154",
      "pattern": "[ipv4-addr:value = '45.133.7.154']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--25a3e83a-2c9f-43fd-b97b-487851259005",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.133.7.156",
      "pattern": "[ipv4-addr:value = '45.133.7.156']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d63fa9d0-8e9b-4afb-bcb2-aa39fee4b799",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.138.16.63",
      "pattern": "[ipv4-addr:value = '45.138.16.63']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c02441f-b86e-4105-9e29-75f4d05ad7f1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 92.38.177.14",
      "pattern": "[ipv4-addr:value = '92.38.177.14']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2c691694-f3d2-48c4-9d3a-954232d031c3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 2df317b8a408d2ad5c94b9de6f20bbef03e46066",
      "pattern": "[file:hashes.'SHA-1' = '2df317b8a408d2ad5c94b9de6f20bbef03e46066']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9a5c9ecc-eba2-49f1-a6bf-d7ad19088600",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 3a32e516c037c37f7bf83171e167511ba53870a7",
      "pattern": "[file:hashes.'SHA-1' = '3a32e516c037c37f7bf83171e167511ba53870a7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea163763-e508-4c89-bdf3-c6fad4ea9f45",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 4fed3d5de4df20d961831be6194b9d595b943bc9",
      "pattern": "[file:hashes.'SHA-1' = '4fed3d5de4df20d961831be6194b9d595b943bc9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--999b398c-a5b0-4195-b27a-bec01ea0a198",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 51aa6e5186ede77545e99b14b8f7e8180a0c6933",
      "pattern": "[file:hashes.'SHA-1' = '51aa6e5186ede77545e99b14b8f7e8180a0c6933']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0c28e659-0718-46a8-b206-a207f4308090",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 5ce062f210e1a5026cb53e9949865312ee477e3c",
      "pattern": "[file:hashes.'SHA-1' = '5ce062f210e1a5026cb53e9949865312ee477e3c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1a53167e-1679-4ef6-98c3-348d538ea591",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 682b9ac9448707024985ad54476acfbf642a03b9",
      "pattern": "[file:hashes.'SHA-1' = '682b9ac9448707024985ad54476acfbf642a03b9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--58e3a58d-2a13-46fa-a350-6cb5dde58af9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 8f5780056107dbc2bb59d63f454d8523091ddde2",
      "pattern": "[file:hashes.'SHA-1' = '8f5780056107dbc2bb59d63f454d8523091ddde2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e988e8af-831a-4c13-a1df-ac617492bc3f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: a4b03f1e981ccdd7e08e786c72283d5551671edf",
      "pattern": "[file:hashes.'SHA-1' = 'a4b03f1e981ccdd7e08e786c72283d5551671edf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d662c11-499e-4c12-8a4b-8d413f41b699",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: a66d76d86448965e57d7be96a57529c497e4b99d",
      "pattern": "[file:hashes.'SHA-1' = 'a66d76d86448965e57d7be96a57529c497e4b99d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e0b2750d-1a66-4a5c-b780-486953bbe6a6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: bcbadf744954660f9a46324649eda6a14d724cbc",
      "pattern": "[file:hashes.'SHA-1' = 'bcbadf744954660f9a46324649eda6a14d724cbc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2b31a10b-5735-4994-be71-944f474efcd8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: d4411f70e0dcc2f88d74ae7251d51c6676075f6f",
      "pattern": "[file:hashes.'SHA-1' = 'd4411f70e0dcc2f88d74ae7251d51c6676075f6f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--250330e9-eb8c-41ad-b24b-09583cb4cbf0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: f836173805a8c4d4ee319fdefe4a5e92f3f55f32",
      "pattern": "[file:hashes.'SHA-1' = 'f836173805a8c4d4ee319fdefe4a5e92f3f55f32']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0143a26f-a904-4f6b-a847-e423afaf731f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 000752074544950ae9020a35ccd77de277f1cd5026b4b9559279dc3b86965eee",
      "pattern": "[file:hashes.'SHA-256' = '000752074544950ae9020a35ccd77de277f1cd5026b4b9559279dc3b86965eee']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--24efc411-f08c-4c47-8101-be6155a11ce7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 0be1908566efb9d23a98797884f2827de040e4cedb642b60ed66e208715ed4aa",
      "pattern": "[file:hashes.'SHA-256' = '0be1908566efb9d23a98797884f2827de040e4cedb642b60ed66e208715ed4aa']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7e3b3d67-1fb1-4d29-961a-e8a9eae3e7d9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d9add2bfdfebfa235575687de356f0cefb3e4c55964c4cb8bfdcdc58294eeaca",
      "pattern": "[file:hashes.'SHA-256' = 'd9add2bfdfebfa235575687de356f0cefb3e4c55964c4cb8bfdcdc58294eeaca']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6f457dfa-bd4f-4691-908c-1450bd2fa11d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e06f29dccfe90ae80812c2357171b5c48fba189ae103d28e972067b107e58795",
      "pattern": "[file:hashes.'SHA-256' = 'e06f29dccfe90ae80812c2357171b5c48fba189ae103d28e972067b107e58795']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dce20392-7c74-4959-977c-3c127babd88f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f251144f7ad0be0045034a1fc33fb896e8c32874e0b05869ff5783e14c062486",
      "pattern": "[file:hashes.'SHA-256' = 'f251144f7ad0be0045034a1fc33fb896e8c32874e0b05869ff5783e14c062486']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c46388a-cccc-4e72-9cd1-8630280d70bf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: fa7f6ac04ec118dd807c1377599f9d369096c6d8fb1ed24ac7a6ec0e817eaab6",
      "pattern": "[file:hashes.'SHA-256' = 'fa7f6ac04ec118dd807c1377599f9d369096c6d8fb1ed24ac7a6ec0e817eaab6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c049323b-2c06-48cb-b525-eb4515edce88",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-38545",
      "pattern": "[vulnerability:name = 'CVE-2023-38545']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "High severity vulnerability found in libcurl and curl (CVE-2",
          "url": "https://snyk.io/blog/curl-high-severity-vulnerability-oct-2023/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e57ad066-4a37-47c7-8459-9264f33dc041",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-38546",
      "pattern": "[vulnerability:name = 'CVE-2023-38546']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "High severity vulnerability found in libcurl and curl (CVE-2",
          "url": "https://snyk.io/blog/curl-high-severity-vulnerability-oct-2023/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--233e974f-2b91-4713-87a5-615109475262",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-4211",
      "pattern": "[vulnerability:name = 'CVE-2023-4211']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-4211 \u2014 Arm Mali GPU Kernel Driver Use-Aft",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bcab5fd0-b8a6-4cf9-bd74-df5b4d47bb26",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-5217",
      "pattern": "[vulnerability:name = 'CVE-2023-5217']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-5217 \u2014 Google Chromium libvpx Heap Buffer",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2295c27e-43a7-438d-adbc-20b6b21f043f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-14667",
      "pattern": "[vulnerability:name = 'CVE-2018-14667']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-14667 \u2014 Red Hat JBoss RichFaces Framework",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b59f296c-eb25-4f76-8cf4-637b18d37621",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-41061",
      "pattern": "[vulnerability:name = 'CVE-2023-41061']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Critical WebP 0-day security CVE-2023-4863 impacts wider sof",
          "url": "https://snyk.io/blog/critical-webp-0-day-cve-2023-4863/"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41064 \u2014 Apple iOS, iPadOS, and macOS Imag",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4e648c9b-9482-420a-8895-36c4f24af8fc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-41064",
      "pattern": "[vulnerability:name = 'CVE-2023-41064']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Critical WebP 0-day security CVE-2023-4863 impacts wider sof",
          "url": "https://snyk.io/blog/critical-webp-0-day-cve-2023-4863/"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41064 \u2014 Apple iOS, iPadOS, and macOS Imag",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--baba72bb-e834-4f0f-8d1e-6a3c9b7747e8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-4863",
      "pattern": "[vulnerability:name = 'CVE-2023-4863']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Critical WebP 0-day security CVE-2023-4863 impacts wider sof",
          "url": "https://snyk.io/blog/critical-webp-0-day-cve-2023-4863/"
        },
        {
          "source_name": "CISA KEV: CVE-2023-4863 \u2014 Google Chromium WebP Heap-Based Bu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--78a03180-090b-4b57-9cb7-d8a85f6a5789",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-5129",
      "pattern": "[vulnerability:name = 'CVE-2023-5129']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Critical WebP 0-day security CVE-2023-4863 impacts wider sof",
          "url": "https://snyk.io/blog/critical-webp-0-day-cve-2023-4863/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--45cd096b-d73c-4413-9416-eebf55b603d0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-41991",
      "pattern": "[vulnerability:name = 'CVE-2023-41991']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Pr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41993 \u2014 Apple Multiple Products WebKit Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f5ac16d-e7ac-4bfe-afd3-9df770667836",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-41992",
      "pattern": "[vulnerability:name = 'CVE-2023-41992']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Pr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41993 \u2014 Apple Multiple Products WebKit Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a3e44c3a-ee1f-48b2-a403-5765c23b5c4f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-41993",
      "pattern": "[vulnerability:name = 'CVE-2023-41993']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Pr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41993 \u2014 Apple Multiple Products WebKit Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--863567dd-b3f9-41c3-9b97-bea709b4e2e2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: almal-news.com",
      "pattern": "[domain-name:value = 'almal-news.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Pr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b0dafe4-2f58-4d3f-aa9e-864bbb6538b9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: betly.me",
      "pattern": "[domain-name:value = 'betly.me']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Pr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9f5ba0e8-bafd-4bce-bbe4-3b322e6561f6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: c.betly.me",
      "pattern": "[domain-name:value = 'c.betly.me']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Pr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--47b6af63-199a-436b-9aa5-de9995f709f2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: chat-support.support",
      "pattern": "[domain-name:value = 'chat-support.support']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Pr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dfb970d7-0ecb-485a-a0d2-349b1d10ee1c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cibeg.online",
      "pattern": "[domain-name:value = 'cibeg.online']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Pr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aac3a3a8-12fc-43a4-ad44-28c1f558c396",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: notifications-sec.com",
      "pattern": "[domain-name:value = 'notifications-sec.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Pr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1b1d21a3-2d65-4bf3-9c87-60ccbf0f2967",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sec-flare.com",
      "pattern": "[domain-name:value = 'sec-flare.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Pr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f5151c3d-8ffb-4c32-8af4-7936f5df8f94",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: t-bit.me",
      "pattern": "[domain-name:value = 't-bit.me']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Pr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--38a1c989-52c6-47fb-9ef5-e026c10750cf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: verifyurl.me",
      "pattern": "[domain-name:value = 'verifyurl.me']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Pr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb115644-a643-4298-af67-b7e764f4e1f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: wa-info.com",
      "pattern": "[domain-name:value = 'wa-info.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Pr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0e03b57f-ea84-4e33-9a4e-42f2b892d66c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: whatssapp.co",
      "pattern": "[domain-name:value = 'whatssapp.co']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Pr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cdb0fda3-76a1-4434-ad45-7e233a673f31",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: wts-app.info",
      "pattern": "[domain-name:value = 'wts-app.info']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Pr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b2c5c10d-f9e9-43df-bfca-faad09ed8e58",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 41.206.153.241",
      "pattern": "[ipv4-addr:value = '41.206.153.241']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6f25155a-6aff-4c99-9c2e-6c1557ccd561",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7af95e7782a807967508a25c6709bd7a2686378b47fab56ccb23341324b7fe40",
      "pattern": "[file:hashes.'SHA-256' = '7af95e7782a807967508a25c6709bd7a2686378b47fab56ccb23341324b7fe40']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0a54bda5-9068-4e8e-bdb1-dcc85a1bbf34",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 85d8f504cadb55851a393a13a026f1833ed6db32cb07882415e029e709ae0750",
      "pattern": "[file:hashes.'SHA-256' = '85d8f504cadb55851a393a13a026f1833ed6db32cb07882415e029e709ae0750']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--19725cbc-6718-4f18-934d-71ded368dedd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e3314bcd085bd547d9b977351ab72a8b83093c47a73eb5502db4b98e0db42cac",
      "pattern": "[file:hashes.'SHA-256' = 'e3314bcd085bd547d9b977351ab72a8b83093c47a73eb5502db4b98e0db42cac']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--77d8db45-0f88-448d-98b4-ecce08902f84",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-41179",
      "pattern": "[vulnerability:name = 'CVE-2023-41179']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-41179 \u2014 Trend Micro Apex One and Worry-Fr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b46ec7b7-e8f4-4825-a07d-f873ce95fd4d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-28434",
      "pattern": "[vulnerability:name = 'CVE-2023-28434']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-28434 \u2014 MinIO Security Feature Bypass Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e75a9424-b040-4a93-b222-4240a93fcce8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-6884",
      "pattern": "[vulnerability:name = 'CVE-2017-6884']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-6884 \u2014 Zyxel EMG2926 Routers Command Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--31659253-9f81-4d9b-be47-e6e1de0b7ecd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-3129",
      "pattern": "[vulnerability:name = 'CVE-2021-3129']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-3129 \u2014 Laravel Ignition File Upload Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--25d0a8e9-30a4-45ac-ba19-590b6ec5177e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-22265",
      "pattern": "[vulnerability:name = 'CVE-2022-22265']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22265 \u2014 Samsung Mobile Devices Use-After-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fc2c6ae9-a913-4049-b258-a8c082200932",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-26369",
      "pattern": "[vulnerability:name = 'CVE-2023-26369']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-26369 \u2014 Adobe Acrobat and Reader Out-of-B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--42c3d3ea-2083-4ccf-a6db-85e1bb2c8584",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-20269",
      "pattern": "[vulnerability:name = 'CVE-2023-20269']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20269 \u2014 Cisco Adaptive Security Appliance",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a195d745-1b6e-4af1-928b-685d060cdbbf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-35674",
      "pattern": "[vulnerability:name = 'CVE-2023-35674']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-35674 \u2014 Android Framework Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2fcd562e-c070-48a3-a4b2-c324f736dcee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-36761",
      "pattern": "[vulnerability:name = 'CVE-2023-36761']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-36761 \u2014 Microsoft Word Information Disclo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4b865df8-ce01-45bf-85ec-6f4feb711e18",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-36802",
      "pattern": "[vulnerability:name = 'CVE-2023-36802']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-36802 \u2014 Microsoft Streaming Service Proxy",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32acd13d-b62c-4f74-a016-cd68c8ee1128",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-33246",
      "pattern": "[vulnerability:name = 'CVE-2023-33246']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33246 \u2014 Apache RocketMQ Command Execution",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0419b3bd-08db-4e8d-b124-7b28113273a8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.85.25.121",
      "pattern": "[ipv4-addr:value = '103.85.25.121']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33246 \u2014 Apache RocketMQ Command Execution",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4e3fd937-8acd-4549-ad31-e7caf2a83ec2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 134.209.58.230",
      "pattern": "[ipv4-addr:value = '134.209.58.230']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33246 \u2014 Apache RocketMQ Command Execution",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b6aebd1-e5cd-4b9a-a57b-96fdb3e98f38",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.15.158.124",
      "pattern": "[ipv4-addr:value = '45.15.158.124']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33246 \u2014 Apache RocketMQ Command Execution",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--908ef9de-8c2e-4d6b-b60b-8763303b5611",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 94.156.6.110",
      "pattern": "[ipv4-addr:value = '94.156.6.110']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33246 \u2014 Apache RocketMQ Command Execution",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--039f0e77-673c-4df1-abff-2e6d39916111",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1d489a41395be76a8101c2e1eba383253a291f4e84a9da389c6b58913786b8ac",
      "pattern": "[file:hashes.'SHA-256' = '1d489a41395be76a8101c2e1eba383253a291f4e84a9da389c6b58913786b8ac']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33246 \u2014 Apache RocketMQ Command Execution",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a2d4eb4c-c33e-4ab7-98d8-c5e70c30468e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 49062378ab3e4a0d78c6db662efb4dbc680808fb75834b4674809bc8903adaea",
      "pattern": "[file:hashes.'SHA-256' = '49062378ab3e4a0d78c6db662efb4dbc680808fb75834b4674809bc8903adaea']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33246 \u2014 Apache RocketMQ Command Execution",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--80007f52-1b1d-450a-8090-6a7e0941ef50",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4feb3dcfe57e3b112568ddd1897b68aeb134ef8addd27b660530442ea1e49cbb",
      "pattern": "[file:hashes.'SHA-256' = '4feb3dcfe57e3b112568ddd1897b68aeb134ef8addd27b660530442ea1e49cbb']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33246 \u2014 Apache RocketMQ Command Execution",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c49625b0-7536-4776-be1a-a296ae428f77",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d7843904e1c25055e14cae8b44b28f9dd4706c0ad8b03f55dfcded36ce8423a0",
      "pattern": "[file:hashes.'SHA-256' = 'd7843904e1c25055e14cae8b44b28f9dd4706c0ad8b03f55dfcded36ce8423a0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33246 \u2014 Apache RocketMQ Command Execution",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--746c4fa3-6abb-4dee-8628-a9ab0e984287",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f93e9bc9583058d82d2d3fe35117cbb9a553d54e7149846b2dc94446f0836201",
      "pattern": "[file:hashes.'SHA-256' = 'f93e9bc9583058d82d2d3fe35117cbb9a553d54e7149846b2dc94446f0836201']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33246 \u2014 Apache RocketMQ Command Execution",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f5564107-7b29-45f3-8aee-85d9ef0083ad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-32315",
      "pattern": "[vulnerability:name = 'CVE-2023-32315']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-32315 \u2014 Ignite Realtime Openfire Path Tra",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c0bfb23-b1d6-43af-bf35-97031a680121",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-27532",
      "pattern": "[vulnerability:name = 'CVE-2023-27532']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a5c12ac0-b449-4f53-ba75-a3e7b41882e5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-38035",
      "pattern": "[vulnerability:name = 'CVE-2023-38035']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-38035 \u2014 Ivanti Sentry Authentication Bypa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2d66b12-353f-4def-9607-5f12e046b816",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 149.28.106.252",
      "pattern": "[ipv4-addr:value = '149.28.106.252']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4acaf4ea-e66f-4f9a-b7aa-1a06eac7dba6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 149.28.99.61",
      "pattern": "[ipv4-addr:value = '149.28.99.61']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--232fb66c-6279-4287-9ddb-79b11c61a1ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 162.248.225.115",
      "pattern": "[ipv4-addr:value = '162.248.225.115']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--83e75c46-b468-4ad8-9f35-95b5b4d1356f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.87.148.41",
      "pattern": "[ipv4-addr:value = '194.87.148.41']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ba9ff510-97fc-46ac-b848-75153925f045",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 195.123.244.162",
      "pattern": "[ipv4-addr:value = '195.123.244.162']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a7c45bff-26c1-4290-b2ed-8abe37eb9ef4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 217.12.206.176",
      "pattern": "[ipv4-addr:value = '217.12.206.176']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--92b9ac7a-5da5-48bc-92f1-5702b64fc315",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.136.199.128",
      "pattern": "[ipv4-addr:value = '45.136.199.128']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--093eae4c-844e-4c5a-9179-e77771335902",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.76.232.205",
      "pattern": "[ipv4-addr:value = '45.76.232.205']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ac9f6e2a-62d4-4943-981e-25ac955458b6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 77.238.245.11",
      "pattern": "[ipv4-addr:value = '77.238.245.11']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da16b060-5b2d-4e40-8873-ccd1a907dcb7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 77.75.230.112",
      "pattern": "[ipv4-addr:value = '77.75.230.112']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ad3788ad-75a9-4bc9-81d8-2c8b2b91cc5e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 91.149.243.181",
      "pattern": "[ipv4-addr:value = '91.149.243.181']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8068e09d-49c0-42cc-9214-9c3ac62adf8b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 91.199.147.152",
      "pattern": "[ipv4-addr:value = '91.199.147.152']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c952f39-b510-44c1-9e36-7df2178cc24e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 95.217.49.123",
      "pattern": "[ipv4-addr:value = '95.217.49.123']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ad9e35c2-abf8-4dcd-8cdd-59ef07a78c3c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 107EC3A7ED7AD908774AD18E3E03D4B999D4690C",
      "pattern": "[file:hashes.'SHA-1' = '107EC3A7ED7AD908774AD18E3E03D4B999D4690C']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--93aba7d4-3c17-47da-9cad-90288c924dc2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 2C56E9BEEA9F0801E0110A7DC5549B4FA0661362",
      "pattern": "[file:hashes.'SHA-1' = '2C56E9BEEA9F0801E0110A7DC5549B4FA0661362']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76a82bce-bdfa-46e6-b050-3b9c5b2856ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 5E460A517F0579B831B09EC99EF158AC0DD3D4FA",
      "pattern": "[file:hashes.'SHA-1' = '5E460A517F0579B831B09EC99EF158AC0DD3D4FA']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--255c8505-4036-4a24-a5bd-654e934b8bb1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 8687B6B1508A93556D6E30D14E5C4EE9971F2D80",
      "pattern": "[file:hashes.'SHA-1' = '8687B6B1508A93556D6E30D14E5C4EE9971F2D80']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32ed02ab-8204-4671-8829-3238fb51a43e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: B621F8C5E9033718B4E9D47A2F0ECCB9783F612A",
      "pattern": "[file:hashes.'SHA-1' = 'B621F8C5E9033718B4E9D47A2F0ECCB9783F612A']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb696ec5-96d7-4dcc-ac6a-b61c92be950b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: CB704D2E8DF80FD3500A5B817966DC262D80DDB8",
      "pattern": "[file:hashes.'SHA-1' = 'CB704D2E8DF80FD3500A5B817966DC262D80DDB8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--80aa3081-6dc3-4187-af16-9f542a39b3c7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: E5480A47172E3F75DBF0384F4CA82C7B47910E0F",
      "pattern": "[file:hashes.'SHA-1' = 'E5480A47172E3F75DBF0384F4CA82C7B47910E0F']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--71ead8b0-3c30-46c8-b8f2-4ff216fd6f92",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-24489",
      "pattern": "[vulnerability:name = 'CVE-2023-24489']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-24489 \u2014 Citrix Content Collaboration Shar",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--edf38dbc-668e-4ca4-aa2b-73ca2fab0c8d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-38180",
      "pattern": "[vulnerability:name = 'CVE-2023-38180']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-38180 \u2014 Microsoft .NET Core and Visual St",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ee02c618-e78c-4e4e-a48d-c0eb4b8248c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-229",
      "pattern": "[vulnerability:name = 'CVE-2022-229']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Manage security issues in Jira with Snyk Security in Jira Cl",
          "url": "https://snyk.io/blog/snyk-security-in-jira-cloud/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4b0836b-b126-4e75-9f81-fe5139005a0b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-22967",
      "pattern": "[vulnerability:name = 'CVE-2022-22967']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Manage security issues in Jira with Snyk Security in Jira Cl",
          "url": "https://snyk.io/blog/snyk-security-in-jira-cloud/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fb18a468-73d4-4799-95df-aefdc91662ee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cdn.devlooped.com",
      "pattern": "[domain-name:value = 'cdn.devlooped.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": ".NET developers alert: Moq NuGET package exfiltrates user em",
          "url": "https://snyk.io/blog/moq-package-exfiltrates-user-emails/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7a58e646-74fb-486d-9dba-91468ab67151",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-37580",
      "pattern": "[vulnerability:name = 'CVE-2023-37580']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-37580 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1303891c-d906-46f6-8fc5-818c36f607d0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: applicationdevsoc.com",
      "pattern": "[domain-name:value = 'applicationdevsoc.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-37580 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--43e4c84f-a9d3-4497-a001-0505ecc2989f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ntcpk.org",
      "pattern": "[domain-name:value = 'ntcpk.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-37580 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--48f973c1-ecb6-4bd8-8a00-badae2c89b9a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: obsorth.opwtjnpoc.ml",
      "pattern": "[domain-name:value = 'obsorth.opwtjnpoc.ml']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-37580 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e9bf76b0-35d1-4eeb-a60b-ddac09396316",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-3519",
      "pattern": "[vulnerability:name = 'CVE-2023-3519']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-3519 \u2014 Citrix NetScaler ADC and NetScaler",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f7767ecd-c42f-4038-9524-b6c997afd3e5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 216.41.162.172",
      "pattern": "[ipv4-addr:value = '216.41.162.172']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-3519 \u2014 Citrix NetScaler ADC and NetScaler",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c81c1e24-998b-497a-91d4-54508431cc85",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 216.51.171.17",
      "pattern": "[ipv4-addr:value = '216.51.171.17']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-3519 \u2014 Citrix NetScaler ADC and NetScaler",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e8d4556f-0aac-44c9-99d3-28a8b8ee9158",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 293fe23849cffb460e8d28691c640a5292fd4649b0f94a019b45cc586be83fd9",
      "pattern": "[file:hashes.'SHA-256' = '293fe23849cffb460e8d28691c640a5292fd4649b0f94a019b45cc586be83fd9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-3519 \u2014 Citrix NetScaler ADC and NetScaler",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67ccd4cf-da76-4378-b912-47803ddc244a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.234.239.26",
      "pattern": "[ipv4-addr:value = '104.234.239.26']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-36884 \u2014 Microsoft Windows Search Remote C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--33a8c13d-ca5f-4f08-a2d3-0d8b5a697658",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a61b2eafcf39715031357df6b01e85e0d1ea2e8ee1dfec241b114e18f7a1163f",
      "pattern": "[file:hashes.'SHA-256' = 'a61b2eafcf39715031357df6b01e85e0d1ea2e8ee1dfec241b114e18f7a1163f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-36884 \u2014 Microsoft Windows Search Remote C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fbad6ef5-6c5f-478f-87ce-352c7749590d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e7cfeb023c3160a7366f209a16a6f6ea5a0bc9a3ddc16c6cba758114dfe6b539",
      "pattern": "[file:hashes.'SHA-256' = 'e7cfeb023c3160a7366f209a16a6f6ea5a0bc9a3ddc16c6cba758114dfe6b539']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-36884 \u2014 Microsoft Windows Search Remote C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1123a224-05e8-4720-8bed-7ec2a9422cf0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-29303",
      "pattern": "[vulnerability:name = 'CVE-2022-29303']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bbd69d1b-2197-4f84-94ca-027080d1a714",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-31374",
      "pattern": "[vulnerability:name = 'CVE-2022-31374']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d22ea04e-5941-469a-8737-274cd082470d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-44354",
      "pattern": "[vulnerability:name = 'CVE-2022-44354']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0f5a599-5c47-4470-8ddf-63067d484287",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-23333",
      "pattern": "[vulnerability:name = 'CVE-2023-23333']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cc91fa6c-05ae-46d2-9cd0-22bacc5af59c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-37450",
      "pattern": "[vulnerability:name = 'CVE-2023-37450']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-37450 \u2014 Apple Multiple Products WebKit Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ca446155-d93c-422d-814e-6bc44384bf67",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-31199",
      "pattern": "[vulnerability:name = 'CVE-2022-31199']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-31199 \u2014 Netwrix Auditor Insecure Object D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f2a9c7c-9f42-45d2-8e03-8a92e658d06f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-32046",
      "pattern": "[vulnerability:name = 'CVE-2023-32046']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-32046 \u2014 Microsoft Windows MSHTML Platform",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-36874 \u2014 Microsoft Windows Error Reporting",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3fcf4e1e-b438-4487-8bbf-482acb5c220b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-32049",
      "pattern": "[vulnerability:name = 'CVE-2023-32049']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a38bcbf8-7cd5-4a75-90f7-d01d8f485e1a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-35311",
      "pattern": "[vulnerability:name = 'CVE-2023-35311']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-35311 \u2014 Microsoft Outlook Security Featur",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cfd7aa5a-9e02-4c6c-96a7-f1d5ff297d65",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-36874",
      "pattern": "[vulnerability:name = 'CVE-2023-36874']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-36874 \u2014 Microsoft Windows Error Reporting",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fcf3ad93-48de-4fe4-94e9-313023eba472",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 66.23.226.102",
      "pattern": "[ipv4-addr:value = '66.23.226.102']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb338556-5ff9-4e96-ab1c-14f0faa5d7d2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 74.50.94.156",
      "pattern": "[ipv4-addr:value = '74.50.94.156']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--665007dd-fdd8-4e08-b86a-6db5207c1e26",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 94.232.40.34",
      "pattern": "[ipv4-addr:value = '94.232.40.34']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--613a40de-4fa1-47ca-aa28-93632e5e06c9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 07377209fe68a98e9bca310d9749daa4eb79558e9fc419cf0b02a9e37679038d",
      "pattern": "[file:hashes.'SHA-256' = '07377209fe68a98e9bca310d9749daa4eb79558e9fc419cf0b02a9e37679038d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87d4b9a6-e872-4899-9fb9-2d43a25e53d5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1a7bb878c826fe0ca9a0677ed072ee9a57a228a09ee02b3c5bd00f54f354930f",
      "pattern": "[file:hashes.'SHA-256' = '1a7bb878c826fe0ca9a0677ed072ee9a57a228a09ee02b3c5bd00f54f354930f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f98397b1-8adf-4445-b6d8-94dd412573b4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3a3138c5add59d2172ad33bc6761f2f82ba344f3d03a2269c623f22c1a35df97",
      "pattern": "[file:hashes.'SHA-256' = '3a3138c5add59d2172ad33bc6761f2f82ba344f3d03a2269c623f22c1a35df97']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aa5724bc-c261-4f27-a2ce-3c4fc9c2b47c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-29256",
      "pattern": "[vulnerability:name = 'CVE-2021-29256']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-29256 \u2014 Arm Mali GPU Kernel Driver Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f5ccce9a-c833-4048-b446-83a4c35ee68c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-17621",
      "pattern": "[vulnerability:name = 'CVE-2019-17621']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e483f8d2-bd6f-4940-ac0c-e8dba21da689",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-20500",
      "pattern": "[vulnerability:name = 'CVE-2019-20500']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-20500 \u2014 D-Link DWL-2600AP Access Point Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0174a0b6-00ce-474f-a4f3-8789677f50f5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-25371",
      "pattern": "[vulnerability:name = 'CVE-2021-25371']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-25371 \u2014 Samsung Mobile Devices Unspecifie",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f6555479-d6cf-4757-87b2-73812b3e84cc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-25372",
      "pattern": "[vulnerability:name = 'CVE-2021-25372']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-25372 \u2014 Samsung Mobile Devices Improper B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c891932c-2019-4d0c-806e-b868c9b7a3e4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-25394",
      "pattern": "[vulnerability:name = 'CVE-2021-25394']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-25394 \u2014 Samsung Mobile Devices Race Condi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--603d9ba8-00fc-45be-b204-fd0b8077bfc3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-25395",
      "pattern": "[vulnerability:name = 'CVE-2021-25395']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-25395 \u2014 Samsung Mobile Devices Race Condi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f0460e2-ce1e-49b8-8fb5-73cb8f384fc3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-25487",
      "pattern": "[vulnerability:name = 'CVE-2021-25487']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-25487 \u2014 Samsung Mobile Devices Out-of-Bou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--671e8084-0d8a-49c3-b538-7c427b6793ac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-25489",
      "pattern": "[vulnerability:name = 'CVE-2021-25489']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-25489 \u2014 Samsung Mobile Devices Improper I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c3faa1d8-9b91-4355-ac21-8e29fe7e4ffe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-27992",
      "pattern": "[vulnerability:name = 'CVE-2023-27992']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27992 \u2014 Zyxel Multiple NAS Devices Comman",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e94e7462-3b15-463b-836e-b08f3c8477ad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-32439",
      "pattern": "[vulnerability:name = 'CVE-2023-32439']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-32439 \u2014 Apple Multiple Products WebKit Ty",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a02bd230-2cf0-469b-be2e-e7e0f6cc7718",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: backuprabbit.com",
      "pattern": "[domain-name:value = 'backuprabbit.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-32434 \u2014 Apple Multiple Products Integer O",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--713af30b-e788-451a-84df-96c4349c4040",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cloudsponcer.com",
      "pattern": "[domain-name:value = 'cloudsponcer.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-32434 \u2014 Apple Multiple Products Integer O",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0435e30e-96bd-4cc0-bba1-e29e60211fc7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: snoweeanalytics.com",
      "pattern": "[domain-name:value = 'snoweeanalytics.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-32434 \u2014 Apple Multiple Products Integer O",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--96971c53-14bc-4df8-b2db-2a43076b58e4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: topographyupdates.com",
      "pattern": "[domain-name:value = 'topographyupdates.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-32434 \u2014 Apple Multiple Products Integer O",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ec70c9fa-35af-4727-b874-0d31a489141f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: unlimitedteacup.com",
      "pattern": "[domain-name:value = 'unlimitedteacup.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-32434 \u2014 Apple Multiple Products Integer O",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aac3328a-8a77-4ade-8d2f-16bacd5de434",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: virtuallaughing.com",
      "pattern": "[domain-name:value = 'virtuallaughing.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-32434 \u2014 Apple Multiple Products Integer O",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--398e7323-3fdd-4b2e-b703-1c5b1b60b4ae",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-0165",
      "pattern": "[vulnerability:name = 'CVE-2016-0165']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-0165 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--620cafc3-bc32-4074-8385-46f92eb4f6f4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-9079",
      "pattern": "[vulnerability:name = 'CVE-2016-9079']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-9079 \u2014 Mozilla Firefox, Firefox ESR, and ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e210a07d-64d5-49ff-b43c-06f920fc4fa9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-20887",
      "pattern": "[vulnerability:name = 'CVE-2023-20887']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20887 \u2014 Vmware Aria Operations for Networ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3f7ce540-3d72-435a-8581-fc43102dd6aa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-1471",
      "pattern": "[vulnerability:name = 'CVE-2022-1471']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "SnakeYaml 2.0: Solving the unsafe deserialization vulnerabil",
          "url": "https://snyk.io/blog/snakeyaml-unsafe-deserialization-vulnerability/"
        },
        {
          "source_name": "Unsafe deserialization vulnerability in SnakeYaml (CVE-2022-",
          "url": "https://snyk.io/blog/unsafe-deserialization-snakeyaml-java-cve-2022-1471/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b805265b-2cf6-4d6d-8137-90b1b8917fb1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-3079",
      "pattern": "[vulnerability:name = 'CVE-2023-3079']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-3079 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d8576ecc-38f1-4ee1-94d8-5f95e431c923",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-33009",
      "pattern": "[vulnerability:name = 'CVE-2023-33009']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33009 \u2014 Zyxel Multiple Firewalls Buffer O",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-33010 \u2014 Zyxel Multiple Firewalls Buffer O",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7f70d588-7537-4d8e-b2ae-5717e052a0b8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-33010",
      "pattern": "[vulnerability:name = 'CVE-2023-33010']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-33009 \u2014 Zyxel Multiple Firewalls Buffer O",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-33010 \u2014 Zyxel Multiple Firewalls Buffer O",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ee9f1128-eb87-4217-8754-a227b6469735",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 0b3220b11698b1436d1d866ac07cc90018e59884e91a8cb71ef8924309f1e0e9",
      "pattern": "[file:hashes.'SHA-256' = '0b3220b11698b1436d1d866ac07cc90018e59884e91a8cb71ef8924309f1e0e9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-34362 \u2014 Progress MOVEit Transfer SQL Inje",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c1a0215b-07da-46f9-acb9-00f7e4091da3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-28771",
      "pattern": "[vulnerability:name = 'CVE-2023-28771']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-28771 \u2014 Zyxel Multiple Firewalls OS Comma",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--995ee4a1-8eca-45f3-a33b-22d9752dcc46",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 101.229.146.218",
      "pattern": "[ipv4-addr:value = '101.229.146.218']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6fbad8c8-a72d-4485-be6a-b71fef9a75fa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.146.179.101",
      "pattern": "[ipv4-addr:value = '103.146.179.101']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--39153dce-2a48-4df7-8a47-017e94f013ed",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.27.108.62",
      "pattern": "[ipv4-addr:value = '103.27.108.62']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cf87c1a9-1107-4f04-9abb-e648c9105969",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.77.192.13",
      "pattern": "[ipv4-addr:value = '103.77.192.13']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d9c7a829-da7e-41cc-8506-4af022e07c72",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.77.192.88",
      "pattern": "[ipv4-addr:value = '103.77.192.88']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5b1f5661-ee45-4103-92a1-a5bc0bcc7f78",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.93.78.142",
      "pattern": "[ipv4-addr:value = '103.93.78.142']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--97b8c659-93dd-40df-a091-c03f56d22c56",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.156.229.226",
      "pattern": "[ipv4-addr:value = '104.156.229.226']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e8879fb4-4d63-4838-bc37-3847a25e6021",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.223.20.222",
      "pattern": "[ipv4-addr:value = '104.223.20.222']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fbc42f78-2e24-49ec-afff-026b54a23b87",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 107.148.149.156",
      "pattern": "[ipv4-addr:value = '107.148.149.156']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0e23b6dc-9a98-4cfa-a178-434c91e65932",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 107.148.219.227",
      "pattern": "[ipv4-addr:value = '107.148.219.227']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fee32e79-ab18-488d-9ec9-58eca162c9d1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 107.148.219.53",
      "pattern": "[ipv4-addr:value = '107.148.219.53']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0e4c480a-ab75-401f-b9e9-29dcbd7e2f05",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 107.148.219.54",
      "pattern": "[ipv4-addr:value = '107.148.219.54']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9a874ade-8906-4e11-b8e1-22a4766a3c62",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 107.148.219.55",
      "pattern": "[ipv4-addr:value = '107.148.219.55']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8e2e2ebd-ba1d-4fa0-ae0f-c9ae23a614e9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 107.148.223.196",
      "pattern": "[ipv4-addr:value = '107.148.223.196']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--48b6d13e-39ea-4d17-a20d-41a6e298d54f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 107.173.62.158",
      "pattern": "[ipv4-addr:value = '107.173.62.158']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0eb5a222-6b1c-43f5-87ce-c127fd2f6fbb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 137.175.19.25",
      "pattern": "[ipv4-addr:value = '137.175.19.25']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eeb2134b-d9d7-4f59-8fa4-35d00c9459e3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 137.175.28.251",
      "pattern": "[ipv4-addr:value = '137.175.28.251']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--574153c8-1c15-4b3c-a105-ef06122c149b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 137.175.30.36",
      "pattern": "[ipv4-addr:value = '137.175.30.36']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67a59dab-0110-4cfc-9bef-d8520299da66",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 137.175.30.86",
      "pattern": "[ipv4-addr:value = '137.175.30.86']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dfa30716-1c20-419c-85c4-9472d9bcba3a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 137.175.51.147",
      "pattern": "[ipv4-addr:value = '137.175.51.147']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--94922ac4-ab21-4935-97ef-af969fcd9f02",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 137.175.53.17",
      "pattern": "[ipv4-addr:value = '137.175.53.17']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9910840f-4c28-460a-8b76-0111b417f51f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 137.175.53.170",
      "pattern": "[ipv4-addr:value = '137.175.53.170']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a6704d41-8c00-494b-bb80-d81e6d0b3225",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 137.175.53.218",
      "pattern": "[ipv4-addr:value = '137.175.53.218']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--99a53275-ebae-405f-a8aa-b30a2c418bca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 137.175.60.252",
      "pattern": "[ipv4-addr:value = '137.175.60.252']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6f0e4013-24ea-4559-86a7-042228d0e3fd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 137.175.60.253",
      "pattern": "[ipv4-addr:value = '137.175.60.253']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ecb1cc2b-e17b-432c-a5f3-d5f9d4756dbd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 137.175.78.66",
      "pattern": "[ipv4-addr:value = '137.175.78.66']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f459d6cd-74d3-4a4f-a976-9e350b442174",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 139.84.227.9",
      "pattern": "[ipv4-addr:value = '139.84.227.9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4f476281-7576-4c83-944e-6223defbec10",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 155.94.160.72",
      "pattern": "[ipv4-addr:value = '155.94.160.72']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f27bf463-4bd9-495a-a3cd-832882257fdb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 182.239.114.135",
      "pattern": "[ipv4-addr:value = '182.239.114.135']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aeec168a-d8d1-4c36-b01e-07418e150d8a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.74.226.142",
      "pattern": "[ipv4-addr:value = '192.74.226.142']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--14ccffdc-5c0c-4056-9544-eb07709b011d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 0d67f50a0bf7a3a017784146ac41ada0",
      "pattern": "[file:hashes.MD5 = '0d67f50a0bf7a3a017784146ac41ada0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--86b00e49-873c-420a-8866-d2daf313299e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 177add288b289d43236d2dba33e65956",
      "pattern": "[file:hashes.MD5 = '177add288b289d43236d2dba33e65956']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc96f94c-0067-4c87-9074-95fe34737d44",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 1fea55b7c9d13d822a64b2370d015da7",
      "pattern": "[file:hashes.MD5 = '1fea55b7c9d13d822a64b2370d015da7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c6b5911-b475-4013-ac4e-796735af74ab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 2ccb9759800154de817bf779a52d48f8",
      "pattern": "[file:hashes.MD5 = '2ccb9759800154de817bf779a52d48f8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7d3e4d94-5a1e-4c84-9353-51042a2ba6f4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 35cf6faf442d325961935f660e2ab5a0",
      "pattern": "[file:hashes.MD5 = '35cf6faf442d325961935f660e2ab5a0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--edb28e3d-60ae-4a7e-8f50-70c4892a63e3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 3b93b524db66f8bb3df8279a141734bb",
      "pattern": "[file:hashes.MD5 = '3b93b524db66f8bb3df8279a141734bb']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--66a4fb11-ba9b-4bd2-964b-d0ea021a501e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 407738e565b4e9dafb07b782ebcf46b0",
      "pattern": "[file:hashes.MD5 = '407738e565b4e9dafb07b782ebcf46b0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a1382c7-117e-42d6-aa61-2c24447c6ce4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 42722b7d04f58dcb8bd80fe41c7ea09e",
      "pattern": "[file:hashes.MD5 = '42722b7d04f58dcb8bd80fe41c7ea09e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c3cdc32b-48bb-4e80-a0f6-bb639104de74",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 436587bad5e061a7e594f9971d89c468",
      "pattern": "[file:hashes.MD5 = '436587bad5e061a7e594f9971d89c468']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--870a9f88-a598-43d7-bcd7-aa1bc3bbc4ef",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 4ca4f582418b2cc0626700511a6315c0",
      "pattern": "[file:hashes.MD5 = '4ca4f582418b2cc0626700511a6315c0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff0c03d5-bf40-4f37-a0bc-66c07a1fd2df",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 5392fb400bd671d4b185fb35a9b23fd3",
      "pattern": "[file:hashes.MD5 = '5392fb400bd671d4b185fb35a9b23fd3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--35199502-1b30-477f-84d9-44245a7e0716",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 5d6cba7909980a7b424b133fbac634ac",
      "pattern": "[file:hashes.MD5 = '5d6cba7909980a7b424b133fbac634ac']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7e88e40b-38cc-4382-98db-953076b99b40",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 5fdee67c82f5480edfa54afc5a9dc834",
      "pattern": "[file:hashes.MD5 = '5fdee67c82f5480edfa54afc5a9dc834']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3db2c21d-e3f9-4a30-802f-7d41473a2f04",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 666da297066a2596cacb13b3da9572bf",
      "pattern": "[file:hashes.MD5 = '666da297066a2596cacb13b3da9572bf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7f68e9b7-3e20-4bda-adf6-6dbf9e5cca0e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 694cdb49879f1321abb4605adf634935",
      "pattern": "[file:hashes.MD5 = '694cdb49879f1321abb4605adf634935']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ec5fc92-894e-462a-a3c0-a20609d89c94",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 6f79ef58b354fd33824c96625590c244",
      "pattern": "[file:hashes.MD5 = '6f79ef58b354fd33824c96625590c244']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--29f953c4-973b-4cbd-877d-b73774cb5722",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 827d507aa3bde0ef903ca5dec60cdec8",
      "pattern": "[file:hashes.MD5 = '827d507aa3bde0ef903ca5dec60cdec8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5bac7ab6-ae89-43f9-bb90-22a3bcff1615",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 82eaf69de710abdc5dea7cd5cb56cf04",
      "pattern": "[file:hashes.MD5 = '82eaf69de710abdc5dea7cd5cb56cf04']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--94f721c5-89df-4fd6-a30d-fb697cc5436b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 85c5b6c408e4bdb87da6764a75008adf",
      "pattern": "[file:hashes.MD5 = '85c5b6c408e4bdb87da6764a75008adf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--73750421-0436-4dbb-b96e-a21b55870955",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 87847445f9524671022d70f2a812728f",
      "pattern": "[file:hashes.MD5 = '87847445f9524671022d70f2a812728f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ed8d79a8-f7fc-4f8c-b3b9-5fcdf0975f0b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 878cf1de91f3ae543fd290c31adcbda4",
      "pattern": "[file:hashes.MD5 = '878cf1de91f3ae543fd290c31adcbda4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c4b99429-9aa7-46ae-bf41-f7b15cae5792",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 9033dc5bac76542b9b752064a56c6ee4",
      "pattern": "[file:hashes.MD5 = '9033dc5bac76542b9b752064a56c6ee4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4c9d5582-1c51-41d4-98aa-53e7dbcc0c1f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: ac4fb6d0bfc871be6f68bfa647fc0125",
      "pattern": "[file:hashes.MD5 = 'ac4fb6d0bfc871be6f68bfa647fc0125']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2c4c65fd-87d4-4948-b78f-1f3dfcb2145e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: c528b6398c86f8bdcfa3f9de7837ebfe",
      "pattern": "[file:hashes.MD5 = 'c528b6398c86f8bdcfa3f9de7837ebfe']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7adc4cc6-8983-418a-9dc9-3c8560d9d792",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: cd2813f0260d63ad5adf0446253c2172",
      "pattern": "[file:hashes.MD5 = 'cd2813f0260d63ad5adf0446253c2172']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--46224faf-528b-4ed8-9eb9-4163a757ff86",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: ce67bb99bc1e26f6cb1f968bc1b1ec21",
      "pattern": "[file:hashes.MD5 = 'ce67bb99bc1e26f6cb1f968bc1b1ec21']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3ab759ef-e1ac-43cb-a98a-907ceaab1f73",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: d098fe9674b6b4cb540699c5eb452cb5",
      "pattern": "[file:hashes.MD5 = 'd098fe9674b6b4cb540699c5eb452cb5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2559f77b-efa7-4ff6-9e17-e92686c56118",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e4e86c273a2b67a605f5d4686783e0cc",
      "pattern": "[file:hashes.MD5 = 'e4e86c273a2b67a605f5d4686783e0cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9a95595b-dbd6-4036-aa4f-02e6c39f2bf7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e52871d82de01b7e7f134c776703f696",
      "pattern": "[file:hashes.MD5 = 'e52871d82de01b7e7f134c776703f696']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--56186306-a304-460a-b8d6-34cb3e57f9b1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e80a85250263d58cc1a1dc39d6cf3942",
      "pattern": "[file:hashes.MD5 = 'e80a85250263d58cc1a1dc39d6cf3942']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--381ed69e-86d1-4819-ad12-90c933534a97",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-28204",
      "pattern": "[vulnerability:name = 'CVE-2023-28204']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-28204 \u2014 Apple Multiple Products WebKit Ou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--864af14b-5e43-494c-bf3b-e1e708ded364",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-32373",
      "pattern": "[vulnerability:name = 'CVE-2023-32373']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-32373 \u2014 Apple Multiple Products WebKit Us",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f7a80380-9121-4bb4-9a8c-fc3f1fe42692",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-32409",
      "pattern": "[vulnerability:name = 'CVE-2023-32409']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-32409 \u2014 Apple Multiple Products WebKit Sa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-28204 \u2014 Apple Multiple Products WebKit Ou",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc69b511-c558-4b9e-9460-8efbe4e8137d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2004-1464",
      "pattern": "[vulnerability:name = 'CVE-2004-1464']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2004-1464 \u2014 Cisco IOS Denial-of-Service Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a0f186e9-af28-40eb-9a83-6a34045ed4d4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-6415",
      "pattern": "[vulnerability:name = 'CVE-2016-6415']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-6415 \u2014 Cisco IOS, IOS XR, and IOS XE IKEv",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--86ba8477-a5b0-4a12-a04c-49817f76f4e9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-21492",
      "pattern": "[vulnerability:name = 'CVE-2023-21492']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-21492 \u2014 Samsung Mobile Devices Insertion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--27c3a01d-429d-4b37-bd2a-2a0dfebdf7fc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-3904",
      "pattern": "[vulnerability:name = 'CVE-2010-3904']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-3904 \u2014 Linux Kernel Improper Input Valida",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--25435b0e-a9bc-4d1c-bf28-7d0a627a63f5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-0196",
      "pattern": "[vulnerability:name = 'CVE-2014-0196']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-0196 \u2014 Linux Kernel Race Condition Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--35501b44-36a6-4e4b-b472-fb53a43cae82",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-5317",
      "pattern": "[vulnerability:name = 'CVE-2015-5317']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-5317 \u2014 Jenkins User Interface (UI) Inform",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--19d10e9f-fe66-410a-90c4-3080b28aec2b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-3427",
      "pattern": "[vulnerability:name = 'CVE-2016-3427']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-3427 \u2014 Oracle Java SE and JRockit Unspeci",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--856d3661-6caf-453d-94f8-3f0cd864525b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-3560",
      "pattern": "[vulnerability:name = 'CVE-2021-3560']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-3560 \u2014 Red Hat Polkit Incorrect Authoriza",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3753066f-0694-4ffa-8b80-61adf3c80592",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-25717",
      "pattern": "[vulnerability:name = 'CVE-2023-25717']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--95a28be8-5309-44c7-a6d2-7091d9524cb8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 163.123.142.146",
      "pattern": "[ipv4-addr:value = '163.123.142.146']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e9cdeff5-d33c-4cc4-b1d6-8ee9ad93d3df",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.153.243.39",
      "pattern": "[ipv4-addr:value = '45.153.243.39']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--54df44f4-660d-42ad-8df8-9de32f1fa209",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 47.87.154.192",
      "pattern": "[ipv4-addr:value = '47.87.154.192']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--98343303-24e3-469f-95c2-5d643ff0a4ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: d2ad2d8d1b7dac89f2fb977c6b2c36a9",
      "pattern": "[file:hashes.MD5 = 'd2ad2d8d1b7dac89f2fb977c6b2c36a9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a411b55c-7532-467b-a5c3-6823293fd788",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 86d630159a13b4a594e3eae23ccbda891a67f696",
      "pattern": "[file:hashes.'SHA-1' = '86d630159a13b4a594e3eae23ccbda891a67f696']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f364f73f-4e87-4120-bdff-4781cfdae74f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1298da097b1c5bdce63f580e14e2c1b372c409476747356a8e9cfaf62b94513d",
      "pattern": "[file:hashes.'SHA-256' = '1298da097b1c5bdce63f580e14e2c1b372c409476747356a8e9cfaf62b94513d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a9abb5bf-02ac-44cc-89f6-909a951d0c22",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2e7136f760f04b1ed7033251a14fef1be1e82ddcbff44dae30db12fe52e0a78a",
      "pattern": "[file:hashes.'SHA-256' = '2e7136f760f04b1ed7033251a14fef1be1e82ddcbff44dae30db12fe52e0a78a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ac0d5cab-94f9-4e04-aefc-b93eeeaf8c1a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3441e88c80e82b933bb09e660d229d74f7b753a188700fe018e74c2db7b2aaa0",
      "pattern": "[file:hashes.'SHA-256' = '3441e88c80e82b933bb09e660d229d74f7b753a188700fe018e74c2db7b2aaa0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--179aa171-04ca-440a-80fc-1af5a496f47e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3c9998b8451022beee346f1afe18cab84e867b43c14ba9c7f04e5c559bfc4c3a",
      "pattern": "[file:hashes.'SHA-256' = '3c9998b8451022beee346f1afe18cab84e867b43c14ba9c7f04e5c559bfc4c3a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--780fb4e2-25d9-4b2c-9011-00451c4f7296",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 55e921a196c92c659305aa9de3edf6297803b60012f83967562a57547875fec1",
      "pattern": "[file:hashes.'SHA-256' = '55e921a196c92c659305aa9de3edf6297803b60012f83967562a57547875fec1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--35031929-36d3-46a9-b2d2-7787b0c949db",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b71b4f478479505f1bfb43663b4a4666ec98cd324acb16892ecb876ade5ca6f9",
      "pattern": "[file:hashes.'SHA-256' = 'b71b4f478479505f1bfb43663b4a4666ec98cd324acb16892ecb876ade5ca6f9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9bc2f69c-7209-422b-8fb8-fa7c87f13591",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c4925a91ed853920d8acee79bf0bb9342da4dabc0a2970823027f39ede399bce",
      "pattern": "[file:hashes.'SHA-256' = 'c4925a91ed853920d8acee79bf0bb9342da4dabc0a2970823027f39ede399bce']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--925de723-484f-4df5-933f-fccd3a268a60",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e740a0d2e42c09e912c43ecdc4dcbd8e92896ac3f725830d16aaa3eddf07fd5c",
      "pattern": "[file:hashes.'SHA-256' = 'e740a0d2e42c09e912c43ecdc4dcbd8e92896ac3f725830d16aaa3eddf07fd5c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cefcfd38-b292-4dda-bf08-4da804beaaa9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ea064dd91d8d9e6036e99f5348e078c43f99fdf98500614bffb736c4b0fff408",
      "pattern": "[file:hashes.'SHA-256' = 'ea064dd91d8d9e6036e99f5348e078c43f99fdf98500614bffb736c4b0fff408']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5b75490-25e9-4de3-9ed9-6f6c85db761b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f42c6cea4c47bf0cbef666a8052633ab85ab6ac5b99b7e31faa1e198c4dd1ee1",
      "pattern": "[file:hashes.'SHA-256' = 'f42c6cea4c47bf0cbef666a8052633ab85ab6ac5b99b7e31faa1e198c4dd1ee1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--354ac597-f391-403b-9f1d-aad2c322de64",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-29336",
      "pattern": "[vulnerability:name = 'CVE-2023-29336']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-29336 \u2014 Microsoft Win32K Privilege Escala",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bbbed298-6d7e-468a-8844-f5bf3b4e1d14",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-2237",
      "pattern": "[vulnerability:name = 'CVE-2022-2237']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Secure JavaScript URL validation",
          "url": "https://snyk.io/blog/secure-javascript-url-validation/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b9a71f60-2665-4fdc-a829-6dd9152e1742",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-45046",
      "pattern": "[vulnerability:name = 'CVE-2021-45046']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-45046 \u2014 Apache Log4j2 Deserialization of ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "How Atlassian used Snyk to solve Log4Shell",
          "url": "https://snyk.io/blog/how-atlassian-used-snyk-to-solve-log4shell/"
        },
        {
          "source_name": "How LiveRamp used Snyk to remediate Log4Shell",
          "url": "https://snyk.io/blog/liveramp-used-snyk-to-remediate-log4shell/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ad47ea40-64ae-4a78-96ae-1a07ca2149e0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-3602",
      "pattern": "[vulnerability:name = 'CVE-2022-3602']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Lessons from OpenSSL vulnerabilities part 2: Finding and fix",
          "url": "https://snyk.io/blog/lessons-from-openssl-vulnerabilities-part-2/"
        },
        {
          "source_name": "Lessons from OpenSSL vulnerabilities part 1: Preparing your ",
          "url": "https://snyk.io/blog/lessons-from-openssl-vulnerabilities-part-1/"
        },
        {
          "source_name": "Update: OpenSSL high severity vulnerabilities",
          "url": "https://snyk.io/blog/openssl-high-severity-vulnerabilities/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--37fa2b6b-3db6-4ba5-a0d8-368c79052dca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-3786",
      "pattern": "[vulnerability:name = 'CVE-2022-3786']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Lessons from OpenSSL vulnerabilities part 2: Finding and fix",
          "url": "https://snyk.io/blog/lessons-from-openssl-vulnerabilities-part-2/"
        },
        {
          "source_name": "Lessons from OpenSSL vulnerabilities part 1: Preparing your ",
          "url": "https://snyk.io/blog/lessons-from-openssl-vulnerabilities-part-1/"
        },
        {
          "source_name": "Update: OpenSSL high severity vulnerabilities",
          "url": "https://snyk.io/blog/openssl-high-severity-vulnerabilities/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bf30b7d2-b7c7-4414-adc4-0a3664d24bf4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-2136",
      "pattern": "[vulnerability:name = 'CVE-2023-2136']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2136 \u2014 Google Chrome Skia Integer Overflo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--686f9161-b8a5-4e44-b0fc-13aea9c2728e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-27350",
      "pattern": "[vulnerability:name = 'CVE-2023-27350']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27350 \u2014 PaperCut MF/NG Improper Access Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ef5ca660-6705-4609-9093-e6a3290d705c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-28432",
      "pattern": "[vulnerability:name = 'CVE-2023-28432']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-28432 \u2014 MinIO Information Disclosure Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ffc103f-fe92-477d-9362-fe8379625a62",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 102.130.112.157",
      "pattern": "[ipv4-addr:value = '102.130.112.157']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27350 \u2014 PaperCut MF/NG Improper Access Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2fe4efc-8e33-40bb-b433-0649a5c6720e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.106.112.46",
      "pattern": "[ipv4-addr:value = '172.106.112.46']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27350 \u2014 PaperCut MF/NG Improper Access Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9cdbf40a-6810-422f-8468-ea9ad1c03378",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.160.102.164",
      "pattern": "[ipv4-addr:value = '192.160.102.164']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-27350 \u2014 PaperCut MF/NG Improper Access Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a06e2b47-5366-4e76-bfea-52bb0e024d95",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-6742",
      "pattern": "[vulnerability:name = 'CVE-2017-6742']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-6742 \u2014 Cisco IOS and IOS XE Software SNMP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1f84e6a0-8f23-4116-9c96-b779b5f52290",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-5941",
      "pattern": "[vulnerability:name = 'CVE-2017-5941']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Preventing insecure deserialization in Node.js",
          "url": "https://snyk.io/blog/preventing-insecure-deserialization-node-js/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3593dc08-c283-47ca-912d-fe158a6ef788",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-5954",
      "pattern": "[vulnerability:name = 'CVE-2017-5954']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Preventing insecure deserialization in Node.js",
          "url": "https://snyk.io/blog/preventing-insecure-deserialization-node-js/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e18b2908-36e1-45aa-9394-dd124519581e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-8526",
      "pattern": "[vulnerability:name = 'CVE-2019-8526']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-8526 \u2014 Apple macOS Use-After-Free Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f13ce56f-7011-4967-bd8d-b4ea9fd75232",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-2033",
      "pattern": "[vulnerability:name = 'CVE-2023-2033']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-2033 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--97d44e35-a657-4253-afb6-1728dceb38ee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-20963",
      "pattern": "[vulnerability:name = 'CVE-2023-20963']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-20963 \u2014 Android Framework Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--574e64a7-4e2a-44f6-8c04-1cd1b0eeba37",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-29492",
      "pattern": "[vulnerability:name = 'CVE-2023-29492']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-29492 \u2014 Novi Survey Insecure Deserializat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e3b47022-4b3c-4266-9192-9f96aea55975",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: devsetgroup.com",
      "pattern": "[domain-name:value = 'devsetgroup.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-28252 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--84a96fcf-5f13-4474-a12e-f341db165e42",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: qooqle.top",
      "pattern": "[domain-name:value = 'qooqle.top']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-28252 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b6fec0c9-da6f-4c74-991a-b9d87e4e0369",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: vnssinc.com",
      "pattern": "[domain-name:value = 'vnssinc.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-28252 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8891751b-4592-42a2-be5d-661770b24894",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: vsexec.com",
      "pattern": "[domain-name:value = 'vsexec.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-28252 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ffd74b8e-7c9e-4d34-a244-421f813178ae",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 1e4dd35b16ddc59c1ecf240c22b8a4c4",
      "pattern": "[file:hashes.MD5 = '1e4dd35b16ddc59c1ecf240c22b8a4c4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-28252 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0400d1bb-08a4-43be-8100-25d86061d5eb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 46168ed7dbe33ffc4179974f8bf401aa",
      "pattern": "[file:hashes.MD5 = '46168ed7dbe33ffc4179974f8bf401aa']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-28252 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3ce44351-32d3-49ec-bac5-52be07640e59",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 8800e6f1501f69a0a04ce709e9fa251c",
      "pattern": "[file:hashes.MD5 = '8800e6f1501f69a0a04ce709e9fa251c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-28252 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a0a4bff0-608d-4977-968b-32891d3399f0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: a2313d7fdb2f8f5e5c1962e22b504a17",
      "pattern": "[file:hashes.MD5 = 'a2313d7fdb2f8f5e5c1962e22b504a17']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-28252 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ef8e8e0-e20c-4d82-a36b-7026887992c4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: f23be19024fcc7c8f885dfa16634e6e7",
      "pattern": "[file:hashes.MD5 = 'f23be19024fcc7c8f885dfa16634e6e7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-28252 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5dde544a-b0b3-454c-9698-b625b4b076fa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-28205",
      "pattern": "[vulnerability:name = 'CVE-2023-28205']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-28205 \u2014 Apple Multiple Products WebKit Us",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--89486fb3-fe65-4bed-ba93-4b35a978ca1a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-28206",
      "pattern": "[vulnerability:name = 'CVE-2023-28206']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-28206 \u2014 Apple iOS, iPadOS, and macOS IOSu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--364eccd1-2f04-48d8-bd2c-380ea0319002",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-1388",
      "pattern": "[vulnerability:name = 'CVE-2019-1388']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1388 \u2014 Microsoft Windows Certificate Dial",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5af76a2f-7644-4ac7-af76-9b823e3b98f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-27876",
      "pattern": "[vulnerability:name = 'CVE-2021-27876']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Ac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b1a1708c-8f47-49ec-ab8f-1829ea0d55c9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-27877",
      "pattern": "[vulnerability:name = 'CVE-2021-27877']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Ac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9a326f76-62d0-4d5b-a430-bc58ca5b05b8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-27878",
      "pattern": "[vulnerability:name = 'CVE-2021-27878']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Ac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f3094f7e-dc1d-4b00-a835-93b559c061bf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-26083",
      "pattern": "[vulnerability:name = 'CVE-2023-26083']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-26083 \u2014 Arm Mali GPU Kernel Driver Inform",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2023-0266 \u2014 Linux Kernel Use-After-Free Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4ad73b11-8cb7-437d-a2b7-90446f5fc32b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.141.62.123",
      "pattern": "[ipv4-addr:value = '185.141.62.123']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Ac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9db8c09e-e554-4b06-b0e6-742487736996",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.99.135.115",
      "pattern": "[ipv4-addr:value = '185.99.135.115']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Ac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e40206a4-c93f-49e5-a6f2-ea5364daa950",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.61.138.109",
      "pattern": "[ipv4-addr:value = '45.61.138.109']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Ac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5509cb65-6a9b-4a35-ba7d-e8ed1cdaf5c9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.199.169.209",
      "pattern": "[ipv4-addr:value = '5.199.169.209']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Ac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--78a55f1d-a1b2-4ce2-9cc8-74d56c56d9da",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 17424a22f01b7b996810ba1274f7b8e9",
      "pattern": "[file:hashes.MD5 = '17424a22f01b7b996810ba1274f7b8e9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Ac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0326000b-ce15-499e-8d8c-30c4d9eefea0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 1f437347917f0a4ced71fb7df53b1a05",
      "pattern": "[file:hashes.MD5 = '1f437347917f0a4ced71fb7df53b1a05']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Ac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--16d65d91-51e4-4d5a-b65c-ef9d539c44e7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 24b0f58f014bd259b57f346fb5aed2ea",
      "pattern": "[file:hashes.MD5 = '24b0f58f014bd259b57f346fb5aed2ea']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Ac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cdadfb70-223e-44f6-aee0-1553c7370507",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 4fdabe571b66ceec3448939bfb3ffcd1",
      "pattern": "[file:hashes.MD5 = '4fdabe571b66ceec3448939bfb3ffcd1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Ac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0014bb85-e1a1-4cb1-b4d3-32c25f3c72cc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 5fe66b2835511f9d4d3703b6c639b866",
      "pattern": "[file:hashes.MD5 = '5fe66b2835511f9d4d3703b6c639b866']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Ac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1710d99f-2306-4c06-a352-2f912b83d10b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 68d3bf2c363144ec6874ab360fdda00a",
      "pattern": "[file:hashes.MD5 = '68d3bf2c363144ec6874ab360fdda00a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Ac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b8683c79-0d0b-4ac3-8942-abc32dadac48",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: b41dc7bef82ef384bc884973f3d0e8ca",
      "pattern": "[file:hashes.MD5 = 'b41dc7bef82ef384bc884973f3d0e8ca']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Ac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--be879da1-e39c-43c5-9708-41003cf53b88",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: c590a84b8c72cf18f35ae166f815c9df",
      "pattern": "[file:hashes.MD5 = 'c590a84b8c72cf18f35ae166f815c9df']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Ac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0aeaf9b3-9aaa-4f8d-b85f-8f75a8c492ea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: da202cc4b3679fdb47003d603a93c90d",
      "pattern": "[file:hashes.MD5 = 'da202cc4b3679fdb47003d603a93c90d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Ac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7adba2bf-8dfc-4c09-a1c4-3dc88f7b0c7f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e31270e4a6f215f45abad65916da9db4",
      "pattern": "[file:hashes.MD5 = 'e31270e4a6f215f45abad65916da9db4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Ac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--502cbe2c-2832-4939-9a99-bc2967a5e937",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: ee6e0cb1b3b7601696e9a05ce66e7f37",
      "pattern": "[file:hashes.MD5 = 'ee6e0cb1b3b7601696e9a05ce66e7f37']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Ac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d18929e7-c3b7-4be1-8407-4e2cb9cdd1c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: f66e1d717b54b95cf32154b770e10ba4",
      "pattern": "[file:hashes.MD5 = 'f66e1d717b54b95cf32154b770e10ba4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Ac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Imprope",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4533e95d-79dd-4d60-93c5-ab849934b270",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-27926",
      "pattern": "[vulnerability:name = 'CVE-2022-27926']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-27926 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--58a2b099-3753-4837-a42f-c62096b3b55e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: bugiplaysec.com",
      "pattern": "[domain-name:value = 'bugiplaysec.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-27926 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8065a3af-886d-4650-8159-2bea71a8cb7b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: nepalihemp.com",
      "pattern": "[domain-name:value = 'nepalihemp.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-27926 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--41b25e1a-efd5-415d-afa2-e8eb764af83e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ocs-romastassec.com",
      "pattern": "[domain-name:value = 'ocs-romastassec.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-27926 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4720fc98-7d39-4d44-a9ba-6d4203af6a97",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ocspdep.com",
      "pattern": "[domain-name:value = 'ocspdep.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-27926 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--02026e69-fb94-4275-a338-8a70276cfd62",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: oscp-avanguard.com",
      "pattern": "[domain-name:value = 'oscp-avanguard.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-27926 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f2911d27-7f4d-4c82-b07d-7df330f676b7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: troadsecow.com",
      "pattern": "[domain-name:value = 'troadsecow.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-27926 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0d8f167-4dcf-4ae1-bfbd-d9e94068a5d7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-3163",
      "pattern": "[vulnerability:name = 'CVE-2013-3163']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3163 \u2014 Microsoft Internet Explorer Memory",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e23cda8d-7aed-477b-aef6-0eb58a62e7e3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-7494",
      "pattern": "[vulnerability:name = 'CVE-2017-7494']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-7494 \u2014 Samba Remote Code Execution Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--20e9a775-8c96-482e-86d5-e49929a4b106",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30900",
      "pattern": "[vulnerability:name = 'CVE-2021-30900']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30900 \u2014 Apple iOS, iPadOS, and macOS Out-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9b5a9249-2d1c-45f7-b4a5-9704e093f83d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-22706",
      "pattern": "[vulnerability:name = 'CVE-2022-22706']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-0266 \u2014 Linux Kernel Use-After-Free Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-22706 \u2014 Arm Mali GPU Kernel Driver Unspec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0704c27d-e56b-4de5-8561-abc3273243d1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-3038",
      "pattern": "[vulnerability:name = 'CVE-2022-3038']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-0266 \u2014 Linux Kernel Use-After-Free Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-3038 \u2014 Google Chromium Network Service Us",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-22706 \u2014 Arm Mali GPU Kernel Driver Unspec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--828e63b3-d2c2-46c0-bd20-076cd63dd730",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-38181",
      "pattern": "[vulnerability:name = 'CVE-2022-38181']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-38181 \u2014 Arm Mali GPU Kernel Driver Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0c771c95-ab34-401f-85b5-65230e8de636",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-39197",
      "pattern": "[vulnerability:name = 'CVE-2022-39197']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-39197 \u2014 Fortra Cobalt Strike Teamserver C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc6b734f-231a-4044-98df-4c6b673ed67a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-4262",
      "pattern": "[vulnerability:name = 'CVE-2022-4262']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-0266 \u2014 Linux Kernel Use-After-Free Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-22706 \u2014 Arm Mali GPU Kernel Driver Unspec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-4262 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fd3e64db-c3be-4003-bd8b-c7c3b9b1fa38",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-42948",
      "pattern": "[vulnerability:name = 'CVE-2022-42948']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42948 \u2014 Fortra Cobalt Strike User Interfa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--396e5274-5475-46dc-b117-f04cda20b517",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-0266",
      "pattern": "[vulnerability:name = 'CVE-2023-0266']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-0266 \u2014 Linux Kernel Use-After-Free Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-22706 \u2014 Arm Mali GPU Kernel Driver Unspec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2cf22211-61ae-4060-91d4-30ded33e325d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: anglesyen.org",
      "pattern": "[domain-name:value = 'anglesyen.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22706 \u2014 Arm Mali GPU Kernel Driver Unspec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--04b75cd5-7b18-4354-965d-6f18ccbc2ddc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sufficeconfigure.com",
      "pattern": "[domain-name:value = 'sufficeconfigure.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22706 \u2014 Arm Mali GPU Kernel Driver Unspec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4c361415-0c8a-4edc-ab63-49f9e4603ce0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 3.72.6.53",
      "pattern": "[ipv4-addr:value = '3.72.6.53']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "The rising trend of malicious packages in open source ecosys",
          "url": "https://snyk.io/blog/malicious-packages-open-source-ecosystems/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--15dca05a-cf14-4c13-871d-2dbdf485bea1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-3807",
      "pattern": "[vulnerability:name = 'CVE-2021-3807']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New language-specific Snyk Top 10 for open source vulnerabil",
          "url": "https://snyk.io/blog/language-specific-snyk-top-10-open-source-2022/"
        },
        {
          "source_name": "Solve Hack the Box and other CTF challenges with Snyk",
          "url": "https://snyk.io/blog/solve-hack-the-box-and-ctf-challenges-with-snyk/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--86d3e004-22ca-47cf-946d-7c936e425f89",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-26360",
      "pattern": "[vulnerability:name = 'CVE-2023-26360']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-26360 \u2014 Adobe ColdFusion Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--27b91a91-d625-4c92-ba96-48e502def88f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-43138",
      "pattern": "[vulnerability:name = 'CVE-2021-43138']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New language-specific Snyk Top 10 for open source vulnerabil",
          "url": "https://snyk.io/blog/language-specific-snyk-top-10-open-source-2022/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--708bad20-d750-4d61-a815-d74ae8ed9736",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-2144",
      "pattern": "[vulnerability:name = 'CVE-2022-2144']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New language-specific Snyk Top 10 for open source vulnerabil",
          "url": "https://snyk.io/blog/language-specific-snyk-top-10-open-source-2022/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a790288c-025e-465f-aab5-c68766ffd2cb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-2421",
      "pattern": "[vulnerability:name = 'CVE-2022-2421']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New language-specific Snyk Top 10 for open source vulnerabil",
          "url": "https://snyk.io/blog/language-specific-snyk-top-10-open-source-2022/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6fe2c571-4c41-4a66-9b07-49632bd2c6b8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-24858",
      "pattern": "[vulnerability:name = 'CVE-2022-24858']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New language-specific Snyk Top 10 for open source vulnerabil",
          "url": "https://snyk.io/blog/language-specific-snyk-top-10-open-source-2022/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--687241e6-8c9f-4bb5-99fb-0d5dc4822304",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-25319",
      "pattern": "[vulnerability:name = 'CVE-2022-25319']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New language-specific Snyk Top 10 for open source vulnerabil",
          "url": "https://snyk.io/blog/language-specific-snyk-top-10-open-source-2022/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc626c72-754e-4cf8-878c-9ddf5280016b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-3518",
      "pattern": "[vulnerability:name = 'CVE-2022-3518']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New language-specific Snyk Top 10 for open source vulnerabil",
          "url": "https://snyk.io/blog/language-specific-snyk-top-10-open-source-2022/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d310833-11fe-424a-acf2-be60c99d3ef1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-41328",
      "pattern": "[vulnerability:name = 'CVE-2022-41328']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9452b846-ac2f-4bd9-892f-a25e1763dedf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-44698",
      "pattern": "[vulnerability:name = 'CVE-2022-44698']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-24880 \u2014 Microsoft Windows SmartScreen Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-44698 \u2014 Microsoft Defender SmartScreen Se",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c833a9a-d594-45f9-a5a1-1de911a5976a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-23397",
      "pattern": "[vulnerability:name = 'CVE-2023-23397']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--26054cc5-2f4a-433a-a757-f46a863471b3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-24880",
      "pattern": "[vulnerability:name = 'CVE-2023-24880']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-24880 \u2014 Microsoft Windows SmartScreen Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-44698 \u2014 Microsoft Defender SmartScreen Se",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--11a4c19a-c3ea-4abd-b532-dbc1af744591",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 101.255.119.42",
      "pattern": "[ipv4-addr:value = '101.255.119.42']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0768b7d6-d2d5-4738-97d5-4b1e90028697",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 113.160.234.229",
      "pattern": "[ipv4-addr:value = '113.160.234.229']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2ed4fbf7-10ac-4df6-9163-a473646c1ec8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 168.205.200.55",
      "pattern": "[ipv4-addr:value = '168.205.200.55']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--82871278-bdce-408c-bbb6-5814327f21e7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 181.209.99.204",
      "pattern": "[ipv4-addr:value = '181.209.99.204']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--945fc906-e118-4fcb-8472-4c6655fda2b0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.132.17.160",
      "pattern": "[ipv4-addr:value = '185.132.17.160']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9069d4a2-4f62-4426-a2d6-fbf9d45a195c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 213.32.252.221",
      "pattern": "[ipv4-addr:value = '213.32.252.221']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2dea3c71-cb02-4ac3-a6e3-b724057a567f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 24.142.165.2",
      "pattern": "[ipv4-addr:value = '24.142.165.2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb0780d7-ac3f-4b91-adfb-543873df250b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 42.98.5.225",
      "pattern": "[ipv4-addr:value = '42.98.5.225']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--710bce22-ff32-4870-a6bf-e6a401593c12",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 47.252.20.90",
      "pattern": "[ipv4-addr:value = '47.252.20.90']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--737bdd29-c73b-44e5-b3c8-12ea72732ef1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.199.162.132",
      "pattern": "[ipv4-addr:value = '5.199.162.132']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--95624f4a-4acf-4b90-a100-c658c7e6b573",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 50.173.136.70",
      "pattern": "[ipv4-addr:value = '50.173.136.70']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76e7b27b-138f-40bf-9bd1-bb3fca368197",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 61.14.68.33",
      "pattern": "[ipv4-addr:value = '61.14.68.33']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67c3e7dd-115b-4323-a70c-c3b48cbe4996",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 69.162.253.21",
      "pattern": "[ipv4-addr:value = '69.162.253.21']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a9e65ff8-fbf4-4947-80e1-cbbc7cb5d649",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 69.51.2.106",
      "pattern": "[ipv4-addr:value = '69.51.2.106']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--74eac22d-e5cf-455d-9410-733b96179b1a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 82.196.113.102",
      "pattern": "[ipv4-addr:value = '82.196.113.102']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2126859-63f0-444a-a2f8-23c98cd0eab4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 85.195.206.7",
      "pattern": "[ipv4-addr:value = '85.195.206.7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3505cc46-647e-4cdc-8ddf-0f66f79f6921",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 3e43511c4f7f551290292394c4e21de7",
      "pattern": "[file:hashes.MD5 = '3e43511c4f7f551290292394c4e21de7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bf91ab07-1297-4613-a530-4b10e5216178",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 53a69adac914808eced2bf8155a7512d",
      "pattern": "[file:hashes.MD5 = '53a69adac914808eced2bf8155a7512d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a48d07e-5328-4e9b-bf13-30faa60e04f2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 88711ebc99e1390f1ce2f42a6de0654d",
      "pattern": "[file:hashes.MD5 = '88711ebc99e1390f1ce2f42a6de0654d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b3b825f9-d470-4b1b-9ab5-c41121e4b221",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 9ce2459168cf4b5af494776a70e0feda",
      "pattern": "[file:hashes.MD5 = '9ce2459168cf4b5af494776a70e0feda']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--38c31421-961c-4fd7-99fb-3e3f0b7bc069",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: a388ebaef45add5da503e4bf2b9da546",
      "pattern": "[file:hashes.MD5 = 'a388ebaef45add5da503e4bf2b9da546']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8dfabc0f-e89f-4bcc-932b-b7a951627100",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: a86a8fe875a89816e5808588154a067e",
      "pattern": "[file:hashes.MD5 = 'a86a8fe875a89816e5808588154a067e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8185fada-b305-4296-88c8-f13b8fceaff1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: b6e92149efaf78e9ce7552297505b9d5",
      "pattern": "[file:hashes.MD5 = 'b6e92149efaf78e9ce7552297505b9d5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a63cda2d-2e9b-4a90-a7ee-892f969aaf58",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e2d2884869f48f40b32fb27cc3bdefff",
      "pattern": "[file:hashes.MD5 = 'e2d2884869f48f40b32fb27cc3bdefff']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f542bcec-3c2e-4b36-a176-1e70666c103d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 1a077212735617a665a6b631e34a6aedcbc41713",
      "pattern": "[file:hashes.'SHA-1' = '1a077212735617a665a6b631e34a6aedcbc41713']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b75a7d8-93a0-4c82-9582-50e666953dfd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 3109b890901499f7ebb90f8870a7d1617d27e7c9",
      "pattern": "[file:hashes.'SHA-1' = '3109b890901499f7ebb90f8870a7d1617d27e7c9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b9426470-19d3-4ea3-8d35-a08a9330de27",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 75c092098e3409d366a46fdde6a92ff97d29cee1",
      "pattern": "[file:hashes.'SHA-1' = '75c092098e3409d366a46fdde6a92ff97d29cee1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e2640299-71dd-4d0b-a968-43e1ed6b55e0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 86f3623b3fb8d5303b6c9d8295292a5c2ceb2889",
      "pattern": "[file:hashes.'SHA-1' = '86f3623b3fb8d5303b6c9d8295292a5c2ceb2889']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f689961-c647-46f1-8189-14e68dab9f26",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 8c40fc87fa3b25a559585b10a8ca11c81fb09f75",
      "pattern": "[file:hashes.'SHA-1' = '8c40fc87fa3b25a559585b10a8ca11c81fb09f75']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--769c000f-4995-4b59-9e7e-81c1af482d1d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 8ef5159944d048fe84e51a818c9b11ebcfa98517",
      "pattern": "[file:hashes.'SHA-1' = '8ef5159944d048fe84e51a818c9b11ebcfa98517']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--64fdbbda-a3da-47cb-9cb4-54d6b01b4484",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 9dca7f1af5752bb007e5cc55acd2511f03049ee5",
      "pattern": "[file:hashes.'SHA-1' = '9dca7f1af5752bb007e5cc55acd2511f03049ee5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--af798731-ff48-40b7-b20f-34c07e5fa138",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: b8bdaa1bd204a6c710875b0c4265655d1fd37d52",
      "pattern": "[file:hashes.'SHA-1' = 'b8bdaa1bd204a6c710875b0c4265655d1fd37d52']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--37b489c8-aa93-4f1b-837b-892168b395ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: d5f8436e9815358e33b8243abda76c9b398943e2",
      "pattern": "[file:hashes.'SHA-1' = 'd5f8436e9815358e33b8243abda76c9b398943e2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--12105a06-93c2-4ff5-9698-798cf6c0b766",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 18afbad17dee0e4330a85b782e8e580c6125d8a7127cda69ad0e2728d505a6f5",
      "pattern": "[file:hashes.'SHA-256' = '18afbad17dee0e4330a85b782e8e580c6125d8a7127cda69ad0e2728d505a6f5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0768cd51-4a81-4e48-8cf8-6eddb2273595",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2266667af7532a32b9c21c330a9fe56356ca66610e39654804a7262f2af61017",
      "pattern": "[file:hashes.'SHA-256' = '2266667af7532a32b9c21c330a9fe56356ca66610e39654804a7262f2af61017']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--316e7c25-4fbe-408f-b6cd-921f6bd09bfa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 245e4646e5d984c2da4cfe223bb2fae679441bcf42b254fc193ae97dc32af7ad",
      "pattern": "[file:hashes.'SHA-256' = '245e4646e5d984c2da4cfe223bb2fae679441bcf42b254fc193ae97dc32af7ad']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--39cf7218-571d-4f1d-a8f2-734e591ab1dd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 33c22b2db8c0948c67204485972d2eb856e13dca16132371337fc3534e3df16d",
      "pattern": "[file:hashes.'SHA-256' = '33c22b2db8c0948c67204485972d2eb856e13dca16132371337fc3534e3df16d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c7140794-1150-4bfb-bd5f-465103e1ed05",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4e4c5e5ca588bd84b67a37b654ec522768fa83e535ff795a5c196da8f8b9737d",
      "pattern": "[file:hashes.'SHA-256' = '4e4c5e5ca588bd84b67a37b654ec522768fa83e535ff795a5c196da8f8b9737d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--def75b9d-831f-4d93-9420-f8d68fdbbc3a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 77e3a3bc905f9a172e95ba70bf01c3236e6c6423f537fa728b1bda5a40a77fe3",
      "pattern": "[file:hashes.'SHA-256' = '77e3a3bc905f9a172e95ba70bf01c3236e6c6423f537fa728b1bda5a40a77fe3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-24880 \u2014 Microsoft Windows SmartScreen Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-44698 \u2014 Microsoft Defender SmartScreen Se",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5e178e8a-9c54-476c-acb3-d618292575ef",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8efb4e8bc17486b816088679d8b10f8985a31bc93488c4b65116f56872c1ff16",
      "pattern": "[file:hashes.'SHA-256' = '8efb4e8bc17486b816088679d8b10f8985a31bc93488c4b65116f56872c1ff16']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-24880 \u2014 Microsoft Windows SmartScreen Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bdbffaa3-26a1-4f1a-b308-b2b1e3ac8ec9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 9fb09fe6db61fbdd19ac9c368e2f64fb9606119649830762fa467719c480ed44",
      "pattern": "[file:hashes.'SHA-256' = '9fb09fe6db61fbdd19ac9c368e2f64fb9606119649830762fa467719c480ed44']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4b84428-4637-4bf6-8adf-83be97d9ab86",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a00fed53b1ece4610c8b52934c20af3667d455f092a77f8d9bc46fdb9047e41a",
      "pattern": "[file:hashes.'SHA-256' = 'a00fed53b1ece4610c8b52934c20af3667d455f092a77f8d9bc46fdb9047e41a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e412a96f-d755-4916-9b91-26f6d4f0b6fd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: abefe121e5c895bf63be80152ccbe2d7bb5ad985aa3ab989bcb7c0804b90d004",
      "pattern": "[file:hashes.'SHA-256' = 'abefe121e5c895bf63be80152ccbe2d7bb5ad985aa3ab989bcb7c0804b90d004']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8bb69b99-a137-4d40-8944-2f594821bcf1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ad89fb8819f98e38cddf6135004e1d93e8c8e4cba681ba16d408c4d69317eb47",
      "pattern": "[file:hashes.'SHA-256' = 'ad89fb8819f98e38cddf6135004e1d93e8c8e4cba681ba16d408c4d69317eb47']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-24880 \u2014 Microsoft Windows SmartScreen Sec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-44698 \u2014 Microsoft Defender SmartScreen Se",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5e80a4c0-5df4-43f9-9df9-c4d3ff020fde",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: eb6af99148f0ce5b58e414162ff2b7567b4cf08953862a088996365ff306014b",
      "pattern": "[file:hashes.'SHA-256' = 'eb6af99148f0ce5b58e414162ff2b7567b4cf08953862a088996365ff306014b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ee1709b2-6e3e-4bdf-9182-d23656fc9ac6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-5741",
      "pattern": "[vulnerability:name = 'CVE-2020-5741']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-5741 \u2014 Plex Media Server Remote Code Exec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--730217a2-9af4-4e94-b44b-ca244780f08b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-39144",
      "pattern": "[vulnerability:name = 'CVE-2021-39144']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-39144 \u2014 XStream Remote Code Execution Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f78ab863-cd17-4bbc-afac-c79790648fcc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-28810",
      "pattern": "[vulnerability:name = 'CVE-2022-28810']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-28810 \u2014 Zoho ManageEngine ADSelfService P",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb1351f5-9aff-487d-8b66-e5fe40f41766",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-35914",
      "pattern": "[vulnerability:name = 'CVE-2022-35914']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-35914 \u2014 Teclib GLPI Remote Code Execution",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3c18bb35-eb64-4844-bd04-4686be96e743",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-32007",
      "pattern": "[vulnerability:name = 'CVE-2023-32007']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-33891 \u2014 Apache Spark Command Injection Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7fe61daf-b3b1-4ca5-bd7e-d1021b5bc048",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-1065",
      "pattern": "[vulnerability:name = 'CVE-2023-1065']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "API authentication vulnerability found in Snyk Kubernetes in",
          "url": "https://snyk.io/blog/api-auth-vuln-snyk-kubernetes-cve-2023-1065/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b7edb561-e168-46e8-9ae5-24b7f53c5b8a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-36537",
      "pattern": "[vulnerability:name = 'CVE-2022-36537']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-36537 \u2014 ZK Framework AuUploader Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--88927e49-0f84-4d2c-ba8f-e120f377cacc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 142.11.195.29",
      "pattern": "[ipv4-addr:value = '142.11.195.29']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-36537 \u2014 ZK Framework AuUploader Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2861cfa-bf33-4b07-b8c7-9f73ecdb67b4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.159.248.213",
      "pattern": "[ipv4-addr:value = '45.159.248.213']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-36537 \u2014 ZK Framework AuUploader Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9558a6c9-fab6-4f32-a37d-d3acb4a4610e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.61.139.187",
      "pattern": "[ipv4-addr:value = '45.61.139.187']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-36537 \u2014 ZK Framework AuUploader Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7dcb6f28-f465-4c82-8ff8-538cefad3862",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.8.33.147",
      "pattern": "[ipv4-addr:value = '5.8.33.147']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-36537 \u2014 ZK Framework AuUploader Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1ae7a129-f2b3-4c2c-a8fe-49df6a916d84",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 77.91.101.140",
      "pattern": "[ipv4-addr:value = '77.91.101.140']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-36537 \u2014 ZK Framework AuUploader Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e8fd5134-468c-4b98-ada9-9df35af66b80",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-26153",
      "pattern": "[vulnerability:name = 'CVE-2023-26153']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Finding YAML Deserialization with Snyk Code",
          "url": "https://snyk.io/blog/finding-yaml-injection-with-snyk-code/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b40f603b-8026-417d-8caa-9f505351f37c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-41223",
      "pattern": "[vulnerability:name = 'CVE-2022-41223']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41223 \u2014 Mitel MiVoice Connect Code Inject",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-40765 \u2014 Mitel MiVoice Connect Command Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e94bd576-d8d4-4f9b-ae67-03a3f339cf02",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-47986",
      "pattern": "[vulnerability:name = 'CVE-2022-47986']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47986 \u2014 IBM Aspera Faspex Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e1a6edb5-5638-4938-b7b5-70335f7c4a3e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-46169",
      "pattern": "[vulnerability:name = 'CVE-2022-46169']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-46169 \u2014 Cacti Command Injection Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--15e17bc1-a9b4-41b3-bc1b-b88805f02d80",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-21715",
      "pattern": "[vulnerability:name = 'CVE-2023-21715']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-21715 \u2014 Microsoft Office Publisher Securi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6df7a44e-bc0d-4261-9b8e-8c7475300bb0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-21823",
      "pattern": "[vulnerability:name = 'CVE-2023-21823']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-21823 \u2014 Microsoft Windows Graphic Compone",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--421588b5-1d28-4250-9fd3-18957e6ba9bb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-23376",
      "pattern": "[vulnerability:name = 'CVE-2023-23376']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-23376 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ec627835-b525-4096-85ea-224c3b612a6c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-23514",
      "pattern": "[vulnerability:name = 'CVE-2023-23514']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-23529 \u2014 Apple Multiple Products WebKit Ty",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1ddf8ba9-8756-4871-b9ec-1d5a6283c94d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-23529",
      "pattern": "[vulnerability:name = 'CVE-2023-23529']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-23529 \u2014 Apple Multiple Products WebKit Ty",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f08a9ba4-93ae-48b4-9c8f-c2f77f339fd4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-2291",
      "pattern": "[vulnerability:name = 'CVE-2015-2291']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-2291 \u2014 Intel Ethernet Diagnostics Driver ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fda40480-8b3c-4cff-8db0-4c2cc6da4a8a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-24989",
      "pattern": "[vulnerability:name = 'CVE-2022-24989']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24990 \u2014 TerraMaster OS Remote Command Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a62452ff-1ef7-4346-b06b-f6fcc109a18a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-24990",
      "pattern": "[vulnerability:name = 'CVE-2022-24990']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24990 \u2014 TerraMaster OS Remote Command Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb8be381-5ac4-40e2-820e-a99bd5fd1d18",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-0669",
      "pattern": "[vulnerability:name = 'CVE-2023-0669']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-0669 \u2014 Fortra GoAnywhere MFT Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ed592a6e-bab6-4f0d-95ea-a52cd69248c3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b6e82a4e6d8b715588bf4252f896e40b766ef981d941d0968f29a3a444f68fef",
      "pattern": "[file:hashes.'SHA-256' = 'b6e82a4e6d8b715588bf4252f896e40b766ef981d941d0968f29a3a444f68fef']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-2291 \u2014 Intel Ethernet Diagnostics Driver ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--27485788-7b38-4b07-b259-f413d0e0d453",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e23283e75ed2bdabf6c703236f5518b4ca37d32f78d3d65b073496c12c643cfe",
      "pattern": "[file:hashes.'SHA-256' = 'e23283e75ed2bdabf6c703236f5518b4ca37d32f78d3d65b073496c12c643cfe']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-2291 \u2014 Intel Ethernet Diagnostics Driver ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--22facc93-6b00-4694-9a04-dcd672576136",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-21587",
      "pattern": "[vulnerability:name = 'CVE-2022-21587']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-21587 \u2014 Oracle E-Business Suite Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0763e8cb-9cf8-4335-a7ca-816b08954df2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-22952",
      "pattern": "[vulnerability:name = 'CVE-2023-22952']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-22952 \u2014 Multiple SugarCRM Products Remote",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c1ace58-d5df-4448-8e71-1fd441004e77",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-11317",
      "pattern": "[vulnerability:name = 'CVE-2017-11317']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11357 \u2014 Telerik UI for ASP.NET AJAX Insec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7cee3403-4e3b-4b07-8868-8ee379aaa6a3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-11357",
      "pattern": "[vulnerability:name = 'CVE-2017-11357']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11357 \u2014 Telerik UI for ASP.NET AJAX Insec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--04dc9372-3eb1-43d1-87cd-de60ef8711f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-",
      "pattern": "[vulnerability:name = 'CVE-2019-']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk enhances ServiceNow with comprehensive insights into vu",
          "url": "https://snyk.io/blog/snyk-servicenow-partnership/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4f368b5-d066-4a68-b0bf-80cb24ed73c9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-47966",
      "pattern": "[vulnerability:name = 'CVE-2022-47966']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--466dfdf3-c61d-4c96-859a-9831930341ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: 0xx1.kaspenskyupdates.com",
      "pattern": "[domain-name:value = '0xx1.kaspenskyupdates.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--743d52a0-4e99-40af-a987-78da1a168741",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: icy51j1b6sbewpauivxwfrmcu30vok.oastify.com",
      "pattern": "[domain-name:value = 'icy51j1b6sbewpauivxwfrmcu30vok.oastify.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cbdeed0a-6256-4e8c-bb68-1776758ae1ad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: satoshidisk.com",
      "pattern": "[domain-name:value = 'satoshidisk.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a604c42b-773d-4716-9658-6ae230610d7a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.223.35.221",
      "pattern": "[ipv4-addr:value = '104.223.35.221']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1ca8ff05-7dd2-451a-846b-ee215b1b1709",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 111.68.7.122",
      "pattern": "[ipv4-addr:value = '111.68.7.122']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ac67e6e7-72e3-4608-86db-ed72251b62e0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 135.181.121.232",
      "pattern": "[ipv4-addr:value = '135.181.121.232']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--24413294-9bfa-4670-a773-3470a85f8c5a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 139.99.118.61",
      "pattern": "[ipv4-addr:value = '139.99.118.61']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2dff9a0c-210a-48df-9b76-a3b5c8e76339",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 143.244.153.229",
      "pattern": "[ipv4-addr:value = '143.244.153.229']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7737abc2-f25f-4762-a34f-8143ce3c12e8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 146.4.21.94",
      "pattern": "[ipv4-addr:value = '146.4.21.94']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--af98775b-d5fe-4d0d-96e1-e9c3aed9eb70",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 146.70.126.178",
      "pattern": "[ipv4-addr:value = '146.70.126.178']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--065f3987-2606-4e6b-9afb-ff64b0417733",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 149.28.57.130",
      "pattern": "[ipv4-addr:value = '149.28.57.130']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9e98b3f4-b9d3-4009-a9db-bc9bae01fa43",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 160.20.147.145",
      "pattern": "[ipv4-addr:value = '160.20.147.145']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3664af8d-5445-4996-9e50-0d2705fd888f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.163.45.86",
      "pattern": "[ipv4-addr:value = '185.163.45.86']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--12dc8c14-2f18-4916-9988-96d0070419e4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.142.226.153",
      "pattern": "[ipv4-addr:value = '192.142.226.153']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9bdc14e9-1d0b-4467-84ac-fae6dd7adb6b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 212.192.246.232",
      "pattern": "[ipv4-addr:value = '212.192.246.232']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f2582939-f82a-4136-a596-7556e3c913c7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.146.7.20",
      "pattern": "[ipv4-addr:value = '45.146.7.20']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--862d385b-0ebb-4f1b-8aa3-ded975c19617",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.154.14.194",
      "pattern": "[ipv4-addr:value = '45.154.14.194']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c663936a-2477-41bc-afdd-1d4d14670c88",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.255.107.19",
      "pattern": "[ipv4-addr:value = '5.255.107.19']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--134e1897-356b-476c-aa91-16ebe7c6d6e4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 78.141.247.105",
      "pattern": "[ipv4-addr:value = '78.141.247.105']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f005a919-8e89-4d0f-b643-a7c8a19cdf93",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 79.141.162.36",
      "pattern": "[ipv4-addr:value = '79.141.162.36']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--df96392c-de18-4252-b43b-55180f24603a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 80.85.156.184",
      "pattern": "[ipv4-addr:value = '80.85.156.184']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6343ef9f-4e98-4c6e-8238-80dfe3e5a8dc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 199cb4936f7ef64fa134eb3cefff0518",
      "pattern": "[file:hashes.MD5 = '199cb4936f7ef64fa134eb3cefff0518']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1550edce-7c22-47b3-b955-a2c7452baf67",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 383b0d0dda2d7557b5cca518f53256b9",
      "pattern": "[file:hashes.MD5 = '383b0d0dda2d7557b5cca518f53256b9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1dddbb1a-dd55-442d-893d-faf31554ce5b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 4960591cc04b080827020393f21c405b",
      "pattern": "[file:hashes.MD5 = '4960591cc04b080827020393f21c405b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--12045355-f746-4bfe-a5e3-6a0f070aed51",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 527c71c523d275c8367b67bbebf48e9f",
      "pattern": "[file:hashes.MD5 = '527c71c523d275c8367b67bbebf48e9f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0dd2675b-d585-4bf0-9f75-6bf1b7e10440",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 53deb494057bb8e5d72b0f53bab1cb44",
      "pattern": "[file:hashes.MD5 = '53deb494057bb8e5d72b0f53bab1cb44']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--81e6a419-bbc7-40aa-9a63-726b46fc2c56",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 5c0227204548c5a768c2e11da02ff774",
      "pattern": "[file:hashes.MD5 = '5c0227204548c5a768c2e11da02ff774']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--44a30af8-8d22-48c3-a7bd-a6fd0e4b986c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 61e82cae3c97887e4b367e507c4995ed",
      "pattern": "[file:hashes.MD5 = '61e82cae3c97887e4b367e507c4995ed']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f22a18b2-b76b-40c2-a91a-89b2beb5e373",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 6e3b1169aac82b4d0e8ea0a24d1477d5",
      "pattern": "[file:hashes.MD5 = '6e3b1169aac82b4d0e8ea0a24d1477d5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cc9e32d1-4ae3-49e3-ac60-956fabe5ebac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 8da896375e5d33e7d7486dbf71d008d8",
      "pattern": "[file:hashes.MD5 = '8da896375e5d33e7d7486dbf71d008d8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dcd5b110-6bd0-43e6-a7b4-45a8983eea79",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 9758c592ef4b9a2279f8e80e992248b6",
      "pattern": "[file:hashes.MD5 = '9758c592ef4b9a2279f8e80e992248b6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4afd719a-727f-4262-b1ed-19bb05876c55",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 988038d8407d510c905183b8f6c421d6",
      "pattern": "[file:hashes.MD5 = '988038d8407d510c905183b8f6c421d6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--37d06aeb-b2f3-46b8-bac3-ccca23207e15",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 9a1d9fe9b1223273c314632d04008384",
      "pattern": "[file:hashes.MD5 = '9a1d9fe9b1223273c314632d04008384']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--632ca146-6dde-4e51-ae46-64de1484e43b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: b777226ef93acdb168980bbca82a48fe",
      "pattern": "[file:hashes.MD5 = 'b777226ef93acdb168980bbca82a48fe']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--edf133bb-c011-48b8-9ebc-afb3dcb6e8f5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: bfe79b11ee1b82ae95b14fd53b6c3fd3",
      "pattern": "[file:hashes.MD5 = 'bfe79b11ee1b82ae95b14fd53b6c3fd3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a83da9e-d319-4d2f-a971-28f9bd13db6e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: c027d641c4c1e9d9ad048cda2af85db6",
      "pattern": "[file:hashes.MD5 = 'c027d641c4c1e9d9ad048cda2af85db6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dcd4b407-a533-489a-905d-d2bbd5d956fa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e0fb946c00b140693e3cf5de258c22a1",
      "pattern": "[file:hashes.MD5 = 'e0fb946c00b140693e3cf5de258c22a1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ec508012-9904-4364-88fa-759e6a52c1f5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e2c644343fad304ccde047f3301066ba",
      "pattern": "[file:hashes.MD5 = 'e2c644343fad304ccde047f3301066ba']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9caf1036-7e91-415f-aad1-1c2310c64b28",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e3cff253b9ad9050eb57d957624b796e",
      "pattern": "[file:hashes.MD5 = 'e3cff253b9ad9050eb57d957624b796e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3146f182-9b32-41a1-9e59-c4a16cc246fb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: edac597788e7c3df14a5fdcd13ee8916",
      "pattern": "[file:hashes.MD5 = 'edac597788e7c3df14a5fdcd13ee8916']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--52703c51-63bc-48fd-9a79-fd6bc737f53d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-44877",
      "pattern": "[vulnerability:name = 'CVE-2022-44877']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-44877 \u2014 CWP Control Web Panel OS Command ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4a659ce5-a3b2-4dc2-bdd1-4a0aba9a3238",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-41040",
      "pattern": "[vulnerability:name = 'CVE-2022-41040']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41080 \u2014 Microsoft Exchange Server Privile",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-41082 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2a685022-2e0f-407d-a633-1283a4b3f851",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-41080",
      "pattern": "[vulnerability:name = 'CVE-2022-41080']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41080 \u2014 Microsoft Exchange Server Privile",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1796ecbe-bceb-4e39-b2d9-5691371dfb22",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-41082",
      "pattern": "[vulnerability:name = 'CVE-2022-41082']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41080 \u2014 Microsoft Exchange Server Privile",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-41082 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a7389d00-13fd-4c92-b21f-9d6aebc1d151",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2023-21674",
      "pattern": "[vulnerability:name = 'CVE-2023-21674']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2023-21674 \u2014 Microsoft Windows Advanced Local ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9198e595-cb11-4521-a792-14e5a691b0ba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.76.141.84",
      "pattern": "[ipv4-addr:value = '45.76.141.84']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41080 \u2014 Microsoft Exchange Server Privile",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53bda3d3-e3aa-46ca-8172-2e025922717c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.76.143.143",
      "pattern": "[ipv4-addr:value = '45.76.143.143']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41080 \u2014 Microsoft Exchange Server Privile",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3234651e-2a2d-412b-9635-286bfc7c3d10",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: potrax.com",
      "pattern": "[domain-name:value = 'potrax.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Supply chain security incident at CircleCI: Rotate your secr",
          "url": "https://snyk.io/blog/supply-chain-security-incident-circleci-secrets/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d0bf7367-2974-4d79-80a4-2d55377d16fd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 111.90.149.55",
      "pattern": "[ipv4-addr:value = '111.90.149.55']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Supply chain security incident at CircleCI: Rotate your secr",
          "url": "https://snyk.io/blog/supply-chain-security-incident-circleci-secrets/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--38b3d3af-3ec7-4e4b-abe3-4ac15fe4de7f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 178.249.214.10",
      "pattern": "[ipv4-addr:value = '178.249.214.10']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Supply chain security incident at CircleCI: Rotate your secr",
          "url": "https://snyk.io/blog/supply-chain-security-incident-circleci-secrets/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f99bf547-919a-4e2c-b6d8-1fc3afc2dc21",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 178.249.214.25",
      "pattern": "[ipv4-addr:value = '178.249.214.25']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Supply chain security incident at CircleCI: Rotate your secr",
          "url": "https://snyk.io/blog/supply-chain-security-incident-circleci-secrets/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2d664ba-1898-4a89-b0d5-5d0ff5403d0b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 188.68.229.52",
      "pattern": "[ipv4-addr:value = '188.68.229.52']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Supply chain security incident at CircleCI: Rotate your secr",
          "url": "https://snyk.io/blog/supply-chain-security-incident-circleci-secrets/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dfd05d4b-5a78-41fa-8fbc-e2b1f3bcc053",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 72.18.132.58",
      "pattern": "[ipv4-addr:value = '72.18.132.58']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Supply chain security incident at CircleCI: Rotate your secr",
          "url": "https://snyk.io/blog/supply-chain-security-incident-circleci-secrets/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--70b6d94a-37fc-48d2-8f49-e59dcd94dc3d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 89.36.78.109",
      "pattern": "[ipv4-addr:value = '89.36.78.109']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Supply chain security incident at CircleCI: Rotate your secr",
          "url": "https://snyk.io/blog/supply-chain-security-incident-circleci-secrets/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7100e251-4946-4506-b62b-73895fb83ae3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 89.36.78.135",
      "pattern": "[ipv4-addr:value = '89.36.78.135']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Supply chain security incident at CircleCI: Rotate your secr",
          "url": "https://snyk.io/blog/supply-chain-security-incident-circleci-secrets/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4f0b9277-5978-4683-9f9f-b4ce19b9ee7e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 89.36.78.75",
      "pattern": "[ipv4-addr:value = '89.36.78.75']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Supply chain security incident at CircleCI: Rotate your secr",
          "url": "https://snyk.io/blog/supply-chain-security-incident-circleci-secrets/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7838d1a1-792e-429f-92f9-21f33ea83964",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8913e38592228adc067d82f66c150d87004ec946e579d4a00c53b61444ff35bf",
      "pattern": "[file:hashes.'SHA-256' = '8913e38592228adc067d82f66c150d87004ec946e579d4a00c53b61444ff35bf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Supply chain security incident at CircleCI: Rotate your secr",
          "url": "https://snyk.io/blog/supply-chain-security-incident-circleci-secrets/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--14cff9b0-6c13-43a0-9d29-70a3a2fcd3fe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-18809",
      "pattern": "[vulnerability:name = 'CVE-2018-18809']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-18809 \u2014 TIBCO JasperReports Library Direc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--41ae8257-5f18-4c2a-88d0-00002bf1c88a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-5430",
      "pattern": "[vulnerability:name = 'CVE-2018-5430']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-5430 \u2014 TIBCO JasperReports Server Informa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--079921fe-9271-42d7-88d8-b618366f7775",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-31692",
      "pattern": "[vulnerability:name = 'CVE-2022-31692']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Exploring the Spring Security authorization bypass (CVE-2022",
          "url": "https://snyk.io/blog/spring-security-authorization-bypass-cve-2022-31692/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--366b73b7-7821-45c2-836a-c32c28b9ab87",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-42856",
      "pattern": "[vulnerability:name = 'CVE-2022-42856']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42856 \u2014 Apple iOS Type Confusion Vulnerab",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d47a9670-39d8-4734-a4f8-14fc4c2394c0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-26500",
      "pattern": "[vulnerability:name = 'CVE-2022-26500']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26500 \u2014 Veeam Backup & Replication Remote",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0a780d6e-8433-4efc-837e-734a337a3bdf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-26501",
      "pattern": "[vulnerability:name = 'CVE-2022-26501']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26501 \u2014 Veeam Backup & Replication Remote",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bbc48709-3d76-4089-805b-58555dad700b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-27518",
      "pattern": "[vulnerability:name = 'CVE-2022-27518']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-27518 \u2014 Citrix Application Delivery Contr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6e8f0ba-3a0f-460e-80c5-c27aba092809",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.131.189.143",
      "pattern": "[ipv4-addr:value = '103.131.189.143']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f423cda-3599-486d-8496-c69337f48ce8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 107.148.27.117",
      "pattern": "[ipv4-addr:value = '107.148.27.117']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b2bd5e9-d5a8-4d7b-9f9a-b86533302e7b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 137.175.30.138",
      "pattern": "[ipv4-addr:value = '137.175.30.138']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--31e491de-5354-4e77-bb03-71e5cad5c538",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 139.180.128.142",
      "pattern": "[ipv4-addr:value = '139.180.128.142']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd2c713d-a36f-404e-81c0-98bfd50fa504",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 139.180.184.197",
      "pattern": "[ipv4-addr:value = '139.180.184.197']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--29661f7d-2d0b-4c3a-8f31-ad4b80f69be3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 139.99.35.116",
      "pattern": "[ipv4-addr:value = '139.99.35.116']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9b01a482-cd83-4cc8-b445-98a77e510f74",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 139.99.37.119",
      "pattern": "[ipv4-addr:value = '139.99.37.119']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--10c73bf3-e2bd-433a-b4c9-608381a06b6c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 146.70.157.133",
      "pattern": "[ipv4-addr:value = '146.70.157.133']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e1992ccd-d569-41ce-8be0-a6349b4124c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 155.138.224.122",
      "pattern": "[ipv4-addr:value = '155.138.224.122']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a1b1bec4-f598-41a1-93cc-595e196be9da",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 156.251.162.111",
      "pattern": "[ipv4-addr:value = '156.251.162.111']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a0b13eed-59c0-403f-b430-6ea0d6befcb0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 156.251.162.76",
      "pattern": "[ipv4-addr:value = '156.251.162.76']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3318a7f4-1525-4836-afb7-6a8a9fc6a267",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 156.251.163.122",
      "pattern": "[ipv4-addr:value = '156.251.163.122']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f020844-fb95-42b7-bf99-a67c4d2fce87",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 156.251.163.19",
      "pattern": "[ipv4-addr:value = '156.251.163.19']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7af4cb20-9b3d-410b-9a43-fcc9956eb421",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 158.247.221.101",
      "pattern": "[ipv4-addr:value = '158.247.221.101']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c5c2f6be-688c-4083-b890-3f0addf931dd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.247.168.153",
      "pattern": "[ipv4-addr:value = '172.247.168.153']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--adc81ecf-87f1-4f81-a91c-e8e885faaea0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.174.136.20",
      "pattern": "[ipv4-addr:value = '185.174.136.20']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd10f868-d717-468b-a175-1081a273f81f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.250.149.32",
      "pattern": "[ipv4-addr:value = '185.250.149.32']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--64d4a51a-3b13-49ef-abbb-b3e24a28e5bf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 188.34.130.40",
      "pattern": "[ipv4-addr:value = '188.34.130.40']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b5f14559-d312-4148-a47d-d14d60359431",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.36.119.61",
      "pattern": "[ipv4-addr:value = '193.36.119.61']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4ae018b1-20ae-45e9-8887-f2c21f795d0d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.62.42.105",
      "pattern": "[ipv4-addr:value = '194.62.42.105']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bdd85f0e-a483-4411-bf63-e854c7466b5d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.86.229.220",
      "pattern": "[ipv4-addr:value = '45.86.229.220']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fd8c6262-3603-41d5-b9a6-b58e5be2ccbe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.86.231.71",
      "pattern": "[ipv4-addr:value = '45.86.231.71']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--07c744c3-d2fe-48f0-a5ff-017ca058d47d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 66.42.91.32",
      "pattern": "[ipv4-addr:value = '66.42.91.32']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4b5381d0-8276-49df-bad1-0a69226cdab9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 08cbaafb176ce6118f7e4e0b2d2d77cf",
      "pattern": "[file:hashes.MD5 = '08cbaafb176ce6118f7e4e0b2d2d77cf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2f27c57e-4f5c-4778-8f45-2fac4ffcd731",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 12e28c14bb7f7b9513a02e5857592ad7",
      "pattern": "[file:hashes.MD5 = '12e28c14bb7f7b9513a02e5857592ad7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2b682ab2-7195-4fc3-b784-e99c022be2f1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 3191cb2e06e9a30792309813793f78b6",
      "pattern": "[file:hashes.MD5 = '3191cb2e06e9a30792309813793f78b6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ac2aca9-33cc-41d9-a127-3cec59c0b2e8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 4548fa6625cb154ab320833186117393",
      "pattern": "[file:hashes.MD5 = '4548fa6625cb154ab320833186117393']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b968ded1-8947-453f-aa39-6667f2f29f55",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 54bbea35b095ddfe9740df97b693627b",
      "pattern": "[file:hashes.MD5 = '54bbea35b095ddfe9740df97b693627b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5b7b4ea4-bcb3-473d-91e1-8b904460a8f7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 856341349dd954d82b112ba9165c4563",
      "pattern": "[file:hashes.MD5 = '856341349dd954d82b112ba9165c4563']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--570fca61-8720-4ac3-a9a6-26fe2119ceed",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: ae0839351721db5a9c269fd75dcb57ce",
      "pattern": "[file:hashes.MD5 = 'ae0839351721db5a9c269fd75dcb57ce']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a00df649-ecb0-4e74-a79d-3fae6a7b421e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: bdc2d2f5d5246f8956711bcce9f456b6",
      "pattern": "[file:hashes.MD5 = 'bdc2d2f5d5246f8956711bcce9f456b6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e6d6aa03-d804-411c-b94f-02360cf3d6b9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e3f640d8785c0c864739529889b1863a",
      "pattern": "[file:hashes.MD5 = 'e3f640d8785c0c864739529889b1863a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--708da2ec-5691-4c11-ba46-a44f7fe84080",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e5d989b651b3eb351e10e408d5a062b3",
      "pattern": "[file:hashes.MD5 = 'e5d989b651b3eb351e10e408d5a062b3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4696be63-f3f3-46bf-90ee-3caf58581ed0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: f68c3f72270800ea675889e82bb02fb8",
      "pattern": "[file:hashes.MD5 = 'f68c3f72270800ea675889e82bb02fb8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6160647e-11ba-4fc5-ac6b-78a8ec8a24ac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 0184e3d3dd8f4778d192d07e2caf44211141a570d45bb47a87894c68ebebeabb",
      "pattern": "[file:hashes.'SHA-256' = '0184e3d3dd8f4778d192d07e2caf44211141a570d45bb47a87894c68ebebeabb']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0718536-1b2c-4ed5-b7de-939a64050b5f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 26f5bc698dfec8e771b781dc19941e2d657eb87fe8669e1f75d9e5a1bb4db1db",
      "pattern": "[file:hashes.'SHA-256' = '26f5bc698dfec8e771b781dc19941e2d657eb87fe8669e1f75d9e5a1bb4db1db']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-44698 \u2014 Microsoft Defender SmartScreen Se",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--61a17866-b48b-4c1d-9a2c-655bc6d06bc1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3da407c1a30d810aaff9a04dfc1ef5861062ebdf0e6d0f6823ca682ca08c37da",
      "pattern": "[file:hashes.'SHA-256' = '3da407c1a30d810aaff9a04dfc1ef5861062ebdf0e6d0f6823ca682ca08c37da']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1bdd3af4-3bd1-41d9-9c26-da4f3cfc3d95",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 61aae0e18c41ec4f610676680d26f6c6e1d4d5aa4e5092e40915fe806b679cd4",
      "pattern": "[file:hashes.'SHA-256' = '61aae0e18c41ec4f610676680d26f6c6e1d4d5aa4e5092e40915fe806b679cd4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5b4558a0-30b1-44ff-8ff4-28174df7c0c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6fb41b33304b65e6e35f04e8cc70f7a24cd36e29bbb97266de68afcf113f9a5f",
      "pattern": "[file:hashes.'SHA-256' = '6fb41b33304b65e6e35f04e8cc70f7a24cd36e29bbb97266de68afcf113f9a5f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-44698 \u2014 Microsoft Defender SmartScreen Se",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3cd0c7f5-6b84-4974-b5ad-da6502c8827f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8ca16991684f7384c12b6622b8d1bcd23bc27f186f499c2059770ddd3031f274",
      "pattern": "[file:hashes.'SHA-256' = '8ca16991684f7384c12b6622b8d1bcd23bc27f186f499c2059770ddd3031f274']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-44698 \u2014 Microsoft Defender SmartScreen Se",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--51242813-0488-4561-931b-6cf0632dc0a3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c5df8f8328103380943d8ead5345ca9fe8a9d495634db53cf9ea3266e353a3b1",
      "pattern": "[file:hashes.'SHA-256' = 'c5df8f8328103380943d8ead5345ca9fe8a9d495634db53cf9ea3266e353a3b1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-44698 \u2014 Microsoft Defender SmartScreen Se",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b190b8c1-482c-4c70-8d8e-d97204923bc7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-22984",
      "pattern": "[vulnerability:name = 'CVE-2022-22984']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Code injection vulnerabilities (CVSSv3 5.8) found in Snyk CL",
          "url": "https://snyk.io/blog/code-injection-vulns-cli-ide-plugins-medium-sev/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c5992e1-8026-41bc-a274-1291f463ba98",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-24441",
      "pattern": "[vulnerability:name = 'CVE-2022-24441']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Code injection vulnerabilities (CVSSv3 5.8) found in Snyk CL",
          "url": "https://snyk.io/blog/code-injection-vulns-cli-ide-plugins-medium-sev/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ea64f29-d7ad-40db-b471-da4ad21943b8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-35587",
      "pattern": "[vulnerability:name = 'CVE-2021-35587']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-35587 \u2014 Oracle Fusion Middleware Unspecif",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1cfca644-0344-47dd-9768-48cf0b6df683",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-4135",
      "pattern": "[vulnerability:name = 'CVE-2022-4135']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-4135 \u2014 Google Chromium GPU Heap Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--df4aa252-c99d-4869-a002-33e60843c25c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-41049",
      "pattern": "[vulnerability:name = 'CVE-2022-41049']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41049 \u2014 Microsoft Windows Mark of the Web",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--660ed435-1540-43e4-96c1-41d6f7506fb3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-26068",
      "pattern": "[vulnerability:name = 'CVE-2022-26068']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Fetch the Flag CTF 2022 writeup: Not So Smart Fridge",
          "url": "https://snyk.io/blog/fetch-the-flag-ctf-2022-writeup-not-so-smart-fridge/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--64942e65-f6cc-4bf1-b6dc-0e5657cb78e5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: moongoose.c.ctf-snyk.io",
      "pattern": "[domain-name:value = 'moongoose.c.ctf-snyk.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Fetch the Flag CTF 2022 writeup: Moongoose",
          "url": "https://snyk.io/blog/fetch-the-flag-ctf-2022-writeup-moongoose/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7d534046-a0b1-4a8f-b61c-e70c1c544574",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: pay-attention.c.ctf-snyk.io",
      "pattern": "[domain-name:value = 'pay-attention.c.ctf-snyk.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Fetch the Flag CTF 2022 writeup: Treasure Trove",
          "url": "https://snyk.io/blog/fetch-the-flag-ctf-2022-writeup-treasure-trove/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d1a9f951-34b4-40d9-b65a-090668262c77",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: disposable-message.c.ctf-snyk.io",
      "pattern": "[domain-name:value = 'disposable-message.c.ctf-snyk.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Fetch the Flag CTF 2022 writeup: Disposable Message",
          "url": "https://snyk.io/blog/fetch-the-flag-ctf-2022-writeup-disposable-message/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--52e861d7-406f-451f-8028-b6db39b4d50f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-3744",
      "pattern": "[vulnerability:name = 'CVE-2014-3744']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Fetch the Flag CTF 2022 writeup: File Explorer",
          "url": "https://snyk.io/blog/fetch-the-flag-ctf-2022-writeup-file-explorer/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--afe84656-7795-42c2-9ae2-8d6aaec606dd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: file-explorer.c.ctf-snyk.io",
      "pattern": "[domain-name:value = 'file-explorer.c.ctf-snyk.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Fetch the Flag CTF 2022 writeup: File Explorer",
          "url": "https://snyk.io/blog/fetch-the-flag-ctf-2022-writeup-file-explorer/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f674d685-1a7b-47b7-95d2-5a107bb1fbd6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-25337",
      "pattern": "[vulnerability:name = 'CVE-2021-25337']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-25337 \u2014 Samsung Mobile Devices Improper A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--28270281-7420-43ed-bb77-0b27bc4f7d47",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-25369",
      "pattern": "[vulnerability:name = 'CVE-2021-25369']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-25337 \u2014 Samsung Mobile Devices Improper A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--df593650-27a4-4d40-8de4-384a0ce4899a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-25370",
      "pattern": "[vulnerability:name = 'CVE-2021-25370']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-25337 \u2014 Samsung Mobile Devices Improper A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cdc667f4-6408-43ab-a229-43aaa3218085",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-23812",
      "pattern": "[vulnerability:name = 'CVE-2022-23812']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "NPM security: preventing supply chain attacks",
          "url": "https://snyk.io/blog/npm-security-preventing-supply-chain-attacks/"
        },
        {
          "source_name": "The npm faker package and the unexpected demise of open sour",
          "url": "https://snyk.io/blog/npm-faker-package-open-source-libraries/"
        },
        {
          "source_name": "Protestware is trending in open source: 4 different types an",
          "url": "https://snyk.io/blog/protestware-open-source-types-impact/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c51e2445-0c37-4b04-9d9c-fbb942489c3c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-41073",
      "pattern": "[vulnerability:name = 'CVE-2022-41073']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41073 \u2014 Microsoft Windows Print Spooler P",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c07a5464-2779-4137-aec1-2f9f15379b83",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-41091",
      "pattern": "[vulnerability:name = 'CVE-2022-41091']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41091 \u2014 Microsoft Windows Mark of the Web",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--05f6a925-62ee-460f-bc38-5415d5ae489e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-41125",
      "pattern": "[vulnerability:name = 'CVE-2022-41125']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41125 \u2014 Microsoft Windows CNG Key Isolati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea7a1893-9c16-46f4-a4e3-9127dd455bd5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ms-office.services",
      "pattern": "[domain-name:value = 'ms-office.services']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Langu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c3fc82a2-e764-480b-bc91-7480fc8de73e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ms-offices.com",
      "pattern": "[domain-name:value = 'ms-offices.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Langu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e55e24e9-834b-421b-99a9-6bc2539f949f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: openxmlformat.org",
      "pattern": "[domain-name:value = 'openxmlformat.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Langu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--df5f0c37-7b82-4001-87fe-983a931f5896",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: template-openxml.com",
      "pattern": "[domain-name:value = 'template-openxml.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Langu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dac4735f-bfbb-4b14-803f-e4645169e206",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: word-template.net",
      "pattern": "[domain-name:value = 'word-template.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Langu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0aa23200-4ef9-402c-888e-37ffcfe1fd37",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 08f93351d0d3905bee5b0c2b9215d448abb0d3cf49c0f8b666c46df4fcc007cb",
      "pattern": "[file:hashes.'SHA-256' = '08f93351d0d3905bee5b0c2b9215d448abb0d3cf49c0f8b666c46df4fcc007cb']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Langu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ad1c9b83-f9e3-49ec-8993-b907f66e1e08",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3bff571823421c013e79cc10793f238f4252f7d7ac91f9ef41435af0a8c09a39",
      "pattern": "[file:hashes.'SHA-256' = '3bff571823421c013e79cc10793f238f4252f7d7ac91f9ef41435af0a8c09a39']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Langu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7d222b5d-7761-47c2-81af-6e0761f72255",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 56ca24b57c4559f834c190d50b0fe89dd4a4040a078ca1f267d0bbc7849e9ed7",
      "pattern": "[file:hashes.'SHA-256' = '56ca24b57c4559f834c190d50b0fe89dd4a4040a078ca1f267d0bbc7849e9ed7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Langu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ec5515c2-d80d-4551-8481-f0755257fb50",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 926a947ea2b59d3e9a5a6875b4de2bd071b15260370f4da5e2a60ece3517a32f",
      "pattern": "[file:hashes.'SHA-256' = '926a947ea2b59d3e9a5a6875b4de2bd071b15260370f4da5e2a60ece3517a32f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Langu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e7ee6286-022e-4955-bb56-353227abf3c8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: af5fb99d3ff18bc625fb63f792ed7cd955171ab509c2f8e7c7ee44515e09cebf",
      "pattern": "[file:hashes.'SHA-256' = 'af5fb99d3ff18bc625fb63f792ed7cd955171ab509c2f8e7c7ee44515e09cebf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Langu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--26a89e6f-cc8f-4b67-a3da-0550336e4ac7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c49b4d370ad0dcd1e28ee8f525ac8e3c12a34cfcf62ebb733ec74cca59b29f82",
      "pattern": "[file:hashes.'SHA-256' = 'c49b4d370ad0dcd1e28ee8f525ac8e3c12a34cfcf62ebb733ec74cca59b29f82']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Langu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--521ac5bf-48f6-4e41-a83e-d497c4d9f6c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-3723",
      "pattern": "[vulnerability:name = 'CVE-2022-3723']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-3723 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--532c67f7-d2e7-4115-8d85-ea8eaad1f4e8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-42827",
      "pattern": "[vulnerability:name = 'CVE-2022-42827']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-42827 \u2014 Apple iOS and iPadOS Out-of-Bound",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d119d52d-27cf-4e7e-8abc-b040935ada55",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-19320",
      "pattern": "[vulnerability:name = 'CVE-2018-19320']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-19323 \u2014 GIGABYTE Multiple Products Privil",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2018-19320 \u2014 GIGABYTE Multiple Products Unspec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6770a554-51d0-4be9-8702-b9db20bdc6d0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-19321",
      "pattern": "[vulnerability:name = 'CVE-2018-19321']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-19323 \u2014 GIGABYTE Multiple Products Privil",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2018-19321 \u2014 GIGABYTE Multiple Products Privil",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6b401c98-9c06-4230-b510-3578cd6fbfbd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-19322",
      "pattern": "[vulnerability:name = 'CVE-2018-19322']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-19323 \u2014 GIGABYTE Multiple Products Privil",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2018-19322 \u2014 GIGABYTE Multiple Products Code E",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0164d0bc-9284-4667-b8ec-375c9a58ae24",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-19323",
      "pattern": "[vulnerability:name = 'CVE-2018-19323']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-19323 \u2014 GIGABYTE Multiple Products Privil",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--281046bd-ee59-4f8e-91c3-8bf6b8959661",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-3153",
      "pattern": "[vulnerability:name = 'CVE-2020-3153']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-3153 \u2014 Cisco AnyConnect Secure Mobility C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e06da377-f783-46d2-8b12-00cbb17b0164",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-3433",
      "pattern": "[vulnerability:name = 'CVE-2020-3433']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-3433 \u2014 Cisco AnyConnect Secure Mobility C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-3153 \u2014 Cisco AnyConnect Secure Mobility C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b6be57d-6de0-4ab2-8664-14443f85a3bd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 0b15b5cc64caf0c6ad9bd759eb35383b1f718edf3d7ab4cd912d0d8c1826edf8",
      "pattern": "[file:hashes.'SHA-256' = '0b15b5cc64caf0c6ad9bd759eb35383b1f718edf3d7ab4cd912d0d8c1826edf8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-19323 \u2014 GIGABYTE Multiple Products Privil",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2018-19320 \u2014 GIGABYTE Multiple Products Unspec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--795cadfe-d185-4b33-82d4-71d481645a5c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 31f4cfb4c71da44120752721103a16512444c13c2ac2d857a7e6f13cb679b427",
      "pattern": "[file:hashes.'SHA-256' = '31f4cfb4c71da44120752721103a16512444c13c2ac2d857a7e6f13cb679b427']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-19323 \u2014 GIGABYTE Multiple Products Privil",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2018-19320 \u2014 GIGABYTE Multiple Products Unspec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d4791cf0-7a4f-41f2-872e-5fedbb8165fb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 791c32a95f401f7464214960e49e716656f6fd6fff135ac2a6ba607236d3346e",
      "pattern": "[file:hashes.'SHA-256' = '791c32a95f401f7464214960e49e716656f6fd6fff135ac2a6ba607236d3346e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-19323 \u2014 GIGABYTE Multiple Products Privil",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2018-19320 \u2014 GIGABYTE Multiple Products Unspec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b1b019f2-0bb4-4535-b187-00d5d34fe6b9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 99c3cc348f8ee4e87bce45b1dd185d31830c370ac43fd3e39ac50340f029ef79",
      "pattern": "[file:hashes.'SHA-256' = '99c3cc348f8ee4e87bce45b1dd185d31830c370ac43fd3e39ac50340f029ef79']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-19323 \u2014 GIGABYTE Multiple Products Privil",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2018-19320 \u2014 GIGABYTE Multiple Products Unspec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--14a3bba1-7f06-4c53-93ac-2a1d6f7d4604",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-1197",
      "pattern": "[vulnerability:name = 'CVE-2015-1197']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41352 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5156f79a-27ad-4e3e-9916-12a1ae13e235",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-3493",
      "pattern": "[vulnerability:name = 'CVE-2021-3493']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-3493 \u2014 Linux Kernel Privilege Escalation ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--821086a7-bad4-4834-9d97-fa33cafebe6a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-41352",
      "pattern": "[vulnerability:name = 'CVE-2022-41352']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41352 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--01c651a1-8094-4354-a550-537658cd90d4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-42889",
      "pattern": "[vulnerability:name = 'CVE-2022-42889']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Reviewing CVE-2022-42889: The arbitrary code execution vulne",
          "url": "https://snyk.io/blog/reviewing-cve-2022-42889-in-apache-commons-text/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f162fd54-f93b-440d-a805-5e49a1c92e50",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-40684",
      "pattern": "[vulnerability:name = 'CVE-2022-40684']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-40684 \u2014 Fortinet Multiple Products Authen",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--225113b0-57a9-4682-8d00-14a598586ea8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-41033",
      "pattern": "[vulnerability:name = 'CVE-2022-41033']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-41033 \u2014 Microsoft Windows COM+ Event Syst",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--39e61512-25e1-4e04-b497-73f09bf8c1da",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-40764",
      "pattern": "[vulnerability:name = 'CVE-2022-40764']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Command injection vulnerability in Snyk CLI released prior t",
          "url": "https://snyk.io/blog/command-injection-vulnerability-cve-2022-40764/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ec246648-6b4b-4cbd-b4c7-618a0d54703f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-36804",
      "pattern": "[vulnerability:name = 'CVE-2022-36804']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-36804 \u2014 Atlassian Bitbucket Server and Da",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b518c0ce-289d-4cff-91b3-4c812bf57bfa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-3236",
      "pattern": "[vulnerability:name = 'CVE-2022-3236']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-3236 \u2014 Sophos Firewall Code Injection Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3a33a17a-3384-4002-9efc-154c62235576",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-35405",
      "pattern": "[vulnerability:name = 'CVE-2022-35405']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-35405 \u2014 Zoho ManageEngine Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c11651d6-20fc-43e0-adcf-14cf21752c74",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-2568",
      "pattern": "[vulnerability:name = 'CVE-2010-2568']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-2568 \u2014 Microsoft Windows Remote Code Exec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0cfa59c6-0eea-46e5-8cb2-7270c3011ee0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-2094",
      "pattern": "[vulnerability:name = 'CVE-2013-2094']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-2094 \u2014 Linux Kernel Privilege Escalation ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--49122277-bfc5-42ee-875b-f908171d66d5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-2596",
      "pattern": "[vulnerability:name = 'CVE-2013-2596']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-2596 \u2014 Linux Kernel Integer Overflow Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a19db0e8-46a5-4340-b643-04c98ad780bd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-2597",
      "pattern": "[vulnerability:name = 'CVE-2013-2597']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-2597 \u2014 Code Aurora ACDB Audio Driver Stac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dca9bab2-4ae9-4fb0-9f07-59c484ec44a9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-6282",
      "pattern": "[vulnerability:name = 'CVE-2013-6282']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-6282 \u2014 Linux Kernel Improper Input Valida",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d27ecefd-a046-4e4d-b38f-596e6d5121ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-40139",
      "pattern": "[vulnerability:name = 'CVE-2022-40139']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-40139 \u2014 Trend Micro Apex One and Apex One",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aa256d53-4431-489e-8b42-f3c17f6ebd17",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: recipient.com",
      "pattern": "[domain-name:value = 'recipient.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Avoiding SMTP Injection: A Whitebox primer",
          "url": "https://snyk.io/blog/avoiding-smtp-injection/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3971e359-516f-4e5a-b59b-2fd1d00f6589",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sender.com",
      "pattern": "[domain-name:value = 'sender.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Avoiding SMTP Injection: A Whitebox primer",
          "url": "https://snyk.io/blog/avoiding-smtp-injection/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--59bf1dc4-6178-43d9-8cf1-14a570caf695",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-32917",
      "pattern": "[vulnerability:name = 'CVE-2022-32917']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-32917 \u2014 Apple iOS, iPadOS, and macOS Remo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7ba87950-a265-4d48-997a-0b474e030a6f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-37969",
      "pattern": "[vulnerability:name = 'CVE-2022-37969']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-37969 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--260fb8ec-ae1b-412c-9062-6f902dd10402",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2011-1823",
      "pattern": "[vulnerability:name = 'CVE-2011-1823']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-1823 \u2014 Android OS Privilege Escalation Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6478b6d-3487-4f22-bbc8-3f826cdc3d6e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2011-4723",
      "pattern": "[vulnerability:name = 'CVE-2011-4723']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-4723 \u2014 D-Link DIR-300 Router Cleartext St",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--517d1e93-3e89-4aa5-b6b1-1af88e6a09a9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-5521",
      "pattern": "[vulnerability:name = 'CVE-2017-5521']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-5521 \u2014 NETGEAR Multiple Devices Exposure ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b93310b-5114-4a9f-a705-0972166e5a31",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-13374",
      "pattern": "[vulnerability:name = 'CVE-2018-13374']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-13374 \u2014 Fortinet FortiOS and FortiADC Imp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1e73d5ee-ba18-482a-8d76-8f0575da8c74",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-2628",
      "pattern": "[vulnerability:name = 'CVE-2018-2628']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-2628 \u2014 Oracle WebLogic Server Unspecified",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4359d0c1-f4ae-4e53-8ce6-a773191d3a7e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-6530",
      "pattern": "[vulnerability:name = 'CVE-2018-6530']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-6530 \u2014 D-Link Multiple Routers OS Command",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2015-2051 \u2014 D-Link DIR-645 Router Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--08e163c3-7982-4516-b3d0-c722533ed181",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-7445",
      "pattern": "[vulnerability:name = 'CVE-2018-7445']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7445 \u2014 MikroTik RouterOS Stack-Based Buff",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--876b0276-aee0-4db1-8079-5b65ffd6936d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-9934",
      "pattern": "[vulnerability:name = 'CVE-2020-9934']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-9934 \u2014 Apple iOS, iPadOS, and macOS Input",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--023e1274-c107-413f-b96b-57af91a5da9f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-26258",
      "pattern": "[vulnerability:name = 'CVE-2022-26258']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26258 \u2014 D-Link DIR-820L Remote Code Execu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2015-2051 \u2014 D-Link DIR-645 Router Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3f564675-748f-4df3-ab35-c0b4db4d7677",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-27593",
      "pattern": "[vulnerability:name = 'CVE-2022-27593']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-27593 \u2014 QNAP Photo Station Externally Con",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--725a4053-61d0-4346-a03c-c680bdd96321",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-3075",
      "pattern": "[vulnerability:name = 'CVE-2022-3075']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-3075 \u2014 Google Chromium Mojo Insufficient ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--917bc188-d404-4779-92c8-659483df890f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-23639",
      "pattern": "[vulnerability:name = 'CVE-2021-23639']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Solve Hack the Box and other CTF challenges with Snyk",
          "url": "https://snyk.io/blog/solve-hack-the-box-and-ctf-challenges-with-snyk/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c97a1ed0-9e46-4d6b-845c-902301708ed4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-21680",
      "pattern": "[vulnerability:name = 'CVE-2022-21680']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Solve Hack the Box and other CTF challenges with Snyk",
          "url": "https://snyk.io/blog/solve-hack-the-box-and-ctf-challenges-with-snyk/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9e477260-8ab2-459e-9616-ba63e4ac0f68",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-21681",
      "pattern": "[vulnerability:name = 'CVE-2022-21681']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Solve Hack the Box and other CTF challenges with Snyk",
          "url": "https://snyk.io/blog/solve-hack-the-box-and-ctf-challenges-with-snyk/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c0112c9-9e97-4fe7-90ef-0e2938a82ac1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-28949",
      "pattern": "[vulnerability:name = 'CVE-2020-28949']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-28949 \u2014 PEAR Archive_Tar Deserialization ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d84e4aec-7f7d-4847-baa7-cb40bb602315",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-36193",
      "pattern": "[vulnerability:name = 'CVE-2020-36193']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-36193 \u2014 PEAR Archive_Tar Improper Link Re",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32f41316-e5c4-4a90-a09c-d453fde64573",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-31010",
      "pattern": "[vulnerability:name = 'CVE-2021-31010']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31010 \u2014 Apple iOS, macOS, watchOS Sandbox",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ab0b7dcd-e406-4697-bfe8-1c20a7e64ccd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-38406",
      "pattern": "[vulnerability:name = 'CVE-2021-38406']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-38406 \u2014 Delta Electronics DOPSoft 2 Impro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8dbccf7d-0f38-4d76-8941-74fd259669f7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-39226",
      "pattern": "[vulnerability:name = 'CVE-2021-39226']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-39226 \u2014 Grafana Authentication Bypass Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d9fb734-923a-4498-8d27-5c73dcd76311",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-2294",
      "pattern": "[vulnerability:name = 'CVE-2022-2294']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-2294 \u2014 WebRTC Heap Buffer Overflow Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6328020c-f1be-4983-af9d-979b9434709a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-22963",
      "pattern": "[vulnerability:name = 'CVE-2022-22963']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22963 \u2014 VMware Tanzu Spring Cloud Functio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "Spring4Shell: What we know about the Java RCE vulnerability",
          "url": "https://snyk.io/blog/is-there-such-a-thing-as-spring4shell/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b242904a-85d6-4591-b9cc-49d1adcfdd80",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-24112",
      "pattern": "[vulnerability:name = 'CVE-2022-24112']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24112 \u2014 Apache APISIX Authentication Bypa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ed9639f9-b826-4fb0-ab12-cd797ea04cea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-24706",
      "pattern": "[vulnerability:name = 'CVE-2022-24706']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24706 \u2014 Apache CouchDB Insecure Default I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e3699edb-c88c-4fa9-b91b-d0515978bd71",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-26352",
      "pattern": "[vulnerability:name = 'CVE-2022-26352']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26352 \u2014 dotCMS Unrestricted Upload of Fil",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--15f5221b-4e82-49a6-8757-c02d68681a5e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: stylishblock.com",
      "pattern": "[domain-name:value = 'stylishblock.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-2294 \u2014 WebRTC Heap Buffer Overflow Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d380936-1672-49ce-b6d7-11afa5e94f09",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.14.30.35",
      "pattern": "[ipv4-addr:value = '185.14.30.35']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24706 \u2014 Apache CouchDB Insecure Default I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c717876-4ee5-4456-b381-2a41442fe387",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.106.191.48",
      "pattern": "[ipv4-addr:value = '193.106.191.48']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24706 \u2014 Apache CouchDB Insecure Default I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aa7ed070-e594-4bd7-8a18-0e0cd9c3849c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 212.22.77.79",
      "pattern": "[ipv4-addr:value = '212.22.77.79']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24706 \u2014 Apache CouchDB Insecure Default I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3401af29-23ec-4cc8-8e88-71e9072ec44e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 91.241.19.134",
      "pattern": "[ipv4-addr:value = '91.241.19.134']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24706 \u2014 Apache CouchDB Insecure Default I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9834f5ca-d462-475d-927c-e10bf34aa122",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 95.182.120.164",
      "pattern": "[ipv4-addr:value = '95.182.120.164']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24706 \u2014 Apache CouchDB Insecure Default I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc034251-27e3-4b86-85e1-c92f67213d97",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5bab937d057b35ffd4e50e2c170863f9b40fbf9424f66d0ddeae2a62b6403937",
      "pattern": "[file:hashes.'SHA-256' = '5bab937d057b35ffd4e50e2c170863f9b40fbf9424f66d0ddeae2a62b6403937']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24706 \u2014 Apache CouchDB Insecure Default I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--97cb4113-b305-4392-be31-3e44ca6ba19f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5d2530b809fd069f97b30a5938d471dd2145341b5793a70656aad6045445cf6d",
      "pattern": "[file:hashes.'SHA-256' = '5d2530b809fd069f97b30a5938d471dd2145341b5793a70656aad6045445cf6d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24706 \u2014 Apache CouchDB Insecure Default I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9ee08045-bba4-4433-ad3f-82d6f1385304",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c38c21120d8c17688f9aeb2af5bdafb6b75e1d2673b025b720e50232f888808a",
      "pattern": "[file:hashes.'SHA-256' = 'c38c21120d8c17688f9aeb2af5bdafb6b75e1d2673b025b720e50232f888808a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24706 \u2014 Apache CouchDB Insecure Default I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f1d11957-3561-4440-80b1-bc2ea1308f1a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d318cdb5fee75d647c784a6dcb2a5a613143caf7740087726911bab35206b666",
      "pattern": "[file:hashes.'SHA-256' = 'd318cdb5fee75d647c784a6dcb2a5a613143caf7740087726911bab35206b666']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24706 \u2014 Apache CouchDB Insecure Default I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2ae6eeef-dd98-415a-bb9b-dd2197ddc84e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-21187",
      "pattern": "[vulnerability:name = 'CVE-2022-21187']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Rediscovering argument injection when using VCS tools \u2014 git ",
          "url": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7a630000-5859-496b-bf13-96c65e4e11e1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-21223",
      "pattern": "[vulnerability:name = 'CVE-2022-21223']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Rediscovering argument injection when using VCS tools \u2014 git ",
          "url": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3f3f9b94-0ea4-4335-946e-75a77987bdc7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-21235",
      "pattern": "[vulnerability:name = 'CVE-2022-21235']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Rediscovering argument injection when using VCS tools \u2014 git ",
          "url": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7e4ab495-2e07-47e2-8049-1e75d9d0801f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-23915",
      "pattern": "[vulnerability:name = 'CVE-2022-23915']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Rediscovering argument injection when using VCS tools \u2014 git ",
          "url": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b999ed0-188e-421a-88b5-fed4036ce3f1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-24065",
      "pattern": "[vulnerability:name = 'CVE-2022-24065']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Rediscovering argument injection when using VCS tools \u2014 git ",
          "url": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b08ff744-d278-4f52-a120-a21fed39d431",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-24433",
      "pattern": "[vulnerability:name = 'CVE-2022-24433']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Rediscovering argument injection when using VCS tools \u2014 git ",
          "url": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--496d84a8-6058-4ce6-9c1d-6612b769b86f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-24440",
      "pattern": "[vulnerability:name = 'CVE-2022-24440']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Rediscovering argument injection when using VCS tools \u2014 git ",
          "url": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--faa49863-4fbd-461e-a70f-ce4b34064b7b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-25648",
      "pattern": "[vulnerability:name = 'CVE-2022-25648']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Rediscovering argument injection when using VCS tools \u2014 git ",
          "url": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e69d5c01-ca88-4dcd-ab02-fa3002be283d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-25766",
      "pattern": "[vulnerability:name = 'CVE-2022-25766']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Rediscovering argument injection when using VCS tools \u2014 git ",
          "url": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a32ffaf6-9125-471e-b080-dd4119db03df",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-25865",
      "pattern": "[vulnerability:name = 'CVE-2022-25865']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Rediscovering argument injection when using VCS tools \u2014 git ",
          "url": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--24c14c49-129b-428e-aa8a-1bc71515c11a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-25866",
      "pattern": "[vulnerability:name = 'CVE-2022-25866']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Rediscovering argument injection when using VCS tools \u2014 git ",
          "url": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cedadc8b-5e41-458f-9098-b7953e03ba53",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-26945",
      "pattern": "[vulnerability:name = 'CVE-2022-26945']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Rediscovering argument injection when using VCS tools \u2014 git ",
          "url": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7f8dfcaa-3883-4bdd-b945-49123024eab2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-29184",
      "pattern": "[vulnerability:name = 'CVE-2022-29184']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Rediscovering argument injection when using VCS tools \u2014 git ",
          "url": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3fc005d0-0fe0-4134-8bc3-473d8648ff84",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-7547",
      "pattern": "[vulnerability:name = 'CVE-2015-7547']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "How open source C++ code can introduce security risks",
          "url": "https://snyk.io/blog/how-open-source-c-code-can-introduce-security-risks/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7d6e048e-bea4-41fc-90a2-49fe8d7bbdc8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-0028",
      "pattern": "[vulnerability:name = 'CVE-2022-0028']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0028 \u2014 Palo Alto Networks PAN-OS Reflecte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--62355a27-aed4-4a22-bf75-d505b001269a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.248.94.23",
      "pattern": "[ipv4-addr:value = '104.248.94.23']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "How open source C++ code can introduce security risks",
          "url": "https://snyk.io/blog/how-open-source-c-code-can-introduce-security-risks/"
        },
        {
          "source_name": "Responsible disclosure: CodeCov CEO & CTO share learnings fr",
          "url": "https://snyk.io/blog/codecov-ceo-cto-share-learnings-from-breach-tsd/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6cef0b31-cb66-4f32-8f51-cba00a1571d8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-15944",
      "pattern": "[vulnerability:name = 'CVE-2017-15944']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-15944 \u2014 Palo Alto Networks PAN-OS Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4ca900f7-7b17-45a8-9e5a-efbe6ad55acc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-21971",
      "pattern": "[vulnerability:name = 'CVE-2022-21971']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-21971 \u2014 Microsoft Windows Runtime Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e19e00f8-baea-40ab-a00e-fb39d7f8bd54",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-22536",
      "pattern": "[vulnerability:name = 'CVE-2022-22536']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22536 \u2014 SAP Multiple Products HTTP Reques",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fec7c921-a55c-4317-ab73-00d22b8f24fa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-26923",
      "pattern": "[vulnerability:name = 'CVE-2022-26923']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26923 \u2014 Microsoft Active Directory Domain",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ad0e55dc-6345-4f50-a72c-8e7e0943720f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-2856",
      "pattern": "[vulnerability:name = 'CVE-2022-2856']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-2856 \u2014 Google Chromium Intents Insufficie",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--539e777d-5320-4bb6-8d5a-50333406d476",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-32893",
      "pattern": "[vulnerability:name = 'CVE-2022-32893']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-32894 \u2014 Apple iOS and macOS Out-of-Bounds",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-32893 \u2014 Apple iOS and macOS Out-of-Bounds",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e27b2a59-299b-403a-b050-f022e5acc933",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-32894",
      "pattern": "[vulnerability:name = 'CVE-2022-32894']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-32894 \u2014 Apple iOS and macOS Out-of-Bounds",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-32893 \u2014 Apple iOS and macOS Out-of-Bounds",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--230c90f7-a510-49f9-8deb-8b98bbfaadf6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cdn.discordapp.com",
      "pattern": "[domain-name:value = 'cdn.discordapp.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk finds PyPi malware that steals Discord and Roblox crede",
          "url": "https://snyk.io/blog/pypi-malware-discord-roblox-credential-payment-info/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2ea3417e-2344-4e43-af5e-b881da0173c4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: github.com/Rdimo/Discord-Injection",
      "pattern": "[domain-name:value = 'github.com/Rdimo/Discord-Injection']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk finds PyPi malware that steals Discord and Roblox crede",
          "url": "https://snyk.io/blog/pypi-malware-discord-roblox-credential-payment-info/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4033b1a6-3bd2-47c1-bd27-65b2e0ccd380",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: https://cdn.discordapp.com/attachments/1003368479442874518/1003368773983682592/ZYRBX.exe",
      "pattern": "[domain-name:value = 'https://cdn.discordapp.com/attachments/1003368479442874518/1003368773983682592/ZYRBX.exe']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk finds PyPi malware that steals Discord and Roblox crede",
          "url": "https://snyk.io/blog/pypi-malware-discord-roblox-credential-payment-info/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b45075f8-4140-43e6-8385-73bbb3e4fab3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: https://cdn.discordapp.com/attachments/1003368479442874518/1003368774335991898/ZYXMN.exe",
      "pattern": "[domain-name:value = 'https://cdn.discordapp.com/attachments/1003368479442874518/1003368774335991898/ZYXMN.exe']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk finds PyPi malware that steals Discord and Roblox crede",
          "url": "https://snyk.io/blog/pypi-malware-discord-roblox-credential-payment-info/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--adf25288-de4f-440f-86ea-d4cf8b719b89",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: https://discord.com/api/webhooks/1003603061530431539/mAOhFLrtafsu1jC3G1_nRR5by1zBTtd4xxdxZPVFkOlCUqMeze6TcUQ3zbR9zVsvG5-m",
      "pattern": "[domain-name:value = 'https://discord.com/api/webhooks/1003603061530431539/mAOhFLrtafsu1jC3G1_nRR5by1zBTtd4xxdxZPVFkOlCUqMeze6TcUQ3zbR9zVsvG5-m']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk finds PyPi malware that steals Discord and Roblox crede",
          "url": "https://snyk.io/blog/pypi-malware-discord-roblox-credential-payment-info/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d0fc70c-711e-4fa0-b530-b468baabb15c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-27924",
      "pattern": "[vulnerability:name = 'CVE-2022-27924']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-27925 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-27924 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--369e814d-ca7e-4565-99ad-e8f733229929",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-27925",
      "pattern": "[vulnerability:name = 'CVE-2022-27925']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-27925 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ba5e0df-04c0-4d47-b645-8ef9074d55d4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-37042",
      "pattern": "[vulnerability:name = 'CVE-2022-37042']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-27925 \u2014 Synacor Zimbra Collaboration Suit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e9cdd3c9-ff0b-49ab-93a0-4b87e0055246",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-33980",
      "pattern": "[vulnerability:name = 'CVE-2022-33980']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Controlling your server with a reverse shell attack",
          "url": "https://snyk.io/blog/reverse-shell-attack/"
        },
        {
          "source_name": "Exploring CVE-2022-33980: the Apache Commons configuration R",
          "url": "https://snyk.io/blog/cve-2022-33980-apache-commons-configuration-rce-vulnerability/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6fa0a2d0-100f-4ee8-9ce8-777070bffcf9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-30333",
      "pattern": "[vulnerability:name = 'CVE-2022-30333']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-30333 \u2014 RARLAB UnRAR Directory Traversal ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8bb1d27c-7d66-40ac-aeb3-22e54c82d597",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-34713",
      "pattern": "[vulnerability:name = 'CVE-2022-34713']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-34713 \u2014 Microsoft Windows Support Diagnos",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ca189d1d-1402-4523-8d0f-87a89555c6ea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-26138",
      "pattern": "[vulnerability:name = 'CVE-2022-26138']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26138 \u2014 Atlassian Questions For Confluenc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0c6e5dc7-8cf0-4d62-9d5d-f67a68d4984b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-28550",
      "pattern": "[vulnerability:name = 'CVE-2021-28550']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-28550 \u2014 Adobe Acrobat and Reader Use-Afte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8501480a-e423-44cf-9331-d62c426b2b1c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-31199",
      "pattern": "[vulnerability:name = 'CVE-2021-31199']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31201 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1d1e298f-36c5-4535-b0d9-5b67baed0b3f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-31201",
      "pattern": "[vulnerability:name = 'CVE-2021-31201']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31201 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--78fc3c5a-64d0-45c4-be57-55cd6c05855c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-36948",
      "pattern": "[vulnerability:name = 'CVE-2021-36948']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-36948 \u2014 Microsoft Windows Update Medic Se",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a5d07f63-e174-4486-a86f-55dd39d94015",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-22047",
      "pattern": "[vulnerability:name = 'CVE-2022-22047']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--548ea8fc-541a-4281-ad6d-ace8eea8ff39",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: acrobatrelay.com",
      "pattern": "[domain-name:value = 'acrobatrelay.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb813c59-d3a7-48fe-aad3-d5111260f910",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: demo3.dsirf.eu",
      "pattern": "[domain-name:value = 'demo3.dsirf.eu']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d5070a4-fc0c-400e-abc1-b0cfef92f4e1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: finconsult.cc",
      "pattern": "[domain-name:value = 'finconsult.cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--24dde1b3-e47a-4597-805c-8fcbddc0b46d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: realmetaldns.com",
      "pattern": "[domain-name:value = 'realmetaldns.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e9b0179-e7be-4287-8237-b6894f538962",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 02a59fe2c94151a08d75a692b550e66a8738eb47f0001234c600b562bf8c227d",
      "pattern": "[file:hashes.'SHA-256' = '02a59fe2c94151a08d75a692b550e66a8738eb47f0001234c600b562bf8c227d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb2f8c93-5ee4-4b90-aebb-33ac69ae0fdd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 0588f61dc7e4b24554cffe4ea56d043d8f6139d2569bc180d4a77cf75b68792f",
      "pattern": "[file:hashes.'SHA-256' = '0588f61dc7e4b24554cffe4ea56d043d8f6139d2569bc180d4a77cf75b68792f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--990c5f7a-a9e9-4537-8002-43126c5ce272",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 441a3810b9e89bae12eea285a63f92e98181e9fb9efd6c57ef6d265435484964",
      "pattern": "[file:hashes.'SHA-256' = '441a3810b9e89bae12eea285a63f92e98181e9fb9efd6c57ef6d265435484964']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a2218a8d-1157-41ac-ad63-6101e366a3dd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4611340fdade4e36f074f75294194b64dcf2ec0db00f3d958956b4b0d6586431",
      "pattern": "[file:hashes.'SHA-256' = '4611340fdade4e36f074f75294194b64dcf2ec0db00f3d958956b4b0d6586431']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aee2ba45-d3b5-4870-a762-b0ec19e7d348",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5d169e083faa73f2920c8593fb95f599dad93d34a6aa2b0f794be978e44c8206",
      "pattern": "[file:hashes.'SHA-256' = '5d169e083faa73f2920c8593fb95f599dad93d34a6aa2b0f794be978e44c8206']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e0e60fa4-2415-46f6-9f5a-269dbf1156d7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 78c255a98003a101fa5ba3f49c50c6922b52ede601edac5db036ab72efc57629",
      "pattern": "[file:hashes.'SHA-256' = '78c255a98003a101fa5ba3f49c50c6922b52ede601edac5db036ab72efc57629']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea621fff-b92a-4554-8e97-03b5a7c439d0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7f29b69eb1af1cc6c1998bad980640bfe779525fd5bb775bc36a0ce3789a8bfc",
      "pattern": "[file:hashes.'SHA-256' = '7f29b69eb1af1cc6c1998bad980640bfe779525fd5bb775bc36a0ce3789a8bfc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0a28264b-3195-416f-9933-976dbe4623af",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7f84bf6a016ca15e654fb5ebc36fd7407cb32c69a0335a32bfc36cb91e36184d",
      "pattern": "[file:hashes.'SHA-256' = '7f84bf6a016ca15e654fb5ebc36fd7407cb32c69a0335a32bfc36cb91e36184d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--58b96342-dfdf-4029-be0e-230716d70c01",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 894138dfeee756e366c65a197b4dbef8816406bc32697fac6621601debe17d53",
      "pattern": "[file:hashes.'SHA-256' = '894138dfeee756e366c65a197b4dbef8816406bc32697fac6621601debe17d53']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--98f042d0-23a8-4eb6-8caf-680c68168ef8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: afab2e77dc14831f1719e746042063a8ec107de0e9730249d5681d07f598e5ec",
      "pattern": "[file:hashes.'SHA-256' = 'afab2e77dc14831f1719e746042063a8ec107de0e9730249d5681d07f598e5ec']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--900b4121-9b85-4acb-8c22-bd623cef8d20",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c96ae21b4cf2e28eec222cfe6ca903c4767a068630a73eca58424f9a975c6b7d",
      "pattern": "[file:hashes.'SHA-256' = 'c96ae21b4cf2e28eec222cfe6ca903c4767a068630a73eca58424f9a975c6b7d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--05025acc-4472-44d7-899f-7660e2caaf6d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: cbae79f66f724e0fe1705d6b5db3cc8a4e89f6bdf4c37004aa1d45eeab26e84b",
      "pattern": "[file:hashes.'SHA-256' = 'cbae79f66f724e0fe1705d6b5db3cc8a4e89f6bdf4c37004aa1d45eeab26e84b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--92782301-4a15-46a2-b403-65cb75cf27cb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e64bea4032cf2694e85ede1745811e7585d3580821a00ae1b9123bb3d2d442d6",
      "pattern": "[file:hashes.'SHA-256' = 'e64bea4032cf2694e85ede1745811e7585d3580821a00ae1b9123bb3d2d442d6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6559e025-155e-440f-8390-47e3fa818f68",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: fa30be45c5c5a8f679b42ae85410f6099f66fe2b38eb7aa460bcc022babb41ca",
      "pattern": "[file:hashes.'SHA-256' = 'fa30be45c5c5a8f679b42ae85410f6099f66fe2b38eb7aa460bcc022babb41ca']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--db5f0549-d4bd-461b-a956-82ff41ec2d11",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: fd6515a71530b8329e2c0104d0866c5c6f87546d4b44cc17bbb03e64663b11fc",
      "pattern": "[file:hashes.'SHA-256' = 'fd6515a71530b8329e2c0104d0866c5c6f87546d4b44cc17bbb03e64663b11fc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d558765b-5643-4728-bdc7-27d925c51617",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-36942",
      "pattern": "[vulnerability:name = 'CVE-2021-36942']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26925 \u2014 Microsoft Windows LSA Spoofing Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31207 \u2014 Microsoft Exchange Server Securit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-36942 \u2014 Microsoft Windows Local Security ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--08e11463-bd3a-45c7-a409-3d399f7ba542",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-26925",
      "pattern": "[vulnerability:name = 'CVE-2022-26925']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26925 \u2014 Microsoft Windows LSA Spoofing Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--94957697-04f1-47a3-8a40-e373cc11ab4a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-4344",
      "pattern": "[vulnerability:name = 'CVE-2018-4344']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-4344 \u2014 Apple Multiple Products Memory Cor",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--132cfba7-4ce6-4358-b25b-197cb0d951cb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-8605",
      "pattern": "[vulnerability:name = 'CVE-2019-8605']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-8605 \u2014 Apple Multiple Products Use-After-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3c58b1de-26fd-4eb5-816a-76e9eac44a1f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-3837",
      "pattern": "[vulnerability:name = 'CVE-2020-3837']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-3837 \u2014 Apple Multiple Products Memory Cor",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--be94c8b5-93c4-4a80-96ca-dd70e98bd1a6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-9907",
      "pattern": "[vulnerability:name = 'CVE-2020-9907']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-9907 \u2014 Apple Multiple Products Memory Cor",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ba7239c2-4a38-4300-aead-0f40e20ea3b4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30533",
      "pattern": "[vulnerability:name = 'CVE-2021-30533']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30533 \u2014 Google Chromium PopupBlocker Secu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32ed303a-cf58-4c8a-be4c-d60bf39c718e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30983",
      "pattern": "[vulnerability:name = 'CVE-2021-30983']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30983 \u2014 Apple iOS and iPadOS Buffer Overf",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--440c79ce-2c83-4855-acad-1bcac85ef4e0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-4034",
      "pattern": "[vulnerability:name = 'CVE-2021-4034']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-4034 \u2014 Red Hat Polkit Out-of-Bounds Read ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "Analyzing the PwnKit local privilege escalation exploit",
          "url": "https://snyk.io/blog/pwnkit-linux-exploit-cve-2021-4034/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c26559ae-40b5-45f6-ae89-7851d76b580c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-29499",
      "pattern": "[vulnerability:name = 'CVE-2022-29499']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-29499 \u2014 Mitel MiVoice Connect Data Valida",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--05daf705-b5a8-4ec1-ab28-86fccd5222f4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 137.184.181.252",
      "pattern": "[ipv4-addr:value = '137.184.181.252']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-29499 \u2014 Mitel MiVoice Connect Data Valida",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb222e9f-3ea2-41cb-9ec7-a6eb6c66338d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 138.197.218.11",
      "pattern": "[ipv4-addr:value = '138.197.218.11']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-29499 \u2014 Mitel MiVoice Connect Data Valida",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ed21fa5f-c96a-4225-b0e5-45bed7402c09",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 138.68.19.94",
      "pattern": "[ipv4-addr:value = '138.68.19.94']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-29499 \u2014 Mitel MiVoice Connect Data Valida",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--43e59c24-c1d4-432c-b269-c568b81b4059",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 138.68.59.16",
      "pattern": "[ipv4-addr:value = '138.68.59.16']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-29499 \u2014 Mitel MiVoice Connect Data Valida",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--423dcd88-022b-4339-be96-a2f949b7ac0e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 159.65.248.159",
      "pattern": "[ipv4-addr:value = '159.65.248.159']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-29499 \u2014 Mitel MiVoice Connect Data Valida",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--47f199b1-bc06-4390-8b77-1a7e54ca9aa2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 206.188.197.125",
      "pattern": "[ipv4-addr:value = '206.188.197.125']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-29499 \u2014 Mitel MiVoice Connect Data Valida",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--83ba06a1-7a10-4e70-96c8-38c5764bdf2b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 64.190.113.100",
      "pattern": "[ipv4-addr:value = '64.190.113.100']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-29499 \u2014 Mitel MiVoice Connect Data Valida",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--295cf1d1-049c-464f-9629-c6596f541d6d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 07838ac8fd5a59bb741aae0cf3abf48296677be7ac0864c4f124c2e168c0af94",
      "pattern": "[file:hashes.'SHA-256' = '07838ac8fd5a59bb741aae0cf3abf48296677be7ac0864c4f124c2e168c0af94']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-29499 \u2014 Mitel MiVoice Connect Data Valida",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--12626e0f-cf96-4a2a-8761-a5ca962c15b5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 97ff99fd824a02106d20d167e2a2b647244712a558639524e7db1e6a2064a68d",
      "pattern": "[file:hashes.'SHA-256' = '97ff99fd824a02106d20d167e2a2b647244712a558639524e7db1e6a2064a68d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-29499 \u2014 Mitel MiVoice Connect Data Valida",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a677c686-1173-45d5-9be7-b0b8471fa70c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-30190",
      "pattern": "[vulnerability:name = 'CVE-2022-30190']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-30190 \u2014 Microsoft Windows Support Diagnos",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f614b7d-d6b8-414b-83e9-f2eeb9bb4ce9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8e0be5e1035777f2ea373593c214d29ad146dd0453e9b8a1cad16d787c0be632",
      "pattern": "[file:hashes.'SHA-256' = '8e0be5e1035777f2ea373593c214d29ad146dd0453e9b8a1cad16d787c0be632']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-30190 \u2014 Microsoft Windows Support Diagnos",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e6c39d4a-008a-4a45-b2b2-61f3372a4ce9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b63fbf80351b3480c62a6a5158334ec8e91fecd057f6c19e4b4dd3febaa9d447",
      "pattern": "[file:hashes.'SHA-256' = 'b63fbf80351b3480c62a6a5158334ec8e91fecd057f6c19e4b4dd3febaa9d447']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-30190 \u2014 Microsoft Windows Support Diagnos",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--269bc361-eb2a-4339-b195-92ecc1b36ed9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e7faa6c18d4906257652253755cf8f9a739c10938db369878907f8ed7dd8524d",
      "pattern": "[file:hashes.'SHA-256' = 'e7faa6c18d4906257652253755cf8f9a739c10938db369878907f8ed7dd8524d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-30190 \u2014 Microsoft Windows Support Diagnos",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--314adc51-fab4-41bf-b23f-04dc90804158",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-2386",
      "pattern": "[vulnerability:name = 'CVE-2016-2386']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-2386 \u2014 SAP NetWeaver SQL Injection Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e18d74ea-00a6-4595-8fe2-05d0af51c64c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-2388",
      "pattern": "[vulnerability:name = 'CVE-2016-2388']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-2388 \u2014 SAP NetWeaver Information Disclosu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2dfa0ead-ae5a-4fda-9f61-751acd7c493a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-38163",
      "pattern": "[vulnerability:name = 'CVE-2021-38163']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-38163 \u2014 SAP NetWeaver Unrestricted File U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a6edd06b-119f-4d16-91fe-8166c583a33d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2006-2492",
      "pattern": "[vulnerability:name = 'CVE-2006-2492']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2006-2492 \u2014 Microsoft Word Malformed Object Po",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fed988ef-2343-4270-b273-18e284470aee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2007-5659",
      "pattern": "[vulnerability:name = 'CVE-2007-5659']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2007-5659 \u2014 Adobe Acrobat and Reader Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--97eedbbc-4de9-4710-9879-dc2884db704f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2008-0655",
      "pattern": "[vulnerability:name = 'CVE-2008-0655']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2008-0655 \u2014 Adobe Acrobat and Reader Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--197cca43-cc17-480b-a842-26e8e325cf7f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2009-0557",
      "pattern": "[vulnerability:name = 'CVE-2009-0557']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2009-0557 \u2014 Microsoft Office Object Record Cor",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e1f7442c-dc96-4da7-b7dd-a1c7b07138ce",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2009-0563",
      "pattern": "[vulnerability:name = 'CVE-2009-0563']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2009-0563 \u2014 Microsoft Office Buffer Overflow V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4264a1ba-316b-4e89-8fde-95bc9e47668a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2009-1862",
      "pattern": "[vulnerability:name = 'CVE-2009-1862']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2009-1862 \u2014 Adobe Acrobat and Reader, Flash Pl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--63a38bd9-8665-4143-9536-7a1e8314e532",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2009-3953",
      "pattern": "[vulnerability:name = 'CVE-2009-3953']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2009-3953 \u2014 Adobe Acrobat and Reader Universal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--200a67ac-6d60-47c2-b569-2e0e70c3acf8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2009-4324",
      "pattern": "[vulnerability:name = 'CVE-2009-4324']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2009-4324 \u2014 Adobe Acrobat and Reader Use-After",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e9db51c0-e477-42d8-856e-6f71841e6c55",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-1297",
      "pattern": "[vulnerability:name = 'CVE-2010-1297']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-1297 \u2014 Adobe Flash Player Memory Corrupti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--72019fda-d858-45a8-a1fa-419959df7a0a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-2572",
      "pattern": "[vulnerability:name = 'CVE-2010-2572']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-2572 \u2014 Microsoft PowerPoint Buffer Overfl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b776a5b-9a1c-43ed-ba46-824497cd4702",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-2883",
      "pattern": "[vulnerability:name = 'CVE-2010-2883']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-2883 \u2014 Adobe Acrobat and Reader Stack-Bas",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2007-5659 \u2014 Adobe Acrobat and Reader Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87aba834-eac6-49b6-b79f-ba12438c1263",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2011-0609",
      "pattern": "[vulnerability:name = 'CVE-2011-0609']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0609 \u2014 Adobe Flash Player Unspecified Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2009-1862 \u2014 Adobe Acrobat and Reader, Flash Pl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bd2bce33-0170-4a2e-a6bc-c32f13cad074",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2011-0611",
      "pattern": "[vulnerability:name = 'CVE-2011-0611']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-1889 \u2014 Microsoft XML Core Services Memory",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--33ce9d4d-ff40-4bb8-9daf-23b5e617a2c6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2011-2462",
      "pattern": "[vulnerability:name = 'CVE-2011-2462']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d85edb85-20ba-433d-a487-bf2445d0dc3e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-0151",
      "pattern": "[vulnerability:name = 'CVE-2012-0151']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-0151 \u2014 Microsoft Windows Authenticode Sig",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2cd67d13-fb30-44dc-bd80-a8638cd3a440",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-0754",
      "pattern": "[vulnerability:name = 'CVE-2012-0754']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corrupti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d821c8ae-9d5c-4bee-9d5d-2997bd802ea9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-0767",
      "pattern": "[vulnerability:name = 'CVE-2012-0767']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-0767 \u2014 Adobe Flash Player Cross-Site Scri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--21eb93ec-440e-4c27-a89c-6ba3d71ed1b2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-1889",
      "pattern": "[vulnerability:name = 'CVE-2012-1889']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-1889 \u2014 Microsoft XML Core Services Memory",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7a3e230b-49f5-42c7-be3d-de568f423c61",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-4969",
      "pattern": "[vulnerability:name = 'CVE-2012-4969']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-4969 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b9004406-ddcb-45c1-8a2b-42088c90d46f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-5054",
      "pattern": "[vulnerability:name = 'CVE-2012-5054']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-5054 \u2014 Adobe Flash Player Integer Overflo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b2b359a2-1231-4382-a74d-fc6e4a287294",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-1331",
      "pattern": "[vulnerability:name = 'CVE-2013-1331']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-1331 \u2014 Microsoft Office Buffer Overflow V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2009-0563 \u2014 Microsoft Office Buffer Overflow V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--02d9efdc-e699-449d-8889-bfaed7d70676",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-1646",
      "pattern": "[vulnerability:name = 'CVE-2016-1646']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-1646 \u2014 Google Chromium V8 Out-of-Bounds R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--18fb0b9c-e65b-4a7c-96b5-0aec3c8f95d4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-5198",
      "pattern": "[vulnerability:name = 'CVE-2016-5198']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-5198 \u2014 Google Chromium V8 Out-of-Bounds M",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-1646 \u2014 Google Chromium V8 Out-of-Bounds R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a72198b1-dafc-4f15-bbe3-e19cab10e410",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-5030",
      "pattern": "[vulnerability:name = 'CVE-2017-5030']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-5030 \u2014 Google Chromium V8 Memory Corrupti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5abc08d-9184-49df-9e06-53308eafe9f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-5070",
      "pattern": "[vulnerability:name = 'CVE-2017-5070']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-5070 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb3bf499-6e02-4c86-9edf-732940136f97",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-6862",
      "pattern": "[vulnerability:name = 'CVE-2017-6862']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-6862 \u2014 NETGEAR Multiple Devices Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--693b5a74-7166-40d1-877d-9ef99b768c9c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-17463",
      "pattern": "[vulnerability:name = 'CVE-2018-17463']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-17463 \u2014 Google Chromium V8 Remote Code Ex",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea7e881e-bbcf-4619-8975-ee035fb7a4d7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-17480",
      "pattern": "[vulnerability:name = 'CVE-2018-17480']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-17480 \u2014 Google Chromium V8 Out-of-Bounds ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--20501af7-60ae-4ad5-933b-8c446d1ea1d5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-4990",
      "pattern": "[vulnerability:name = 'CVE-2018-4990']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-4990 \u2014 Adobe Acrobat and Reader Double Fr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2009-4324 \u2014 Adobe Acrobat and Reader Use-After",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2018-8120 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b7ff7ca-4ae2-4326-9153-6836722f55de",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-6065",
      "pattern": "[vulnerability:name = 'CVE-2018-6065']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-6065 \u2014 Google Chromium V8 Integer Overflo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--80b4d712-6728-49af-a479-cefe401d1813",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-15271",
      "pattern": "[vulnerability:name = 'CVE-2019-15271']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-15271 \u2014 Cisco RV Series Routers Deseriali",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--38149a7b-283d-4738-8d4c-4b7af3ef04e4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-5825",
      "pattern": "[vulnerability:name = 'CVE-2019-5825']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-5825 \u2014 Google Chromium V8 Out-of-Bounds W",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a6af271c-e353-433c-ae31-39492e1b3fcb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-7192",
      "pattern": "[vulnerability:name = 'CVE-2019-7192']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-7192 \u2014 QNAP Photo Station Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0afdc146-6399-4948-9bfe-89dc6685f86a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-7193",
      "pattern": "[vulnerability:name = 'CVE-2019-7193']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-7193 \u2014 QNAP QTS Improper Input Validation",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-7192 \u2014 QNAP Photo Station Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0c4d59b0-f6f7-4b0e-b0cf-455d996b21ba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-7194",
      "pattern": "[vulnerability:name = 'CVE-2019-7194']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-7194 \u2014 QNAP Photo Station Path Traversal ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-7192 \u2014 QNAP Photo Station Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0da4c969-ebb0-48d4-a4d8-8436b00058f6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-7195",
      "pattern": "[vulnerability:name = 'CVE-2019-7195']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-7195 \u2014 QNAP Photo Station Path Traversal ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-7192 \u2014 QNAP Photo Station Improper Access",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--58342b2a-db4f-4480-825e-5d0408a3d53f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ccnslc.com",
      "pattern": "[domain-name:value = 'ccnslc.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc637d9d-ae99-49e4-ab4b-80f12277170d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: desktop.newcarstyle.com",
      "pattern": "[domain-name:value = 'desktop.newcarstyle.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0e79132c-2d30-43ab-80af-22b76917de2d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: documents.mypicture.info",
      "pattern": "[domain-name:value = 'documents.mypicture.info']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corrupti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--51af2dc4-fc5a-49d6-87c6-5e9839cee68c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: edns.biz",
      "pattern": "[domain-name:value = 'edns.biz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corrupti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b05a48b7-be2b-49ad-a5f6-cd2d55091bd1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: info.kimfishions.com",
      "pattern": "[domain-name:value = 'info.kimfishions.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--80a28edf-ad28-46fc-ba68-782d2e039340",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: kiki.edns.biz",
      "pattern": "[domain-name:value = 'kiki.edns.biz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corrupti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3ab8161c-970a-478b-93fa-554f0add6f26",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: mypicture.info",
      "pattern": "[domain-name:value = 'mypicture.info']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corrupti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--69f7e757-6809-4512-87b5-7d0f76f489b4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: prettylikeher.com",
      "pattern": "[domain-name:value = 'prettylikeher.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6262cb20-e0df-402c-b8ca-bdb8a8818d43",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 199.192.156.134",
      "pattern": "[ipv4-addr:value = '199.192.156.134']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corrupti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6c81454e-5eb2-49a0-83ee-4e4b1d18723b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 208.115.230.76",
      "pattern": "[ipv4-addr:value = '208.115.230.76']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corrupti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7f646c2f-916f-4adf-b37f-55bde7768fd3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 61.196.209.58",
      "pattern": "[ipv4-addr:value = '61.196.209.58']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corrupti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bf37a5b4-db8c-4b55-aafa-3ccece0fa26e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 71.36.88.82",
      "pattern": "[ipv4-addr:value = '71.36.88.82']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a380a507-99a3-4df5-b18c-e040fd559e1d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 128a66cc3efe6f424c3fedcc4b6235ac",
      "pattern": "[file:hashes.MD5 = '128a66cc3efe6f424c3fedcc4b6235ac']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corrupti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a9961d2b-b98e-4091-8df6-c89ad988b932",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 1e46c60e65ae9f9c9c8850372d8da491",
      "pattern": "[file:hashes.MD5 = '1e46c60e65ae9f9c9c8850372d8da491']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2d8c8b7e-ca9e-44fe-8af4-31f67f5980a0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 2172079c9c4aa385624de6b4987dbc15",
      "pattern": "[file:hashes.MD5 = '2172079c9c4aa385624de6b4987dbc15']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a95355bc-4165-45d3-8816-f32b3b019de4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 517fe6ba9417e6c8b4d0a0b3b9c4c9a9",
      "pattern": "[file:hashes.MD5 = '517fe6ba9417e6c8b4d0a0b3b9c4c9a9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd8f0659-ad1c-4a11-9b3e-8e362facab05",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 601f8f52cedf043ee4d3d3c83706329f",
      "pattern": "[file:hashes.MD5 = '601f8f52cedf043ee4d3d3c83706329f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--855a2f87-4a78-4d78-a95f-cc9e394ef25e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 721fda5df552f4130218ad9bd2a4ab78",
      "pattern": "[file:hashes.MD5 = '721fda5df552f4130218ad9bd2a4ab78']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d1e9c882-ed03-41c0-93b6-d951f6c53012",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 7eab072b76abc4c3e8cba8173c79890c",
      "pattern": "[file:hashes.MD5 = '7eab072b76abc4c3e8cba8173c79890c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d676d12b-2c41-4ba5-a749-6d782a514ef7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 8933598c8b1fa5e493497b11c48da4f2",
      "pattern": "[file:hashes.MD5 = '8933598c8b1fa5e493497b11c48da4f2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corrupti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--02e9b1bd-ca82-430e-954f-c258c1f7e4c8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: b025b06549caae5a7c1d23ac1d014892",
      "pattern": "[file:hashes.MD5 = 'b025b06549caae5a7c1d23ac1d014892']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb09f2b3-f05f-4a32-8f4f-358141d4a0ee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: b9872f4b6d2290de75a7ff2874a28850",
      "pattern": "[file:hashes.MD5 = 'b9872f4b6d2290de75a7ff2874a28850']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--93f91bd0-457b-4b93-9646-8d95b4d3eaac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: ba7793845fe2a02187263a96e8daaec6",
      "pattern": "[file:hashes.MD5 = 'ba7793845fe2a02187263a96e8daaec6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1f0ae024-e5e1-451a-b729-5831149b077d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: cb3dcde34fd9ff0e19381d99b02f9692",
      "pattern": "[file:hashes.MD5 = 'cb3dcde34fd9ff0e19381d99b02f9692']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corrupti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1cf6a928-4982-4b64-84a2-7f69740fd20b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e769a920b12d019679c43a9a4c0d7e2c",
      "pattern": "[file:hashes.MD5 = 'e769a920b12d019679c43a9a4c0d7e2c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--755ea97e-510c-4bef-958c-b408119834b4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e92a4fc283eb2802ad6d0e24c7fcc857",
      "pattern": "[file:hashes.MD5 = 'e92a4fc283eb2802ad6d0e24c7fcc857']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corrupti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f72abe71-a58f-4b62-bac9-55a040fdbf81",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: fd1be09e499e8e380424b3835fc973a8",
      "pattern": "[file:hashes.MD5 = 'fd1be09e499e8e380424b3835fc973a8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corrupti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2ba8359d-60ba-4aef-ba3d-42c056779e0f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: fd778c023020a23311b68127bf7e7692",
      "pattern": "[file:hashes.MD5 = 'fd778c023020a23311b68127bf7e7692']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fffa9d62-6fb9-4ec9-b1a2-767f53576a3f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2dd92dcfe5a46143b9a879122432e48ef0b9016736b66cd322f5c9fb5d3441dd",
      "pattern": "[file:hashes.'SHA-256' = '2dd92dcfe5a46143b9a879122432e48ef0b9016736b66cd322f5c9fb5d3441dd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corrupti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--99f88d39-afd4-47a2-b572-a35bbea1bef7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 68360603794c0f6d1aff9f6853dbdbb1860a89269d3147dab768034d4195ca62",
      "pattern": "[file:hashes.'SHA-256' = '68360603794c0f6d1aff9f6853dbdbb1860a89269d3147dab768034d4195ca62']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corrupti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ec94420e-6f83-44ab-88b7-0054778db67d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-23771",
      "pattern": "[vulnerability:name = 'CVE-2021-23771']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Safer together: Snyk and CISPA collaborate for the greater g",
          "url": "https://snyk.io/blog/safer-together-snyk-and-cispa-collaborate/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc2b55f9-0aaf-41f3-85d1-63a25342cc17",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-21144",
      "pattern": "[vulnerability:name = 'CVE-2022-21144']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Safer together: Snyk and CISPA collaborate for the greater g",
          "url": "https://snyk.io/blog/safer-together-snyk-and-cispa-collaborate/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8124088-fdcb-4d57-ac6a-4d30450ea451",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 154.146.34.145",
      "pattern": "[ipv4-addr:value = '154.146.34.145']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f763608e-1638-469e-b403-27d33358287a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 154.16.105.147",
      "pattern": "[ipv4-addr:value = '154.16.105.147']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--753aa18d-0a2f-46a1-aa7d-91b59d0864f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 156.146.34.46",
      "pattern": "[ipv4-addr:value = '156.146.34.46']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--55051a7e-907e-41b4-a68a-1b2448970111",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 156.146.34.52",
      "pattern": "[ipv4-addr:value = '156.146.34.52']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fc9d4e14-4fd0-4423-ab62-dde4cafb391b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 156.146.34.9",
      "pattern": "[ipv4-addr:value = '156.146.34.9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b6b5416-617c-437a-b61d-0f75580a443a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 156.146.56.136",
      "pattern": "[ipv4-addr:value = '156.146.56.136']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4a4106d-e544-4aa4-9bb3-93c40a826abe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 198.147.22.148",
      "pattern": "[ipv4-addr:value = '198.147.22.148']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--82049a9e-a113-44db-bcb4-aef08e184bcf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 221.178.126.244",
      "pattern": "[ipv4-addr:value = '221.178.126.244']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--671f9d6c-05ca-49f8-815e-524bce1712e5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.43.19.91",
      "pattern": "[ipv4-addr:value = '45.43.19.91']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--223f04f7-9bd6-434f-8925-bbe7cd1dae28",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 59.163.248.170",
      "pattern": "[ipv4-addr:value = '59.163.248.170']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--80c77909-3949-4ed6-b087-e1c10e0e0bdb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 64.64.228.239",
      "pattern": "[ipv4-addr:value = '64.64.228.239']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--51edbac1-dfa4-4d3c-b0f7-80727563f36e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 66.115.182.102",
      "pattern": "[ipv4-addr:value = '66.115.182.102']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--460b46b5-899f-46d0-ab8e-daa1df882226",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 66.115.182.111",
      "pattern": "[ipv4-addr:value = '66.115.182.111']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da3f1739-32c9-4264-9740-e67f6c624c49",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 67.149.61.16",
      "pattern": "[ipv4-addr:value = '67.149.61.16']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7e09ca0f-1516-4d91-8869-0d2460c958e9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 98.32.230.38",
      "pattern": "[ipv4-addr:value = '98.32.230.38']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d46903a7-6953-4ff2-93fb-00ac9b25806a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: ea18fb65d92e1f0671f23372bacf60e7",
      "pattern": "[file:hashes.MD5 = 'ea18fb65d92e1f0671f23372bacf60e7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a4c62e43-87a4-48b4-8630-8fbec3d718e8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: f8df4dd46f02dc86d37d46cf4793e036",
      "pattern": "[file:hashes.MD5 = 'f8df4dd46f02dc86d37d46cf4793e036']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1181084b-405c-42f3-b466-6cbf42964c7e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 4c02c3a150de6b70d6fca584c29888202cc1deef",
      "pattern": "[file:hashes.'SHA-1' = '4c02c3a150de6b70d6fca584c29888202cc1deef']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5047cedf-073d-46ff-bea6-b0555fb98f46",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 80b327ec19c7d14cc10511060ed3a4abffc821af",
      "pattern": "[file:hashes.'SHA-1' = '80b327ec19c7d14cc10511060ed3a4abffc821af']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f54710f8-f342-4256-b222-b3efddc82c32",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-0738",
      "pattern": "[vulnerability:name = 'CVE-2010-0738']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0738 \u2014 Red Hat JBoss Authentication Bypas",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b3dfd11-d379-4ce2-9db4-ff17c2157177",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-0840",
      "pattern": "[vulnerability:name = 'CVE-2010-0840']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0840 \u2014 Oracle JRE Unspecified Vulnerabili",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--be41603a-8674-4e44-bf12-35dd8d936577",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-1428",
      "pattern": "[vulnerability:name = 'CVE-2010-1428']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-1428 \u2014 Red Hat JBoss Information Disclosu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--40cd736d-6ed2-4383-8b0e-1affa6f76625",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-1710",
      "pattern": "[vulnerability:name = 'CVE-2012-1710']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-1710 \u2014 Oracle Fusion Middleware Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d73931cb-7c09-458a-98fe-9c50d41fd909",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-0074",
      "pattern": "[vulnerability:name = 'CVE-2013-0074']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Deref",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bd4588bd-f001-4eee-99a1-7b3ad43be7fd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-0422",
      "pattern": "[vulnerability:name = 'CVE-2013-0422']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0422 \u2014 Oracle JRE Remote Code Execution V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3432750b-e3e0-4ee2-a46f-9ffe172c20f8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-0431",
      "pattern": "[vulnerability:name = 'CVE-2013-0431']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0431 \u2014 Oracle JRE Sandbox Bypass Vulnerab",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea4abd02-03f0-408f-acbd-079b45bfa817",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-2423",
      "pattern": "[vulnerability:name = 'CVE-2013-2423']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-2423 \u2014 Oracle JRE Unspecified Vulnerabili",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2013-0431 \u2014 Oracle JRE Sandbox Bypass Vulnerab",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e54d43f3-3291-4953-a9d0-e398b7e2e0d5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-3896",
      "pattern": "[vulnerability:name = 'CVE-2013-3896']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3896 \u2014 Microsoft Silverlight Information ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Deref",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d4bccf8-08eb-4647-a7b9-9dc52ba245a2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-3993",
      "pattern": "[vulnerability:name = 'CVE-2013-3993']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3993 \u2014 IBM InfoSphere BigInsights Invalid",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--68974d64-c8fc-4198-9d73-3efd9367e7d3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-7331",
      "pattern": "[vulnerability:name = 'CVE-2013-7331']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-7331 \u2014 Microsoft Internet Explorer Inform",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bebc187f-166d-4106-9132-f1bff82692d5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-0546",
      "pattern": "[vulnerability:name = 'CVE-2014-0546']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-0546 \u2014 Adobe Reader and Acrobat Sandbox B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--039ccb1e-fbfa-4ef3-856a-356c1f9fbab2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-2817",
      "pattern": "[vulnerability:name = 'CVE-2014-2817']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-2817 \u2014 Microsoft Internet Explorer Privil",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--929f61bc-8611-4efc-a58e-8e575cbf7621",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-3153",
      "pattern": "[vulnerability:name = 'CVE-2014-3153']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-3153 \u2014 Linux Kernel Privilege Escalation ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--55688139-8694-44fa-a37e-a9e0fe2b9f52",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-4077",
      "pattern": "[vulnerability:name = 'CVE-2014-4077']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-4077 \u2014 Microsoft IME Japanese Privilege E",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--558f0061-aa59-434b-9226-4b9915aba103",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-4123",
      "pattern": "[vulnerability:name = 'CVE-2014-4123']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-4123 \u2014 Microsoft Internet Explorer Privil",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--73ff3990-a663-4373-a28b-47b6d9ab47d4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-4148",
      "pattern": "[vulnerability:name = 'CVE-2014-4148']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-4148 \u2014 Microsoft Windows Remote Code Exec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f072831-28ea-4850-8b73-6d878cbb5e6c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-8439",
      "pattern": "[vulnerability:name = 'CVE-2014-8439']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-8439 \u2014 Adobe Flash Player Dereferenced Po",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--49ca569f-6188-444c-b9f7-9e97ceddaf65",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-0016",
      "pattern": "[vulnerability:name = 'CVE-2015-0016']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-0016 \u2014 Microsoft Windows TS WebProxy Dire",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b233546d-3baa-436e-aa71-3e99618b9b9e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-0071",
      "pattern": "[vulnerability:name = 'CVE-2015-0071']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-0071 \u2014 Microsoft Internet Explorer ASLR B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0678458e-3a89-43a5-a15f-7e127d63df42",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-0310",
      "pattern": "[vulnerability:name = 'CVE-2015-0310']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-0310 \u2014 Adobe Flash Player ASLR Bypass Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2a70aaf0-3d75-4416-85f1-84f6239110f7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-0311",
      "pattern": "[vulnerability:name = 'CVE-2015-0311']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-0310 \u2014 Adobe Flash Player ASLR Bypass Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2015-0311 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--547524dd-c49b-4fce-8546-5166993effd6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-1671",
      "pattern": "[vulnerability:name = 'CVE-2015-1671']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-1671 \u2014 Microsoft Windows Remote Code Exec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f8fea57d-84d4-45cc-a3b1-c9a496abad15",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-1769",
      "pattern": "[vulnerability:name = 'CVE-2015-1769']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-1769 \u2014 Microsoft Windows Mount Manager Pr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8e6ff5e2-81e1-484e-ba1a-edd6c1c079f4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-2360",
      "pattern": "[vulnerability:name = 'CVE-2015-2360']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-2360 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9bf6b755-d579-4166-ae51-b8af8f8e5916",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-2425",
      "pattern": "[vulnerability:name = 'CVE-2015-2425']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-2425 \u2014 Microsoft Internet Explorer Memory",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--972acd4c-a533-4c28-b6d9-21f1e708b099",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-4495",
      "pattern": "[vulnerability:name = 'CVE-2015-4495']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-4495 \u2014 Mozilla Firefox Security Feature B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cba2963e-7dca-401a-8456-85db6876488f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-6175",
      "pattern": "[vulnerability:name = 'CVE-2015-6175']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-6175 \u2014 Microsoft Windows Kernel Privilege",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a7cf424f-9f2f-4c24-8f80-813108ad8ed2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-8651",
      "pattern": "[vulnerability:name = 'CVE-2015-8651']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-8651 \u2014 Adobe Flash Player Integer Overflo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6cea4d8f-146f-4c48-8b55-e2ea65e08067",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-0034",
      "pattern": "[vulnerability:name = 'CVE-2016-0034']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-0034 \u2014 Microsoft Silverlight Runtime Remo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--34b8c31d-2717-46d3-9ac0-11295e9df997",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-0189",
      "pattern": "[vulnerability:name = 'CVE-2016-0189']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-0016 \u2014 Microsoft Windows TS WebProxy Dire",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-0189 \u2014 Microsoft Internet Explorer Memory",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76ef212e-578e-4e5a-8270-68ccc4528f85",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-0984",
      "pattern": "[vulnerability:name = 'CVE-2016-0984']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-0984 \u2014 Adobe Flash Player and AIR Use-Aft",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0392bfc3-3685-4f81-b83e-f5ca048b077a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-1010",
      "pattern": "[vulnerability:name = 'CVE-2016-1010']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-1010 \u2014 Adobe Flash Player and AIR Integer",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--312a50fc-9da8-4c03-8d40-fbaa9a4b0cff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-3393",
      "pattern": "[vulnerability:name = 'CVE-2016-3393']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-3393 \u2014 Microsoft Windows Graphics Device ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--abb3ed13-a5c4-40c8-bef2-997b87faf14d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-7256",
      "pattern": "[vulnerability:name = 'CVE-2016-7256']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-7256 \u2014 Microsoft Windows Open Type Font R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c9297ddf-dce4-4b9a-bc02-c978462aec2c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-3010",
      "pattern": "[vulnerability:name = 'CVE-2019-3010']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-3010 \u2014 Oracle Solaris Privilege Escalatio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5afdac50-2fec-42de-a1e7-46ecf4c04652",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: besexeweryopko.com",
      "pattern": "[domain-name:value = 'besexeweryopko.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Deref",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d600da0-f9ed-40f6-bcda-607fa5af35d1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cnacom-organied.rhcloud.com",
      "pattern": "[domain-name:value = 'cnacom-organied.rhcloud.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-0016 \u2014 Microsoft Windows TS WebProxy Dire",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--26c900ae-5746-4d4a-8cd3-dd5720367ab3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: disabilitybenefitsinsider.com",
      "pattern": "[domain-name:value = 'disabilitybenefitsinsider.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Deref",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d49667ac-2fe8-4d95-a50a-e1cf35325dce",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: img.hitres.in",
      "pattern": "[domain-name:value = 'img.hitres.in']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Deref",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4436698c-f302-4fbd-bf34-b99afd40ffc9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: jvdsdveee.pw",
      "pattern": "[domain-name:value = 'jvdsdveee.pw']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Deref",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4dafc3fe-9744-42eb-b979-598a67ae1078",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: peragretisque.yevgenimalkin.com",
      "pattern": "[domain-name:value = 'peragretisque.yevgenimalkin.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Deref",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3ef9302c-bedd-4967-9c27-8398f85ffed3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: www1.gh1pn3avb63m2.4pu.com",
      "pattern": "[domain-name:value = 'www1.gh1pn3avb63m2.4pu.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Deref",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7cf29475-7425-4edc-893f-bbbe7e6f4812",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: www2.h-qo05lqa59ljh7.wpbh.org",
      "pattern": "[domain-name:value = 'www2.h-qo05lqa59ljh7.wpbh.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Deref",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0c273c36-b1fb-441c-8a1e-17f248083ca5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: www3.3b812bc6.kjyg.com",
      "pattern": "[domain-name:value = 'www3.3b812bc6.kjyg.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Deref",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--47577712-2020-4a3e-b353-21adab4d4cae",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 74.200.214.226",
      "pattern": "[ipv4-addr:value = '74.200.214.226']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-0016 \u2014 Microsoft Windows TS WebProxy Dire",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e6bc503d-85bd-4fca-8a77-ade31d0d0900",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 01ce22f87227f869b7978dc5fe625e16",
      "pattern": "[file:hashes.MD5 = '01ce22f87227f869b7978dc5fe625e16']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-0034 \u2014 Microsoft Silverlight Runtime Remo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--514c4312-470b-4d3e-83f0-cb9cee123589",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 167a0ffcfb6d828f5090b58d0b3c6b30",
      "pattern": "[file:hashes.MD5 = '167a0ffcfb6d828f5090b58d0b3c6b30']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Deref",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f41cad3f-fa71-479e-8149-2e9ff85458f5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 22a9f342eb367ea9b00508adb738d858",
      "pattern": "[file:hashes.MD5 = '22a9f342eb367ea9b00508adb738d858']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-0034 \u2014 Microsoft Silverlight Runtime Remo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e6506098-721d-4119-8397-75cc7b8d1ca6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 5f36a4c019d559f1be9fdd0cd770be2e",
      "pattern": "[file:hashes.MD5 = '5f36a4c019d559f1be9fdd0cd770be2e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Deref",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d159d99b-9ef1-4756-bde4-cc63a6b41ead",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 5faca70a46982cb945cd8e4b3a544aa8",
      "pattern": "[file:hashes.MD5 = '5faca70a46982cb945cd8e4b3a544aa8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Deref",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e9356b75-25b9-4a2b-84a7-23d8bc473922",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 6a01421a9bd82f02051ce6a4ea4e2edc",
      "pattern": "[file:hashes.MD5 = '6a01421a9bd82f02051ce6a4ea4e2edc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-0034 \u2014 Microsoft Silverlight Runtime Remo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8bd2a673-d6b1-44b8-b291-198bb4147075",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 7043831f829fd8305a59cc6df09cc8b6",
      "pattern": "[file:hashes.MD5 = '7043831f829fd8305a59cc6df09cc8b6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Deref",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e2616f8b-cd8a-4980-a47a-877cbc7f20ac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 83b0c1ff586044dbc6c0b99c55e27534",
      "pattern": "[file:hashes.MD5 = '83b0c1ff586044dbc6c0b99c55e27534']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Deref",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6753cf2d-0d89-425f-b1b7-b0a29400721d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: acfa9c664016bfe5db92557e923744f0",
      "pattern": "[file:hashes.MD5 = 'acfa9c664016bfe5db92557e923744f0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-0016 \u2014 Microsoft Windows TS WebProxy Dire",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87fcf5c1-e2ed-4cd6-8df2-314703e0c503",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: b61b986194de5fef36d805923a0f9379",
      "pattern": "[file:hashes.MD5 = 'b61b986194de5fef36d805923a0f9379']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Deref",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c16b40a-7911-447e-83fe-c127c9367d30",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: bdcfe33dbc7f86b929ddfbfa7a4ce43d",
      "pattern": "[file:hashes.MD5 = 'bdcfe33dbc7f86b929ddfbfa7a4ce43d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Deref",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1227a7dd-2770-4bfa-870b-0ff86219f120",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: cb9f864eb3b63172d01f9f45d849cc15",
      "pattern": "[file:hashes.MD5 = 'cb9f864eb3b63172d01f9f45d849cc15']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Deref",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4dbacab0-c7a4-4982-ad0f-45d44a2cd90b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: ce056895e07d2a9d04c5e8db844013ea",
      "pattern": "[file:hashes.MD5 = 'ce056895e07d2a9d04c5e8db844013ea']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Deref",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--91d9271e-b021-40fa-849f-4be50a57f6dd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: dc7647bc7896912b0fea4b93815e7fd0",
      "pattern": "[file:hashes.MD5 = 'dc7647bc7896912b0fea4b93815e7fd0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Deref",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--74410daf-50d3-414a-8025-3c5678a5b701",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 061be17741f0918bbf458812f6a04ebf3b70dea5",
      "pattern": "[file:hashes.'SHA-1' = '061be17741f0918bbf458812f6a04ebf3b70dea5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-2423 \u2014 Oracle JRE Unspecified Vulnerabili",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c2e7a7ca-8582-4756-84a7-ae5c73bc65e8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 28dc42c7b66a6a9e45d07397f1be684e1acb1372",
      "pattern": "[file:hashes.'SHA-1' = '28dc42c7b66a6a9e45d07397f1be684e1acb1372']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-2423 \u2014 Oracle JRE Unspecified Vulnerabili",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c24c8cf3-8da9-45ae-a856-51cda88a4f76",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 3866d78f233e5458c3244043b43006e9b3213582",
      "pattern": "[file:hashes.'SHA-1' = '3866d78f233e5458c3244043b43006e9b3213582']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-2423 \u2014 Oracle JRE Unspecified Vulnerabili",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3497a9b7-20d3-4bc6-a2e6-794d4388ec79",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 5b90f226256b2853e38ffab6f3b1cb651b9f90b2",
      "pattern": "[file:hashes.'SHA-1' = '5b90f226256b2853e38ffab6f3b1cb651b9f90b2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-2423 \u2014 Oracle JRE Unspecified Vulnerabili",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--83f9b660-8218-4244-a13c-1653edc89c20",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 5e0ad173659e9e2e06d89ffa3e98738a6ddecdac",
      "pattern": "[file:hashes.'SHA-1' = '5e0ad173659e9e2e06d89ffa3e98738a6ddecdac']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-2423 \u2014 Oracle JRE Unspecified Vulnerabili",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b96aac3-58a3-471b-8437-841556fc921b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 6c388af46e222a264344c67168d21569cf6e088c",
      "pattern": "[file:hashes.'SHA-1' = '6c388af46e222a264344c67168d21569cf6e088c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-2423 \u2014 Oracle JRE Unspecified Vulnerabili",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--23245579-b5ac-47cb-b0d0-58f8166c29ef",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 8619454ec435a727f52ca795c2b1316420e82c4e",
      "pattern": "[file:hashes.'SHA-1' = '8619454ec435a727f52ca795c2b1316420e82c4e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-2423 \u2014 Oracle JRE Unspecified Vulnerabili",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5637a5b6-e89f-48ea-96e5-bbc23d6a4ab3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3242561cc9bb3e131e0738078e2e44886df307035f3be0bd3defbbc631e34c80",
      "pattern": "[file:hashes.'SHA-256' = '3242561cc9bb3e131e0738078e2e44886df307035f3be0bd3defbbc631e34c80']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-0034 \u2014 Microsoft Silverlight Runtime Remo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--39c2926c-68c9-4c88-b9c3-6ac9f6f58413",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: acb74c05a1b0f97cc1a45661ea72a67a080b77f8eb9849ca440037a077461f6b",
      "pattern": "[file:hashes.'SHA-256' = 'acb74c05a1b0f97cc1a45661ea72a67a080b77f8eb9849ca440037a077461f6b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-0034 \u2014 Microsoft Silverlight Runtime Remo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc872d56-d6b9-4326-bd2a-f51e8c53ecea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e535cf04335e92587f640432d4ec3838b4605cd7e3864cfba2db94baae060415",
      "pattern": "[file:hashes.'SHA-256' = 'e535cf04335e92587f640432d4ec3838b4605cd7e3864cfba2db94baae060415']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-0034 \u2014 Microsoft Silverlight Runtime Remo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b5dd2bc9-536b-4972-bd71-ede24a72039f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-0162",
      "pattern": "[vulnerability:name = 'CVE-2016-0162']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-0162 \u2014 Microsoft Internet Explorer Inform",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-3351 \u2014 Microsoft Internet Explorer and Ed",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0ad3c38-3c52-4416-aa5e-a6a6fb339c58",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-3298",
      "pattern": "[vulnerability:name = 'CVE-2016-3298']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-3298 \u2014 Microsoft Internet Explorer Messag",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a91019f-28e8-40ef-a8bf-ab8883711515",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-3351",
      "pattern": "[vulnerability:name = 'CVE-2016-3351']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-3351 \u2014 Microsoft Internet Explorer and Ed",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-3298 \u2014 Microsoft Internet Explorer Messag",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--540e1a37-d9ee-4996-b1f4-e7987143475e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-4655",
      "pattern": "[vulnerability:name = 'CVE-2016-4655']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-4655 \u2014 Apple iOS Information Disclosure V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-4656 \u2014 Apple iOS Memory Corruption Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-4657 \u2014 Apple iOS Webkit Memory Corruption",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--62f3e9f5-b996-4e2c-b053-842b0f2dcc4e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-4656",
      "pattern": "[vulnerability:name = 'CVE-2016-4656']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-4656 \u2014 Apple iOS Memory Corruption Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-4657 \u2014 Apple iOS Webkit Memory Corruption",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--acbb9d68-6614-4bb3-8c0e-c5f50b2acb79",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-4657",
      "pattern": "[vulnerability:name = 'CVE-2016-4657']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-4656 \u2014 Apple iOS Memory Corruption Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-4657 \u2014 Apple iOS Webkit Memory Corruption",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--be98c2eb-6e6c-46e6-933e-470832d02902",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-6366",
      "pattern": "[vulnerability:name = 'CVE-2016-6366']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-6366 \u2014 Cisco Adaptive Security Appliance ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5843ae6e-45d7-444a-8d6c-b507a24d59c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-6367",
      "pattern": "[vulnerability:name = 'CVE-2016-6367']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-6367 \u2014 Cisco Adaptive Security Appliance ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4983b661-cb6e-442f-b8ad-fe42f9c6e353",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-0005",
      "pattern": "[vulnerability:name = 'CVE-2017-0005']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0005 \u2014 Microsoft Windows Graphics Device ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--081093d1-fe58-4f16-8613-e6254fc07474",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-0022",
      "pattern": "[vulnerability:name = 'CVE-2017-0022']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0022 \u2014 Microsoft XML Core Services Inform",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--301fd4ab-6374-4560-80b4-aba9a331193f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-0147",
      "pattern": "[vulnerability:name = 'CVE-2017-0147']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0147 \u2014 Microsoft Windows SMBv1 Informatio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76d9857b-d7f9-4984-8fff-e60c98659823",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-0149",
      "pattern": "[vulnerability:name = 'CVE-2017-0149']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0149 \u2014 Microsoft Internet Explorer Memory",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--89581ead-2696-48c3-87fb-4ce94d11ab3d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-0210",
      "pattern": "[vulnerability:name = 'CVE-2017-0210']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0210 \u2014 Microsoft Internet Explorer Privil",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--98238965-aac0-4c3e-a565-0babe42847d8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-18362",
      "pattern": "[vulnerability:name = 'CVE-2017-18362']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-18362 \u2014 Kaseya VSA SQL Injection Vulnerab",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e4fbe8b2-68dc-4a43-8172-a50bd7828c81",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-8291",
      "pattern": "[vulnerability:name = 'CVE-2017-8291']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-8291 \u2014 Artifex Ghostscript Type Confusion",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3e6eaf87-a130-4c60-8988-01f31d93c1ab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-8543",
      "pattern": "[vulnerability:name = 'CVE-2017-8543']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-8543 \u2014 Microsoft Windows Search Remote Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0fe37854-a7ed-4cf2-b2ac-44089945f5a1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-19943",
      "pattern": "[vulnerability:name = 'CVE-2018-19943']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-19943 \u2014 QNAP NAS File Station Cross-Site ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dedfe7dc-07b9-46b5-aaf2-38708041189b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-19949",
      "pattern": "[vulnerability:name = 'CVE-2018-19949']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-19949 \u2014 QNAP NAS File Station Command Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e46468b0-4fa4-4add-85b9-89a7118c5f65",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-19953",
      "pattern": "[vulnerability:name = 'CVE-2018-19953']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-19953 \u2014 QNAP NAS File Station Cross-Site ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--097371ae-c001-49b1-a1a7-94dcfa3dff73",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-8611",
      "pattern": "[vulnerability:name = 'CVE-2018-8611']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-8611 \u2014 Microsoft Windows Kernel Privilege",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--facadcab-5c38-4512-8a02-254eb5859fdc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: aalaan.tv",
      "pattern": "[domain-name:value = 'aalaan.tv']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-4657 \u2014 Apple iOS Webkit Memory Corruption",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4cf2f494-1494-4da2-b57a-4e153e29dccc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: apis.crosif.fr",
      "pattern": "[domain-name:value = 'apis.crosif.fr']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-3298 \u2014 Microsoft Internet Explorer Messag",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e61bcfd3-9608-4b6c-9deb-1d5e58d3d958",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: denwey.site",
      "pattern": "[domain-name:value = 'denwey.site']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-3298 \u2014 Microsoft Internet Explorer Messag",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c546dd8-3fad-4b3b-b9f6-38349ff06668",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: forete.site",
      "pattern": "[domain-name:value = 'forete.site']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-3298 \u2014 Microsoft Internet Explorer Messag",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--619cbc28-9bd7-4b11-9114-8227adf02e5c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: jpitohuiny.chinchillawalk.site",
      "pattern": "[domain-name:value = 'jpitohuiny.chinchillawalk.site']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-3298 \u2014 Microsoft Internet Explorer Messag",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d951ab30-f997-4d09-b0fe-2871e84027f6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: manoraonline.net",
      "pattern": "[domain-name:value = 'manoraonline.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-4657 \u2014 Apple iOS Webkit Memory Corruption",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--008de005-9c82-47a4-9014-b3ac8b160202",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: nbbrnofl.hotemichael.site",
      "pattern": "[domain-name:value = 'nbbrnofl.hotemichael.site']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-3298 \u2014 Microsoft Internet Explorer Messag",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0d02a413-572c-4429-a8e7-0cb670acb40b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: pkgio.com",
      "pattern": "[domain-name:value = 'pkgio.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk finds 200+ malicious npm packages, including Cobalt Str",
          "url": "https://snyk.io/blog/snyk-200-malicious-npm-packages-cobalt-strike-dependency-confusion-attacks/"
        },
        {
          "source_name": "Targeted npm dependency confusion attack caught red-handed",
          "url": "https://snyk.io/blog/npm-dependency-confusion-attack-gxm-reference/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--51172b2e-117a-42c7-8986-637f7e632a25",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sms.webadv.co",
      "pattern": "[domain-name:value = 'sms.webadv.co']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-4657 \u2014 Apple iOS Webkit Memory Corruption",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--74dcb685-9d3b-473d-874a-c93d5a11fd2f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: www.pkgio.com",
      "pattern": "[domain-name:value = 'www.pkgio.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk finds 200+ malicious npm packages, including Cobalt Str",
          "url": "https://snyk.io/blog/snyk-200-malicious-npm-packages-cobalt-strike-dependency-confusion-attacks/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8075f112-8146-4b1f-adec-a81b198c3ddb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 162.209.103.68",
      "pattern": "[ipv4-addr:value = '162.209.103.68']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-4657 \u2014 Apple iOS Webkit Memory Corruption",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1428db38-40b6-4e86-8b5c-fcd34784d2e4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.76.145.77",
      "pattern": "[ipv4-addr:value = '45.76.145.77']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-3298 \u2014 Microsoft Internet Explorer Messag",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--43e72099-8d6a-4611-bff8-79207d9d54ae",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.135.68.242",
      "pattern": "[ipv4-addr:value = '5.135.68.242']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-3298 \u2014 Microsoft Internet Explorer Messag",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0a1d2fe7-1fec-47e5-93b6-794141bab4a7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 51.255.146.122",
      "pattern": "[ipv4-addr:value = '51.255.146.122']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-3298 \u2014 Microsoft Internet Explorer Messag",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b87c59f7-7ff1-4e40-abab-956aa121247e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 52.8.153.44",
      "pattern": "[ipv4-addr:value = '52.8.153.44']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-4657 \u2014 Apple iOS Webkit Memory Corruption",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cc61e566-0bf1-4cd7-9e58-78838e016064",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 52.8.52.166",
      "pattern": "[ipv4-addr:value = '52.8.52.166']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-4657 \u2014 Apple iOS Webkit Memory Corruption",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--05dec595-7065-4dfa-a41e-265bed5bbb37",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 94.23.212.89",
      "pattern": "[ipv4-addr:value = '94.23.212.89']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-3298 \u2014 Microsoft Internet Explorer Messag",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e6fb2a0f-ccdb-412c-a0ee-50bf41916653",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 634a80e37e4b32706ad1ea4a2ff414473618a8c42a369880db7cc127c0eb705e",
      "pattern": "[file:hashes.'SHA-256' = '634a80e37e4b32706ad1ea4a2ff414473618a8c42a369880db7cc127c0eb705e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0005 \u2014 Microsoft Windows Graphics Device ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2ad0d702-0613-4a12-bdd9-f1d9c2b22184",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ae512f13136774b4aab79ebcc378927143be77181e3b256e6f9940ce73696de4",
      "pattern": "[file:hashes.'SHA-256' = 'ae512f13136774b4aab79ebcc378927143be77181e3b256e6f9940ce73696de4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0005 \u2014 Microsoft Windows Graphics Device ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--10c606db-6bba-4ca1-8f0e-3ebfdb49f79c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-5002",
      "pattern": "[vulnerability:name = 'CVE-2018-5002']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-5002 \u2014 Adobe Flash Player Stack-based Buf",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--36251da0-f5c2-459b-8579-a19034f1be86",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-8589",
      "pattern": "[vulnerability:name = 'CVE-2018-8589']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-8589 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--44edec19-63ed-4e2e-9a3a-a3ef4f76bb84",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-0676",
      "pattern": "[vulnerability:name = 'CVE-2019-0676']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-0676 \u2014 Microsoft Internet Explorer Inform",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--30380203-74ae-443a-8608-3880d72e593b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-0703",
      "pattern": "[vulnerability:name = 'CVE-2019-0703']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-0703 \u2014 Microsoft Windows SMB Information ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1958dca5-2aaf-4c1a-aaba-246244ba5581",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-0808",
      "pattern": "[vulnerability:name = 'CVE-2019-0808']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-5786 \u2014 Google Chrome Blink Use-After-Free",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-0808 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--79675d95-619d-4bfb-a849-6eed2e8e8b82",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-0880",
      "pattern": "[vulnerability:name = 'CVE-2019-0880']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-0880 \u2014 Microsoft Windows Privilege Escala",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e86266c9-f8c0-4973-8b88-13e4dd6fdaf9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-1130",
      "pattern": "[vulnerability:name = 'CVE-2019-1130']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1130 \u2014 Microsoft Windows AppX Deployment ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0c759583-db32-4129-b4f7-ae95d4e854ac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-11707",
      "pattern": "[vulnerability:name = 'CVE-2019-11707']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11707 \u2014 Mozilla Firefox and Thunderbird T",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-11708 \u2014 Mozilla Firefox and Thunderbird S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--07c936de-3e24-4bf7-a7b6-e2170804d833",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-11708",
      "pattern": "[vulnerability:name = 'CVE-2019-11708']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11707 \u2014 Mozilla Firefox and Thunderbird T",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-11708 \u2014 Mozilla Firefox and Thunderbird S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e51f4951-3b40-4810-9f24-e2d792768f96",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-13720",
      "pattern": "[vulnerability:name = 'CVE-2019-13720']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-13720 \u2014 Google Chrome WebAudio Use-After-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-1458 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d3ae32f7-2724-49cc-86cc-8021b78914f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-1385",
      "pattern": "[vulnerability:name = 'CVE-2019-1385']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1385 \u2014 Microsoft Windows AppX Deployment ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c96c9d5b-9a07-47cd-b5d1-9824bf4e2195",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-1458",
      "pattern": "[vulnerability:name = 'CVE-2019-1458']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-13720 \u2014 Google Chrome WebAudio Use-After-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-1458 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--33488b3d-9fe8-4df1-82ec-7a4cfc16709d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-18426",
      "pattern": "[vulnerability:name = 'CVE-2019-18426']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-18426 \u2014 WhatsApp Cross-Site Scripting Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--381760d8-9cf6-4ab7-8510-75540b227f5b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-5786",
      "pattern": "[vulnerability:name = 'CVE-2019-5786']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-5786 \u2014 Google Chrome Blink Use-After-Free",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--81fdf139-8c85-4ba5-b4d0-97e1df9d966e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-7286",
      "pattern": "[vulnerability:name = 'CVE-2019-7286']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-7286 \u2014 Apple Multiple Products Memory Cor",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d271e08b-7f58-48b3-a22b-bbb1e3a976c4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-7287",
      "pattern": "[vulnerability:name = 'CVE-2019-7287']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-7286 \u2014 Apple Multiple Products Memory Cor",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-7287 \u2014 Apple iOS Memory Corruption Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fbdd47ce-cc66-481d-83ba-dfb56ecbd1f1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-8720",
      "pattern": "[vulnerability:name = 'CVE-2019-8720']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-8720 \u2014 WebKitGTK Memory Corruption Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3370fa4f-7ef4-4ddf-aadc-89b55538faf8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-0638",
      "pattern": "[vulnerability:name = 'CVE-2020-0638']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-0638 \u2014 Microsoft Update Notification Mana",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6895e870-50b4-4041-95f4-177f2fbb4768",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-1027",
      "pattern": "[vulnerability:name = 'CVE-2020-1027']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-1027 \u2014 Microsoft Windows Kernel Privilege",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-0880 \u2014 Microsoft Windows Privilege Escala",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-6418 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bec71011-586d-43a2-ab3b-9a23fdd1b0d2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-0920",
      "pattern": "[vulnerability:name = 'CVE-2021-0920']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-0920 \u2014 Android Kernel Race Condition Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--07ac023e-a008-49e7-b910-6005cc19a2dd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-1048",
      "pattern": "[vulnerability:name = 'CVE-2021-1048']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-1048 \u2014 Android Kernel Use-After-Free Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4c2ae507-dda7-4c1d-b9c7-42371c51c06a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30883",
      "pattern": "[vulnerability:name = 'CVE-2021-30883']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30883 \u2014 Apple Multiple Products Memory Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3675df89-6284-44a5-8573-04f412268bdb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-20821",
      "pattern": "[vulnerability:name = 'CVE-2022-20821']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-20821 \u2014 Cisco IOS XR Open Port Vulnerabil",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--24de0fb1-d2fb-4856-b97f-24900f54e6c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: behindcorona.com",
      "pattern": "[domain-name:value = 'behindcorona.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-13720 \u2014 Google Chrome WebAudio Use-After-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4adb0f78-7a2c-470d-919f-536a1b925d89",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: code.jquery.cdn.behindcorona.com",
      "pattern": "[domain-name:value = 'code.jquery.cdn.behindcorona.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-13720 \u2014 Google Chrome WebAudio Use-After-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a37769f9-ca76-4b1a-a4f0-01549b4ee3ca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.49.69.210",
      "pattern": "[ipv4-addr:value = '185.49.69.210']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11707 \u2014 Mozilla Firefox and Thunderbird T",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3f01ad98-0d9e-481c-9f98-99a40b3cc570",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 27e941683d09a7405a9e806cc7d156c9",
      "pattern": "[file:hashes.MD5 = '27e941683d09a7405a9e806cc7d156c9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-13720 \u2014 Google Chrome WebAudio Use-After-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fd6a0c11-6460-41d8-a53a-fb054e39fb57",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 474d33349c808c86f0039d6130eb1c3e",
      "pattern": "[file:hashes.MD5 = '474d33349c808c86f0039d6130eb1c3e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11707 \u2014 Mozilla Firefox and Thunderbird T",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4272cdf7-01bc-4d2d-a5fe-09c4d5afb8a2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 8f3cd9299b2f241daf1f5057ba0b9054",
      "pattern": "[file:hashes.MD5 = '8f3cd9299b2f241daf1f5057ba0b9054']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-13720 \u2014 Google Chrome WebAudio Use-After-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--12e88b7c-9f9c-49fd-b301-483f328b930a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: bfad2737fe8ea987c1cc5f8f38031677",
      "pattern": "[file:hashes.MD5 = 'bfad2737fe8ea987c1cc5f8f38031677']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11707 \u2014 Mozilla Firefox and Thunderbird T",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0d0d0b6a-b396-4d7a-81a6-47be30a774e2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: c494e0efe766d657a55a1fd37f5d94c1",
      "pattern": "[file:hashes.MD5 = 'c494e0efe766d657a55a1fd37f5d94c1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11707 \u2014 Mozilla Firefox and Thunderbird T",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bced62c7-e793-46a7-afb1-f7be9cf6e4df",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: c8030abb9b95ba961a1c8ebcab43c862",
      "pattern": "[file:hashes.MD5 = 'c8030abb9b95ba961a1c8ebcab43c862']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11707 \u2014 Mozilla Firefox and Thunderbird T",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--50327eeb-d1eb-47a7-b753-ce8540c98ac8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e5d4af62734babc54f43d8a11f640be2",
      "pattern": "[file:hashes.MD5 = 'e5d4af62734babc54f43d8a11f640be2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11707 \u2014 Mozilla Firefox and Thunderbird T",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b7a57c5d-b258-4e22-9c64-abbdbefc86cd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: ece82aa35ebd3223504634661d07bd41",
      "pattern": "[file:hashes.MD5 = 'ece82aa35ebd3223504634661d07bd41']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11707 \u2014 Mozilla Firefox and Thunderbird T",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d535929f-b546-4009-9c51-9d45054669db",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: f614909fbd57ece81d00b01958338ec2",
      "pattern": "[file:hashes.MD5 = 'f614909fbd57ece81d00b01958338ec2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-13720 \u2014 Google Chrome WebAudio Use-After-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--88157366-0593-4cca-915c-550f57c4c58b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 23017a55b3d25a2597b7148214fd8fb2372591a5",
      "pattern": "[file:hashes.'SHA-1' = '23017a55b3d25a2597b7148214fd8fb2372591a5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11707 \u2014 Mozilla Firefox and Thunderbird T",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9b22a05d-095b-49ef-a206-8ed2eda70bd7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 35373d07c2e408838812ff210aa28d90e97e38f2d0132a86085b0d54256cc1cd",
      "pattern": "[file:hashes.'SHA-256' = '35373d07c2e408838812ff210aa28d90e97e38f2d0132a86085b0d54256cc1cd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-13720 \u2014 Google Chrome WebAudio Use-After-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--55467036-3703-4569-a740-f93b981cad5e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8fb2558765cf648305493e1dfea7a2b26f4fc8f44ff72c95e9165a904a9a6a48",
      "pattern": "[file:hashes.'SHA-256' = '8fb2558765cf648305493e1dfea7a2b26f4fc8f44ff72c95e9165a904a9a6a48']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-13720 \u2014 Google Chrome WebAudio Use-After-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fb390f4d-fc3e-4544-b0f8-72039fc9ad99",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: cafe8f704095b1f5e0a885f75b1b41a7395a1c62fd893ef44348f9702b3a0deb",
      "pattern": "[file:hashes.'SHA-256' = 'cafe8f704095b1f5e0a885f75b1b41a7395a1c62fd893ef44348f9702b3a0deb']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-13720 \u2014 Google Chrome WebAudio Use-After-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76062eed-4054-4558-8f7c-9b22fcb5fb08",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-45105",
      "pattern": "[vulnerability:name = 'CVE-2021-45105']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "How LiveRamp used Snyk to remediate Log4Shell",
          "url": "https://snyk.io/blog/liveramp-used-snyk-to-remediate-log4shell/"
        },
        {
          "source_name": "Log4j 2.16 High Severity Vulnerability (CVE-2021-45105) Disc",
          "url": "https://snyk.io/blog/log4j-2-16-vulnerability-cve-2021-45105-discovered/"
        },
        {
          "source_name": "Log4j 2.15 vulnerability CVE-2021-45046 upgraded to a critic",
          "url": "https://snyk.io/blog/log4j-2-15-vulnerability-cve-2021-45046-critical-ace/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--12278a74-7bf8-4132-b93e-a6f95f0558a9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-22947",
      "pattern": "[vulnerability:name = 'CVE-2022-22947']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22947 \u2014 VMware Spring Cloud Gateway Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--092a2b08-62e0-40f2-ad87-6d255431015e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-1388",
      "pattern": "[vulnerability:name = 'CVE-2022-1388']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-1388 \u2014 F5 BIG-IP Missing Authentication V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e3b6d2fd-2bfe-450c-91aa-25cefb6e09f5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-0160",
      "pattern": "[vulnerability:name = 'CVE-2014-0160']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-0160 \u2014 OpenSSL Information Disclosure Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e7bef8bb-91fa-4987-89ec-8a5a3ae0750f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-0322",
      "pattern": "[vulnerability:name = 'CVE-2014-0322']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-0322 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da976aa6-b73d-4991-b192-270466e943ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-4113",
      "pattern": "[vulnerability:name = 'CVE-2014-4113']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-4113 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--936a40ef-7bcc-4a03-a6e8-dc88af707bdf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-8506",
      "pattern": "[vulnerability:name = 'CVE-2019-8506']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-8506 \u2014 Apple Multiple Products Type Confu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--94c01bc3-4796-4f45-847c-5d5d07b8fc69",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-1789",
      "pattern": "[vulnerability:name = 'CVE-2021-1789']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-1789 \u2014 Apple Multiple Products Type Confu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e3910199-ca23-4548-ab8b-2a2127dafed6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-3156",
      "pattern": "[vulnerability:name = 'CVE-2021-3156']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "3\u00a0Jedi-inspired lessons to level up your JavaScript security",
          "url": "https://snyk.io/blog/jedi-lessons-to-level-up-javascript-security/"
        },
        {
          "source_name": "CISA KEV: CVE-2021-3156 \u2014 Sudo Heap-Based Buffer Overflow Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d7ece847-d7cc-43e9-b201-94e7015a9ac4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2003-1564",
      "pattern": "[vulnerability:name = 'CVE-2003-1564']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Under the C: A glance at C/C++ vulnerabilities in Python lan",
          "url": "https://snyk.io/blog/under-the-c-vulnerabilities-in-python/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3bb4be88-9a41-4d98-90a0-215dcfddcaf6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-1003029",
      "pattern": "[vulnerability:name = 'CVE-2019-1003029']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1003029 \u2014 Jenkins Script Security Plugin ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--561f828c-9731-4848-a7f7-5432a49dac72",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-40450",
      "pattern": "[vulnerability:name = 'CVE-2021-40450']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-40450 \u2014 Microsoft Win32k Privilege Escala",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2d637235-10b9-4542-8673-ffc82e28591c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-41357",
      "pattern": "[vulnerability:name = 'CVE-2021-41357']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-41357 \u2014 Microsoft Win32k Privilege Escala",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb81a13f-1790-4f32-8262-4ba413a41944",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-0847",
      "pattern": "[vulnerability:name = 'CVE-2022-0847']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0847 \u2014 Linux Kernel Privilege Escalation ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "\"Dirty Pipe\" Linux vulnerability and your containerized appl",
          "url": "https://snyk.io/blog/dirty-pipe-vulnerability-cve-2022-0847-containerized-applications/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8046e1b7-1a99-416b-a280-06519e6edc4f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-21919",
      "pattern": "[vulnerability:name = 'CVE-2022-21919']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-21919 \u2014 Microsoft Windows User Profile Se",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d1508183-9c8b-45f2-a8a7-b845937bd692",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-26904",
      "pattern": "[vulnerability:name = 'CVE-2022-26904']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26904 \u2014 Microsoft Windows User Profile Se",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ca49ec3-c2b3-45ce-b7cf-75b335d67c2d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-6882",
      "pattern": "[vulnerability:name = 'CVE-2018-6882']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-6882 \u2014 Synacor Zimbra Collaboration Suite",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2393034-b604-4679-8464-2c8eeb5f908c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-3568",
      "pattern": "[vulnerability:name = 'CVE-2019-3568']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-3568 \u2014 WhatsApp VOIP Stack Buffer Overflo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--504eb2d7-640a-4e3a-800a-38aac3fdc4f5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-23682",
      "pattern": "[vulnerability:name = 'CVE-2021-23682']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Modernizing SAST rules maintenance to catch vulnerabilities ",
          "url": "https://snyk.io/blog/modernizing-sast-rules-maintenance-catch-vulnerabilities-faster/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6c83f924-64d2-45f3-a810-5bd5e4fb6296",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-22718",
      "pattern": "[vulnerability:name = 'CVE-2022-22718']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22718 \u2014 Microsoft Windows Print Spooler P",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fafad0a9-9bdb-4f7a-9d17-0a4ff2cde5dd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-5330",
      "pattern": "[vulnerability:name = 'CVE-2010-5330']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-5330 \u2014 Ubiquiti AirOS Command Injection V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7af411f8-3cc8-4dd1-8287-7cab8ab4f151",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-0780",
      "pattern": "[vulnerability:name = 'CVE-2014-0780']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-0780 \u2014 InduSoft Web Studio NTWebServer Di",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fb3c3f31-af14-4c12-96c5-562c0ba585b1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-4523",
      "pattern": "[vulnerability:name = 'CVE-2016-4523']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-4523 \u2014 Trihedral VTScada (formerly VTS) D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--44584e8d-a6db-4ea9-912b-6f299c3b1707",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-7841",
      "pattern": "[vulnerability:name = 'CVE-2018-7841']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7841 \u2014 Schneider Electric U.motion Builde",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--16c70dbf-05db-4b0b-82b4-36b8c833d5e3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-16057",
      "pattern": "[vulnerability:name = 'CVE-2019-16057']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16057 \u2014 D-Link DNS-320 Remote Code Execut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--25d6a754-a9ee-4a30-90ec-2dc4bfb45f17",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-3929",
      "pattern": "[vulnerability:name = 'CVE-2019-3929']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-3929 \u2014 Crestron Multiple Products Command",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--69d66f1f-be0c-4b64-bfec-c98ccfe9e2af",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-1364",
      "pattern": "[vulnerability:name = 'CVE-2022-1364']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-1364 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0862ff07-13a5-4beb-9ccc-36288f23b4cc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-22954",
      "pattern": "[vulnerability:name = 'CVE-2022-22954']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22960 \u2014 VMware Multiple Products Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-22954 \u2014 VMware Workspace ONE Access and I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--55cde848-b1eb-43bb-8e77-545565f542a2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-22960",
      "pattern": "[vulnerability:name = 'CVE-2022-22960']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22960 \u2014 VMware Multiple Products Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-22954 \u2014 VMware Workspace ONE Access and I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3f919537-364d-402b-afba-e57d94578fd3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 84.38.133.149",
      "pattern": "[ipv4-addr:value = '84.38.133.149']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22960 \u2014 VMware Multiple Products Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d50cc8c4-6d15-4f76-9aea-735e33df7fff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 5b0bfda04a1e0d8dcb02556dc4e56e6a",
      "pattern": "[file:hashes.MD5 = '5b0bfda04a1e0d8dcb02556dc4e56e6a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22960 \u2014 VMware Multiple Products Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--91447cb9-2eb3-42cb-a698-2163dd27f541",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: f8ff5c72e8ffa2112b01802113148bd1",
      "pattern": "[file:hashes.MD5 = 'f8ff5c72e8ffa2112b01802113148bd1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22960 \u2014 VMware Multiple Products Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--69175b0c-3f34-4353-8e2b-142a14d5a58b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2002-0639",
      "pattern": "[vulnerability:name = 'CVE-2002-0639']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "An unintimidating introduction to the dark arts of C/C++ vul",
          "url": "https://snyk.io/blog/unintimidating-intro-to-c-cpp-vulnerabilities/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a179c8ed-6b91-4b1c-8b79-c7cf1ef2ca76",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-9365",
      "pattern": "[vulnerability:name = 'CVE-2020-9365']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "An unintimidating introduction to the dark arts of C/C++ vul",
          "url": "https://snyk.io/blog/unintimidating-intro-to-c-cpp-vulnerabilities/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f9b95a20-b77d-495d-823e-060a8e3e81c4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cnc.goodpackets.cc",
      "pattern": "[domain-name:value = 'cnc.goodpackets.cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22954 \u2014 VMware Workspace ONE Access and I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--850a4d48-9734-4960-b279-4054edbd202a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-9163",
      "pattern": "[vulnerability:name = 'CVE-2014-9163']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-9163 \u2014 Adobe Flash Player Stack-Based Buf",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e9ac46c0-ef63-4979-abdc-21720e576fdf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-0313",
      "pattern": "[vulnerability:name = 'CVE-2015-0313']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-0313 \u2014 Adobe Flash Player Use-After-Free ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b9e2954-0202-4078-a1f4-4541662e4042",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-2502",
      "pattern": "[vulnerability:name = 'CVE-2015-2502']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-2502 \u2014 Microsoft Internet Explorer Memory",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1d74d604-533c-475a-ac4d-3c0295ddbe2d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-3113",
      "pattern": "[vulnerability:name = 'CVE-2015-3113']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-3113 \u2014 Adobe Flash Player Heap-Based Buff",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d06ca622-6014-4936-90d4-2d0de70986f6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-5122",
      "pattern": "[vulnerability:name = 'CVE-2015-5122']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-5122 \u2014 Adobe Flash Player Use-After-Free ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cbb7298c-0748-4711-bb5d-cc5afe5c36b4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-5123",
      "pattern": "[vulnerability:name = 'CVE-2015-5123']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-5123 \u2014 Adobe Flash Player Use-After-Free ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2015-5122 \u2014 Adobe Flash Player Use-After-Free ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6b2afd31-1f4e-42c5-aa6b-f31ae6e8fbe4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-20753",
      "pattern": "[vulnerability:name = 'CVE-2018-20753']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-20753 \u2014 Kaseya VSA Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b47f0a3c-95be-427c-b002-2d2f5599cc3a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-7600",
      "pattern": "[vulnerability:name = 'CVE-2018-7600']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2018-7600 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8ce2a2c-eca8-4aa9-aa26-967a9214fd48",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-7602",
      "pattern": "[vulnerability:name = 'CVE-2018-7602']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--47818053-cda1-4ebf-a6ea-23a84d4675b2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-24521",
      "pattern": "[vulnerability:name = 'CVE-2022-24521']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24521 \u2014 Microsoft Windows CLFS Driver Pri",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2e3d4011-50f7-4323-9cca-0b2e32efa7f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.160.176.178",
      "pattern": "[ipv4-addr:value = '104.160.176.178']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e3dbe9b5-68ae-4c58-af72-fe9608a3c06f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 142.44.240.14",
      "pattern": "[ipv4-addr:value = '142.44.240.14']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--52941b33-8b99-478f-87f3-0ea6a585dd0e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 145.239.93.215",
      "pattern": "[ipv4-addr:value = '145.239.93.215']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--34deac98-7438-42d7-be87-face7719f1cd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 188.166.148.89",
      "pattern": "[ipv4-addr:value = '188.166.148.89']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eabc2458-d0bf-4a2c-bfa1-14c21c710e91",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.241.247.212",
      "pattern": "[ipv4-addr:value = '192.241.247.212']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d66859d9-ad69-4392-a5e2-c163e9f8dee7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 195.22.126.16",
      "pattern": "[ipv4-addr:value = '195.22.126.16']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7fedd321-df0f-466f-a63a-98e398531b4b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 195.22.127.225",
      "pattern": "[ipv4-addr:value = '195.22.127.225']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a1096487-4aaa-44e0-bde3-6de2fec3e668",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 198.50.179.109",
      "pattern": "[ipv4-addr:value = '198.50.179.109']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--106402c1-8bf4-461d-9986-6786b729e1b2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 217.182.231.56",
      "pattern": "[ipv4-addr:value = '217.182.231.56']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f00f4915-83a3-4a8e-bcff-61258e48585e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 93.174.93.149",
      "pattern": "[ipv4-addr:value = '93.174.93.149']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2aaccdd-e5e7-4828-8fa0-03b2b83656ba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 94.41.167.11",
      "pattern": "[ipv4-addr:value = '94.41.167.11']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--542e9a91-8a8a-4a28-992b-7b2ae370225b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 046a9c9838269fc5f76890b141bb39d22e6b9456",
      "pattern": "[file:hashes.'SHA-1' = '046a9c9838269fc5f76890b141bb39d22e6b9456']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6c58156a-ffc7-4a11-a918-e6fa3158c121",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 0f4a3e0c6523fe0a0677f91182a1eabc536ff480",
      "pattern": "[file:hashes.'SHA-1' = '0f4a3e0c6523fe0a0677f91182a1eabc536ff480']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--90b7350f-ec17-4207-8aae-2e6fd76fa468",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 68efd61193fc9b70394abb2327de2bf6b1f368b7",
      "pattern": "[file:hashes.'SHA-1' = '68efd61193fc9b70394abb2327de2bf6b1f368b7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--543e65f7-ea6a-4278-8564-8b1d54b6df62",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 7602c5cbc63e1bf2e484db63c94d5a22b7e17304",
      "pattern": "[file:hashes.'SHA-1' = '7602c5cbc63e1bf2e484db63c94d5a22b7e17304']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9118ce8c-969d-42b2-8d48-928120627e56",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 8360f0d2df9008240f1d5e0f8acdbd2c98bad58c",
      "pattern": "[file:hashes.'SHA-1' = '8360f0d2df9008240f1d5e0f8acdbd2c98bad58c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fa50c292-d55d-40c1-b714-c9eeb8c4d113",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 8822037953274ddd9f78b49ee73185be20e5e3ef",
      "pattern": "[file:hashes.'SHA-1' = '8822037953274ddd9f78b49ee73185be20e5e3ef']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--540048e3-1191-4ccd-91ed-aa1398f1ce1e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 94c2ea3cf1cdb034df2e9aa5779fa0472396bff7",
      "pattern": "[file:hashes.'SHA-1' = '94c2ea3cf1cdb034df2e9aa5779fa0472396bff7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--82388ff0-2045-445a-a342-04508173c245",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: c84dc265859d58827369eb25b752b6305b8306e7",
      "pattern": "[file:hashes.'SHA-1' = 'c84dc265859d58827369eb25b752b6305b8306e7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c22cfb1-c786-4142-9fda-6c02b1f2be3a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: cb00248b8bcd91e68c08a061a91cc3317db5724b",
      "pattern": "[file:hashes.'SHA-1' = 'cb00248b8bcd91e68c08a061a91cc3317db5724b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bf275f0a-ddbf-4cc9-a12e-1d5f57ba6029",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: d7eb30269b3ba40ef59c0acef8948898fa54895f",
      "pattern": "[file:hashes.'SHA-1' = 'd7eb30269b3ba40ef59c0acef8948898fa54895f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6cd97d95-5645-46cd-8b27-231b0beba1dc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: e6f914790b3888a46dff60f51a98c7191208685a",
      "pattern": "[file:hashes.'SHA-1' = 'e6f914790b3888a46dff60f51a98c7191208685a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ebef76a2-65ed-459e-af76-b2f09d9d35f4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: e9e09b90cfdc1cd2ddb867385afa60816a7ee7d5",
      "pattern": "[file:hashes.'SHA-1' = 'e9e09b90cfdc1cd2ddb867385afa60816a7ee7d5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--078ff44c-fd06-4269-8cac-e0dd9214f463",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: f92f1b03bcc45b692716789387d837905c8d4d76",
      "pattern": "[file:hashes.'SHA-1' = 'f92f1b03bcc45b692716789387d837905c8d4d76']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ccfc7c29-5f30-4dfd-a708-b84c8edab976",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: fcdd9c19b6b134dc31b3b688002eb51cac76a3ff",
      "pattern": "[file:hashes.'SHA-1' = 'fcdd9c19b6b134dc31b3b688002eb51cac76a3ff']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e8a83002-8bec-461e-8e39-f732eb1fd11f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-2509",
      "pattern": "[vulnerability:name = 'CVE-2020-2509']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-2509 \u2014 QNAP Network-Attached Storage (NAS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c32b6db-9778-4b4a-9539-e9237de36654",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-22600",
      "pattern": "[vulnerability:name = 'CVE-2021-22600']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-22600 \u2014 Linux Kernel Privilege Escalation",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b36332c3-5388-4032-9404-896b5fc51b11",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-27852",
      "pattern": "[vulnerability:name = 'CVE-2021-27852']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27852 \u2014 Checkbox Survey Deserialization o",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9397de91-58a7-4ceb-9ce9-9c1ac7f16f34",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-39793",
      "pattern": "[vulnerability:name = 'CVE-2021-39793']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-39793 \u2014 Google Pixel Out-of-Bounds Write ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ee04345a-66ee-4d1c-b40d-dbbd236ee60d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-42278",
      "pattern": "[vulnerability:name = 'CVE-2021-42278']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-42287 \u2014 Microsoft Active Directory Domain",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-42278 \u2014 Microsoft Active Directory Domain",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a991fd41-bd21-418b-8c50-99784dadda25",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-42287",
      "pattern": "[vulnerability:name = 'CVE-2021-42287']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-42287 \u2014 Microsoft Active Directory Domain",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-42278 \u2014 Microsoft Active Directory Domain",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b2d9fa95-ce02-467b-bb06-909dc633bc0f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-23176",
      "pattern": "[vulnerability:name = 'CVE-2022-23176']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-23176 \u2014 WatchGuard Firebox and XTM Privil",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--35f294ba-8a2b-4862-9d8c-d85dfc9064c4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.225.129.102",
      "pattern": "[ipv4-addr:value = '104.225.129.102']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--923ec1de-8be3-460a-8d5f-096f4a25c7cc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 137.184.130.162",
      "pattern": "[ipv4-addr:value = '137.184.130.162']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--225f62b2-675c-40cd-8332-e4ebab3877a1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 144.96.103.245",
      "pattern": "[ipv4-addr:value = '144.96.103.245']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--03495266-6ef5-4d47-b8a8-868c011169b4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 149.28.85.24",
      "pattern": "[ipv4-addr:value = '149.28.85.24']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--918ffc19-bdc1-42fb-b599-1f9d5136bc4e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 184.168.104.171",
      "pattern": "[ipv4-addr:value = '184.168.104.171']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff3e240f-d6ab-40f8-be30-aec3cced9d68",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.186.245.72",
      "pattern": "[ipv4-addr:value = '185.186.245.72']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0bad6e45-e07b-4d16-9fc2-e8b42197679d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.8.172.113",
      "pattern": "[ipv4-addr:value = '193.8.172.113']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7187afc8-4536-4b12-9c71-775f8c98593d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.8.172.13",
      "pattern": "[ipv4-addr:value = '193.8.172.13']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--504fb9f5-de25-4373-87b8-fb08954f1466",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 216.120.201.12",
      "pattern": "[ipv4-addr:value = '216.120.201.12']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6be1f5f-343a-4e6e-b6f8-eddfc3d18309",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.77.212.12",
      "pattern": "[ipv4-addr:value = '45.77.212.12']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fbc719aa-9143-4020-b704-dddb44d181c7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.34.178.246",
      "pattern": "[ipv4-addr:value = '5.34.178.246']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--20f773f2-697a-484b-90fb-1012b5d4d86b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 79.133.124.242",
      "pattern": "[ipv4-addr:value = '79.133.124.242']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c0d450d5-b78e-47ce-8b08-cd41c1fa4030",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 92.38.169.193",
      "pattern": "[ipv4-addr:value = '92.38.169.193']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--869f25b4-4bb8-48dc-8df6-096c8c1b4507",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 92.38.176.109",
      "pattern": "[ipv4-addr:value = '92.38.176.109']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8caa53ec-e26e-4661-a93c-1e5287cc1c0c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 92.38.176.130",
      "pattern": "[ipv4-addr:value = '92.38.176.130']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--55c34e3f-521f-4408-b755-0e952e7e8bc3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 37e173b932596af62fefc4dc10c8551d",
      "pattern": "[file:hashes.MD5 = '37e173b932596af62fefc4dc10c8551d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc9b77ad-a814-4e00-85b2-a4a41ef0d420",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 815d262d38a26d5695606d03d5a1a49b9c00915ead1d8a2c04eb47846100e93f",
      "pattern": "[file:hashes.'SHA-256' = '815d262d38a26d5695606d03d5a1a49b9c00915ead1d8a2c04eb47846100e93f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--85822647-e8bd-41c2-a971-e1e3bb4596bb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-1622",
      "pattern": "[vulnerability:name = 'CVE-2010-1622']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Spring4Shell extends to Glassfish and Payara: same vulnerabi",
          "url": "https://snyk.io/blog/spring4shell-rce-vulnerability-glassfish-payara/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e6fb39bf-7899-46e1-9ef2-cc5b7abb9383",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-1914",
      "pattern": "[vulnerability:name = 'CVE-2020-1914']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Getting started with React Native security",
          "url": "https://snyk.io/blog/getting-started-react-native-security/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--06b73abf-eb36-43ea-be42-bf28c46c2896",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-0148",
      "pattern": "[vulnerability:name = 'CVE-2017-0148']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0148 \u2014 Microsoft SMBv1 Server Remote Code",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--89da4123-5285-403a-9bc2-5d19e45d1e48",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-31166",
      "pattern": "[vulnerability:name = 'CVE-2021-31166']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31166 \u2014 Microsoft HTTP Protocol Stack Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--25d9f3da-7fe0-4327-acc8-76e21cb24c0e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-5674",
      "pattern": "[vulnerability:name = 'CVE-2016-5674']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-45382 \u2014 D-Link Multiple Routers Remote Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2ded78d1-e42b-498a-baf1-f1a6d1f5d213",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-23514",
      "pattern": "[vulnerability:name = 'CVE-2021-23514']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Exploring 3 types of directory traversal vulnerabilities in ",
          "url": "https://snyk.io/blog/exploring-3-types-of-directory-traversal-vulnerabilities-in-c-c/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--df2e6399-4fb5-4d95-9daf-e1f45116c5b6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-23520",
      "pattern": "[vulnerability:name = 'CVE-2021-23520']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Exploring 3 types of directory traversal vulnerabilities in ",
          "url": "https://snyk.io/blog/exploring-3-types-of-directory-traversal-vulnerabilities-in-c-c/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d1a2595a-2995-404b-a79c-b66732a53bb6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-23521",
      "pattern": "[vulnerability:name = 'CVE-2021-23521']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Exploring 3 types of directory traversal vulnerabilities in ",
          "url": "https://snyk.io/blog/exploring-3-types-of-directory-traversal-vulnerabilities-in-c-c/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b82562ca-a48c-4e88-9ac8-17388a39fe21",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-4045",
      "pattern": "[vulnerability:name = 'CVE-2021-4045']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-45382 \u2014 D-Link Multiple Routers Remote Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--96d1755d-d73a-4221-ac1c-7456b80dee22",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-45382",
      "pattern": "[vulnerability:name = 'CVE-2021-45382']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-45382 \u2014 D-Link Multiple Routers Remote Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dafce721-5e27-4856-b89c-b2db243394eb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-22674",
      "pattern": "[vulnerability:name = 'CVE-2022-22674']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22674 \u2014 Apple macOS Out-of-Bounds Read Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b012800c-1ff2-4fb5-b5cd-72d25ef6b8b1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-22675",
      "pattern": "[vulnerability:name = 'CVE-2022-22675']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22675 \u2014 Apple macOS Out-of-Bounds Write V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--03fa912a-4131-4276-9c05-75a822ca32eb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-25299",
      "pattern": "[vulnerability:name = 'CVE-2022-25299']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Exploring 3 types of directory traversal vulnerabilities in ",
          "url": "https://snyk.io/blog/exploring-3-types-of-directory-traversal-vulnerabilities-in-c-c/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--64ae5484-da51-4065-8b20-cbfdcef96c39",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: test6.ggdd.co.uk",
      "pattern": "[domain-name:value = 'test6.ggdd.co.uk']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22965 \u2014 Spring Framework JDK 9+ Remote Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "Spring4Shell: What we know about the Java RCE vulnerability",
          "url": "https://snyk.io/blog/is-there-such-a-thing-as-spring4shell/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e4ec6f47-f6b0-45c9-bf7a-11f2a11871ee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 107.174.133.167",
      "pattern": "[ipv4-addr:value = '107.174.133.167']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22965 \u2014 Spring Framework JDK 9+ Remote Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "Spring4Shell: What we know about the Java RCE vulnerability",
          "url": "https://snyk.io/blog/is-there-such-a-thing-as-spring4shell/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6b1e9b40-5f24-40e3-86c9-2904008369d5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.31.98.186",
      "pattern": "[ipv4-addr:value = '194.31.98.186']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22965 \u2014 Spring Framework JDK 9+ Remote Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "Spring4Shell: What we know about the Java RCE vulnerability",
          "url": "https://snyk.io/blog/is-there-such-a-thing-as-spring4shell/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8a466ced-2b63-4210-b51c-5f86775001cf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-21551",
      "pattern": "[vulnerability:name = 'CVE-2021-21551']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21551 \u2014 Dell dbutil Driver Insufficient A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe7a1315-bcf0-48f1-9fc8-826cde600926",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-28799",
      "pattern": "[vulnerability:name = 'CVE-2021-28799']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-28799 \u2014 QNAP NAS Improper Authorization V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76c31bb5-6848-46ee-b3a9-bcf8868f55d8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-34484",
      "pattern": "[vulnerability:name = 'CVE-2021-34484']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34484 \u2014 Microsoft Windows User Profile Se",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d93b821a-17c3-484c-b13c-df15d3fae6f6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-1040",
      "pattern": "[vulnerability:name = 'CVE-2022-1040']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-1040 \u2014 Sophos Firewall Authentication Byp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5efc22a5-e62d-40f2-bebe-c8d18e173af8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-26871",
      "pattern": "[vulnerability:name = 'CVE-2022-26871']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26871 \u2014 Trend Micro Apex Central Arbitrar",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--304d6c6b-1091-4b87-ae27-fc1a6f1ce517",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 109.74.204.123",
      "pattern": "[ipv4-addr:value = '109.74.204.123']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Spring4Shell: What we know about the Java RCE vulnerability",
          "url": "https://snyk.io/blog/is-there-such-a-thing-as-spring4shell/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--40a02afd-62e7-4612-b471-431b5d8edbef",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 118.70.80.143",
      "pattern": "[ipv4-addr:value = '118.70.80.143']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Inject",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f734021-4a15-4aac-8a04-369137a290f2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 149.28.96.126",
      "pattern": "[ipv4-addr:value = '149.28.96.126']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Inject",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4e56db06-a6fe-4292-83bf-afa28d91b050",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.104.159.48",
      "pattern": "[ipv4-addr:value = '172.104.159.48']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Spring4Shell: What we know about the Java RCE vulnerability",
          "url": "https://snyk.io/blog/is-there-such-a-thing-as-spring4shell/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--880c5ff6-f8e4-404d-8697-2161dc397312",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 178.79.148.229",
      "pattern": "[ipv4-addr:value = '178.79.148.229']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Spring4Shell: What we know about the Java RCE vulnerability",
          "url": "https://snyk.io/blog/is-there-such-a-thing-as-spring4shell/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--074e4911-ff39-409d-a902-701e395bdc8a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.246.152.173",
      "pattern": "[ipv4-addr:value = '185.246.152.173']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Inject",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e5f2414f-6f91-4ea1-8dd6-c5b0a3449011",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 210.245.26.180",
      "pattern": "[ipv4-addr:value = '210.245.26.180']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Inject",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a276837c-5e8b-43f7-93cd-35106033a601",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 46.243.189.102",
      "pattern": "[ipv4-addr:value = '46.243.189.102']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Inject",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b75128c-1993-49d7-b518-e63f1c148ff1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 46.243.189.60",
      "pattern": "[ipv4-addr:value = '46.243.189.60']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Inject",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--22ba3e10-67f0-4aeb-a249-9ec6db3a250f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 5.253.204.37",
      "pattern": "[ipv4-addr:value = '5.253.204.37']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Spring4Shell: What we know about the Java RCE vulnerability",
          "url": "https://snyk.io/blog/is-there-such-a-thing-as-spring4shell/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6c705fbb-8c86-491c-a262-a6b930c01f3d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 51.15.106.135",
      "pattern": "[ipv4-addr:value = '51.15.106.135']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Inject",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b86058d-d9fb-4762-9567-5986d9bbd295",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 82.165.137.177",
      "pattern": "[ipv4-addr:value = '82.165.137.177']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Spring4Shell: What we know about the Java RCE vulnerability",
          "url": "https://snyk.io/blog/is-there-such-a-thing-as-spring4shell/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c233fe13-ed45-4226-90b5-2541915ff887",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 084bd27e151fef55b5d80025c3114d35",
      "pattern": "[file:hashes.MD5 = '084bd27e151fef55b5d80025c3114d35']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21551 \u2014 Dell dbutil Driver Insufficient A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de647036-9970-4c7d-8c39-4c88e6328a7c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 8cca32fb1fe4826007b087b4aee20941",
      "pattern": "[file:hashes.MD5 = '8cca32fb1fe4826007b087b4aee20941']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Inject",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c025f784-0f68-44f2-a80b-9c4b10e0b8ce",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 8e2c6a92a024f8b8bb3c086b86fa50f9",
      "pattern": "[file:hashes.MD5 = '8e2c6a92a024f8b8bb3c086b86fa50f9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Inject",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c97b6704-2f09-43cf-a9ca-97f7cc5d56fd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: c6dc9f7cf09a267fefe53c5c481e7ea0",
      "pattern": "[file:hashes.MD5 = 'c6dc9f7cf09a267fefe53c5c481e7ea0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Inject",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b54bc1a7-2bab-42b0-918e-f473fa653f55",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: c996d7971c49252c582171d9380360f2",
      "pattern": "[file:hashes.MD5 = 'c996d7971c49252c582171d9380360f2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21551 \u2014 Dell dbutil Driver Insufficient A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b5e7e690-ac03-48d3-afc4-03112d8e2875",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: d2fd132ab7bbc6bbb87a84f026fa0244",
      "pattern": "[file:hashes.MD5 = 'd2fd132ab7bbc6bbb87a84f026fa0244']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21551 \u2014 Dell dbutil Driver Insufficient A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--baa53536-cc97-4a79-bf20-fbaf2cea2ee0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: e06e1e7993ea310ce0fba9dd76cdf377",
      "pattern": "[file:hashes.MD5 = 'e06e1e7993ea310ce0fba9dd76cdf377']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Inject",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--03bf3696-f6aa-42b2-a4ec-ac1762545eb5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: ed1306e24196533553571d5433312a2d",
      "pattern": "[file:hashes.MD5 = 'ed1306e24196533553571d5433312a2d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Inject",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d9f2a85f-e315-4ac5-a368-dc19698f290d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 10b30bdee43b3a2ec4aa63375577ade650269d25",
      "pattern": "[file:hashes.'SHA-1' = '10b30bdee43b3a2ec4aa63375577ade650269d25']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21551 \u2014 Dell dbutil Driver Insufficient A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--17162019-5b4f-48e2-bd51-f0b8a1a34f6a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: c6920171fa6dff2c17eb83befb5fd28e8dddf5f0",
      "pattern": "[file:hashes.'SHA-1' = 'c6920171fa6dff2c17eb83befb5fd28e8dddf5f0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21551 \u2014 Dell dbutil Driver Insufficient A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6b678c08-86c4-4077-9489-4aaab141f89e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: c948ae14761095e4d76b55d9de86412258be7afd",
      "pattern": "[file:hashes.'SHA-1' = 'c948ae14761095e4d76b55d9de86412258be7afd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21551 \u2014 Dell dbutil Driver Insufficient A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--674f9a49-76d9-4e71-8a2b-98cac33b556f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 0296e2ce999e67c76352613a718e11516fe1b0efc3ffdb8918fc999dd76a73a5",
      "pattern": "[file:hashes.'SHA-256' = '0296e2ce999e67c76352613a718e11516fe1b0efc3ffdb8918fc999dd76a73a5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21551 \u2014 Dell dbutil Driver Insufficient A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b34801fa-09a6-46a1-9639-470d338f9bd0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 87e38e7aeaaaa96efe1a74f59fca8371de93544b7af22862eb0e574cec49c7c3",
      "pattern": "[file:hashes.'SHA-256' = '87e38e7aeaaaa96efe1a74f59fca8371de93544b7af22862eb0e574cec49c7c3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21551 \u2014 Dell dbutil Driver Insufficient A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--11124fca-945d-45f0-993b-8f3a3778b143",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ddbf5ecca5c8086afde1fb4f551e9e6400e94f4428fe7fb5559da5cffa654cc1",
      "pattern": "[file:hashes.'SHA-256' = 'ddbf5ecca5c8086afde1fb4f551e9e6400e94f4428fe7fb5559da5cffa654cc1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21551 \u2014 Dell dbutil Driver Insufficient A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6554a59c-6f16-4f91-9190-6d62c7380734",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-2570",
      "pattern": "[vulnerability:name = 'CVE-2014-2570']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Using the Snyk Vulnerability Database to find projects for T",
          "url": "https://snyk.io/blog/the-big-fix-snyk-vulnerability-database/"
        },
        {
          "source_name": "Using the Snyk Vulnerability database to identify projects f",
          "url": "https://snyk.io/blog/using-the-snyk-vulnerability-database-to-identify-projects-for-the-big-fix/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cf453307-96b7-4a6d-aa63-dffd2316851f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-4398",
      "pattern": "[vulnerability:name = 'CVE-2010-4398']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-4398 \u2014 Microsoft Windows Kernel Stack-Bas",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fef0bd02-ed84-4b20-9fb2-a1d7ee90b0e5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2011-2005",
      "pattern": "[vulnerability:name = 'CVE-2011-2005']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-2005 \u2014 Microsoft Ancillary Function Drive",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--69c85192-af70-401d-a90f-f65ff1d22cc5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-0518",
      "pattern": "[vulnerability:name = 'CVE-2012-0518']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-0518 \u2014 Oracle Fusion Middleware Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4822ee89-7d58-4d32-affd-647c78ac5f8a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-2034",
      "pattern": "[vulnerability:name = 'CVE-2012-2034']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-2034 \u2014 Adobe Flash Player Memory Corrupti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--16f9a202-6c2b-4970-b55e-665280714766",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-2539",
      "pattern": "[vulnerability:name = 'CVE-2012-2539']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-2539 \u2014 Microsoft Word Remote Code Executi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3ae56e6c-1956-4851-8fee-46e8eb7b520d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-5076",
      "pattern": "[vulnerability:name = 'CVE-2012-5076']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-5076 \u2014 Oracle Java SE Sandbox Bypass Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0b928dc-e12f-4e26-a0c9-b5a75f11b0c1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-1690",
      "pattern": "[vulnerability:name = 'CVE-2013-1690']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-1690 \u2014 Mozilla Firefox and Thunderbird De",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6b57a0f3-9f83-4c97-8f1e-34a24a4c63a4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-2465",
      "pattern": "[vulnerability:name = 'CVE-2013-2465']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-2465 \u2014 Oracle Java SE Unspecified Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d1a25d28-2d74-41b7-b5bd-724bf58f229e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-2551",
      "pattern": "[vulnerability:name = 'CVE-2013-2551']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-2551 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87aa5f7b-d2f8-452c-bd86-8cf04957bda7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-2729",
      "pattern": "[vulnerability:name = 'CVE-2013-2729']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-2729 \u2014 Adobe Reader and Acrobat Arbitrary",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dba007eb-4e85-418b-b9d8-e546365bb9d1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-3660",
      "pattern": "[vulnerability:name = 'CVE-2013-3660']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3660 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e485f189-cadd-4f1d-944a-429549500c14",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-1770",
      "pattern": "[vulnerability:name = 'CVE-2015-1770']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-1770 \u2014 Microsoft Office Uninitialized Mem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6099799c-779f-4f43-94ca-02a339afc3b5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-2419",
      "pattern": "[vulnerability:name = 'CVE-2015-2419']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-2419 \u2014 Microsoft Internet Explorer Memory",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ac1608ac-f1e3-409b-9e2b-ed4f30bf4a4f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-2426",
      "pattern": "[vulnerability:name = 'CVE-2015-2426']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-2426 \u2014 Microsoft Windows Adobe Type Manag",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--74aa20a4-4d7e-4a78-848b-1a741cceebe6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-0040",
      "pattern": "[vulnerability:name = 'CVE-2016-0040']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-0040 \u2014 Microsoft Windows Kernel Privilege",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--289a5e67-ab80-41ae-aa26-c9b470a0bd87",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-0151",
      "pattern": "[vulnerability:name = 'CVE-2016-0151']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-0151 \u2014 Microsoft Windows CSRSS Security F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a4d44690-3bb5-4ca9-aa0e-a47b2e56924f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-7200",
      "pattern": "[vulnerability:name = 'CVE-2016-7200']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4e0f258d-112f-4971-a8d5-30620c35bd4b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-7201",
      "pattern": "[vulnerability:name = 'CVE-2016-7201']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c54aea63-5dd8-4278-afc6-1c4dea2a69c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-0037",
      "pattern": "[vulnerability:name = 'CVE-2017-0037']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0037 \u2014 Microsoft Edge and Internet Explor",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--494479b5-9edf-4081-9467-1e08930c69d4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-0059",
      "pattern": "[vulnerability:name = 'CVE-2017-0059']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0059 \u2014 Microsoft Internet Explorer Inform",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5aae2ee6-8268-4833-bbf8-5d2c78d8eb33",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-0213",
      "pattern": "[vulnerability:name = 'CVE-2017-0213']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0213 \u2014 Microsoft Windows Privilege Escala",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--92e424a4-2fd5-4d57-a085-64f0b2cc8260",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-8405",
      "pattern": "[vulnerability:name = 'CVE-2018-8405']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-8405 \u2014 Microsoft DirectX Graphics Kernel ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--99a66182-53e1-46c6-98b0-0dd5e916238f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-8406",
      "pattern": "[vulnerability:name = 'CVE-2018-8406']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-8406 \u2014 Microsoft DirectX Graphics Kernel ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1d165033-8dab-4f3d-a7fd-0153ade5ac77",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-8440",
      "pattern": "[vulnerability:name = 'CVE-2018-8440']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-8440 \u2014 Microsoft Windows Privilege Escala",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eed60d6c-8c9b-46f5-92dc-8c88e557fecc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-7483",
      "pattern": "[vulnerability:name = 'CVE-2019-7483']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-7483 \u2014 SonicWall SMA100 Directory Travers",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a1284601-0ffc-4d1f-a995-7855991978a3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-20028",
      "pattern": "[vulnerability:name = 'CVE-2021-20028']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-20028 \u2014 SonicWall Secure Remote Access (S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--64e9377c-ffa9-4d6c-9883-a6931c9ccad7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-26085",
      "pattern": "[vulnerability:name = 'CVE-2021-26085']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26085 \u2014 Atlassian Confluence Server Pre-A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--523f5559-8ada-49b4-a22b-af20498d0ae8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-34486",
      "pattern": "[vulnerability:name = 'CVE-2021-34486']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34486 \u2014 Microsoft Windows Event Tracing P",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fcc7ecb5-d3ea-41c5-bf8c-dcbacbb2ee70",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-38646",
      "pattern": "[vulnerability:name = 'CVE-2021-38646']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-38646 \u2014 Microsoft Office Access Connectiv",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7f8ec48c-a55b-48c4-983e-62f5ea201e93",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-0543",
      "pattern": "[vulnerability:name = 'CVE-2022-0543']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0543 \u2014 Debian-specific Redis Server Lua S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b64eedad-096d-4b4e-8113-5135af4bceb2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-1096",
      "pattern": "[vulnerability:name = 'CVE-2022-1096']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-1096 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--12b33251-0e86-4585-8782-63ad219cd944",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: buyyou.org",
      "pattern": "[domain-name:value = 'buyyou.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dacd56e6-966e-4aa4-8193-aa273ada8f42",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: fastfuriedts.org",
      "pattern": "[domain-name:value = 'fastfuriedts.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e613d326-7235-4a82-a530-2b0817ceb554",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: felixesedit.com",
      "pattern": "[domain-name:value = 'felixesedit.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4f72829d-63f1-4b28-bc19-75d78c315e7f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: monobrosexeld.org",
      "pattern": "[domain-name:value = 'monobrosexeld.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e36829a9-16fc-4f3b-8300-427117e291b4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: reveild.space",
      "pattern": "[domain-name:value = 'reveild.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d35e1ec-4dcb-418b-be09-097260481b31",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: reveiled.space",
      "pattern": "[domain-name:value = 'reveiled.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5dfb735b-eca0-4a7d-b40e-a19a7c620ece",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: vfwdgpx.amentionq.win",
      "pattern": "[domain-name:value = 'vfwdgpx.amentionq.win']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5ef4c3c2-c38f-458a-a61b-532b9224f21b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 106.246.224.219",
      "pattern": "[ipv4-addr:value = '106.246.224.219']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0543 \u2014 Debian-specific Redis Server Lua S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--92f20346-c2a0-45d5-a7f2-ce5a40a31b9f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 149.56.115.166",
      "pattern": "[ipv4-addr:value = '149.56.115.166']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ba8e13d8-25cf-46cc-a307-b1e39d5bdd41",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 204.44.118.228",
      "pattern": "[ipv4-addr:value = '204.44.118.228']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--169e0d38-1589-403f-bb0a-614a4ab3dc53",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.32.113.97",
      "pattern": "[ipv4-addr:value = '45.32.113.97']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--00ce0547-5bfe-4b29-98de-5497b3799ee4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 67.198.186.254",
      "pattern": "[ipv4-addr:value = '67.198.186.254']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d9e5ff74-fe93-407f-81ec-29d34ea26cb0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 1232980a2bffc5423f50dab4453b8363412acb55",
      "pattern": "[file:hashes.'SHA-1' = '1232980a2bffc5423f50dab4453b8363412acb55']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-2465 \u2014 Oracle Java SE Unspecified Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--34b5dcc7-5046-4624-a216-c0136336c5ff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 2c353782b7fe6280f73e3ff5d01b1f7ccfdfc0ee",
      "pattern": "[file:hashes.'SHA-1' = '2c353782b7fe6280f73e3ff5d01b1f7ccfdfc0ee']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-2465 \u2014 Oracle Java SE Unspecified Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5bfcbae1-58c3-4327-9601-fe74de13e2ba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 2d35aebfa9772562bd2757e7b50da9ad68227767",
      "pattern": "[file:hashes.'SHA-1' = '2d35aebfa9772562bd2757e7b50da9ad68227767']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-2465 \u2014 Oracle Java SE Unspecified Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1dda4dba-4875-4736-8c9e-d8f7eda407af",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 31cb898d1f9daa95d0e04626adae283471d7c7b8",
      "pattern": "[file:hashes.'SHA-1' = '31cb898d1f9daa95d0e04626adae283471d7c7b8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-2465 \u2014 Oracle Java SE Unspecified Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6113ec94-df48-488e-9805-63b02a10add1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 4787f4e7ba4d16cf569c41c77d55fde806f90cba",
      "pattern": "[file:hashes.'SHA-1' = '4787f4e7ba4d16cf569c41c77d55fde806f90cba']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-2465 \u2014 Oracle Java SE Unspecified Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8b8eacf1-e681-4994-b58f-0f80bc0db016",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 65ec5926aa212cf9bf65154772df8ffbe1530bea",
      "pattern": "[file:hashes.'SHA-1' = '65ec5926aa212cf9bf65154772df8ffbe1530bea']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-2465 \u2014 Oracle Java SE Unspecified Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1df97ac2-e4df-4347-846b-0388e89c7fa8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: eb45fa565a33aeb01b65eda72918f90f5fa90838",
      "pattern": "[file:hashes.'SHA-1' = 'eb45fa565a33aeb01b65eda72918f90f5fa90838']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-2465 \u2014 Oracle Java SE Unspecified Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7795603e-073a-4b1d-a241-800d7d4af3c7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6c919213b5318cdb60d67a4b4ace709dfb7e544982c0e101c8526eff067c8332",
      "pattern": "[file:hashes.'SHA-256' = '6c919213b5318cdb60d67a4b4ace709dfb7e544982c0e101c8526eff067c8332']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8b6d1ce5-eb8a-44b5-a67b-fbf8239fbe5e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b5567655caabb75af68f6ea33c7a22dbc1a6006ca427da6be0066c093f592610",
      "pattern": "[file:hashes.'SHA-256' = 'b5567655caabb75af68f6ea33c7a22dbc1a6006ca427da6be0066c093f592610']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a51da91a-783e-4f28-be98-d09427559429",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2005-2773",
      "pattern": "[vulnerability:name = 'CVE-2005-2773']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2005-2773 \u2014 HP OpenView Network Node Manager R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc3cb387-f0d8-4e2b-91d9-bbc8b46298ed",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2009-0927",
      "pattern": "[vulnerability:name = 'CVE-2009-0927']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2009-0927 \u2014 Adobe Reader and Adobe Acrobat Sta",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0d031828-5850-4271-b0ef-15da27f4ff3e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2009-1151",
      "pattern": "[vulnerability:name = 'CVE-2009-1151']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2009-1151 \u2014 phpMyAdmin Remote Code Execution V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4508bdc3-fc36-4ac1-8121-b2afcd69d43b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2009-2055",
      "pattern": "[vulnerability:name = 'CVE-2009-2055']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2009-2055 \u2014 Cisco IOS XR Border Gateway Protoc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bd7168a8-4f10-4ec9-a302-7625725a0849",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2009-3960",
      "pattern": "[vulnerability:name = 'CVE-2009-3960']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-2861 \u2014 Adobe ColdFusion Directory Travers",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2009-3960 \u2014 Adobe BlazeDS Information Disclosu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--be00139f-1ee9-4ac1-b655-af623798a8f4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-2861",
      "pattern": "[vulnerability:name = 'CVE-2010-2861']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-2861 \u2014 Adobe ColdFusion Directory Travers",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de102e19-b126-4628-910e-8e44bb608447",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-3035",
      "pattern": "[vulnerability:name = 'CVE-2010-3035']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-3035 \u2014 Cisco IOS XR Border Gateway Protoc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c2977af-5f0f-4c13-96b9-2a943deec4a7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-4344",
      "pattern": "[vulnerability:name = 'CVE-2010-4344']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-4344 \u2014 Exim Heap-Based Buffer Overflow Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dfa1c216-b735-4861-86d9-e79593181f08",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-4345",
      "pattern": "[vulnerability:name = 'CVE-2010-4345']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-4345 \u2014 Exim Privilege Escalation Vulnerab",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c4a34bb7-f1eb-4074-950b-9ea383e3dc94",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-2251",
      "pattern": "[vulnerability:name = 'CVE-2013-2251']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-2251 \u2014 Apache Struts Improper Input Valid",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ef9f1b1-88df-4a63-a11a-03d6008fe857",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-4810",
      "pattern": "[vulnerability:name = 'CVE-2013-4810']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-4810 \u2014 HP Multiple Products Remote Code E",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--13c4da2c-91f1-4c68-b536-a972dc3b1e75",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-5223",
      "pattern": "[vulnerability:name = 'CVE-2013-5223']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-5223 \u2014 D-Link DSL-2760U Gateway Cross-Sit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0844d80-22e4-41da-a63a-658231065e82",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-0130",
      "pattern": "[vulnerability:name = 'CVE-2014-0130']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-0130 \u2014 Ruby on Rails Directory Traversal ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e7403457-46b4-4b30-a53f-e812c7d2e2cd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-3120",
      "pattern": "[vulnerability:name = 'CVE-2014-3120']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-3120 \u2014 Elasticsearch Remote Code Executio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe26dd0f-cf9c-480c-8545-12186888cb53",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-6287",
      "pattern": "[vulnerability:name = 'CVE-2014-6287']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-6287 \u2014 Rejetto HTTP File Server (HFS) Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53771359-1ffa-4bb4-8fb2-d21583122a17",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-6324",
      "pattern": "[vulnerability:name = 'CVE-2014-6324']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-6324 \u2014 Microsoft Kerberos Key Distributio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--232ee063-2105-45fa-a607-7b735caec00d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-6332",
      "pattern": "[vulnerability:name = 'CVE-2014-6332']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-6332 \u2014 Microsoft Windows Object Linking &",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c6326c1-35c3-4956-afbb-028baf82d674",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-0666",
      "pattern": "[vulnerability:name = 'CVE-2015-0666']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-0666 \u2014 Cisco Prime Data Center Network Ma",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--02deb4bc-cbcc-4f82-8e2c-b697a09ef686",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-1187",
      "pattern": "[vulnerability:name = 'CVE-2015-1187']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-1187 \u2014 D-Link and TRENDnet Multiple Devic",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--94205951-982c-4961-ba8e-9318755fc98a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-1427",
      "pattern": "[vulnerability:name = 'CVE-2015-1427']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-1427 \u2014 Elasticsearch Groovy Scripting Eng",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e94c97e4-6f7a-4df5-a270-ad413b54e753",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-3035",
      "pattern": "[vulnerability:name = 'CVE-2015-3035']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-3035 \u2014 TP-Link Multiple Archer Devices Di",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--49d7bca8-c224-4a1e-8ef4-890ad6455c60",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-4068",
      "pattern": "[vulnerability:name = 'CVE-2015-4068']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-4068 \u2014 Arcserve Unified Data Protection (",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--380cee53-2fc0-46ea-85cc-baee84be6879",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-0752",
      "pattern": "[vulnerability:name = 'CVE-2016-0752']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-0752 \u2014 Ruby on Rails Directory Traversal ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd82fba7-705a-4ba8-ad9a-6d2d22c3dd4c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-10174",
      "pattern": "[vulnerability:name = 'CVE-2016-10174']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-10174 \u2014 NETGEAR WNR2000v5 Router Buffer O",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--68230c38-2dd4-4095-9fb1-9c8eb531709f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-11021",
      "pattern": "[vulnerability:name = 'CVE-2016-11021']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-11021 \u2014 D-Link DCS-930L Devices OS Comman",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7bd44adb-1b51-4b5c-952c-89b3542352fc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-1555",
      "pattern": "[vulnerability:name = 'CVE-2016-1555']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-1555 \u2014 NETGEAR Multiple WAP Devices Comma",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ec513e34-9bb7-4344-8927-063c2b2d5877",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-4171",
      "pattern": "[vulnerability:name = 'CVE-2016-4171']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-4171 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6cd24fc9-d960-44be-9c1c-b5e6b4bfb036",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-7892",
      "pattern": "[vulnerability:name = 'CVE-2016-7892']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-7892 \u2014 Adobe Flash Player Use-After-Free ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ccbed8c4-4f0a-4f9f-b3be-6c539c7a0ce4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-0146",
      "pattern": "[vulnerability:name = 'CVE-2017-0146']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0146 \u2014 Microsoft Windows SMB Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--efe10ffa-15e4-4fb6-9dc9-687c92b66946",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-12615",
      "pattern": "[vulnerability:name = 'CVE-2017-12615']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-12615 \u2014 Apache Tomcat on Windows Remote C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a83ec90-5460-4dfd-b565-f1ffeef0cafd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-12617",
      "pattern": "[vulnerability:name = 'CVE-2017-12617']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-12617 \u2014 Apache Tomcat Remote Code Executi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-12615 \u2014 Apache Tomcat on Windows Remote C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32722e3a-c7f5-4935-a4a2-08051ccca616",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-6316",
      "pattern": "[vulnerability:name = 'CVE-2017-6316']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-6316 \u2014 Citrix Multiple Products Remote Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--225d121d-af45-4233-b70c-356fea8ab487",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-6334",
      "pattern": "[vulnerability:name = 'CVE-2017-6334']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-6334 \u2014 NETGEAR DGN2200 Devices OS Command",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f98cfa74-07db-4b45-bd8c-5b0fd6e38e61",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-0125",
      "pattern": "[vulnerability:name = 'CVE-2018-0125']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0125 \u2014 Cisco VPN Routers Remote Code Exec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a16151b0-9540-4e46-a875-d99963af84ff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-0147",
      "pattern": "[vulnerability:name = 'CVE-2018-0147']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0147 \u2014 Cisco Secure Access Control System",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4d0a0269-74e8-40b7-938c-94420b291664",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-11138",
      "pattern": "[vulnerability:name = 'CVE-2018-11138']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-11138 \u2014 Quest KACE System Management Appl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe012d99-a99f-45a5-8dd1-ac25756de4f0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-1273",
      "pattern": "[vulnerability:name = 'CVE-2018-1273']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-1273 \u2014 VMware Tanzu Spring Data Commons P",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c0ed580c-464f-429e-a089-53e4ffbd576a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-14839",
      "pattern": "[vulnerability:name = 'CVE-2018-14839']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-14839 \u2014 LG N1A1 NAS Remote Command Execut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e42146e0-3269-417a-a03d-7440eef18a47",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-6961",
      "pattern": "[vulnerability:name = 'CVE-2018-6961']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-6961 \u2014 VMware SD-WAN Edge by VeloCloud Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3e3077aa-6e79-4142-87bb-5eb7fcf3e752",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-8174",
      "pattern": "[vulnerability:name = 'CVE-2018-8174']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-8373 \u2014 Microsoft Scripting Engine Memory ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2018-8174 \u2014 Microsoft Windows VBScript Engine ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--29c4f73e-e86e-4f1b-9a6d-d02e67a3b270",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-8373",
      "pattern": "[vulnerability:name = 'CVE-2018-8373']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-8373 \u2014 Microsoft Scripting Engine Memory ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4fac7ad1-a4e9-421e-90b5-c3d801343d80",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-8414",
      "pattern": "[vulnerability:name = 'CVE-2018-8414']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-8414 \u2014 Microsoft Windows Shell Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-0146 \u2014 Microsoft Windows SMB Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0e4d7a9b-618f-4846-83c5-081df67c0019",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-0903",
      "pattern": "[vulnerability:name = 'CVE-2019-0903']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-0903 \u2014 Microsoft GDI Remote Code Executio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8dcdc218-2f5d-4b97-97ec-fb0de4f5482e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-1003030",
      "pattern": "[vulnerability:name = 'CVE-2019-1003030']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1003030 \u2014 Jenkins Matrix Project Plugin R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d7f75a4-e657-4485-8e8c-40745f97fb7f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-10068",
      "pattern": "[vulnerability:name = 'CVE-2019-10068']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-10068 \u2014 Kentico Xperience Deserialization",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--74f22d2e-c938-4b08-aa00-2476ea313904",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-11043",
      "pattern": "[vulnerability:name = 'CVE-2019-11043']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11043 \u2014 PHP FastCGI Process Manager (FPM)",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4196735f-f665-4692-b54e-d8255d537105",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-12989",
      "pattern": "[vulnerability:name = 'CVE-2019-12989']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-12989 \u2014 Citrix SD-WAN and NetScaler SQL I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d4d4d4e-055a-46d7-979d-022bb192c7a6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-12991",
      "pattern": "[vulnerability:name = 'CVE-2019-12991']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-12991 \u2014 Citrix SD-WAN and NetScaler Comma",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e27c9c37-e0b3-414a-bd2e-90e935c15e37",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-15107",
      "pattern": "[vulnerability:name = 'CVE-2019-15107']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-15107 \u2014 Webmin Command Injection Vulnerab",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f884522e-f0c5-42fe-af10-20165ca2f1b9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-16920",
      "pattern": "[vulnerability:name = 'CVE-2019-16920']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16920 \u2014 D-Link Multiple Routers Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--37f4fe65-cdab-40fe-a378-4b2a64e150ef",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-2616",
      "pattern": "[vulnerability:name = 'CVE-2019-2616']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-2616 \u2014 Oracle BI Publisher Unauthorized A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1efe47a2-dfa1-4a34-9f22-d16279f49245",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-6340",
      "pattern": "[vulnerability:name = 'CVE-2019-6340']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-6340 \u2014 Drupal Core Remote Code Execution ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-0903 \u2014 Microsoft GDI Remote Code Executio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a253e91-067c-4653-8f25-8bdb20f0cc1b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-1631",
      "pattern": "[vulnerability:name = 'CVE-2020-1631']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-1631 \u2014 Juniper Junos OS Path Traversal Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7a3ab54d-d7f6-452a-b00d-6a12c1552401",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-1956",
      "pattern": "[vulnerability:name = 'CVE-2020-1956']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-1956 \u2014 Apache Kylin OS Command Injection ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9d175d4b-6c74-443c-b10c-7d57c02d1df4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-2021",
      "pattern": "[vulnerability:name = 'CVE-2020-2021']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-2021 \u2014 Palo Alto Networks PAN-OS Authenti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e2dac8bc-d52f-4e0d-9b6b-4551b69d519d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-2506",
      "pattern": "[vulnerability:name = 'CVE-2020-2506']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-2506 \u2014 QNAP Helpdesk Improper Access Cont",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eea882b7-5fa2-434b-88d8-10b774c8b6ea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-25223",
      "pattern": "[vulnerability:name = 'CVE-2020-25223']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25223 \u2014 Sophos SG UTM Remote Code Executi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67f59c93-45d1-4287-8760-3d14695180fe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-5410",
      "pattern": "[vulnerability:name = 'CVE-2020-5410']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-5410 \u2014 VMware Tanzu Spring Cloud Config D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--db283809-b2a0-440c-994c-3ef5fb167d83",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-7247",
      "pattern": "[vulnerability:name = 'CVE-2020-7247']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-7247 \u2014 OpenSMTPD Remote Code Execution Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--910ac527-3a00-4c82-ba24-8c01aab6d3c9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-9054",
      "pattern": "[vulnerability:name = 'CVE-2020-9054']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-9054 \u2014 Zyxel Multiple NAS Devices OS Comm",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--70d3240c-02ce-44ab-ad43-a4ef1a976fce",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-9377",
      "pattern": "[vulnerability:name = 'CVE-2020-9377']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-9377 \u2014 D-Link DIR-610 Devices Remote Comm",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d0ad99bd-b902-4a9d-bfc5-7fd01a089a39",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-22941",
      "pattern": "[vulnerability:name = 'CVE-2021-22941']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-22941 \u2014 Citrix ShareFile Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f28da637-984d-434d-a507-1a46f2df2356",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-42237",
      "pattern": "[vulnerability:name = 'CVE-2021-42237']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-42237 \u2014 Sitecore XP Remote Command Execut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7563dbb2-4ad4-40d5-93d1-84a26b8ded9b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-21999",
      "pattern": "[vulnerability:name = 'CVE-2022-21999']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-21999 \u2014 Microsoft Windows Print Spooler P",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--24b0a527-5ea5-45b8-9276-c4065fec5da5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-26143",
      "pattern": "[vulnerability:name = 'CVE-2022-26143']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26143 \u2014 MiCollab, MiVoice Business Expres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e0111c0c-3cd5-49b9-a6a9-ce95a046aad0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-26318",
      "pattern": "[vulnerability:name = 'CVE-2022-26318']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26318 \u2014 WatchGuard Firebox and XTM Applia",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5e59ced6-b44a-41c0-ba1b-5f70ba62581b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: windows-updater.net",
      "pattern": "[domain-name:value = 'windows-updater.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-8373 \u2014 Microsoft Scripting Engine Memory ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3700f026-df26-4b74-94e1-aebf0d52861f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 107.181.187.184",
      "pattern": "[ipv4-addr:value = '107.181.187.184']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-22941 \u2014 Citrix ShareFile Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--664cab20-6abc-4399-bda7-6d0c9eb0c2af",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 188.119.149.160",
      "pattern": "[ipv4-addr:value = '188.119.149.160']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-22941 \u2014 Citrix ShareFile Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6eaad51-a7eb-4c78-a43f-6200c92e3c67",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.61.136.39",
      "pattern": "[ipv4-addr:value = '45.61.136.39']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-22941 \u2014 Citrix ShareFile Improper Access ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--212a2359-5b45-433d-8ff9-75af18419959",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.84.196.75",
      "pattern": "[ipv4-addr:value = '45.84.196.75']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-9054 \u2014 Zyxel Multiple NAS Devices OS Comm",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1034a4e9-b868-454f-991b-c4ce210914d5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 46228151b547c905de9772211ce559592498e0c8894379f14adb1ef6c44f8933",
      "pattern": "[file:hashes.'SHA-256' = '46228151b547c905de9772211ce559592498e0c8894379f14adb1ef6c44f8933']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-9054 \u2014 Zyxel Multiple NAS Devices OS Comm",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc448ca9-7b09-48f4-ad92-0fe87e4bcbf9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5f918c2b5316c52cbb564269b116ce63935691ee6debe06ce1693ad29dbb5740",
      "pattern": "[file:hashes.'SHA-256' = '5f918c2b5316c52cbb564269b116ce63935691ee6debe06ce1693ad29dbb5740']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-9054 \u2014 Zyxel Multiple NAS Devices OS Comm",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--19a4b4ba-b0c5-41af-a259-0ec2a9e5c13e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 675f4af00520905e31ff96ecef2d4dc77166481f584da89a39a798ea18ae2144",
      "pattern": "[file:hashes.'SHA-256' = '675f4af00520905e31ff96ecef2d4dc77166481f584da89a39a798ea18ae2144']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-9054 \u2014 Zyxel Multiple NAS Devices OS Comm",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ed64a252-9176-4180-8649-03ca66308f47",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 753914aa3549e52af2627992731ca18e702f652391c161483f532173daeb0bbd",
      "pattern": "[file:hashes.'SHA-256' = '753914aa3549e52af2627992731ca18e702f652391c161483f532173daeb0bbd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-9054 \u2014 Zyxel Multiple NAS Devices OS Comm",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f7e3ef4d-ea70-4a6e-80ce-649a54374eac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8c0c4d8d727bff5e03f6b2aae125d3e3607948d9dff578b18be0add2fff3411c",
      "pattern": "[file:hashes.'SHA-256' = '8c0c4d8d727bff5e03f6b2aae125d3e3607948d9dff578b18be0add2fff3411c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-9054 \u2014 Zyxel Multiple NAS Devices OS Comm",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--149cd186-870d-47b3-89b0-47612126ab7e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8fa54788885679e4677296fca4fe4e949ca85783a057750c658543645fb8682f",
      "pattern": "[file:hashes.'SHA-256' = '8fa54788885679e4677296fca4fe4e949ca85783a057750c658543645fb8682f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-9054 \u2014 Zyxel Multiple NAS Devices OS Comm",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d14a24f-6888-409b-b08c-8cc8acd5a7d0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 90392af3fdc7af968cc6d054fc1a99c5156de5b1834d6432076c40d548283c22",
      "pattern": "[file:hashes.'SHA-256' = '90392af3fdc7af968cc6d054fc1a99c5156de5b1834d6432076c40d548283c22']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-9054 \u2014 Zyxel Multiple NAS Devices OS Comm",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5cc0fe28-fe58-48ff-9e59-3a23a138b373",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a059e47b4c76b6bbd70ca4db6b454fd9aa19e5a0487c8032fe54fa707b0f926d",
      "pattern": "[file:hashes.'SHA-256' = 'a059e47b4c76b6bbd70ca4db6b454fd9aa19e5a0487c8032fe54fa707b0f926d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-9054 \u2014 Zyxel Multiple NAS Devices OS Comm",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f18f682b-9711-40c0-9ad3-e7fd052e70d6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ce793ddec5410c5104d0ea23809a40dd222473e3d984a1e531e735aebf46c9dc",
      "pattern": "[file:hashes.'SHA-256' = 'ce793ddec5410c5104d0ea23809a40dd222473e3d984a1e531e735aebf46c9dc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-9054 \u2014 Zyxel Multiple NAS Devices OS Comm",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2d867685-4581-47be-bc1a-76abf43a5774",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: api.ipgeolocation.io",
      "pattern": "[domain-name:value = 'api.ipgeolocation.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Alert: peacenotwar module sabotages npm developers in the no",
          "url": "https://snyk.io/blog/peacenotwar-malicious-npm-node-ipc-package-vulnerability/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cdc25a56-a885-4d4a-84e5-2f953c5380ff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-2546",
      "pattern": "[vulnerability:name = 'CVE-2015-2546']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-2546 \u2014 Microsoft Win32k Memory Corruption",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fdb5b7bc-06a1-4beb-ad9c-598d87168c59",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-3309",
      "pattern": "[vulnerability:name = 'CVE-2016-3309']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-3309 \u2014 Microsoft Windows Kernel Privilege",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5faedaac-bb29-4559-918e-6b038a1d41eb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-0101",
      "pattern": "[vulnerability:name = 'CVE-2017-0101']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0101 \u2014 Microsoft Windows Transaction Mana",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--36097be8-bb2a-4b4a-a3ef-29ffa959605c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-8120",
      "pattern": "[vulnerability:name = 'CVE-2018-8120']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-8120 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--20f35678-0a41-42eb-b991-a5e9178e3ba2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-0543",
      "pattern": "[vulnerability:name = 'CVE-2019-0543']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-0543 \u2014 Microsoft Windows Privilege Escala",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6c16d554-dc32-451c-9786-6d77902b6be8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-0841",
      "pattern": "[vulnerability:name = 'CVE-2019-0841']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-0841 \u2014 Microsoft Windows AppX Deployment ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9e89f5d6-2700-40f2-b336-77f875617f82",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-1064",
      "pattern": "[vulnerability:name = 'CVE-2019-1064']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1064 \u2014 Microsoft Windows AppX Deployment ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--71c6cc07-f195-4b45-a21e-125e569ae6c9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-1069",
      "pattern": "[vulnerability:name = 'CVE-2019-1069']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1069 \u2014 Microsoft Task Scheduler Privilege",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7a2288c2-a21c-4359-b63b-51badfdaf265",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-1129",
      "pattern": "[vulnerability:name = 'CVE-2019-1129']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1129 \u2014 Microsoft Windows AppX Deployment ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f2dce8c4-5f8d-4350-99be-a39262446fba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-1132",
      "pattern": "[vulnerability:name = 'CVE-2019-1132']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1132 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76079528-c07e-44fa-b041-da1ce62b519b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-1253",
      "pattern": "[vulnerability:name = 'CVE-2019-1253']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1253 \u2014 Microsoft Windows AppX Deployment ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-1129 \u2014 Microsoft Windows AppX Deployment ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb343b0a-331d-4f33-87e7-a531bdfdbb9b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-1315",
      "pattern": "[vulnerability:name = 'CVE-2019-1315']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1315 \u2014 Microsoft Windows Error Reporting ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--71513fd1-1405-46a6-b5ee-b6df7fdee890",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-1322",
      "pattern": "[vulnerability:name = 'CVE-2019-1322']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1405 \u2014 Microsoft Windows Universal Plug a",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-1322 \u2014 Microsoft Windows Privilege Escala",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cff272cd-391c-4eda-8eda-11d14c848ce4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-1405",
      "pattern": "[vulnerability:name = 'CVE-2019-1405']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1405 \u2014 Microsoft Windows Universal Plug a",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-1322 \u2014 Microsoft Windows Privilege Escala",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--19a7307e-b94d-47fc-bb04-a81091847255",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-5135",
      "pattern": "[vulnerability:name = 'CVE-2020-5135']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-5135 \u2014 SonicWall SonicOS Buffer Overflow ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--301a6d3f-63a2-4532-ae4c-88d41ade14aa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: hdfilm-seyret.com",
      "pattern": "[domain-name:value = 'hdfilm-seyret.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1132 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff2e7190-708a-4534-8121-d86f24c4a1d8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: redmond.corp-microsoft.com",
      "pattern": "[domain-name:value = 'redmond.corp-microsoft.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1132 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8e20be27-22eb-4398-935d-e2a0bfbb76ed",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: secure-telemetry.net",
      "pattern": "[domain-name:value = 'secure-telemetry.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1132 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1b96aa8c-ebdd-4690-98be-370b4b5bcd84",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: services-glbdns2.com",
      "pattern": "[domain-name:value = 'services-glbdns2.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1132 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--26ed5f9e-8fea-4b2b-a4ad-97be6f1e976b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: win10.ipv6-microsoft.org",
      "pattern": "[domain-name:value = 'win10.ipv6-microsoft.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1132 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1166e4a0-521e-4728-ab14-b7fceafdf4cb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 2F2640720CCE2F83CA2F0633330F13651384DD6A",
      "pattern": "[file:hashes.'SHA-1' = '2F2640720CCE2F83CA2F0633330F13651384DD6A']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1132 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a9494802-dc2a-4c61-bc21-e1012cce47b9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 9C3434EBDF29E5A4762AFB610EA59714D8BE2392",
      "pattern": "[file:hashes.'SHA-1' = '9C3434EBDF29E5A4762AFB610EA59714D8BE2392']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1132 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f3be6061-9a8b-48ac-97d9-56fa8317813f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: C17C335B7DDB5C8979444EC36AB668AE8E4E0A72",
      "pattern": "[file:hashes.'SHA-1' = 'C17C335B7DDB5C8979444EC36AB668AE8E4E0A72']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1132 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eadd8371-b2b2-4748-8db8-7a338985d8c1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: E0F3557EA9F2BA4F7074CAA0D0CF3B187C4472FF",
      "pattern": "[file:hashes.'SHA-1' = 'E0F3557EA9F2BA4F7074CAA0D0CF3B187C4472FF']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1132 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--05f91e28-c13b-48ab-b8e3-5c08d4ba21e2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-3507",
      "pattern": "[vulnerability:name = 'CVE-2021-3507']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Simplifying container security with Snyk\u2019s security expertis",
          "url": "https://snyk.io/blog/simplifying-container-security-snyk-expertise/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--47a9b9a9-9769-4e74-8627-8d9c52115cfc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-0625",
      "pattern": "[vulnerability:name = 'CVE-2013-0625']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0625 \u2014 Adobe ColdFusion Authentication By",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--739479bd-1c95-4971-8601-bc5447968d75",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-0629",
      "pattern": "[vulnerability:name = 'CVE-2013-0629']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0629 \u2014 Adobe ColdFusion Directory Travers",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--04cf2e25-8d3c-4c46-9141-ba98ea815bf0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-0631",
      "pattern": "[vulnerability:name = 'CVE-2013-0631']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0631 \u2014 Adobe ColdFusion Information Discl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f48185a8-d50f-446e-abfa-503caecf1e0e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-6077",
      "pattern": "[vulnerability:name = 'CVE-2017-6077']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-6077 \u2014 NETGEAR DGN2200 Remote Code Execut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ba14aed4-34c8-4d38-8262-b0580725e3b2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-1000861",
      "pattern": "[vulnerability:name = 'CVE-2018-1000861']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Ce",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2018-1000861 \u2014 Jenkins Stapler Web Framework D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a7d580c6-a7aa-44cf-82e9-623347947560",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-0192",
      "pattern": "[vulnerability:name = 'CVE-2019-0192']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Ce",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd65d594-ef69-40b3-a04e-f848be131af2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-0708",
      "pattern": "[vulnerability:name = 'CVE-2019-0708']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Ce",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-0708 \u2014 Microsoft Remote Desktop Services ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--29fadb59-6c54-4790-a96b-88429ebef82f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-10149",
      "pattern": "[vulnerability:name = 'CVE-2019-10149']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Ce",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-10149 \u2014 Exim Mail Transfer Agent (MTA) Im",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9e9ee268-32d5-446f-b727-3b1d0ceb8b16",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-11581",
      "pattern": "[vulnerability:name = 'CVE-2019-11581']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Ce",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a16e9bb-5864-4907-9fdc-632bec351ab5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-7238",
      "pattern": "[vulnerability:name = 'CVE-2019-7238']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Ce",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-7238 \u2014 Sonatype Nexus Repository Manager ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3772143c-37ec-401b-926f-190248c0aa90",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-8218",
      "pattern": "[vulnerability:name = 'CVE-2020-8218']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-8218 \u2014 Pulse Connect Secure Code Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--abc55871-2fc9-4776-aa6f-2e9692eaa37f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-21973",
      "pattern": "[vulnerability:name = 'CVE-2021-21973']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21973 \u2014 VMware vCenter Server and Cloud F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--895fdd43-6616-48b2-b800-7be0b7355c2a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-26485",
      "pattern": "[vulnerability:name = 'CVE-2022-26485']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26485 \u2014 Mozilla Firefox Use-After-Free Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b77bbdd-1204-4dc8-a1dd-3d1e0288d992",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-26486",
      "pattern": "[vulnerability:name = 'CVE-2022-26486']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-26486 \u2014 Mozilla Firefox Use-After-Free Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2022-26485 \u2014 Mozilla Firefox Use-After-Free Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--daa2b02d-3661-45c5-812d-a905f7701f88",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: 7dc5fb4e.ngrok.io",
      "pattern": "[domain-name:value = '7dc5fb4e.ngrok.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Ce",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f637f450-67a8-44ca-b20b-1420e14d02ae",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: 9d842cb6.ngrok.io",
      "pattern": "[domain-name:value = '9d842cb6.ngrok.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Ce",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2c2fed70-d199-4432-a6a0-aa5989bebec0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: z5r6anrjbcasuikp.onion.to",
      "pattern": "[domain-name:value = 'z5r6anrjbcasuikp.onion.to']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Ce",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6f977efb-d542-4556-8104-3990099bd6c4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 18.188.14.65",
      "pattern": "[ipv4-addr:value = '18.188.14.65']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Ce",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4be0029-15b7-4f6e-b044-58feef57f79f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 3.14.202.129",
      "pattern": "[ipv4-addr:value = '3.14.202.129']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Ce",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b0a27a9-d6f5-45d1-a947-95417703b9ae",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 3.14.212.173",
      "pattern": "[ipv4-addr:value = '3.14.212.173']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Ce",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ef5f562b-3ca5-4b4b-9e6c-0f3aabda4d64",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 3.17.202.129",
      "pattern": "[ipv4-addr:value = '3.17.202.129']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Ce",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b6bc97f8-a366-4e0b-90a7-9899702b9961",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 3.19.3.150",
      "pattern": "[ipv4-addr:value = '3.19.3.150']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Ce",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--25bd82b7-5b57-43ce-b571-fac16d1603f9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: f839fc8e7f22be30d73286fd665c8c3c",
      "pattern": "[file:hashes.MD5 = 'f839fc8e7f22be30d73286fd665c8c3c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Ce",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e467229f-213d-48ef-a163-0c575839ccbd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 26ebeac4492616baf977903bb8deb7803bd5a22d8a005f02398c188b0375dfa4",
      "pattern": "[file:hashes.'SHA-256' = '26ebeac4492616baf977903bb8deb7803bd5a22d8a005f02398c188b0375dfa4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Ce",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc528611-b391-4b99-8ab7-8a97a20c59d4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b17829d758e8689143456240ebd79b420f963722707246f5dc9b085a411f7b5e",
      "pattern": "[file:hashes.'SHA-256' = 'b17829d758e8689143456240ebd79b420f963722707246f5dc9b085a411f7b5e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Ce",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--74aac48f-ea14-4cc9-bfaf-8f24b78c985c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c47d8dfa8337d21e3c3e1560ac4f6713bfd686bce2d7a4ef268fe992d8f93a52",
      "pattern": "[file:hashes.'SHA-256' = 'c47d8dfa8337d21e3c3e1560ac4f6713bfd686bce2d7a4ef268fe992d8f93a52']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Ce",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4f69e313-f996-4809-a13f-7c622fa73edb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: cdf11a1fa7e551fe6be1f170ba9dedee80401396adf7e39ccde5df635c1117a9",
      "pattern": "[file:hashes.'SHA-256' = 'cdf11a1fa7e551fe6be1f170ba9dedee80401396adf7e39ccde5df635c1117a9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Ce",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7350d3c1-2b16-4b5e-9dab-c64ae7204239",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2002-0367",
      "pattern": "[vulnerability:name = 'CVE-2002-0367']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2002-0367 \u2014 Microsoft Windows Privilege Escala",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b56af1c1-8d2f-4c0f-91d9-66c439c7f070",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2004-0210",
      "pattern": "[vulnerability:name = 'CVE-2004-0210']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2004-0210 \u2014 Microsoft Windows Privilege Escala",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2002-0367 \u2014 Microsoft Windows Privilege Escala",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f730faed-5ff6-453d-ae69-7c3c545f73ab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2008-2992",
      "pattern": "[vulnerability:name = 'CVE-2008-2992']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2008-2992 \u2014 Adobe Reader and Acrobat Input Val",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--72e2750f-5de3-48b7-abca-08637c48cf69",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2008-3431",
      "pattern": "[vulnerability:name = 'CVE-2008-3431']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2008-3431 \u2014 Oracle VirtualBox Insufficient Inp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--15f66fb1-b9db-49c4-afd8-1b321eff413b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2009-1123",
      "pattern": "[vulnerability:name = 'CVE-2009-1123']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2009-1123 \u2014 Microsoft Windows Improper Input V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f152cb28-3e6e-40c2-8080-034163558f33",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2009-3129",
      "pattern": "[vulnerability:name = 'CVE-2009-3129']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2009-3129 \u2014 Microsoft Excel Featheader Record ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b107027-9c4a-4495-aaa4-b30a54988183",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-0188",
      "pattern": "[vulnerability:name = 'CVE-2010-0188']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0188 \u2014 Adobe Reader and Acrobat Arbitrary",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--755db656-73d9-41e3-9660-06af2d2c9115",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-0232",
      "pattern": "[vulnerability:name = 'CVE-2010-0232']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-0232 \u2014 Microsoft Windows Kernel Exception",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f10bd7f9-fe3e-4947-8122-1a499baf6c7a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-3333",
      "pattern": "[vulnerability:name = 'CVE-2010-3333']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-3333 \u2014 Microsoft Office Stack-based Buffe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--88f59a71-5196-44a1-b71e-902664b2ece9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2011-1889",
      "pattern": "[vulnerability:name = 'CVE-2011-1889']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-1889 \u2014 Microsoft Forefront TMG Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6baea9d9-eb30-4c72-9093-7ee1dea0d650",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2011-3544",
      "pattern": "[vulnerability:name = 'CVE-2011-3544']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-3544 \u2014 Oracle Java SE Runtime Environment",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4e5e0e78-04e2-40db-bcca-258841618899",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-0158",
      "pattern": "[vulnerability:name = 'CVE-2012-0158']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-2590 \u2014 Oracle Java SE and Java SE Embedde",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2012-0158 \u2014 Microsoft MSCOMCTL.OCX Remote Code",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--119cbc94-e391-4214-a490-c4ce4669215e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-0507",
      "pattern": "[vulnerability:name = 'CVE-2012-0507']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-0507 \u2014 Oracle Java SE Runtime Environment",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f23e4c75-b366-40b8-b003-959b02b704c8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-1535",
      "pattern": "[vulnerability:name = 'CVE-2012-1535']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-1535 \u2014 Adobe Flash Player Arbitrary Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4b1259c4-b972-45ec-aa67-1600c5ecda30",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-1723",
      "pattern": "[vulnerability:name = 'CVE-2012-1723']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-1723 \u2014 Oracle Java SE Runtime Environment",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5707456f-03df-4a35-9830-fd02c84d4458",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-1856",
      "pattern": "[vulnerability:name = 'CVE-2012-1856']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-1856 \u2014 Microsoft Office MSCOMCTL.OCX Remo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8967c729-e9c3-4862-b819-e9d56eccd746",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-4681",
      "pattern": "[vulnerability:name = 'CVE-2012-4681']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-4681 \u2014 Oracle Java SE Runtime Environment",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2012-1723 \u2014 Oracle Java SE Runtime Environment",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2012-0507 \u2014 Oracle Java SE Runtime Environment",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--75b6df20-9aac-4f20-9e4e-a97c8aa34c25",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-0632",
      "pattern": "[vulnerability:name = 'CVE-2013-0632']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0632 \u2014 Adobe ColdFusion Authentication By",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--11dbfc81-15ae-4234-80ad-b1c17f4b2b4d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-0640",
      "pattern": "[vulnerability:name = 'CVE-2013-0640']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0640 \u2014 Adobe Reader and Acrobat Memory Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32af5026-8f6c-4faa-92af-3835f43f79d3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-0641",
      "pattern": "[vulnerability:name = 'CVE-2013-0641']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-0641 \u2014 Adobe Reader Buffer Overflow Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2013-0640 \u2014 Adobe Reader and Acrobat Memory Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7d905ad4-564d-4e11-9d2f-01f706b3a42d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-1347",
      "pattern": "[vulnerability:name = 'CVE-2013-1347']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-1347 \u2014 Microsoft Internet Explorer Remote",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c38feee0-7b14-4d50-99d9-11152ccee1f2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-1675",
      "pattern": "[vulnerability:name = 'CVE-2013-1675']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-1675 \u2014 Mozilla Firefox Information Disclo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ad8ce899-84ea-490f-82f3-8acf33710957",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-3346",
      "pattern": "[vulnerability:name = 'CVE-2013-3346']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3346 \u2014 Adobe Reader and Acrobat Memory Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--656dd532-5dff-4ab6-8dac-e3cc0f3d8aa4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-3897",
      "pattern": "[vulnerability:name = 'CVE-2013-3897']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3897 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--08de12d7-0f99-4683-b158-73b891257ffb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-5065",
      "pattern": "[vulnerability:name = 'CVE-2013-5065']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-5065 \u2014 Microsoft Windows Kernel Privilege",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2013-3346 \u2014 Adobe Reader and Acrobat Memory Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6a2f3893-2a37-4bbc-8491-02b4c1de52c3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-0496",
      "pattern": "[vulnerability:name = 'CVE-2014-0496']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-0496 \u2014 Adobe Reader and Acrobat Use-After",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fea9fd55-a3d7-4404-8d53-98670300218c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-4114",
      "pattern": "[vulnerability:name = 'CVE-2014-4114']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-4114 \u2014 Microsoft Windows Object Linking &",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--66117c9f-4831-432b-8e5e-d2f072827a40",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-1642",
      "pattern": "[vulnerability:name = 'CVE-2015-1642']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-1642 \u2014 Microsoft Office Memory Corruption",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--60224b5b-5363-43ac-8a80-1eca8c00b31d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-1701",
      "pattern": "[vulnerability:name = 'CVE-2015-1701']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-3043 \u2014 Adobe Flash Player Memory Corrupti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2015-1701 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c2118d5-f41c-47ce-8cdd-ac80f1f9bfcb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-2387",
      "pattern": "[vulnerability:name = 'CVE-2015-2387']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-2387 \u2014 Microsoft ATM Font Driver Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2015-1701 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cfb1483d-3e4c-4b8d-ab72-fac71dc231e5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-2424",
      "pattern": "[vulnerability:name = 'CVE-2015-2424']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-2424 \u2014 Microsoft PowerPoint Memory Corrup",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--89c73ee2-76a0-4056-b97a-633351b759a3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-2545",
      "pattern": "[vulnerability:name = 'CVE-2015-2545']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-2545 \u2014 Microsoft Office Malformed EPS Fil",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c6f248bb-9e3c-43b3-9a47-65b353623541",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-2590",
      "pattern": "[vulnerability:name = 'CVE-2015-2590']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-4902 \u2014 Oracle Java SE Integrity Check Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2015-2590 \u2014 Oracle Java SE and Java SE Embedde",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1f2a945b-ab90-4247-83d5-3c71b8f91c06",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-3043",
      "pattern": "[vulnerability:name = 'CVE-2015-3043']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-3043 \u2014 Adobe Flash Player Memory Corrupti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f2f8d0e-0008-4282-ad02-0fe8071fec2a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-4902",
      "pattern": "[vulnerability:name = 'CVE-2015-4902']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-4902 \u2014 Oracle Java SE Integrity Check Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2015-2590 \u2014 Oracle Java SE and Java SE Embedde",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9da0ed92-9d73-4922-91ae-459f7960e98b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-5119",
      "pattern": "[vulnerability:name = 'CVE-2015-5119']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-5119 \u2014 Adobe Flash Player Use-After-Free ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c6756491-2eb3-4bcc-99ed-d649d1ab1e05",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-7645",
      "pattern": "[vulnerability:name = 'CVE-2015-7645']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-7645 \u2014 Adobe Flash Player Arbitrary Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2015-4902 \u2014 Oracle Java SE Integrity Check Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f6eae7b6-ffc9-4d88-841b-04bc842a8ccc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-0099",
      "pattern": "[vulnerability:name = 'CVE-2016-0099']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-0099 \u2014 Microsoft Windows Secondary Logon ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f194af94-8d6d-47a9-94ad-3789ad3b0244",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-1019",
      "pattern": "[vulnerability:name = 'CVE-2016-1019']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-1019 \u2014 Adobe Flash Player Arbitrary Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb60f76a-1352-4678-85b0-4681e8b76b5c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-4117",
      "pattern": "[vulnerability:name = 'CVE-2016-4117']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-4117 \u2014 Adobe Flash Player Arbitrary Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2012-1535 \u2014 Adobe Flash Player Arbitrary Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1f6dc1af-8eed-4fad-9b72-ff25a2d34991",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-7193",
      "pattern": "[vulnerability:name = 'CVE-2016-7193']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-7193 \u2014 Microsoft Office Memory Corruption",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2015-1642 \u2014 Microsoft Office Memory Corruption",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b2d37dc4-855c-4838-a83c-e39aec7deb3b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-7255",
      "pattern": "[vulnerability:name = 'CVE-2016-7255']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-7855 \u2014 Adobe Flash Player Use-After-Free ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-7255 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--237059d7-b1d8-4487-b616-7321dd8b5819",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-7262",
      "pattern": "[vulnerability:name = 'CVE-2016-7262']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-7262 \u2014 Microsoft Office Security Feature ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--69658b98-7d01-4318-9054-3392974ce74a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-7855",
      "pattern": "[vulnerability:name = 'CVE-2016-7855']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-7855 \u2014 Adobe Flash Player Use-After-Free ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2015-5119 \u2014 Adobe Flash Player Use-After-Free ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-7255 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--50c050b6-396b-4ea7-9daa-ebe33c3376f3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-8562",
      "pattern": "[vulnerability:name = 'CVE-2016-8562']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-8562 \u2014 Siemens SIMATIC CP 1543-1 Improper",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e3ef4c25-19d5-4c4d-ad6d-1285afd50acf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-0001",
      "pattern": "[vulnerability:name = 'CVE-2017-0001']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0001 \u2014 Microsoft Graphics Device Interfac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f1cfc0ca-d40c-4563-82d9-5acefff882d4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-0261",
      "pattern": "[vulnerability:name = 'CVE-2017-0261']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0261 \u2014 Microsoft Office Use-After-Free Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c89d3ae-5d9c-480c-b919-54986c5ddab0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-11292",
      "pattern": "[vulnerability:name = 'CVE-2017-11292']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11292 \u2014 Adobe Flash Player Type Confusion",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b463e3ea-cdf5-4c4b-8bcc-79f6b7978c0f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-11826",
      "pattern": "[vulnerability:name = 'CVE-2017-11826']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11826 \u2014 Microsoft Office Remote Code Exec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--23bb2c7c-2a70-4bef-a124-4203342de198",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-12231",
      "pattern": "[vulnerability:name = 'CVE-2017-12231']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-12231 \u2014 Cisco IOS Software Network Addres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6fbd94eb-3416-4880-8ffb-47bade7b893d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-12232",
      "pattern": "[vulnerability:name = 'CVE-2017-12232']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-12232 \u2014 Cisco IOS Software for Cisco Inte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--664224c5-2e48-4031-8ef5-c9374b78fe86",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-12233",
      "pattern": "[vulnerability:name = 'CVE-2017-12233']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-12233 \u2014 Cisco IOS Software Common Industr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2847faca-4015-4807-a738-c364393b7429",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-12234",
      "pattern": "[vulnerability:name = 'CVE-2017-12234']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-12234 \u2014 Cisco IOS Software Common Industr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--deb57d27-68a6-4ba0-86a8-e03155b26820",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-12235",
      "pattern": "[vulnerability:name = 'CVE-2017-12235']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-12235 \u2014 Cisco IOS Software for Cisco Indu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d59f3c81-904b-40dd-84e6-0d67cdc9ee4e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-12237",
      "pattern": "[vulnerability:name = 'CVE-2017-12237']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-12237 \u2014 Cisco IOS and IOS XE Software Int",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--39b9d37a-212c-48d4-aeec-74b8e9e851cf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-12238",
      "pattern": "[vulnerability:name = 'CVE-2017-12238']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-12238 \u2014 Cisco Catalyst 6800 Series Switch",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--29511b0c-bbe6-40fc-9419-5f733e487735",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-12240",
      "pattern": "[vulnerability:name = 'CVE-2017-12240']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-12240 \u2014 Cisco IOS and IOS XE Software DHC",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4fc237b1-ae6a-4caa-b7bc-9a199a8921df",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-12319",
      "pattern": "[vulnerability:name = 'CVE-2017-12319']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-12319 \u2014 Cisco IOS XE Software Ethernet Vi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bf45279e-fb01-4040-923e-6ae8e58add8e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-6627",
      "pattern": "[vulnerability:name = 'CVE-2017-6627']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-6627 \u2014 Cisco IOS Software and Cisco IOS X",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4202324e-f4e7-4f0d-a331-205d9d60cda3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-6663",
      "pattern": "[vulnerability:name = 'CVE-2017-6663']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-6663 \u2014 Cisco IOS Software and Cisco IOS X",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--41939f47-b7b1-4b65-b244-60237dbfbc68",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-6736",
      "pattern": "[vulnerability:name = 'CVE-2017-6736']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-6736 \u2014 Cisco IOS and IOS XE Software SNMP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-12240 \u2014 Cisco IOS and IOS XE Software DHC",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cfce1aeb-bba6-4a92-b600-297fde774d8b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-6737",
      "pattern": "[vulnerability:name = 'CVE-2017-6737']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-6737 \u2014 Cisco IOS and IOS XE Software SNMP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f1df976-4e8a-4cbf-8e69-14e320683581",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-6738",
      "pattern": "[vulnerability:name = 'CVE-2017-6738']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-6738 \u2014 Cisco IOS and IOS XE Software SNMP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--58fadd54-d39d-41d5-a134-99b40025dd7b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-6739",
      "pattern": "[vulnerability:name = 'CVE-2017-6739']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-6739 \u2014 Cisco IOS and IOS XE Software SNMP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d7bd0682-766e-4212-a821-4932cfac1006",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-6740",
      "pattern": "[vulnerability:name = 'CVE-2017-6740']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-6740 \u2014 Cisco IOS and IOS XE Software SNMP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--94dee682-17d1-43be-b58c-9387034a199c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-6743",
      "pattern": "[vulnerability:name = 'CVE-2017-6743']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-6743 \u2014 Cisco IOS and IOS XE Software SNMP",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f3d8149a-11f3-4ce0-aa1f-514f1c594a47",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-6744",
      "pattern": "[vulnerability:name = 'CVE-2017-6744']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-6744 \u2014 Cisco IOS Software SNMP Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f9e61462-ff8f-4637-835d-99a2b8939383",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-8540",
      "pattern": "[vulnerability:name = 'CVE-2017-8540']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-8540 \u2014 Microsoft Malware Protection Engin",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b095e6c8-1758-406d-8f0d-30a50af37af3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-0151",
      "pattern": "[vulnerability:name = 'CVE-2018-0151']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0151 \u2014 Cisco IOS Software and Cisco IOS X",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-6744 \u2014 Cisco IOS Software SNMP Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--555beebe-b905-46db-868a-198915da8a89",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-0154",
      "pattern": "[vulnerability:name = 'CVE-2018-0154']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0154 \u2014 Cisco IOS Software Integrated Serv",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-12232 \u2014 Cisco IOS Software for Cisco Inte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--869ff3da-fa5a-4db4-b408-d9d410d8b595",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-0155",
      "pattern": "[vulnerability:name = 'CVE-2018-0155']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0155 \u2014 Cisco Catalyst Bidirectional Forwa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--29702cfc-3ad9-4066-9441-720e6202a733",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-0156",
      "pattern": "[vulnerability:name = 'CVE-2018-0156']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0156 \u2014 Cisco IOS Software and Cisco IOS X",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7a00da26-a4dd-44be-a742-3de4c5f48976",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-0158",
      "pattern": "[vulnerability:name = 'CVE-2018-0158']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0158 \u2014 Cisco IOS and XE Software Internet",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e4faac1-c287-4952-879b-c2308687117c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-0159",
      "pattern": "[vulnerability:name = 'CVE-2018-0159']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0159 \u2014 Cisco IOS and XE Software Internet",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3e6e1d26-f1cb-456f-bdc9-faaf0a488bf8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-0161",
      "pattern": "[vulnerability:name = 'CVE-2018-0161']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0161 \u2014 Cisco IOS Software Resource Manage",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7a9717e9-b193-46e1-b9d0-74fbd597bb27",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-0167",
      "pattern": "[vulnerability:name = 'CVE-2018-0167']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0167 \u2014 Cisco IOS, XR, and XE Software Buf",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--85cb8922-8c85-4d67-8693-57134f1f7178",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-0172",
      "pattern": "[vulnerability:name = 'CVE-2018-0172']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0172 \u2014 Cisco IOS and IOS XE Software Impr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4619b1fd-82d0-4530-b3c4-06fb2fdcf5d7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-0173",
      "pattern": "[vulnerability:name = 'CVE-2018-0173']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0173 \u2014 Cisco IOS and IOS XE Software Impr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e478c147-7ce0-4967-9269-e2bdb8e9a3d2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-0174",
      "pattern": "[vulnerability:name = 'CVE-2018-0174']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0174 \u2014 Cisco IOS Software and Cisco IOS X",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2018-0173 \u2014 Cisco IOS and IOS XE Software Impr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--94dee6f3-aef0-481b-ad20-ec6997a5b724",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-0175",
      "pattern": "[vulnerability:name = 'CVE-2018-0175']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0175 \u2014 Cisco IOS, XR, and XE Software Buf",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--52182dd2-b29f-44ef-bd43-6907280c90b5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-0179",
      "pattern": "[vulnerability:name = 'CVE-2018-0179']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0179 \u2014 Cisco IOS Software Denial-of-Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--42f205e3-5528-43f5-812d-74b847e2091f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-0180",
      "pattern": "[vulnerability:name = 'CVE-2018-0180']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0180 \u2014 Cisco IOS Software Denial-of-Servi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d38e1822-7a69-4fb1-9fbb-71dff891dec5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-8298",
      "pattern": "[vulnerability:name = 'CVE-2018-8298']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-8298 \u2014 ChakraCore Scripting Engine Type C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b3372534-b511-4af4-b2dc-828a838baa58",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-8581",
      "pattern": "[vulnerability:name = 'CVE-2018-8581']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-8581 \u2014 Microsoft Exchange Server Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c1a7439a-bd22-4f7d-9774-cf560d303c99",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-1297",
      "pattern": "[vulnerability:name = 'CVE-2019-1297']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1297 \u2014 Microsoft Excel Remote Code Execut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-11826 \u2014 Microsoft Office Remote Code Exec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--69927636-2689-4275-b996-91f9e790caa6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-1652",
      "pattern": "[vulnerability:name = 'CVE-2019-1652']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1652 \u2014 Cisco Small Business Routers Impro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-1653 \u2014 Cisco Small Business RV320 and RV3",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1a12cb6d-2b5c-4645-8943-e1b80bb5a710",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-1653",
      "pattern": "[vulnerability:name = 'CVE-2019-1653']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1652 \u2014 Cisco Small Business Routers Impro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-1653 \u2014 Cisco Small Business RV320 and RV3",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9b06ea2f-0a26-4607-94fa-52b3a9ed9f0c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-16928",
      "pattern": "[vulnerability:name = 'CVE-2019-16928']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16928 \u2014 Exim Out-of-bounds Write Vulnerab",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e5586bbf-2000-4113-b490-8f067472fc5e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-11899",
      "pattern": "[vulnerability:name = 'CVE-2020-11899']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-11899 \u2014 Treck TCP/IP stack Out-of-Bounds ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--476111a6-b60f-4b79-a16e-430d40c3558f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-1938",
      "pattern": "[vulnerability:name = 'CVE-2020-1938']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-1938 \u2014 Apache Tomcat Improper Privilege M",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "Ghostcat breach affects all Tomcat versions",
          "url": "https://snyk.io/blog/ghostcat-breach-affects-all-tomcat-versions/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7bba98bf-f9d6-4a6e-8d2f-704f1dbed085",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-41379",
      "pattern": "[vulnerability:name = 'CVE-2021-41379']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-41379 \u2014 Microsoft Windows Installer Privi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2013-5065 \u2014 Microsoft Windows Kernel Privilege",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2eeeea3d-dac1-4fe8-b2d0-8bd78339ddd6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-20699",
      "pattern": "[vulnerability:name = 'CVE-2022-20699']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-20699 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d80970ac-a209-48cc-a342-d71af732c0e7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-20700",
      "pattern": "[vulnerability:name = 'CVE-2022-20700']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-20700 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--838e0264-8001-40ed-b6e0-6dacc1dd17f2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-20701",
      "pattern": "[vulnerability:name = 'CVE-2022-20701']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-20701 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f8e8bb9b-437f-4ac5-bb08-cc0faffe5291",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-20703",
      "pattern": "[vulnerability:name = 'CVE-2022-20703']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-20703 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b17155df-a30b-4056-905a-8b7cee83e226",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-20708",
      "pattern": "[vulnerability:name = 'CVE-2022-20708']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-20708 \u2014 Cisco Small Business RV Series Ro",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5b7f3815-0e62-490f-a2f2-8020072d5177",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: dol.ns01.us",
      "pattern": "[domain-name:value = 'dol.ns01.us']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-1347 \u2014 Microsoft Internet Explorer Remote",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32e0b628-f5ee-4980-a2a6-742f3b5cd019",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: liciayee.dyndns-free.com",
      "pattern": "[domain-name:value = 'liciayee.dyndns-free.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--011fe447-87b3-4b07-8dbf-fd6b89806cc8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: microsoftupdate.ns1.name",
      "pattern": "[domain-name:value = 'microsoftupdate.ns1.name']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-1347 \u2014 Microsoft Internet Explorer Remote",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--56ab4752-1816-4955-becb-db91a4bf5b3b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ssl-icloud.com",
      "pattern": "[domain-name:value = 'ssl-icloud.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-3043 \u2014 Adobe Flash Player Memory Corrupti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c49ffe0-76c5-4035-bbc4-d4572c544f58",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 1.234.31.142",
      "pattern": "[ipv4-addr:value = '1.234.31.142']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3897 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb89e3b0-e466-46e1-952d-2cdb7f4d3b4e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 1.234.31.153",
      "pattern": "[ipv4-addr:value = '1.234.31.153']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3897 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--859e7ab3-a718-4f10-af89-d8719811ff86",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 1.234.31.154",
      "pattern": "[ipv4-addr:value = '1.234.31.154']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3897 \u2014 Microsoft Internet Explorer Use-Af",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5be8a94c-8ed9-4ffb-aa6e-1efbe9f684a0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 208.106.153.173",
      "pattern": "[ipv4-addr:value = '208.106.153.173']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--86840fce-83bd-4a42-b16a-170c0cd2f467",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 218.38.77.104",
      "pattern": "[ipv4-addr:value = '218.38.77.104']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--07f55f5a-fc25-4f14-a0f8-a2a81362a5d3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 60.234.77.197",
      "pattern": "[ipv4-addr:value = '60.234.77.197']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7939b684-04b8-426b-a58c-cc19f1138878",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 63.223.113.63",
      "pattern": "[ipv4-addr:value = '63.223.113.63']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--60cc9770-50f4-48b9-8111-3196be7c7ae4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 87.236.215.246",
      "pattern": "[ipv4-addr:value = '87.236.215.246']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-3043 \u2014 Adobe Flash Player Memory Corrupti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6bd7daea-b45f-4250-8fcb-8bd704d2e814",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 96.44.136.115",
      "pattern": "[ipv4-addr:value = '96.44.136.115']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-1347 \u2014 Microsoft Internet Explorer Remote",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--86fba9ae-d15d-4039-a188-963bfd6a4e70",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 41bb0ff7b57a354e4c9f65dfd47ea3ae",
      "pattern": "[file:hashes.MD5 = '41bb0ff7b57a354e4c9f65dfd47ea3ae']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2be33143-09e4-47a0-a22d-1df45fd8498e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 78c628fc44fe40bff47176613d3e1776",
      "pattern": "[file:hashes.MD5 = '78c628fc44fe40bff47176613d3e1776']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f5ef1a29-375c-4507-9137-debfcb9c5af6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 803b0cfe58f766e3e717992ca8a8f9e9",
      "pattern": "[file:hashes.MD5 = '803b0cfe58f766e3e717992ca8a8f9e9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a5fd26bd-ae60-4537-9097-b6e8c47ec73b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 96cf54e6d7e228a2c6418aba93d6bd49",
      "pattern": "[file:hashes.MD5 = '96cf54e6d7e228a2c6418aba93d6bd49']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--236de86b-de7a-4940-9b63-63ed989947c3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 9bdefcc465c73fc5eedf41ebf47b5f6c",
      "pattern": "[file:hashes.MD5 = '9bdefcc465c73fc5eedf41ebf47b5f6c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--84f40b5c-1b7d-4445-9fca-c26b82ce95cb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: a421d074611188cfcfcedba55cc7e194",
      "pattern": "[file:hashes.MD5 = 'a421d074611188cfcfcedba55cc7e194']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--062bd243-9c8b-40be-bda9-a154de9a836e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: a51edd010f3c0d33249be771891265cb",
      "pattern": "[file:hashes.MD5 = 'a51edd010f3c0d33249be771891265cb']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--65b5be9a-0f1e-450f-b856-2c8db55da93a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: d1bfe000e745207c32343bfe5abd94c9",
      "pattern": "[file:hashes.MD5 = 'd1bfe000e745207c32343bfe5abd94c9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dceba906-751e-4340-bebd-914dfd4833d5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: ec2420e3b03316f13dc922cf7dd48cef",
      "pattern": "[file:hashes.MD5 = 'ec2420e3b03316f13dc922cf7dd48cef']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4d6007c-6999-4563-831d-9a58d0352b20",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: f27990c8369205d5167f7d64b7749ff8",
      "pattern": "[file:hashes.MD5 = 'f27990c8369205d5167f7d64b7749ff8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f2bbbaf-4e03-4387-827e-c821aa35eaf1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 0ac9da07feff242f4eaaca081b11b645f4435f03",
      "pattern": "[file:hashes.'SHA-1' = '0ac9da07feff242f4eaaca081b11b645f4435f03']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6047057-94e5-4305-9700-0187c35d456f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 45573ee5d89c1d7e7adb98149cca2dfee48b5d1f",
      "pattern": "[file:hashes.'SHA-1' = '45573ee5d89c1d7e7adb98149cca2dfee48b5d1f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--603b6681-288d-4259-a05b-ce68bce61faf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 5cc31b8cc90c9cda4781517678e27a15cf55d27d",
      "pattern": "[file:hashes.'SHA-1' = '5cc31b8cc90c9cda4781517678e27a15cf55d27d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--94f9ee8f-c5cf-4fe9-a166-0f951a942602",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 6f969aad92fe9340d00b31eab95355088767b9ed",
      "pattern": "[file:hashes.'SHA-1' = '6f969aad92fe9340d00b31eab95355088767b9ed']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8bf89238-6e69-4cf0-9f69-7f55545f2d5c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 820699d9999ea3ba07e7f0d0c7f08fe10eae1d2d",
      "pattern": "[file:hashes.'SHA-1' = '820699d9999ea3ba07e7f0d0c7f08fe10eae1d2d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f11e3aee-785b-4bc3-b80d-693bb472370b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: aaff5eabe5d803742dbb8b405e7a7c4cb659f12c",
      "pattern": "[file:hashes.'SHA-1' = 'aaff5eabe5d803742dbb8b405e7a7c4cb659f12c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f0f245e-bf0c-490d-8de6-30184ddfc2f0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: c9de4570d5022e55102e4edfac55b46a2362ef0d",
      "pattern": "[file:hashes.'SHA-1' = 'c9de4570d5022e55102e4edfac55b46a2362ef0d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8eefb71-268d-4784-998d-a3c1feeb5691",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: ca044e91761e633a0580c947adc39a6ca248e5e9",
      "pattern": "[file:hashes.'SHA-1' = 'ca044e91761e633a0580c947adc39a6ca248e5e9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fb7dfb11-486f-4201-9d74-156cae5ddd8b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: e6a3c14eb59a681115878432f5519138b69b5847",
      "pattern": "[file:hashes.'SHA-1' = 'e6a3c14eb59a681115878432f5519138b69b5847']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--62a6ce23-4d71-4949-98d6-906b37475c24",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a43bafb2af2a1adcd1371ab3810b2908b591bc32798f3ad35ad662cf967b12fd",
      "pattern": "[file:hashes.'SHA-256' = 'a43bafb2af2a1adcd1371ab3810b2908b591bc32798f3ad35ad662cf967b12fd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-41379 \u2014 Microsoft Windows Installer Privi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--573db9d8-564c-4a9f-9b32-e2e6dd546ba0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: registry.terraform.io",
      "pattern": "[domain-name:value = 'registry.terraform.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Adding Container and IaC security to the Snyk plugin for Jet",
          "url": "https://snyk.io/blog/snyk-jetbrains-plugin-iac-container/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--52325492-b194-40e8-9dea-6a72c45553c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-6352",
      "pattern": "[vulnerability:name = 'CVE-2014-6352']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-6352 \u2014 Microsoft Windows Code Injection V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--26702006-4134-4b10-bc3b-5994c85aca7c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-0222",
      "pattern": "[vulnerability:name = 'CVE-2017-0222']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0222 \u2014 Microsoft Internet Explorer Remote",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0854d59-7622-45f1-bd81-85ec4402a9ac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-8570",
      "pattern": "[vulnerability:name = 'CVE-2017-8570']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-8570 \u2014 Microsoft Office Remote Code Execu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fff8f734-7678-4a21-aa8f-15d4514856df",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-24682",
      "pattern": "[vulnerability:name = 'CVE-2022-24682']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e5ff5e4-f3aa-4419-8a5d-39d171adc7ea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: amazon-check.cf",
      "pattern": "[domain-name:value = 'amazon-check.cf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0c0c8b60-29f1-4da7-b658-40a0ced73642",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: amazon-check.ga",
      "pattern": "[domain-name:value = 'amazon-check.ga']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bae7275a-3eb9-4184-b0ff-9078db033907",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: amazon-check.gq",
      "pattern": "[domain-name:value = 'amazon-check.gq']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4809a57c-1f6c-45da-82fb-61d5f34c8b78",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: amazon-check.tk",
      "pattern": "[domain-name:value = 'amazon-check.tk']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6b72f137-4ac3-4a23-a48f-615f27ea5b93",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: amazon-team.tk",
      "pattern": "[domain-name:value = 'amazon-team.tk']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f412fa49-3c8b-42cf-955a-45b243b4d661",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: bruising-intellect.ml",
      "pattern": "[domain-name:value = 'bruising-intellect.ml']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3283c395-52ac-47ac-a423-8cf98df37073",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: findtruth.ml",
      "pattern": "[domain-name:value = 'findtruth.ml']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--923183ea-700e-4492-b88b-d951ffa7b3b5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: iceywindflow.cf",
      "pattern": "[domain-name:value = 'iceywindflow.cf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--245da591-1949-41ef-a769-7c8b48600046",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: iceywindflow.gq",
      "pattern": "[domain-name:value = 'iceywindflow.gq']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--adb2c55c-f75d-4de3-a483-6ddbdc536718",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: iceywindflow.ml",
      "pattern": "[domain-name:value = 'iceywindflow.ml']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7e5b9bb2-f13f-4332-aae1-79bb807c60ae",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: mail.bruising-intellect.ml",
      "pattern": "[domain-name:value = 'mail.bruising-intellect.ml']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1f1981d1-600f-45b4-b561-33e20267997b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: news-online.ml",
      "pattern": "[domain-name:value = 'news-online.ml']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--df786ac7-9032-4f87-9748-c881ec79e3c5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: news-voice.ml",
      "pattern": "[domain-name:value = 'news-voice.ml']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c9000b2c-a474-4d64-9825-10df476be33f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: newsonline.gq",
      "pattern": "[domain-name:value = 'newsonline.gq']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7ec394cc-308f-442c-bf99-f3a2fa1af005",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: petapixel.fun",
      "pattern": "[domain-name:value = 'petapixel.fun']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-8570 \u2014 Microsoft Office Remote Code Execu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--793f0fba-93f8-406a-a6cf-4be8d583dafb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: playquicksand.cf",
      "pattern": "[domain-name:value = 'playquicksand.cf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aac3978c-2742-42a9-9024-ff413645d930",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: playquicksand.gq",
      "pattern": "[domain-name:value = 'playquicksand.gq']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ae7360cb-6c9e-4a1d-beef-bf90d38a25b8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: playquicksand.ml",
      "pattern": "[domain-name:value = 'playquicksand.ml']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--db7ec4ae-d96e-4b8f-9536-beff55f98078",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: playquicksand.tk",
      "pattern": "[domain-name:value = 'playquicksand.tk']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9db51b57-9dbe-4a09-958d-33310e21fcc1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: secretstep.tk",
      "pattern": "[domain-name:value = 'secretstep.tk']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--13ebf340-4103-43a9-8336-c40539119ac7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: spiritfield.cf",
      "pattern": "[domain-name:value = 'spiritfield.cf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ae736142-39a0-410d-a3e9-f77f5c883b2d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: spiritfield.ga",
      "pattern": "[domain-name:value = 'spiritfield.ga']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e97fefd3-c20d-4d2e-a967-3eb0adba6f74",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: spiritfield.ml",
      "pattern": "[domain-name:value = 'spiritfield.ml']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e42a3587-d4c3-4200-80d7-0603f3d89b27",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: spiritfield.tk",
      "pattern": "[domain-name:value = 'spiritfield.tk']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--11462956-07be-491c-a336-5a4ed04ae36a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: spiritx.ga",
      "pattern": "[domain-name:value = 'spiritx.ga']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fa4e03cd-eadc-4ec1-9c9d-085ad6c8a718",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: thunderchannel.cf",
      "pattern": "[domain-name:value = 'thunderchannel.cf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3da6cde4-f69e-4c85-bbd3-307f76dd536b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: thunderchannel.tk",
      "pattern": "[domain-name:value = 'thunderchannel.tk']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9967f8c4-6d68-425c-ac99-a852a472646f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: update.secretstep.tk",
      "pattern": "[domain-name:value = 'update.secretstep.tk']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f44d267d-29af-4c3e-a466-687b92bf8290",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: weavesilk.space",
      "pattern": "[domain-name:value = 'weavesilk.space']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-8570 \u2014 Microsoft Office Remote Code Execu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--013d704c-832d-4da1-baa5-89f18ea7b54e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: windsoft.cf",
      "pattern": "[domain-name:value = 'windsoft.cf']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4a4a4084-46db-4553-82ab-52ccd86326d3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: yahoo-corporation.ml",
      "pattern": "[domain-name:value = 'yahoo-corporation.ml']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff369b7a-70c3-45ab-8a6d-4c4e1f9793af",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: yahoo-corporation.tk",
      "pattern": "[domain-name:value = 'yahoo-corporation.tk']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ddb7f09a-84ff-4083-a6d2-bd76da45dcbb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 108.160.133.32",
      "pattern": "[ipv4-addr:value = '108.160.133.32']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0314e9c9-5e7e-456a-8d4b-f63afc0199c3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.86.75.158",
      "pattern": "[ipv4-addr:value = '172.86.75.158']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0c40663-f159-4e7c-ba67-9dfb09e3a7de",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 206.166.251.141",
      "pattern": "[ipv4-addr:value = '206.166.251.141']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b696e48-8406-4b77-b71a-050739df1073",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 206.166.251.166",
      "pattern": "[ipv4-addr:value = '206.166.251.166']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cf0ef0b0-53ac-4230-a83b-d09786a76cc4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-24086",
      "pattern": "[vulnerability:name = 'CVE-2022-24086']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Magento security requires additional patch to fix sanitizati",
          "url": "https://snyk.io/blog/magento-vulnerability-cve-2022-24087-sanitization/"
        },
        {
          "source_name": "CVE-2022-24086 Vulnerability alert for websites using Magent",
          "url": "https://snyk.io/blog/vulnerability-alert-for-websites-using-magento-ecommerce/"
        },
        {
          "source_name": "CISA KEV: CVE-2022-24086 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32297521-31c6-4185-8849-4bd858941060",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-24087",
      "pattern": "[vulnerability:name = 'CVE-2022-24087']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Magento security requires additional patch to fix sanitizati",
          "url": "https://snyk.io/blog/magento-vulnerability-cve-2022-24087-sanitization/"
        },
        {
          "source_name": "CVE-2022-24086 Vulnerability alert for websites using Magent",
          "url": "https://snyk.io/blog/vulnerability-alert-for-websites-using-magento-ecommerce/"
        },
        {
          "source_name": "CISA KEV: CVE-2022-24086 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1dd88c16-b7f5-4f3d-8066-fd99b7ee7c7a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.134.20.11",
      "pattern": "[ipv4-addr:value = '45.134.20.11']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Magento security requires additional patch to fix sanitizati",
          "url": "https://snyk.io/blog/magento-vulnerability-cve-2022-24087-sanitization/"
        },
        {
          "source_name": "CVE-2022-24086 Vulnerability alert for websites using Magent",
          "url": "https://snyk.io/blog/vulnerability-alert-for-websites-using-magento-ecommerce/"
        },
        {
          "source_name": "CISA KEV: CVE-2022-24086 \u2014 Adobe Commerce and Magento Open S",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk",
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d8103e22-d4f8-463d-b9d7-6130ec046987",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-23131",
      "pattern": "[vulnerability:name = 'CVE-2022-23131']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-23131 \u2014 Zabbix Frontend Authentication By",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4993f2d2-119c-4ee6-840a-2892c5e25538",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-23134",
      "pattern": "[vulnerability:name = 'CVE-2022-23134']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-23134 \u2014 Zabbix Frontend Improper Access C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d82e9e76-cd5a-4148-8667-c9c40e732adc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-3906",
      "pattern": "[vulnerability:name = 'CVE-2013-3906']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3906 \u2014 Microsoft Graphics Component Memor",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fd2dba76-4578-4613-8dd7-eb28a862a762",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-1761",
      "pattern": "[vulnerability:name = 'CVE-2014-1761']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-1761 \u2014 Microsoft Word Memory Corruption V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1211cc94-d325-4ecf-8dde-4de226939d96",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-15982",
      "pattern": "[vulnerability:name = 'CVE-2018-15982']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-15982 \u2014 Adobe Flash Player Use-After-Free",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--04b3d683-547d-4b78-80dc-3a21ece7904a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-20250",
      "pattern": "[vulnerability:name = 'CVE-2018-20250']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-20250 \u2014 WinRAR Absolute Path Traversal Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0ec27f6-4f9d-499f-9535-c955fdb9d167",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-0752",
      "pattern": "[vulnerability:name = 'CVE-2019-0752']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-0752 \u2014 Microsoft Internet Explorer Type C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--13a2e97b-4271-46b1-a46c-07e04723e951",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-23727",
      "pattern": "[vulnerability:name = 'CVE-2021-23727']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Case study: Python RCE vulnerability in Celery",
          "url": "https://snyk.io/blog/python-rce-vulnerability/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b6dee1d2-a6c7-4e7c-90f7-c8b6dc9b7ab4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-0609",
      "pattern": "[vulnerability:name = 'CVE-2022-0609']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-Afte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87e2e189-9db4-414a-8a03-35fabbc054c3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: blockchainnews.vip",
      "pattern": "[domain-name:value = 'blockchainnews.vip']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-Afte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8553e80f-e63e-4544-9133-4415a13cde09",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: chainnews-star.com",
      "pattern": "[domain-name:value = 'chainnews-star.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-Afte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--59912714-1dbb-4a73-b6e6-3ae0edd82f4e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: colasprint.com",
      "pattern": "[domain-name:value = 'colasprint.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-Afte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--be0bbacc-8231-4857-af73-d56c4e080746",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: disneycareers.net",
      "pattern": "[domain-name:value = 'disneycareers.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-Afte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb4061d5-fe3a-4357-8d1b-3c5a4b5079db",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: financialtimes365.com",
      "pattern": "[domain-name:value = 'financialtimes365.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-Afte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2ea9631c-3a5a-405f-84ac-59e5d797a2ed",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: find-dreamjob.com",
      "pattern": "[domain-name:value = 'find-dreamjob.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-Afte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5fbbbc0d-eda5-4d6e-9664-f97725b8e5ba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: fireblocks.vip",
      "pattern": "[domain-name:value = 'fireblocks.vip']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-Afte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff158fa9-db2c-4fbb-ad80-ddb11bfab090",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: gatexpiring.com",
      "pattern": "[domain-name:value = 'gatexpiring.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-Afte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea7ae58a-c00e-434d-bb75-d7b98fcb0e24",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: gbclabs.com",
      "pattern": "[domain-name:value = 'gbclabs.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-Afte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d985f0a-e0d1-4a5d-98c5-085dcf1d4adc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: giantblock.org",
      "pattern": "[domain-name:value = 'giantblock.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-Afte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a13c7728-c367-4c84-ba9b-efe3cdfa5a76",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: humingbot.io",
      "pattern": "[domain-name:value = 'humingbot.io']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-Afte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--49856ac0-6d34-4022-9f39-0e9a1c4d2e6d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: indeedus.org",
      "pattern": "[domain-name:value = 'indeedus.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-Afte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2cdd4493-4bf4-4418-8a75-2c50327f24fa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: onlynova.org",
      "pattern": "[domain-name:value = 'onlynova.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-Afte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cd28666d-b986-4725-b33b-6789cee39491",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: teenbeanjs.com",
      "pattern": "[domain-name:value = 'teenbeanjs.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-Afte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--23041631-a262-47f7-ab44-78fdbdb6a36c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: varietyjob.com",
      "pattern": "[domain-name:value = 'varietyjob.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-Afte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2f6afde7-f154-4efc-9ef3-642964bf0fdf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ziprecruiters.org",
      "pattern": "[domain-name:value = 'ziprecruiters.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-Afte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--877c6e49-c23f-4f27-9b43-fa6efc604545",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 116.99.50.13",
      "pattern": "[ipv4-addr:value = '116.99.50.13']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-9841 \u2014 PHPUnit Command Injection Vulnerab",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f619314f-b789-4959-869b-1c15fe93cc69",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 125.135.169.171",
      "pattern": "[ipv4-addr:value = '125.135.169.171']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-9841 \u2014 PHPUnit Command Injection Vulnerab",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a4b40888-4ede-4d2f-aff1-124a2b3c5c49",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 167.86.88.40",
      "pattern": "[ipv4-addr:value = '167.86.88.40']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-9841 \u2014 PHPUnit Command Injection Vulnerab",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--86b01936-716d-4fe8-b6a8-681033386a49",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.177.72.51",
      "pattern": "[ipv4-addr:value = '185.177.72.51']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-9841 \u2014 PHPUnit Command Injection Vulnerab",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bd731953-e439-4174-bd1e-bc4817f8f9a0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.177.72.68",
      "pattern": "[ipv4-addr:value = '185.177.72.68']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-9841 \u2014 PHPUnit Command Injection Vulnerab",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c24b9afa-66da-41eb-b03e-3865a53533fc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.38.148.2",
      "pattern": "[ipv4-addr:value = '185.38.148.2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-9841 \u2014 PHPUnit Command Injection Vulnerab",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a0e6ef5-5300-48b5-b70c-dc3f01682f59",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 66.179.137.126",
      "pattern": "[ipv4-addr:value = '66.179.137.126']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-9841 \u2014 PHPUnit Command Injection Vulnerab",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e91ef924-2ec2-4920-bd22-a784400bf9d6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 83.168.88.41",
      "pattern": "[ipv4-addr:value = '83.168.88.41']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-9841 \u2014 PHPUnit Command Injection Vulnerab",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--69e35d4f-111b-443d-a09f-58e54f9f7cad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 7dd89c99ed7cec0ebc4afa8cd010f1f1",
      "pattern": "[file:hashes.MD5 = '7dd89c99ed7cec0ebc4afa8cd010f1f1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3906 \u2014 Microsoft Graphics Component Memor",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--36a561ac-4090-44e3-9199-e023e65c03c0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 03a41d29e3c9763093aca13f1cc8bcc41b201a6839c381aaaccf891204335685",
      "pattern": "[file:hashes.'SHA-256' = '03a41d29e3c9763093aca13f1cc8bcc41b201a6839c381aaaccf891204335685']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-Afte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0695ed89-ea23-4139-ae92-638f98a7694c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-22620",
      "pattern": "[vulnerability:name = 'CVE-2022-22620']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22620 \u2014 Apple iOS, iPadOS, and macOS Webk",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3195e625-2b4c-48b1-bea1-45952d7521da",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-4404",
      "pattern": "[vulnerability:name = 'CVE-2014-4404']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-4404 \u2014 Apple OS X Heap-Based Buffer Overf",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1b7db37c-15a6-4720-b410-6e930b75b321",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-1130",
      "pattern": "[vulnerability:name = 'CVE-2015-1130']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-1130 \u2014 Apple OS X Authentication Bypass V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c6f6e6b2-beb1-42a1-ac0c-9f732c11b7ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-1635",
      "pattern": "[vulnerability:name = 'CVE-2015-1635']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-1635 \u2014 Microsoft HTTP.sys Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9ea3e0e5-c1fd-411f-942a-298a703436c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-2051",
      "pattern": "[vulnerability:name = 'CVE-2015-2051']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-2051 \u2014 D-Link DIR-645 Router Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--692c2ee0-c583-4029-b069-51a783f439be",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-3088",
      "pattern": "[vulnerability:name = 'CVE-2016-3088']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-3088 \u2014 Apache ActiveMQ Improper Input Val",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8672c6ec-1abc-4a22-a62f-94b04b2efb8e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-0144",
      "pattern": "[vulnerability:name = 'CVE-2017-0144']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-0144 \u2014 Microsoft SMBv1 Remote Code Execut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ae5f4635-2164-4a95-b9a0-39bee00133ed",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-0145",
      "pattern": "[vulnerability:name = 'CVE-2017-0145']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0145 \u2014 Microsoft SMBv1 Remote Code Execut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ed114776-db67-4a4f-8974-e0829d9df13a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-0262",
      "pattern": "[vulnerability:name = 'CVE-2017-0262']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0263 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-0262 \u2014 Microsoft Office Remote Code Execu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2c83d156-900b-40bd-906c-4d7e340d6eed",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-0263",
      "pattern": "[vulnerability:name = 'CVE-2017-0263']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0263 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--200caa0b-d7f3-4064-a3a3-eced69c79eba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-8464",
      "pattern": "[vulnerability:name = 'CVE-2017-8464']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-8464 \u2014 Microsoft Windows Shell (.lnk) Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aa8d595c-fb62-424c-9031-a703b9623c7d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-9791",
      "pattern": "[vulnerability:name = 'CVE-2017-9791']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-9791 \u2014 Apache Struts 1 Improper Input Val",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4f4b4b95-b299-4ad6-9508-e6d44f11d496",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-2725",
      "pattern": "[vulnerability:name = 'CVE-2019-2725']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7ecbd3bc-cd47-43cf-a42d-531aa3cc7169",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-0796",
      "pattern": "[vulnerability:name = 'CVE-2020-0796']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-0796 \u2014 Microsoft SMBv3 Remote Code Execut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c4199dc-9b17-4a52-b90c-cd63285f6cfe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-36934",
      "pattern": "[vulnerability:name = 'CVE-2021-36934']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-36934 \u2014 Microsoft Windows SAM Local Privi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0e0799d5-6719-4e73-a8a5-b786f5b398e0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-28958",
      "pattern": "[vulnerability:name = 'CVE-2022-28958']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-2051 \u2014 D-Link DIR-645 Router Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b9943b8f-b9be-4e5f-9759-3870066c67ac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: aplebzu47wgazapdqks6vrcv6zcnjppkbxbr6wketf56nf6aq2nmyoyd.onion",
      "pattern": "[domain-name:value = 'aplebzu47wgazapdqks6vrcv6zcnjppkbxbr6wketf56nf6aq2nmyoyd.onion']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4bd0a801-1b0e-4c04-b1a3-5e1d6e519087",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: decryptor.top",
      "pattern": "[domain-name:value = 'decryptor.top']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b27736a-ae9b-4848-9f82-3f95babb9682",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: vpn.komaru.today",
      "pattern": "[domain-name:value = 'vpn.komaru.today']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-2051 \u2014 D-Link DIR-645 Router Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ea23ec7-13c6-4c66-b587-45919ad0f770",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: wmdmediacodecs.com",
      "pattern": "[domain-name:value = 'wmdmediacodecs.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0263 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d633679-e215-4eb6-afa6-9f4394dbaf2b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 107.174.47.156",
      "pattern": "[ipv4-addr:value = '107.174.47.156']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ba86e031-1902-4525-8a45-15896aa1990c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 159.203.15.179",
      "pattern": "[ipv4-addr:value = '159.203.15.179']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-2051 \u2014 D-Link DIR-645 Router Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c37d1f72-186c-40b8-858e-2a8b9e2ac88a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 165.22.155.69",
      "pattern": "[ipv4-addr:value = '165.22.155.69']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--61f765fb-de31-49d0-988b-f8cbc1fc458c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.161.70.34",
      "pattern": "[ipv4-addr:value = '185.161.70.34']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--02d1179f-e968-4e4e-be9f-7d0051ddb513",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 188.166.74.218",
      "pattern": "[ipv4-addr:value = '188.166.74.218']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3502efb3-9e70-4d59-8f8f-05e3469a2b74",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 202.144.193.184",
      "pattern": "[ipv4-addr:value = '202.144.193.184']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--21acc077-4bff-4136-bf5b-ff036488a2d8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 205.185.122.99",
      "pattern": "[ipv4-addr:value = '205.185.122.99']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--71a2f4ed-e953-473c-87b0-4d20911b069f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 26404fede71f3f713175a3a3cebc619b",
      "pattern": "[file:hashes.MD5 = '26404fede71f3f713175a3a3cebc619b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1e98904e-b92c-4c03-84b9-8e3e96d969d6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 3421a769308d39d4e9c7e8caecaf7fc4",
      "pattern": "[file:hashes.MD5 = '3421a769308d39d4e9c7e8caecaf7fc4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b6ac1bf-3d80-47e9-ad47-7abb6b5e45a1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 3542ac729035c0f3db186ddf2178b6a0",
      "pattern": "[file:hashes.MD5 = '3542ac729035c0f3db186ddf2178b6a0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--14d3154a-743a-41d8-838a-91fdf9d812f6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 3aad3fabf29f9df65dcbd0f308ff0fa8",
      "pattern": "[file:hashes.MD5 = '3aad3fabf29f9df65dcbd0f308ff0fa8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5bfac4b4-f5f0-4752-9241-02987c3b2aca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 933633f2acfc5909c83f5c73b6fc97cc",
      "pattern": "[file:hashes.MD5 = '933633f2acfc5909c83f5c73b6fc97cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e8559abd-6c5b-4743-a7a8-0df354d6cada",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 9c91b5cf6eced54abb82d1050c5893f2",
      "pattern": "[file:hashes.MD5 = '9c91b5cf6eced54abb82d1050c5893f2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9090e11f-b686-4206-916a-36fa14d5c4a4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: b3a831bfa590274902c77b6c7d4c31ae",
      "pattern": "[file:hashes.MD5 = 'b3a831bfa590274902c77b6c7d4c31ae']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2b1d2947-0be0-4b61-98b9-ccd2df031b07",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: b47daf937897043745df81f32b9d7565",
      "pattern": "[file:hashes.MD5 = 'b47daf937897043745df81f32b9d7565']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8d8c47c-b806-439d-bd55-cea32d955fbb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: d3d10faa69a10ac754e3b7dde9178c22",
      "pattern": "[file:hashes.MD5 = 'd3d10faa69a10ac754e3b7dde9178c22']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--09b19212-b247-4111-a0c8-9330006b9169",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: f8e92d8b5488ea76c40601c8f1a08790",
      "pattern": "[file:hashes.MD5 = 'f8e92d8b5488ea76c40601c8f1a08790']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0263 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c660577-d370-47f0-b9f5-4028e382b465",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 33135d6e0b8ac14693758ca2e37f27059e202ee72b419ab362fc07d232bb8a10",
      "pattern": "[file:hashes.'SHA-256' = '33135d6e0b8ac14693758ca2e37f27059e202ee72b419ab362fc07d232bb8a10']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--10cf7212-e8cf-4d4d-9746-a18e30dda1e9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3e35f125ea1256a443dcc4eee612f87025f9af7c45a22e95e5a2bd3e53f491eb",
      "pattern": "[file:hashes.'SHA-256' = '3e35f125ea1256a443dcc4eee612f87025f9af7c45a22e95e5a2bd3e53f491eb']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5d3b40b-7670-4174-93dc-0bd55c51f947",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 46BB6E2F80B6CB96FF7D0F78B3BDBC496B69EB7F22CE15EFCAA275F07CFAE075",
      "pattern": "[file:hashes.'SHA-256' = '46BB6E2F80B6CB96FF7D0F78B3BDBC496B69EB7F22CE15EFCAA275F07CFAE075']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-2051 \u2014 D-Link DIR-645 Router Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--55ad73f9-7662-4478-b76f-20a75b159414",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4f9020f7e1c2a43a08c117b8d3323421eb1c920b5bad70adb92cbbf882cdf3a9",
      "pattern": "[file:hashes.'SHA-256' = '4f9020f7e1c2a43a08c117b8d3323421eb1c920b5bad70adb92cbbf882cdf3a9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--92628b07-cac7-43c0-9497-c88229e4a124",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: B7EE57A42C6A4545AC6D6C29E1075FA1628E1D09B8C1572C848A70112D4C90A1",
      "pattern": "[file:hashes.'SHA-256' = 'B7EE57A42C6A4545AC6D6C29E1075FA1628E1D09B8C1572C848A70112D4C90A1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-2051 \u2014 D-Link DIR-645 Router Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b18df6f0-3243-4e21-8dff-e0ca5a225deb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c213492008177ae1cda8903a46fb1b766f41c58051f1527237a597243885a87e",
      "pattern": "[file:hashes.'SHA-256' = 'c213492008177ae1cda8903a46fb1b766f41c58051f1527237a597243885a87e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--18b66fe5-e942-408b-b553-97e14ccdb7cc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c799b4a7d14bb911e40c427517eeef96111383a4b3960c8707a27055eef8ecb0",
      "pattern": "[file:hashes.'SHA-256' = 'c799b4a7d14bb911e40c427517eeef96111383a4b3960c8707a27055eef8ecb0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Serve",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67a8054c-ae71-4e84-a674-8845b52ce4ae",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-1025",
      "pattern": "[vulnerability:name = 'CVE-2022-1025']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Lessons learned from the Argo CD zero-day vulnerability (CVE",
          "url": "https://snyk.io/blog/argo-cd-zero-day-cve-2022-24348-lessons-supply-chain/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4b70410d-1b0a-41bd-b4f2-8682b318df28",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-24348",
      "pattern": "[vulnerability:name = 'CVE-2022-24348']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Lessons learned from the Argo CD zero-day vulnerability (CVE",
          "url": "https://snyk.io/blog/argo-cd-zero-day-cve-2022-24348-lessons-supply-chain/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dda69306-a7b0-43fd-b616-e9a85ff7e8f8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-21882",
      "pattern": "[vulnerability:name = 'CVE-2022-21882']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-21882 \u2014 Microsoft Win32k Privilege Escala",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--15d2a634-dbfb-4c7d-ab8b-b3188164a963",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-1776",
      "pattern": "[vulnerability:name = 'CVE-2014-1776']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-1776 \u2014 Microsoft Internet Explorer Memory",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eee4d011-016f-4e95-9aa7-c5ebb2804f45",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-5689",
      "pattern": "[vulnerability:name = 'CVE-2017-5689']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-5689 \u2014 Intel Active Management Technology",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ae8c798c-5164-46b3-83a9-ced7a0463bd0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-0787",
      "pattern": "[vulnerability:name = 'CVE-2020-0787']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-0787 \u2014 Microsoft Windows Background Intel",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b5b30d2-b330-4cee-a15e-d0791b55d66e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-5722",
      "pattern": "[vulnerability:name = 'CVE-2020-5722']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-5722 \u2014 Grandstream Networks UCM6200 Serie",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2080abc0-ff0a-4a89-916c-54cbbc74f6a2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2022-22587",
      "pattern": "[vulnerability:name = 'CVE-2022-22587']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2022-22587 \u2014 Apple Memory Corruption Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5609741c-7192-489c-b7d0-d792f4517020",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: evil.com",
      "pattern": "[domain-name:value = 'evil.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Stranger Danger: Live hack of how a Log4Shell exploit works",
          "url": "https://snyk.io/blog/stranger-danger-live-hack-log4shell-exploit/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--22e27fd2-7150-4cd5-922c-916f25e0b82a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2006-1547",
      "pattern": "[vulnerability:name = 'CVE-2006-1547']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2006-1547 \u2014 Apache Struts 1 ActionForm Denial-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5e821d88-0bf9-4e58-94b3-042fc7fc894b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-0391",
      "pattern": "[vulnerability:name = 'CVE-2012-0391']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-0391 \u2014 Apache Struts 2 Improper Input Val",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2d18fca2-fe5a-4cf0-8ee7-a343b362b824",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-8453",
      "pattern": "[vulnerability:name = 'CVE-2018-8453']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-8453 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8e05b6fa-242c-4e01-b380-e12f413e2f2c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-35247",
      "pattern": "[vulnerability:name = 'CVE-2021-35247']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-35247 \u2014 SolarWinds Serv-U Improper Input ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--197f326f-62fa-4987-92fc-83aa1587dcf5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: api.rogerscorp.org",
      "pattern": "[domain-name:value = 'api.rogerscorp.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-35247 \u2014 SolarWinds Serv-U Improper Input ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7d54ba58-30c2-47bf-a9f9-3f7986a064f4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: api.sophosantivirus.ga",
      "pattern": "[domain-name:value = 'api.sophosantivirus.ga']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-35247 \u2014 SolarWinds Serv-U Improper Input ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a72e9da8-e440-4e09-9167-5e6a78288aff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: apicon.nvidialab.us",
      "pattern": "[domain-name:value = 'apicon.nvidialab.us']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-35247 \u2014 SolarWinds Serv-U Improper Input ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4ea1c665-b5c5-49e6-a439-0e35f754134d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: service.trendmrcio.com",
      "pattern": "[domain-name:value = 'service.trendmrcio.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-35247 \u2014 SolarWinds Serv-U Improper Input ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--266bd404-9c83-4128-a4d3-c2a6f28e9fea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: shelves-design.com",
      "pattern": "[domain-name:value = 'shelves-design.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-8453 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--17e84a48-269d-4f3a-8b29-36bb10f8add4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: w2zmii7kjb81pfj0ped16kg8szyvmk.burpcollaborator.net",
      "pattern": "[domain-name:value = 'w2zmii7kjb81pfj0ped16kg8szyvmk.burpcollaborator.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-35247 \u2014 SolarWinds Serv-U Improper Input ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4b4b8d44-ce33-4af8-99d4-4d90b9b73269",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: weekendstrips.net",
      "pattern": "[domain-name:value = 'weekendstrips.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-8453 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a065bcc4-8543-465a-a949-8d7e376a60f0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 139.180.217.203",
      "pattern": "[ipv4-addr:value = '139.180.217.203']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-35247 \u2014 SolarWinds Serv-U Improper Input ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--45c05c94-85ed-4592-a58e-2de9beeb89e3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-11978",
      "pattern": "[vulnerability:name = 'CVE-2020-11978']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-11978 \u2014 Apache Airflow Command Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d1ec2522-18f4-4f45-b10e-fed33e1e1f31",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-13671",
      "pattern": "[vulnerability:name = 'CVE-2020-13671']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-13671 \u2014 Drupal core Un-restricted Upload ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--22d12546-dc6f-4a02-ad9d-0b94825965aa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-13927",
      "pattern": "[vulnerability:name = 'CVE-2020-13927']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-13927 \u2014 Apache Airflow's Experimental API",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1db46205-ad5f-40ad-bf29-21290eb24bc2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-14864",
      "pattern": "[vulnerability:name = 'CVE-2020-14864']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-14864 \u2014 Oracle Business Intelligence Ente",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f47dab1d-7da8-41ec-964c-07dcb0ed7c40",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-21315",
      "pattern": "[vulnerability:name = 'CVE-2021-21315']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21315 \u2014 System Information Library for No",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de5da5a6-4821-4c3b-b58a-488fc29b60a8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-21975",
      "pattern": "[vulnerability:name = 'CVE-2021-21975']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21975 \u2014 VMware Server Side Request Forger",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3afcb052-b2ba-477c-88c3-7ee4926ad85b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-21983",
      "pattern": "[vulnerability:name = 'CVE-2021-21983']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21975 \u2014 VMware Server Side Request Forger",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ed3d5528-1e37-47ba-8d15-92711c8e93c7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-22991",
      "pattern": "[vulnerability:name = 'CVE-2021-22991']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-22991 \u2014 F5 BIG-IP Traffic Management Micr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--05ad6784-0ad5-4319-a908-a885b3db45f9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-25296",
      "pattern": "[vulnerability:name = 'CVE-2021-25296']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-25296 \u2014 Nagios XI OS Command Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0aa9c39c-73ee-4242-b298-dec43980d325",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-25297",
      "pattern": "[vulnerability:name = 'CVE-2021-25297']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-25297 \u2014 Nagios XI OS Command Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--db38dac9-58b2-4919-8b55-d40d82c5fd46",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-25298",
      "pattern": "[vulnerability:name = 'CVE-2021-25298']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-25298 \u2014 Nagios XI OS Command Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--947341c6-4173-4248-b816-c231a9ef49b8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-32648",
      "pattern": "[vulnerability:name = 'CVE-2021-32648']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-32648 \u2014 October CMS Improper Authenticati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a67db5de-713e-4f9b-8e3a-2fd2e322f668",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-33766",
      "pattern": "[vulnerability:name = 'CVE-2021-33766']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-33766 \u2014 Microsoft Exchange Server Informa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cef4d9e4-5d6e-473e-8730-5aa241ab0098",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-40870",
      "pattern": "[vulnerability:name = 'CVE-2021-40870']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-40870 \u2014 Aviatrix Controller Unrestricted ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cfff902f-0194-4aae-8b93-65089d422538",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a196c6b8ffcb97ffb276d04f354696e2391311db3841ae16c8c9f56f36a38e92",
      "pattern": "[file:hashes.'SHA-256' = 'a196c6b8ffcb97ffb276d04f354696e2391311db3841ae16c8c9f56f36a38e92']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-32648 \u2014 October CMS Improper Authenticati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4039bd57-4be6-4441-b949-a8c9aa3b6d7d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: brianvermeer.nl",
      "pattern": "[domain-name:value = 'brianvermeer.nl']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New years resolution: Don\u2019t show my security tokens when hac",
          "url": "https://snyk.io/blog/dont-show-security-tokens-on-stage/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5291b84a-23d0-41c1-9bb4-fb9f24690a97",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2013-3900",
      "pattern": "[vulnerability:name = 'CVE-2013-3900']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2013-3900 \u2014 Microsoft WinVerifyTrust function ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bcae199f-29d4-44bc-aa4c-767f634bf3d6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-7450",
      "pattern": "[vulnerability:name = 'CVE-2015-7450']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-7450 \u2014 IBM WebSphere Application Server a",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--404fef2f-d1fe-4e30-8163-71173987ee5c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-1000486",
      "pattern": "[vulnerability:name = 'CVE-2017-1000486']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-1000486 \u2014 Primetek Primefaces Remote Code",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76bf30a2-0cfb-4391-8671-33267a0e133f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-13382",
      "pattern": "[vulnerability:name = 'CVE-2018-13382']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-13382 \u2014 Fortinet FortiOS and FortiProxy I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6a017af4-ca32-4e29-a0b3-eed624d1e7b7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-13383",
      "pattern": "[vulnerability:name = 'CVE-2018-13383']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-13383 \u2014 Fortinet FortiOS and FortiProxy O",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fd5892c5-f202-4ee5-8ac3-f8c31c99cb3f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-1579",
      "pattern": "[vulnerability:name = 'CVE-2019-1579']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1579 \u2014 Palo Alto Networks PAN-OS Remote C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--93e50811-07e9-40cb-9249-616c4d33c020",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-7609",
      "pattern": "[vulnerability:name = 'CVE-2019-7609']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-7609 \u2014 Kibana Arbitrary Code Execution",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d1ef9ce0-ca48-4e37-81f3-76c362e242b8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-6572",
      "pattern": "[vulnerability:name = 'CVE-2020-6572']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-6572 \u2014 Google Chrome Media Use-After-Free",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5143f450-12a0-4093-84f9-e2e0bbeefc37",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-22017",
      "pattern": "[vulnerability:name = 'CVE-2021-22017']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-22017 \u2014 VMware vCenter Server Improper Ac",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--33988568-0dc7-409f-be37-b57d503f9f60",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-23385",
      "pattern": "[vulnerability:name = 'CVE-2021-23385']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "URL confusion vulnerabilities in the wild: Exploring parser ",
          "url": "https://snyk.io/blog/url-confusion-vulnerabilities/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--037c1024-6958-4a0f-8886-291ed5e0c7e1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-23393",
      "pattern": "[vulnerability:name = 'CVE-2021-23393']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "URL confusion vulnerabilities in the wild: Exploring parser ",
          "url": "https://snyk.io/blog/url-confusion-vulnerabilities/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ea43a92-1d1d-4112-99f2-4e3220ee02d2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-23401",
      "pattern": "[vulnerability:name = 'CVE-2021-23401']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "URL confusion vulnerabilities in the wild: Exploring parser ",
          "url": "https://snyk.io/blog/url-confusion-vulnerabilities/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ad3b5468-2eeb-4887-9a3c-4038769c58a7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-23414",
      "pattern": "[vulnerability:name = 'CVE-2021-23414']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "URL confusion vulnerabilities in the wild: Exploring parser ",
          "url": "https://snyk.io/blog/url-confusion-vulnerabilities/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe3d867b-60a9-403b-b742-d713e37a7f6e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-23435",
      "pattern": "[vulnerability:name = 'CVE-2021-23435']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "URL confusion vulnerabilities in the wild: Exploring parser ",
          "url": "https://snyk.io/blog/url-confusion-vulnerabilities/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--611cbb8a-1917-4e18-b675-17b3bc4820f6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-27860",
      "pattern": "[vulnerability:name = 'CVE-2021-27860']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27860 \u2014 FatPipe WARP, IPVPN, and MPVPN Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3189ab78-fbc7-4bf7-a6f6-48413a59f578",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-32618",
      "pattern": "[vulnerability:name = 'CVE-2021-32618']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "URL confusion vulnerabilities in the wild: Exploring parser ",
          "url": "https://snyk.io/blog/url-confusion-vulnerabilities/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a7c06a45-b45b-4367-8dbd-45d0732b0883",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-33056",
      "pattern": "[vulnerability:name = 'CVE-2021-33056']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "URL confusion vulnerabilities in the wild: Exploring parser ",
          "url": "https://snyk.io/blog/url-confusion-vulnerabilities/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--040c2637-39e9-45ed-8421-84bbe1fffe93",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-37352",
      "pattern": "[vulnerability:name = 'CVE-2021-37352']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "URL confusion vulnerabilities in the wild: Exploring parser ",
          "url": "https://snyk.io/blog/url-confusion-vulnerabilities/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--deb316d1-5420-4cb3-b68d-8fa2d52be0b5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: arg0s-co.uk",
      "pattern": "[domain-name:value = 'arg0s-co.uk']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9a29ef73-24ac-4287-97ff-e7a5ffe4f7bd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: hostapp.be",
      "pattern": "[domain-name:value = 'hostapp.be']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-10149 \u2014 Exim Mail Transfer Agent (MTA) Im",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--242c9c2b-76c0-4f13-beec-388c839d3eb6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: life.zerobytes.cc",
      "pattern": "[domain-name:value = 'life.zerobytes.cc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-36260 \u2014 Hikvision Improper Input Validati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--043adf4b-3559-4fe0-a979-4615a28c162e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: projectstore.guru",
      "pattern": "[domain-name:value = 'projectstore.guru']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--737ca606-7eb6-4009-a4b0-f8eacc62feb3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.94.157.5",
      "pattern": "[ipv4-addr:value = '103.94.157.5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-10149 \u2014 Exim Mail Transfer Agent (MTA) Im",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b5435cb0-68b0-4b79-8287-f27118be6678",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 130.61.54.136",
      "pattern": "[ipv4-addr:value = '130.61.54.136']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cafdd52d-b283-4c48-a291-70303b7f3b52",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 165.227.78.159",
      "pattern": "[ipv4-addr:value = '165.227.78.159']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f8d6a33f-fb78-4137-82ee-1317cd9c1aa9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 173.212.214.137",
      "pattern": "[ipv4-addr:value = '173.212.214.137']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-10149 \u2014 Exim Mail Transfer Agent (MTA) Im",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--03e6370c-c281-4929-b43e-64c3b0d3357f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.106.120.118",
      "pattern": "[ipv4-addr:value = '185.106.120.118']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-9670 \u2014 Synacor Zimbra Collaboration Suite",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f57cf8cc-08ee-48b8-b50b-aa38f33fc5a2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 199.195.250.233",
      "pattern": "[ipv4-addr:value = '199.195.250.233']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-36260 \u2014 Hikvision Improper Input Validati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cc2cdcef-664a-43a2-99f4-2a9e7e50efd3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.146.165.123",
      "pattern": "[ipv4-addr:value = '45.146.165.123']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-9670 \u2014 Synacor Zimbra Collaboration Suite",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff26e80b-d653-49b9-bd00-1d5a0491eb06",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.55.211.79",
      "pattern": "[ipv4-addr:value = '45.55.211.79']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--983d155e-7748-4e14-a00a-eb23f2ae8578",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 95.216.13.196",
      "pattern": "[ipv4-addr:value = '95.216.13.196']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-10149 \u2014 Exim Mail Transfer Agent (MTA) Im",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f42def8c-4816-4d05-b07a-1b368a10574d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 0fa207940ea53e2b54a2b769d8ab033a6b2c5e08c78bf4d7dade79849960b54d",
      "pattern": "[file:hashes.'SHA-256' = '0fa207940ea53e2b54a2b769d8ab033a6b2c5e08c78bf4d7dade79849960b54d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2affe032-9686-461d-9913-040ce44b3376",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1dce6f3ba4a8d355df21a17584c514697ee0c37b51ab5657bc5b3a297b65955f",
      "pattern": "[file:hashes.'SHA-256' = '1dce6f3ba4a8d355df21a17584c514697ee0c37b51ab5657bc5b3a297b65955f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-36260 \u2014 Hikvision Improper Input Validati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d450dc88-2e0f-4e4a-9b43-17eb08aa9992",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 34dffdb04ca07b014cdaee857690f86e490050335291ccc84c94994fa91e0160",
      "pattern": "[file:hashes.'SHA-256' = '34dffdb04ca07b014cdaee857690f86e490050335291ccc84c94994fa91e0160']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8a7582b3-0e69-4806-abbe-ee3e3a427f1f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 38414bb5850a7076f4b33bf81bac9db0376a4df188355fac39d80193d7c7f557",
      "pattern": "[file:hashes.'SHA-256' = '38414bb5850a7076f4b33bf81bac9db0376a4df188355fac39d80193d7c7f557']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-36260 \u2014 Hikvision Improper Input Validati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2244a143-25fc-439b-bd3e-a51e71942314",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 74bc2f9a81ad2cc609b7730dbabb146506f58244e5e655cbb42044913384a6ac",
      "pattern": "[file:hashes.'SHA-256' = '74bc2f9a81ad2cc609b7730dbabb146506f58244e5e655cbb42044913384a6ac']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4fa46303-4593-4011-9f4b-2bab41c2b146",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 95ac3903127b74f8e4d73d987f5e3736f5bdd909ba756260e187b6bf53fb1a05",
      "pattern": "[file:hashes.'SHA-256' = '95ac3903127b74f8e4d73d987f5e3736f5bdd909ba756260e187b6bf53fb1a05']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a9353450-720c-4286-8ee2-23146490a076",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: fa2bccdb9db2583c2f9ff6a536e824f4311c9a8a9842505a0323f027b8b51451",
      "pattern": "[file:hashes.'SHA-256' = 'fa2bccdb9db2583c2f9ff6a536e824f4311c9a8a9842505a0323f027b8b51451']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--72987e37-caee-4bb5-ac33-48570ce7d085",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-23567",
      "pattern": "[vulnerability:name = 'CVE-2021-23567']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Open source maintainer pulls the plug on npm packages colors",
          "url": "https://snyk.io/blog/open-source-npm-packages-colors-faker/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9be7f3ec-9fac-4387-ba9f-82bee15beafb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-44832",
      "pattern": "[vulnerability:name = 'CVE-2021-44832']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New Log4j 2.17.1 fixes CVE-2021-44832 remote code execution ",
          "url": "https://snyk.io/blog/new-log4j-2-17-1-fixes-cve-2021-44832-remote-code-execution-but-its-not-as-bad-as-it-sounds/"
        },
        {
          "source_name": "Log4j 2.15 vulnerability CVE-2021-45046 upgraded to a critic",
          "url": "https://snyk.io/blog/log4j-2-15-vulnerability-cve-2021-45046-critical-ace/"
        },
        {
          "source_name": "Log4Shell in a nutshell (for non-developers & non-Java devel",
          "url": "https://snyk.io/blog/log4shell-in-a-nutshell/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--42ad696a-ded8-4d55-9382-fa96074582d2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-4104",
      "pattern": "[vulnerability:name = 'CVE-2021-4104']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "New Log4j 2.17.1 fixes CVE-2021-44832 remote code execution ",
          "url": "https://snyk.io/blog/new-log4j-2-17-1-fixes-cve-2021-44832-remote-code-execution-but-its-not-as-bad-as-it-sounds/"
        },
        {
          "source_name": "Log4j 2.15 vulnerability CVE-2021-45046 upgraded to a critic",
          "url": "https://snyk.io/blog/log4j-2-15-vulnerability-cve-2021-45046-critical-ace/"
        },
        {
          "source_name": "Security in context: When is a CVE not a CVE?",
          "url": "https://snyk.io/blog/when-is-a-cve-not-a-cve/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2708d8f5-b220-402c-baa9-bfff700e667d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-42550",
      "pattern": "[vulnerability:name = 'CVE-2021-42550']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Security in context: When is a CVE not a CVE?",
          "url": "https://snyk.io/blog/when-is-a-cve-not-a-cve/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e120ccab-33ae-490f-a7a1-5bf142cf002f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-4102",
      "pattern": "[vulnerability:name = 'CVE-2021-4102']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-4102 \u2014 Google Chromium V8 Use-After-Free ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a50064b6-c0c9-4abf-ba37-f0694fd32503",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-43890",
      "pattern": "[vulnerability:name = 'CVE-2021-43890']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-43890 \u2014 Microsoft Windows AppX Installer ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5b654264-7577-45e3-8b04-a9e179926f56",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-1871",
      "pattern": "[vulnerability:name = 'CVE-2010-1871']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-1871 \u2014 Red Hat Linux JBoss Seam 2 Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0c7cc3d6-f855-4b30-a75a-d21aad4e09d5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-12149",
      "pattern": "[vulnerability:name = 'CVE-2017-12149']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-12149 \u2014 Red Hat JBoss Application Server ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2010-1871 \u2014 Red Hat Linux JBoss Seam 2 Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d96b6696-7676-492d-8aa9-c2fdb8a747fd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-17562",
      "pattern": "[vulnerability:name = 'CVE-2017-17562']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-17562 \u2014 Embedthis GoAhead Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e740bd1-d01c-4d1c-89b1-a5994d79437a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-0193",
      "pattern": "[vulnerability:name = 'CVE-2019-0193']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-0193 \u2014 Apache Solr DataImportHandler Code",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--77eb8c3b-cb60-49ce-b0f9-d4da6900ccf1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-10758",
      "pattern": "[vulnerability:name = 'CVE-2019-10758']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-10758 \u2014 MongoDB mongo-express Remote Code",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b2b6e755-a48e-4678-98a4-67c7adcbd6b2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-13272",
      "pattern": "[vulnerability:name = 'CVE-2019-13272']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-13272 \u2014 Linux Kernel Improper Privilege M",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b4224766-6546-4bb2-b21f-bc2ccbaf4761",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-17463",
      "pattern": "[vulnerability:name = 'CVE-2020-17463']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-17463 \u2014 Fuel CMS SQL Injection Vulnerabil",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--916af2d9-70fc-4d4c-a38d-dee516da4850",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-8816",
      "pattern": "[vulnerability:name = 'CVE-2020-8816']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-8816 \u2014 Pi-Hole AdminLTE Remote Code Execu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--821aa005-fa11-4332-ab3c-0ed3b8f53bdb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-35394",
      "pattern": "[vulnerability:name = 'CVE-2021-35394']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-35394 \u2014 Realtek Jungle SDK Remote Code Ex",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b432f4c2-0869-425a-a511-27a53f1e3504",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-44168",
      "pattern": "[vulnerability:name = 'CVE-2021-44168']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44168 \u2014 Fortinet FortiOS Arbitrary File D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9b08f8ea-7ae6-404f-bd83-2fd79c04d233",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-44515",
      "pattern": "[vulnerability:name = 'CVE-2021-44515']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44515 \u2014 Zoho Desktop Central Authenticati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--997f6bce-7b32-4d9a-9656-12e03694c356",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.149.137.124",
      "pattern": "[ipv4-addr:value = '103.149.137.124']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-35394 \u2014 Realtek Jungle SDK Remote Code Ex",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3905ae59-a4fe-4dc5-8da3-e2e50b8d8ea1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 135.148.104.21",
      "pattern": "[ipv4-addr:value = '135.148.104.21']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-35394 \u2014 Realtek Jungle SDK Remote Code Ex",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dbdef26b-d4e7-4533-98ea-7afb53a4de44",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 172.81.41.196",
      "pattern": "[ipv4-addr:value = '172.81.41.196']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-35394 \u2014 Realtek Jungle SDK Remote Code Ex",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a6a605ff-a6c2-4768-91f6-2be340e3b5eb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.205.12.157",
      "pattern": "[ipv4-addr:value = '185.205.12.157']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-35394 \u2014 Realtek Jungle SDK Remote Code Ex",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e5b99a42-9271-414c-a171-869409bc3610",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 199.195.251.190",
      "pattern": "[ipv4-addr:value = '199.195.251.190']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-35394 \u2014 Realtek Jungle SDK Remote Code Ex",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4f21c938-9eff-4a5a-9210-0bec17e9a171",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 9809bdf6e9981fbc3ad515b731124342",
      "pattern": "[file:hashes.MD5 = '9809bdf6e9981fbc3ad515b731124342']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44515 \u2014 Zoho Desktop Central Authenticati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3f5b22d9-add2-4a16-9e74-293466718b11",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 178.62.86.114",
      "pattern": "[ipv4-addr:value = '178.62.86.114']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Responsible disclosure: CodeCov CEO & CTO share learnings fr",
          "url": "https://snyk.io/blog/codecov-ceo-cto-share-learnings-from-breach-tsd/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a518406f-0cd7-4055-8c0f-5e24f74dbfcc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.211.156.78",
      "pattern": "[ipv4-addr:value = '185.211.156.78']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Responsible disclosure: CodeCov CEO & CTO share learnings fr",
          "url": "https://snyk.io/blog/codecov-ceo-cto-share-learnings-from-breach-tsd/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--13a3ae92-b8e7-4d17-9249-b2b7b2629262",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 79.135.72.34",
      "pattern": "[ipv4-addr:value = '79.135.72.34']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Responsible disclosure: CodeCov CEO & CTO share learnings fr",
          "url": "https://snyk.io/blog/codecov-ceo-cto-share-learnings-from-breach-tsd/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b079fe7e-0bea-4246-ab11-f8de6772c94b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-5481",
      "pattern": "[vulnerability:name = 'CVE-2019-5481']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk Open Source adds beta C/C++ security scanning for unman",
          "url": "https://snyk.io/blog/snyk-launches-beta-support-for-cpp/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d4884bf0-b53a-4929-a9fd-97143bf72020",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-5482",
      "pattern": "[vulnerability:name = 'CVE-2019-5482']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk Open Source adds beta C/C++ security scanning for unman",
          "url": "https://snyk.io/blog/snyk-launches-beta-support-for-cpp/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--220d34c0-417b-4648-8787-bf7d26d89cf8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-8285",
      "pattern": "[vulnerability:name = 'CVE-2020-8285']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk Open Source adds beta C/C++ security scanning for unman",
          "url": "https://snyk.io/blog/snyk-launches-beta-support-for-cpp/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1d317cdf-f3ad-43df-919f-30eb19c75d2a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-8286",
      "pattern": "[vulnerability:name = 'CVE-2020-8286']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk Open Source adds beta C/C++ security scanning for unman",
          "url": "https://snyk.io/blog/snyk-launches-beta-support-for-cpp/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f2473532-f316-47fa-9533-d746339da73b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-22876",
      "pattern": "[vulnerability:name = 'CVE-2021-22876']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk Open Source adds beta C/C++ security scanning for unman",
          "url": "https://snyk.io/blog/snyk-launches-beta-support-for-cpp/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aed7f42e-6807-4d4a-adee-6967b1dd8807",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-22898",
      "pattern": "[vulnerability:name = 'CVE-2021-22898']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk Open Source adds beta C/C++ security scanning for unman",
          "url": "https://snyk.io/blog/snyk-launches-beta-support-for-cpp/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fdc51e22-8f80-4029-9554-473e52ac15af",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-14847",
      "pattern": "[vulnerability:name = 'CVE-2018-14847']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-14847 \u2014 MikroTik Router OS Directory Trav",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3ff84ad3-4c55-4929-bc46-ee5672e789c1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-37415",
      "pattern": "[vulnerability:name = 'CVE-2021-37415']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-37415 \u2014 Zoho ManageEngine ServiceDesk Aut",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a65e497-d420-4727-a771-117d5e6710ba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-40438",
      "pattern": "[vulnerability:name = 'CVE-2021-40438']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-40438 \u2014 Apache HTTP Server-Side Request F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c9be539d-4a1f-444a-a309-8cd816c62c4c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-40539",
      "pattern": "[vulnerability:name = 'CVE-2021-40539']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44077 \u2014 Zoho ManageEngine ServiceDesk Plu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-40539 \u2014 Zoho ManageEngine ADSelfService P",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e6f0ba51-c8d5-4614-a217-30ab36807315",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-44077",
      "pattern": "[vulnerability:name = 'CVE-2021-44077']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44077 \u2014 Zoho ManageEngine ServiceDesk Plu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eaf8f58c-2f20-4cf7-a6ee-4d8c46a35866",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 67ee552d7c1d46885b91628c603f24b66a9755858e098748f7e7862a71baa015",
      "pattern": "[file:hashes.'SHA-256' = '67ee552d7c1d46885b91628c603f24b66a9755858e098748f7e7862a71baa015']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44077 \u2014 Zoho ManageEngine ServiceDesk Plu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5ac533db-dde4-4cc9-a661-46f2254d6a32",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ecd8c9967b0127a12d6db61964a82970ee5d38f82618d5db4d8eddbb3b5726b7",
      "pattern": "[file:hashes.'SHA-256' = 'ecd8c9967b0127a12d6db61964a82970ee5d38f82618d5db4d8eddbb3b5726b7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-44077 \u2014 Zoho ManageEngine ServiceDesk Plu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--98e08d7b-b102-454b-b5de-27f969df571c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-12384",
      "pattern": "[vulnerability:name = 'CVE-2019-12384']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Java JSON deserialization problems with the Jackson ObjectMa",
          "url": "https://snyk.io/blog/java-json-deserialization-problems-jackson-objectmapper/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f515966-3c94-4df9-9ee9-70fe1c96525a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-22204",
      "pattern": "[vulnerability:name = 'CVE-2021-22204']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-22204 \u2014 ExifTool Remote Code Execution Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-22205 \u2014 GitLab Community and Enterprise E",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2dcb6012-5a23-4a28-9faa-f2092a8aa0e3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-40449",
      "pattern": "[vulnerability:name = 'CVE-2021-40449']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-40449 \u2014 Microsoft Windows Win32k Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c3dc5a3c-0e5a-4c0e-add8-9a2b71147983",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-42292",
      "pattern": "[vulnerability:name = 'CVE-2021-42292']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-42292 \u2014 Microsoft Excel Security Feature ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b956fffe-63d0-4759-a83b-ca974aa1cdb1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-42321",
      "pattern": "[vulnerability:name = 'CVE-2021-42321']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-42321 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--af75e172-8f78-446f-9d1d-ed488bdaed97",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2010-5326",
      "pattern": "[vulnerability:name = 'CVE-2010-5326']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2010-5326 \u2014 SAP NetWeaver Remote Code Executio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6f0d3dd2-b5fd-455b-a47a-88d02206ee58",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-3152",
      "pattern": "[vulnerability:name = 'CVE-2012-3152']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-3152 \u2014 Oracle Fusion Middleware Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9e12eee0-4c46-49ff-90d3-9ce1483dc84f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2012-3153",
      "pattern": "[vulnerability:name = 'CVE-2012-3153']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2012-3152 \u2014 Oracle Fusion Middleware Unspecifi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--59bf3411-52f9-4e52-872e-6612b10452c0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2014-1812",
      "pattern": "[vulnerability:name = 'CVE-2014-1812']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2014-1812 \u2014 Microsoft Windows Group Policy Pre",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ad2dbf83-2c6f-4a92-b16d-743e56467dd6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-1641",
      "pattern": "[vulnerability:name = 'CVE-2015-1641']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-1641 \u2014 Microsoft Office Memory Corruption",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--17efb81f-a50e-4961-a74b-de7b31dc263e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-1805",
      "pattern": "[vulnerability:name = 'CVE-2015-1805']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-2215 \u2014 Android Kernel Use-After-Free Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0c912b9-d5bd-4e0c-bd7d-743b92164676",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-3636",
      "pattern": "[vulnerability:name = 'CVE-2015-3636']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-2215 \u2014 Android Kernel Use-After-Free Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f27f1578-a4a7-4f5d-a9a5-e09788f9ca8e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2015-4852",
      "pattern": "[vulnerability:name = 'CVE-2015-4852']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2015-4852 \u2014 Oracle WebLogic Server Deserializa",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6624e370-ecf2-4f4b-8b15-c44d7e7c0ad2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-0167",
      "pattern": "[vulnerability:name = 'CVE-2016-0167']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-0167 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-7255 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--458a2cf3-b02a-40bb-8265-dda1c18d25e2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-0185",
      "pattern": "[vulnerability:name = 'CVE-2016-0185']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-0185 \u2014 Microsoft Windows Media Center Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cbe8d816-e543-4895-8763-b62c8a050550",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-3235",
      "pattern": "[vulnerability:name = 'CVE-2016-3235']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-3235 \u2014 Microsoft Office OLE DLL Side Load",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a089b53d-e17d-44e0-845e-4ae951e2e231",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-3643",
      "pattern": "[vulnerability:name = 'CVE-2016-3643']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-3643 \u2014 SolarWinds Virtualization Manager ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8a236aef-3fb2-4059-9207-57bd7fc92ebd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-3715",
      "pattern": "[vulnerability:name = 'CVE-2016-3715']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-3715 \u2014 ImageMagick Arbitrary File Deletio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--96572f8a-5740-4059-b99b-951285ec6780",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-3718",
      "pattern": "[vulnerability:name = 'CVE-2016-3718']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-3718 \u2014 ImageMagick Server-Side Request Fo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b19894a2-9827-4be7-b4dd-df9b35ddc356",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-3976",
      "pattern": "[vulnerability:name = 'CVE-2016-3976']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-2380 \u2014 SAP Customer Relationship Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2016-3976 \u2014 SAP NetWeaver Directory Traversal ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--61086839-9c7e-4ab3-b683-bc257a3e7a35",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-4437",
      "pattern": "[vulnerability:name = 'CVE-2016-4437']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-4437 \u2014 Apache Shiro Code Execution Vulner",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ac06edd-843f-4afe-bb7f-7a4cb96dd96e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-9563",
      "pattern": "[vulnerability:name = 'CVE-2016-9563']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2016-9563 \u2014 SAP NetWeaver XML External Entity ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--abca3b69-e462-4bc2-839b-3a3a981a15fd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-0143",
      "pattern": "[vulnerability:name = 'CVE-2017-0143']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0143 \u2014 Microsoft Windows Server Message B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e1f3a59c-efb5-4544-9b20-9fbfac9b7d0d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-0199",
      "pattern": "[vulnerability:name = 'CVE-2017-0199']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-0199 \u2014 Microsoft Office and WordPad Remot",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--58c41d3d-db96-403c-ae9f-852375475c22",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-11774",
      "pattern": "[vulnerability:name = 'CVE-2017-11774']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11774 \u2014 Microsoft Office Outlook Security",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fbad70d6-640d-44de-84ca-33e82920b7b1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-11882",
      "pattern": "[vulnerability:name = 'CVE-2017-11882']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-11882 \u2014 Microsoft Office Memory Corruptio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5eae8097-7b70-4aa6-8528-4a2ecc41282e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-16651",
      "pattern": "[vulnerability:name = 'CVE-2017-16651']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-16651 \u2014 Roundcube Webmail File Disclosure",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a907b23c-ac5f-4dda-b8d6-77be45e81b7b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-5638",
      "pattern": "[vulnerability:name = 'CVE-2017-5638']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-5638 \u2014 Apache Struts Remote Code Executio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4b84d05b-98c9-4813-b386-d55fdcb03b28",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-6327",
      "pattern": "[vulnerability:name = 'CVE-2017-6327']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-6327 \u2014 Symantec Messaging Gateway Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--614f6c4f-3c98-4248-a4f7-be33897ede78",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-7269",
      "pattern": "[vulnerability:name = 'CVE-2017-7269']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--367c7c73-3d2e-4c82-be25-acacc3e4a10c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-8759",
      "pattern": "[vulnerability:name = 'CVE-2017-8759']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-8759 \u2014 Microsoft .NET Framework Remote Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2017-0199 \u2014 Microsoft Office and WordPad Remot",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--398b3708-df31-4bf4-9fa3-0bff1be34470",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-9805",
      "pattern": "[vulnerability:name = 'CVE-2017-9805']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-9805 \u2014 Apache Struts Deserialization of U",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d4109c66-aa09-4233-a4ac-f7fef6bbee1e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-9822",
      "pattern": "[vulnerability:name = 'CVE-2017-9822']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-9822 \u2014 DotNetNuke (DNN) Remote Code Execu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--80b928a4-0588-4b71-8ca1-c07e424dcd03",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-0171",
      "pattern": "[vulnerability:name = 'CVE-2018-0171']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0171 \u2014 Cisco IOS and IOS XE Software Smar",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--66c9fceb-c30c-4d58-806a-53cee9454c80",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-0296",
      "pattern": "[vulnerability:name = 'CVE-2018-0296']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0296 \u2014 Cisco Adaptive Security Appliance ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1a1be84c-b5a0-4b17-9a54-aa23b669f633",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-0798",
      "pattern": "[vulnerability:name = 'CVE-2018-0798']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0798 \u2014 Microsoft Office Memory Corruption",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ef0c49e-099c-477d-a57a-c5d406a4d46e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-0802",
      "pattern": "[vulnerability:name = 'CVE-2018-0802']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0798 \u2014 Microsoft Office Memory Corruption",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--037c064f-de62-4a8e-90bb-fc812fc66471",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-11776",
      "pattern": "[vulnerability:name = 'CVE-2018-11776']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-11776 \u2014 Apache Struts Remote Code Executi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--83ff562b-cd76-402e-addb-ed4ae7851e9d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-13379",
      "pattern": "[vulnerability:name = 'CVE-2018-13379']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-13379 \u2014 Fortinet FortiOS SSL VPN Path Tra",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de509c8e-062b-4d1c-9d94-77623fccbf88",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-15811",
      "pattern": "[vulnerability:name = 'CVE-2018-15811']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-15811 \u2014 DotNetNuke (DNN) Inadequate Encry",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--784ed6c8-b005-451d-93de-a7baa84a66b1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-15961",
      "pattern": "[vulnerability:name = 'CVE-2018-15961']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-15961 \u2014 Adobe ColdFusion Unrestricted Fil",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bfed1469-18cc-4725-bc15-2306fc53f938",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-18325",
      "pattern": "[vulnerability:name = 'CVE-2018-18325']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-15811 \u2014 DotNetNuke (DNN) Inadequate Encry",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--06b1887d-94bd-43fd-b22e-73acb80d75b0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-20062",
      "pattern": "[vulnerability:name = 'CVE-2018-20062']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-20062 \u2014 ThinkPHP \"noneCms\" Remote Code Ex",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eba870cf-8347-4a71-baf4-6e4c055e64a7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-2380",
      "pattern": "[vulnerability:name = 'CVE-2018-2380']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-2380 \u2014 SAP Customer Relationship Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d75d064e-9783-4fbb-aa3e-da4e50ddac8c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-4878",
      "pattern": "[vulnerability:name = 'CVE-2018-4878']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-4878 \u2014 Adobe Flash Player Use-After-Free ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c825426-bcad-460b-8bdb-bb564cb59e20",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-4939",
      "pattern": "[vulnerability:name = 'CVE-2018-4939']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-4939 \u2014 Adobe ColdFusion Deserialization o",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b5a337ed-48fb-4ee0-ac12-294c5c81c237",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-6789",
      "pattern": "[vulnerability:name = 'CVE-2018-6789']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-6789 \u2014 Exim Buffer Overflow Vulnerability",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b7640a89-8a59-453c-a49f-8adf795c7843",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-8653",
      "pattern": "[vulnerability:name = 'CVE-2018-8653']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-8653 \u2014 Microsoft Internet Explorer Script",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b082604d-2c2f-499a-ba30-86c61e2fe88a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-0211",
      "pattern": "[vulnerability:name = 'CVE-2019-0211']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-0211 \u2014 Apache HTTP Server Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--92181f89-f798-4076-9cb1-319b26d202de",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-0541",
      "pattern": "[vulnerability:name = 'CVE-2019-0541']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-0541 \u2014 Microsoft MSHTML Remote Code Execu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fcab46d0-9175-49cd-955e-4e4099845ca1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-0604",
      "pattern": "[vulnerability:name = 'CVE-2019-0604']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-0604 \u2014 Microsoft SharePoint Remote Code E",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9754e96b-20e6-4bf3-9112-39d85416a3c6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-0797",
      "pattern": "[vulnerability:name = 'CVE-2019-0797']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-0797 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c834e3d-215c-42f3-88a1-0cc369c3066b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-0803",
      "pattern": "[vulnerability:name = 'CVE-2019-0803']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-0803 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-1215 \u2014 Microsoft Windows Privilege Escala",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--994e27ec-42b1-41e4-8c82-227de59b290c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-0859",
      "pattern": "[vulnerability:name = 'CVE-2019-0859']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-0859 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d1c0c1c9-cc91-4fc1-9e29-1691963216d6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-0863",
      "pattern": "[vulnerability:name = 'CVE-2019-0863']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-0863 \u2014 Microsoft Windows Error Reporting ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--46fb134a-a583-470c-86fa-004e36ad6587",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-11510",
      "pattern": "[vulnerability:name = 'CVE-2019-11510']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11510 \u2014 Ivanti Pulse Connect Secure Arbit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a1e7333a-2085-49d0-aae8-d80fd2fbbbdf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-11539",
      "pattern": "[vulnerability:name = 'CVE-2019-11539']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11539 \u2014 Ivanti Pulse Connect Secure and P",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2eb597fe-a986-482e-8086-5fad914af4c0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-11580",
      "pattern": "[vulnerability:name = 'CVE-2019-11580']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11580 \u2014 Atlassian Crowd and Crowd Data Ce",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--27880f90-ec50-46cf-aef0-8f4202cfd0cb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-11634",
      "pattern": "[vulnerability:name = 'CVE-2019-11634']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-11634 \u2014 Citrix Workspace Application and ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1991a587-a708-4254-a292-919089cdd9b2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-1214",
      "pattern": "[vulnerability:name = 'CVE-2019-1214']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1214 \u2014 Microsoft Windows Privilege Common",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-36955 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e31ced2d-248a-4841-b94b-de8da07e1451",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-1215",
      "pattern": "[vulnerability:name = 'CVE-2019-1215']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1215 \u2014 Microsoft Windows Privilege Escala",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1e44685a-623e-45cc-9e08-6b83baec2c42",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-13608",
      "pattern": "[vulnerability:name = 'CVE-2019-13608']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-13608 \u2014 Citrix StoreFront Server XML Exte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b8cb8aed-5811-4ca4-bcff-c5d5a1203319",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-1367",
      "pattern": "[vulnerability:name = 'CVE-2019-1367']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1367 \u2014 Microsoft Internet Explorer Script",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--592b3c77-ae36-4a3c-a2de-c404c72cd7aa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-1429",
      "pattern": "[vulnerability:name = 'CVE-2019-1429']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-1429 \u2014 Microsoft Internet Explorer Script",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4095d476-6f21-43c5-aae3-f272269b6a15",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-15752",
      "pattern": "[vulnerability:name = 'CVE-2019-15752']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-15752 \u2014 Docker Desktop Community Edition ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ce82509f-a9d3-4edd-a46d-6d98ae241fc8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-15949",
      "pattern": "[vulnerability:name = 'CVE-2019-15949']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-15949 \u2014 Nagios XI Remote Code Execution V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--259ba021-13af-4d86-84be-ceef1861ccb1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-16256",
      "pattern": "[vulnerability:name = 'CVE-2019-16256']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16256 \u2014 SIMalliance Toolbox Browser Comma",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f9fbae40-5ab0-44a4-8328-b9dd2d7a72f7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-16759",
      "pattern": "[vulnerability:name = 'CVE-2019-16759']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb36014e-187f-48bb-970f-44197f40d6c2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-17026",
      "pattern": "[vulnerability:name = 'CVE-2019-17026']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-17026 \u2014 Mozilla Firefox And Thunderbird T",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--540a4269-9585-419c-8e0b-849d7266ec2a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-17558",
      "pattern": "[vulnerability:name = 'CVE-2019-17558']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-17558 \u2014 Apache Solr VelocityResponseWrite",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--46280832-a10f-45ca-b3eb-f3e4e61aa185",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-18187",
      "pattern": "[vulnerability:name = 'CVE-2019-18187']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-18187 \u2014 Trend Micro OfficeScan Directory ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--37c470f5-9580-4f0c-bce9-543188fd661d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-18988",
      "pattern": "[vulnerability:name = 'CVE-2019-18988']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-18988 \u2014 TeamViewer Desktop Bypass Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d85fba94-90ca-4058-9dfa-735388aee835",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-19356",
      "pattern": "[vulnerability:name = 'CVE-2019-19356']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-19356 \u2014 Netis WF2419 Devices Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1ddfccdc-4949-4ba5-a8a2-8a08acb210db",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-19781",
      "pattern": "[vulnerability:name = 'CVE-2019-19781']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-19781 \u2014 Citrix ADC, Gateway, and SD-WAN W",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--24f93e6a-3c2e-4db9-86c5-37b8f4fabf74",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-20085",
      "pattern": "[vulnerability:name = 'CVE-2019-20085']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-20085 \u2014 TVT NVMS-1000 Directory Traversal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--92c87dfa-81e2-4ab5-9799-002c9ac21e31",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-2215",
      "pattern": "[vulnerability:name = 'CVE-2019-2215']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-2215 \u2014 Android Kernel Use-After-Free Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9e3e8cac-79d5-4ed4-9506-593ebcbfca89",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-3396",
      "pattern": "[vulnerability:name = 'CVE-2019-3396']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-3396 \u2014 Atlassian Confluence Server and Da",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9bc635dd-02f4-49ef-8087-3e18c684eeb4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-3398",
      "pattern": "[vulnerability:name = 'CVE-2019-3398']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-3398 \u2014 Atlassian Confluence Server and Da",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--59b60010-174c-450e-97bb-bf5fb919b228",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-4716",
      "pattern": "[vulnerability:name = 'CVE-2019-4716']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-4716 \u2014 IBM Planning Analytics Remote Code",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fc26782e-fcbf-45d8-852d-ec84202a8372",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-5544",
      "pattern": "[vulnerability:name = 'CVE-2019-5544']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-5544 \u2014 VMware ESXi and Horizon DaaS OpenS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-3992 \u2014 VMware ESXi OpenSLP Use-After-Free",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4a8aecc3-bc7b-42dd-be56-0e492211b766",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-5591",
      "pattern": "[vulnerability:name = 'CVE-2019-5591']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-5591 \u2014 Fortinet FortiOS Default Configura",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9288e756-f690-44d8-93bd-f929d25aeff7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-6223",
      "pattern": "[vulnerability:name = 'CVE-2019-6223']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-6223 \u2014 Apple iOS and macOS Group Facetime",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f3cd8423-a06f-4a77-9563-0aeefd689e10",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-7481",
      "pattern": "[vulnerability:name = 'CVE-2019-7481']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-7481 \u2014 SonicWall SMA100 SQL Injection Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-20016 \u2014 SonicWall SSLVPN SMA100 SQL Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb0abb09-cfcc-43d9-ba57-429739139714",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-8394",
      "pattern": "[vulnerability:name = 'CVE-2019-8394']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-8394 \u2014 Zoho ManageEngine ServiceDesk Plus",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d3925a5-8443-470c-83cf-51d18848df76",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-9082",
      "pattern": "[vulnerability:name = 'CVE-2019-9082']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-9082 \u2014 ThinkPHP Remote Code Execution Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f28c16ba-c466-4041-b9c2-2ff86cbf568a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-9978",
      "pattern": "[vulnerability:name = 'CVE-2019-9978']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-9978 \u2014 WordPress Social Warfare Plugin Cr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--857cb377-219e-4be2-9ab0-ee204227e6fc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-0041",
      "pattern": "[vulnerability:name = 'CVE-2020-0041']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-2215 \u2014 Android Kernel Use-After-Free Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4afb04ff-d101-4faa-9c9f-2089f162e553",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-0069",
      "pattern": "[vulnerability:name = 'CVE-2020-0069']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-2215 \u2014 Android Kernel Use-After-Free Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7cef7448-f453-4a2a-8538-a7fbc5829467",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-0601",
      "pattern": "[vulnerability:name = 'CVE-2020-0601']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-0601 \u2014 Microsoft Windows CryptoAPI Spoofi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1943abbf-0b1c-4b06-bae4-706e0370ec60",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-0646",
      "pattern": "[vulnerability:name = 'CVE-2020-0646']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-0646 \u2014 Microsoft .NET Framework Remote Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d41e2c5c-9e9b-4f3c-a13f-9658ba99c340",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-0674",
      "pattern": "[vulnerability:name = 'CVE-2020-0674']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-0674 \u2014 Microsoft Internet Explorer Script",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-17026 \u2014 Mozilla Firefox And Thunderbird T",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2eb680d8-f75f-4c2d-bcc2-16240c764018",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-0683",
      "pattern": "[vulnerability:name = 'CVE-2020-0683']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-0683 \u2014 Microsoft Windows Installer Privil",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0e69bfb7-f640-4e17-8024-604db7c77173",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-0878",
      "pattern": "[vulnerability:name = 'CVE-2020-0878']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-0878 \u2014 Microsoft Edge and Internet Explor",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-1367 \u2014 Microsoft Internet Explorer Script",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--705202f8-9d49-424a-bc2c-e268ade85fd6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-0938",
      "pattern": "[vulnerability:name = 'CVE-2020-0938']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-6418 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-0938 \u2014 Microsoft Windows Adobe Font Manag",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-1020 \u2014 Microsoft Windows Adobe Font Manag",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53a4734d-cbc2-4322-be6b-47f26c6ae1b0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-0968",
      "pattern": "[vulnerability:name = 'CVE-2020-0968']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-0968 \u2014 Microsoft Internet Explorer Script",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4f7f8ea5-289b-4bd7-8857-aa133e590cdb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-0986",
      "pattern": "[vulnerability:name = 'CVE-2020-0986']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-0986 \u2014 Microsoft Windows Kernel Privilege",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ef3f3b2-1fae-4e4d-94da-852421dcd95c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-10148",
      "pattern": "[vulnerability:name = 'CVE-2020-10148']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-10148 \u2014 SolarWinds Orion Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--01a8389c-41db-46ac-ac93-ae744abd138a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-10181",
      "pattern": "[vulnerability:name = 'CVE-2020-10181']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-10181 \u2014 Sumavision EMR Cross-Site Request",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--64b50e61-f941-4796-8f31-41314440a279",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-10189",
      "pattern": "[vulnerability:name = 'CVE-2020-10189']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--22ee4948-c24d-4dad-8bd0-fc6937a2c4dd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-10199",
      "pattern": "[vulnerability:name = 'CVE-2020-10199']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-10199 \u2014 Sonatype Nexus Repository Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da0e409a-06bc-4b31-942d-ac56b5e166c0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-1020",
      "pattern": "[vulnerability:name = 'CVE-2020-1020']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-6418 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-1020 \u2014 Microsoft Windows Adobe Font Manag",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6b0cfe23-d15e-4dd0-9a31-8e3527613d50",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-10221",
      "pattern": "[vulnerability:name = 'CVE-2020-10221']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-10221 \u2014 rConfig OS Command Injection Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3a79c832-a696-4bb0-b384-cfc9cb2db97f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-1040",
      "pattern": "[vulnerability:name = 'CVE-2020-1040']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-1040 \u2014 Microsoft Hyper-V RemoteFX vGPU Re",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--54a344b6-82af-4681-8d4c-4c84738d2e8e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-1054",
      "pattern": "[vulnerability:name = 'CVE-2020-1054']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-1054 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a785a7bd-f9f7-4e31-a0bc-24f51894a6b1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-1147",
      "pattern": "[vulnerability:name = 'CVE-2020-1147']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-1147 \u2014 Microsoft .NET Framework, SharePoi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c0e8267b-2fb3-4480-8cc8-a1a965b42901",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-11651",
      "pattern": "[vulnerability:name = 'CVE-2020-11651']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-11652 \u2014 SaltStack Salt Path Traversal Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-11651 \u2014 SaltStack Salt Authentication Byp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a9017eb2-a7e1-49fb-aef3-d3a77d7d20e8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-11652",
      "pattern": "[vulnerability:name = 'CVE-2020-11652']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-11652 \u2014 SaltStack Salt Path Traversal Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-11651 \u2014 SaltStack Salt Authentication Byp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0966c9a5-5f86-4963-b0dd-606f59842130",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-11738",
      "pattern": "[vulnerability:name = 'CVE-2020-11738']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-11738 \u2014 WordPress Snap Creek Duplicator P",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9dac00a1-9342-401b-a814-90a1d96dd711",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-12271",
      "pattern": "[vulnerability:name = 'CVE-2020-12271']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-12271 \u2014 Sophos SFOS SQL Injection Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--80fc125b-7462-4726-92c3-a1efb8cfcfcc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-12812",
      "pattern": "[vulnerability:name = 'CVE-2020-12812']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-12812 \u2014 Fortinet FortiOS SSL VPN Improper",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ba782036-999a-4f84-8e09-f117a95cefd3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-1350",
      "pattern": "[vulnerability:name = 'CVE-2020-1350']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-1350 \u2014 Microsoft Windows DNS Server Remot",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bbb0c5c8-4475-4400-b0ff-eb9edaf8927f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-1464",
      "pattern": "[vulnerability:name = 'CVE-2020-1464']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-1464 \u2014 Microsoft Windows Spoofing Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-0601 \u2014 Microsoft Windows CryptoAPI Spoofi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0e1bfc06-0541-4e08-b0b1-d9a835425a68",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-1472",
      "pattern": "[vulnerability:name = 'CVE-2020-1472']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-1472 \u2014 Microsoft Netlogon Privilege Escal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76bb366d-0031-4485-8059-e18b5f072037",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-14750",
      "pattern": "[vulnerability:name = 'CVE-2020-14750']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-14750 \u2014 Oracle WebLogic Server Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e13a215d-78bd-49c5-85b8-27896fbef281",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-14871",
      "pattern": "[vulnerability:name = 'CVE-2020-14871']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-14871 \u2014 Oracle Solaris and Zettabyte File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f23a41b1-8c1b-482b-b41c-ece578c0c7d9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-14882",
      "pattern": "[vulnerability:name = 'CVE-2020-14882']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-14750 \u2014 Oracle WebLogic Server Remote Cod",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-14883 \u2014 Oracle WebLogic Server Unspecifie",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--41fc5541-8ab3-4e59-ae87-8ef688b3f6f8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-14883",
      "pattern": "[vulnerability:name = 'CVE-2020-14883']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-14883 \u2014 Oracle WebLogic Server Unspecifie",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a6e4e1db-d69c-4f49-bd69-d3d6b5c8d814",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-15505",
      "pattern": "[vulnerability:name = 'CVE-2020-15505']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-15505 \u2014 Ivanti MobileIron Multiple Produc",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e211ccbe-ae7f-4c25-859c-6d259b4ccf34",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-15999",
      "pattern": "[vulnerability:name = 'CVE-2020-15999']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-16010 \u2014 Google Chrome for Android UI Heap",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "Buffer overflow in Chromium affecting multiple packages",
          "url": "https://snyk.io/blog/buffer-overflow-in-chromium-affecting-multiple-packages/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV",
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--35c3f39c-c6c2-4301-a782-8d968d7b1da7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-16009",
      "pattern": "[vulnerability:name = 'CVE-2020-16009']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-16010 \u2014 Google Chrome for Android UI Heap",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-16009 \u2014 Google Chromium V8 Type Confusion",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d06345f-dfc0-4bd9-96ee-7edf0a44e50b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-16010",
      "pattern": "[vulnerability:name = 'CVE-2020-16010']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-16010 \u2014 Google Chrome for Android UI Heap",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f23372c-ca73-4c7d-aa92-4350625ba380",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-16013",
      "pattern": "[vulnerability:name = 'CVE-2020-16013']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-16013 \u2014 Google Chromium V8 Incorrect Impl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--167e431a-921a-4670-be0f-dd738e50278b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-16017",
      "pattern": "[vulnerability:name = 'CVE-2020-16017']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-16017 \u2014 Google Chrome Use-After-Free Vuln",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b406018f-8a85-4a45-a0bf-e805546582f2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-16846",
      "pattern": "[vulnerability:name = 'CVE-2020-16846']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-16846 \u2014 SaltStack Salt Shell Injection Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--62c99f19-150d-4a49-8cae-2bab879064b6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-17087",
      "pattern": "[vulnerability:name = 'CVE-2020-17087']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-16010 \u2014 Google Chrome for Android UI Heap",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-17087 \u2014 Microsoft Windows Kernel Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--900c540f-8386-4fa6-ac8a-3a4fd9e173db",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-17144",
      "pattern": "[vulnerability:name = 'CVE-2020-17144']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-17144 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--72aaa707-3a8d-4232-afd0-a048456809b5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-17496",
      "pattern": "[vulnerability:name = 'CVE-2020-17496']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6d201e7-af63-44d3-ab98-5db39ff52f31",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-17530",
      "pattern": "[vulnerability:name = 'CVE-2020-17530']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-17530 \u2014 Apache Struts Remote Code Executi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a52d0bb1-9935-480b-9f4a-c188a3517740",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-24557",
      "pattern": "[vulnerability:name = 'CVE-2020-24557']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-24557 \u2014 Trend Micro Multiple Products Imp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2d5da22f-69dd-45ec-9235-b1553850deff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-25213",
      "pattern": "[vulnerability:name = 'CVE-2020-25213']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--963fbfdb-ea09-47f0-bcad-1e352498c022",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-25506",
      "pattern": "[vulnerability:name = 'CVE-2020-25506']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--017dfb07-fb21-47ec-b0ae-218eccc9c54f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-25592",
      "pattern": "[vulnerability:name = 'CVE-2020-25592']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-16846 \u2014 SaltStack Salt Shell Injection Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dfea3a38-dc7e-4fc7-a235-01169aad9b16",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-26919",
      "pattern": "[vulnerability:name = 'CVE-2020-26919']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-26919 \u2014 Netgear JGS516PE Devices Missing ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5f8cd2d-3ca6-426c-b942-3fc61043bd3e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-27930",
      "pattern": "[vulnerability:name = 'CVE-2020-27930']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-27930 \u2014 Apple Multiple Products Memory Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-27950 \u2014 Apple Multiple Products Memory In",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-27932 \u2014 Apple Multiple Products Type Conf",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--359b742f-5c0b-4cff-865b-bfc8437eb3cf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-27932",
      "pattern": "[vulnerability:name = 'CVE-2020-27932']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-27950 \u2014 Apple Multiple Products Memory In",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-27932 \u2014 Apple Multiple Products Type Conf",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8dec04bb-d85e-4bc1-ae46-af9b7ca9e29f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-27950",
      "pattern": "[vulnerability:name = 'CVE-2020-27950']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-27950 \u2014 Apple Multiple Products Memory In",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-27932 \u2014 Apple Multiple Products Type Conf",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--119a40f0-cfc7-4359-acfb-a00984a95c45",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-28188",
      "pattern": "[vulnerability:name = 'CVE-2020-28188']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-7961 \u2014 Liferay Portal Deserialization of ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8279acf-fdea-4104-bd9b-8d274dc5af24",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-29557",
      "pattern": "[vulnerability:name = 'CVE-2020-29557']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-29557 \u2014 D-Link DIR-825 R1 Devices Buffer ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a9f6f617-b6a9-417e-a382-3608410f4fa7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-29583",
      "pattern": "[vulnerability:name = 'CVE-2020-29583']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-29583 \u2014 Zyxel Multiple Products Use of Ha",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c11e45d-f2a1-4b67-b059-c2b8a974bade",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-3118",
      "pattern": "[vulnerability:name = 'CVE-2020-3118']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-3118 \u2014 Cisco IOS XR Software Discovery Pr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6bb08231-7d17-4207-967c-c068cdb543c0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-3161",
      "pattern": "[vulnerability:name = 'CVE-2020-3161']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-3161 \u2014 Cisco IP Phones Web Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--47f30e2b-9d4a-4cc6-9cce-9bd954bcf801",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-3452",
      "pattern": "[vulnerability:name = 'CVE-2020-3452']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-3452 \u2014 Cisco ASA and FTD Read-Only Path T",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f3e7b91-3906-47a6-af10-2d17cc569577",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-3566",
      "pattern": "[vulnerability:name = 'CVE-2020-3566']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-3566 \u2014 Cisco IOS XR Software DVMRP Memory",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-3569 \u2014 Cisco IOS XR Software DVMRP Memory",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f29d632-dc93-4993-b460-a7061c7daffb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-3569",
      "pattern": "[vulnerability:name = 'CVE-2020-3569']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-3566 \u2014 Cisco IOS XR Software DVMRP Memory",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-3569 \u2014 Cisco IOS XR Software DVMRP Memory",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b1770323-3ccf-4c5a-be4f-30ad0964bd3f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-3580",
      "pattern": "[vulnerability:name = 'CVE-2020-3580']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-3580 \u2014 Cisco ASA and FTD Cross-Site Scrip",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ced2a9e3-67db-4206-9d62-0d8b8e248576",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-3950",
      "pattern": "[vulnerability:name = 'CVE-2020-3950']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-3950 \u2014 VMware Multiple Products Privilege",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c6d07ef5-6508-48c1-8d4e-1256397bec6e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-3952",
      "pattern": "[vulnerability:name = 'CVE-2020-3952']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-3952 \u2014 VMware vCenter Server Information ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--617ba5d1-334f-4322-979e-1059da5d2e5a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-3992",
      "pattern": "[vulnerability:name = 'CVE-2020-3992']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-3992 \u2014 VMware ESXi OpenSLP Use-After-Free",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--112207c3-2906-4c1b-be3f-829c8c713fe4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-4006",
      "pattern": "[vulnerability:name = 'CVE-2020-4006']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-4006 \u2014 Multiple VMware Products Command I",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ead67f9c-b5f3-4f04-8a94-6f4cd7e322a6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-4427",
      "pattern": "[vulnerability:name = 'CVE-2020-4427']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-4427 \u2014 IBM Data Risk Manager Security Byp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--15fb9ecb-3b45-4eae-9e13-84cc4e3b5798",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-4428",
      "pattern": "[vulnerability:name = 'CVE-2020-4428']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-4428 \u2014 IBM Data Risk Manager Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c42a2ee2-1a78-4c6f-adf8-5d70fd8148e5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-4430",
      "pattern": "[vulnerability:name = 'CVE-2020-4430']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-4430 \u2014 IBM Data Risk Manager Directory Tr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3e360d37-2555-4396-aafa-135072843967",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-5735",
      "pattern": "[vulnerability:name = 'CVE-2020-5735']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-5735 \u2014 Amcrest Cameras and NVR Stack-base",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4204014b-71ea-4c78-96ab-072e5d646191",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-5847",
      "pattern": "[vulnerability:name = 'CVE-2020-5847']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-5849 \u2014 Unraid Authentication Bypass Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--10042564-b72b-4b59-9a09-194430f42567",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-5849",
      "pattern": "[vulnerability:name = 'CVE-2020-5849']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-5849 \u2014 Unraid Authentication Bypass Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--09fbf324-6f65-466a-98ec-db7fded2551d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-5902",
      "pattern": "[vulnerability:name = 'CVE-2020-5902']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-5902 \u2014 F5 BIG-IP Traffic Management User ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--125eb27c-c170-4f09-960d-9165b51aac75",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-6207",
      "pattern": "[vulnerability:name = 'CVE-2020-6207']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-6207 \u2014 SAP Solution Manager Missing Authe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--52a271ba-dec0-4217-a368-d85c4f4941a8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-6287",
      "pattern": "[vulnerability:name = 'CVE-2020-6287']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-2380 \u2014 SAP Customer Relationship Manageme",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-6287 \u2014 SAP NetWeaver Missing Authenticati",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--223fb5e1-fcda-4e03-955d-6cf31f6f975e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-6418",
      "pattern": "[vulnerability:name = 'CVE-2020-6418']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-6418 \u2014 Google Chromium V8 Type Confusion ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--95a8abc0-642d-4f0b-b69f-c5c3324bba7f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-6819",
      "pattern": "[vulnerability:name = 'CVE-2020-6819']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-6819 \u2014 Mozilla Firefox And Thunderbird Us",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4b2d1ec9-e280-4886-a00f-9818bff8c9a4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-6820",
      "pattern": "[vulnerability:name = 'CVE-2020-6820']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-6820 \u2014 Mozilla Firefox And Thunderbird Us",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2f674d16-2640-4466-b32f-d1fa18cb1087",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-7961",
      "pattern": "[vulnerability:name = 'CVE-2020-7961']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-7961 \u2014 Liferay Portal Deserialization of ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--40a2e3eb-dc90-40fd-9a3d-8038a7bf565b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-8193",
      "pattern": "[vulnerability:name = 'CVE-2020-8193']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-8193 \u2014 Citrix ADC, Gateway, and SD-WAN WA",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-8195 \u2014 Citrix ADC, Gateway, and SD-WAN WA",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc077f9e-0c21-44f0-a0ba-73f637431f5f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-8195",
      "pattern": "[vulnerability:name = 'CVE-2020-8195']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-8195 \u2014 Citrix ADC, Gateway, and SD-WAN WA",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--666abc75-c16a-4df5-be77-094fe81b7c41",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-8196",
      "pattern": "[vulnerability:name = 'CVE-2020-8196']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-8195 \u2014 Citrix ADC, Gateway, and SD-WAN WA",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-8196 \u2014 Citrix ADC, Gateway, and SD-WAN WA",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3edb7798-facc-45d0-8891-c2f024b208d8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-8243",
      "pattern": "[vulnerability:name = 'CVE-2020-8243']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-8243 \u2014 Ivanti Pulse Connect Secure Code E",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0728375d-1440-4780-9b0b-cb10e15a3e3a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-8260",
      "pattern": "[vulnerability:name = 'CVE-2020-8260']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-8260 \u2014 Ivanti Pulse Connect Secure Code E",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb724ac4-bedb-4eab-8ad8-5dd8c8a484a0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-8467",
      "pattern": "[vulnerability:name = 'CVE-2020-8467']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-8467 \u2014 Trend Micro Apex One and OfficeSca",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-8599 \u2014 Trend Micro Apex One and OfficeSca",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--253a6e3f-e164-4ca8-9313-fda3f4131fe8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-8468",
      "pattern": "[vulnerability:name = 'CVE-2020-8468']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-8468 \u2014 Trend Micro Multiple Products Cont",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7fa97539-8347-41c6-8a49-a7c1af6b817c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-8599",
      "pattern": "[vulnerability:name = 'CVE-2020-8599']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-8599 \u2014 Trend Micro Apex One and OfficeSca",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4f96c9ea-4287-47db-9991-35b2df13c02c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-8644",
      "pattern": "[vulnerability:name = 'CVE-2020-8644']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-8644 \u2014 PlaySMS Server-Side Template Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e81a7384-8378-4b20-a217-f8a36d884fc2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-8655",
      "pattern": "[vulnerability:name = 'CVE-2020-8655']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-8655 \u2014 EyesOfNetwork Improper Privilege M",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4c59c35a-7a45-4456-b3cf-5d7cbcba540a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-8657",
      "pattern": "[vulnerability:name = 'CVE-2020-8657']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-8657 \u2014 EyesOfNetwork Use of Hard-Coded Cr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dae72f23-1a58-449f-bd31-ba0188e649b7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-9818",
      "pattern": "[vulnerability:name = 'CVE-2020-9818']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-9818 \u2014 Apple iOS, iPadOS, and watchOS Out",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-9819 \u2014 Apple iOS, iPadOS, and watchOS Mem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0e2797f5-2cdb-416c-87ca-1bf13493b1f5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-9819",
      "pattern": "[vulnerability:name = 'CVE-2020-9819']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-9818 \u2014 Apple iOS, iPadOS, and watchOS Out",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-9819 \u2014 Apple iOS, iPadOS, and watchOS Mem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e9a9466f-f3cc-4ce4-be21-d0b677fd0fd7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-9859",
      "pattern": "[vulnerability:name = 'CVE-2020-9859']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-9859 \u2014 Apple Multiple Products Code Execu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9b28d241-da83-4ce1-9b26-ccf9e46009cf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-1497",
      "pattern": "[vulnerability:name = 'CVE-2021-1497']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-1497 \u2014 Cisco HyperFlex HX Installer Virtu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-1498 \u2014 Cisco HyperFlex HX Data Platform C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--730d36af-f49b-49f6-8af3-2de5c9e19c28",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-1498",
      "pattern": "[vulnerability:name = 'CVE-2021-1498']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-1498 \u2014 Cisco HyperFlex HX Data Platform C",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a818fbdf-35c8-4212-8762-3acdd28ce7ac",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-1647",
      "pattern": "[vulnerability:name = 'CVE-2021-1647']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-1647 \u2014 Microsoft Defender Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--04d548c2-4321-46b8-aeba-af1395628351",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-1675",
      "pattern": "[vulnerability:name = 'CVE-2021-1675']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34527 \u2014 Microsoft Windows Print Spooler R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-1675 \u2014 Microsoft Windows Print Spooler Re",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--24d1a81e-7278-46de-81f6-d0dbe8529f01",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-1732",
      "pattern": "[vulnerability:name = 'CVE-2021-1732']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-1732 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e3708d83-0b2d-4582-b235-00ae2a3100fa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-1782",
      "pattern": "[vulnerability:name = 'CVE-2021-1782']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-1782 \u2014 Apple Multiple Products Race Condi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-1870 \u2014 Apple iOS, iPadOS, and macOS WebKi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e8a02e42-f767-4cde-a71d-f6d11532fb37",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-1870",
      "pattern": "[vulnerability:name = 'CVE-2021-1870']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-1870 \u2014 Apple iOS, iPadOS, and macOS WebKi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--23012bf6-6755-461d-9990-47b3509d0e46",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-1871",
      "pattern": "[vulnerability:name = 'CVE-2021-1871']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-1870 \u2014 Apple iOS, iPadOS, and macOS WebKi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-1871 \u2014 Apple iOS, iPadOS, and macOS WebKi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d170a74-090f-43bf-b923-ba5269c42aad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-1879",
      "pattern": "[vulnerability:name = 'CVE-2021-1879']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-1879 \u2014 Apple iOS, iPadOS, and watchOS Web",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2f1bb61a-2bc5-4226-b8a2-fecace580185",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-1905",
      "pattern": "[vulnerability:name = 'CVE-2021-1905']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-1905 \u2014 Qualcomm Multiple Chipsets Use-Aft",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--066b961a-9517-48fd-864b-864e6f13c84e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-1906",
      "pattern": "[vulnerability:name = 'CVE-2021-1906']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-1906 \u2014 Qualcomm Multiple Chipsets Detecti",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aebdb038-6e0d-47c1-bb0f-74882e5d28ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-20016",
      "pattern": "[vulnerability:name = 'CVE-2021-20016']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-20016 \u2014 SonicWall SSLVPN SMA100 SQL Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7de28cfe-83e8-4e6e-b35a-ba27b94ffb92",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-20021",
      "pattern": "[vulnerability:name = 'CVE-2021-20021']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-20021 \u2014 SonicWall Email Security Improper",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4e51a3d6-2611-415e-953f-fa458546f0df",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-20022",
      "pattern": "[vulnerability:name = 'CVE-2021-20022']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-20021 \u2014 SonicWall Email Security Improper",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f26f3d05-1488-425e-b88c-6a0fa04fc07f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-20023",
      "pattern": "[vulnerability:name = 'CVE-2021-20023']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-20021 \u2014 SonicWall Email Security Improper",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--343713eb-2a92-4632-9907-0ca61c918cdf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-20090",
      "pattern": "[vulnerability:name = 'CVE-2021-20090']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-20090 \u2014 Arcadyan Buffalo Firmware Path Tr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ef186d2b-8c07-4dfb-bf90-c4c0a2fe8a0b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-21017",
      "pattern": "[vulnerability:name = 'CVE-2021-21017']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21017 \u2014 Adobe Acrobat and Reader Heap-bas",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--79b79855-14b1-4c1d-aa0b-7940910df462",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-21148",
      "pattern": "[vulnerability:name = 'CVE-2021-21148']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21148 \u2014 Google Chromium V8 Heap Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d63e2667-3de8-49a2-b919-683966dc279e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-21166",
      "pattern": "[vulnerability:name = 'CVE-2021-21166']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21166 \u2014 Google Chromium Race Condition Vu",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b7757f28-5be0-41be-b0db-3e1441da585f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-21193",
      "pattern": "[vulnerability:name = 'CVE-2021-21193']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21193 \u2014 Google Chromium Blink Use-After-F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8b91dc5f-b20b-4a77-8516-d6d204d84d3f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-21206",
      "pattern": "[vulnerability:name = 'CVE-2021-21206']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21206 \u2014 Google Chromium Blink Use-After-F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a1b49114-c845-40ad-8e21-edba650581d9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-21220",
      "pattern": "[vulnerability:name = 'CVE-2021-21220']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21220 \u2014 Google Chromium V8 Improper Input",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31955 \u2014 Microsoft Windows Kernel Informat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31956 \u2014 Microsoft Windows NTFS Privilege ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7235c94d-f6f4-47b4-ad34-0ca125f69668",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-21224",
      "pattern": "[vulnerability:name = 'CVE-2021-21224']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21224 \u2014 Google Chromium V8 Type Confusion",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31955 \u2014 Microsoft Windows Kernel Informat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31956 \u2014 Microsoft Windows NTFS Privilege ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8e383fe3-97b1-4db5-89fb-d5adeaf61d76",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-21972",
      "pattern": "[vulnerability:name = 'CVE-2021-21972']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21972 \u2014 VMware vCenter Server Remote Code",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b437e449-d7de-4b22-ab9e-2ac1f65a3445",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-21974",
      "pattern": "[vulnerability:name = 'CVE-2021-21974']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-5544 \u2014 VMware ESXi and Horizon DaaS OpenS",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb1ebb7a-ce65-4c76-b760-b2a935c0ed3c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-21985",
      "pattern": "[vulnerability:name = 'CVE-2021-21985']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-21985 \u2014 VMware vCenter Server Improper In",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1edecbb6-1340-49f6-b346-8cb55bdd9162",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-22005",
      "pattern": "[vulnerability:name = 'CVE-2021-22005']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-22005 \u2014 VMware vCenter Server File Upload",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f45fc6f9-215c-4fea-84f4-a1f2c21ad420",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-22205",
      "pattern": "[vulnerability:name = 'CVE-2021-22205']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-22205 \u2014 GitLab Community and Enterprise E",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--20d61250-35e7-418a-968e-476f479e8f33",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-22502",
      "pattern": "[vulnerability:name = 'CVE-2021-22502']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-22502 \u2014 Micro Focus Operation Bridge Repo",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9b5ba1d6-caa5-489b-8e65-e11f8d6854fc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-22506",
      "pattern": "[vulnerability:name = 'CVE-2021-22506']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-22506 \u2014 Micro Focus Access Manager Inform",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e17db1b0-748a-42e8-a9f5-0115eebfaf30",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-22893",
      "pattern": "[vulnerability:name = 'CVE-2021-22893']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-22893 \u2014 Ivanti Pulse Connect Secure Use-A",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-22900 \u2014 Ivanti Pulse Connect Secure Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d467831c-748e-4ad9-a1e7-9caae8094c4c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-22894",
      "pattern": "[vulnerability:name = 'CVE-2021-22894']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-22894 \u2014 Ivanti Pulse Connect Secure Colla",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--04348446-4f4e-4dd2-9310-067ab8970814",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-22899",
      "pattern": "[vulnerability:name = 'CVE-2021-22899']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-22899 \u2014 Ivanti Pulse Connect Secure Comma",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2019-11539 \u2014 Ivanti Pulse Connect Secure and P",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0012545-febc-4388-bd82-1cb6d67cb46f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-22900",
      "pattern": "[vulnerability:name = 'CVE-2021-22900']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-22900 \u2014 Ivanti Pulse Connect Secure Unres",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b5f38130-1294-4083-be9d-361d3e63615d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-22986",
      "pattern": "[vulnerability:name = 'CVE-2021-22986']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-22986 \u2014 F5 BIG-IP and BIG-IQ Centralized ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3f685f48-cf91-44b3-aced-a46390d21fbd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-23434",
      "pattern": "[vulnerability:name = 'CVE-2021-23434']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "JavaScript type confusion: Bypassed input validation (and ho",
          "url": "https://snyk.io/blog/remediate-javascript-type-confusion-bypassed-input-validation/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb28af0b-3508-4e93-8f8a-9dfc0bb28b71",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-23436",
      "pattern": "[vulnerability:name = 'CVE-2021-23436']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "JavaScript type confusion: Bypassed input validation (and ho",
          "url": "https://snyk.io/blog/remediate-javascript-type-confusion-bypassed-input-validation/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--107a2d68-e240-431e-8db2-3973b8f955e5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-23438",
      "pattern": "[vulnerability:name = 'CVE-2021-23438']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "JavaScript type confusion: Bypassed input validation (and ho",
          "url": "https://snyk.io/blog/remediate-javascript-type-confusion-bypassed-input-validation/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f357ebde-4d00-4169-8e96-ccdc817776f0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-23440",
      "pattern": "[vulnerability:name = 'CVE-2021-23440']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "JavaScript type confusion: Bypassed input validation (and ho",
          "url": "https://snyk.io/blog/remediate-javascript-type-confusion-bypassed-input-validation/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4c995ce4-af71-4b7e-ba0b-4398ff0768b3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-23443",
      "pattern": "[vulnerability:name = 'CVE-2021-23443']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "JavaScript type confusion: Bypassed input validation (and ho",
          "url": "https://snyk.io/blog/remediate-javascript-type-confusion-bypassed-input-validation/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--429fec4a-61d5-455a-a9ad-7f7fb5e71f85",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-23444",
      "pattern": "[vulnerability:name = 'CVE-2021-23444']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "JavaScript type confusion: Bypassed input validation (and ho",
          "url": "https://snyk.io/blog/remediate-javascript-type-confusion-bypassed-input-validation/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b1911ce-830a-4a29-b2d2-3faf9db5930d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-23874",
      "pattern": "[vulnerability:name = 'CVE-2021-23874']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-23874 \u2014 McAfee Total Protection (MTP) Imp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cd4fc7be-8d45-4424-a040-42e2b664c11c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-26084",
      "pattern": "[vulnerability:name = 'CVE-2021-26084']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c08ce684-042a-456a-9a4d-f95c1f2e415c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-26411",
      "pattern": "[vulnerability:name = 'CVE-2021-26411']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26411 \u2014 Microsoft Internet Explorer Memor",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--761c8ec5-80a7-4ae9-a2f7-727d1b10a6f1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-26855",
      "pattern": "[vulnerability:name = 'CVE-2021-26855']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26855 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-26857 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8a827104-01cf-4dc4-8b0d-8d2a48be37ba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-26857",
      "pattern": "[vulnerability:name = 'CVE-2021-26857']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26857 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--19bdd1de-3e81-485a-af67-f8a9ae6ca9f7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-26858",
      "pattern": "[vulnerability:name = 'CVE-2021-26858']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26858 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-26857 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ab24fb37-2f2a-409b-8b7f-6c2dc06ec421",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-27059",
      "pattern": "[vulnerability:name = 'CVE-2021-27059']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27059 \u2014 Microsoft Office Remote Code Exec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--913972ba-8b71-4b72-9001-e91697db93f2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-27065",
      "pattern": "[vulnerability:name = 'CVE-2021-27065']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26855 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27065 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-26857 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--49554f32-f937-486b-bd54-8da39a2796d6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-27085",
      "pattern": "[vulnerability:name = 'CVE-2021-27085']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27085 \u2014 Microsoft Internet Explorer Remot",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ef1d6d2d-618c-4bcd-9547-10efa1efbff1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-27101",
      "pattern": "[vulnerability:name = 'CVE-2021-27101']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cc661d99-4734-494a-b1d0-389b628afabe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-27102",
      "pattern": "[vulnerability:name = 'CVE-2021-27102']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d518e46f-1be2-4540-99c5-a2beda6962d3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-27103",
      "pattern": "[vulnerability:name = 'CVE-2021-27103']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a04484a3-f8ca-4f9a-92d9-4fda52705609",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-27104",
      "pattern": "[vulnerability:name = 'CVE-2021-27104']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--60c2a7d9-b834-4674-8c3a-1465b0749aaa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-27561",
      "pattern": "[vulnerability:name = 'CVE-2021-27561']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27561 \u2014 Yealink Device Management Server-",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--350ba27f-d3f2-4fcf-91fa-53b3c9984419",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-27562",
      "pattern": "[vulnerability:name = 'CVE-2021-27562']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27562 \u2014 Arm Trusted Firmware Out-of-Bound",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dbfe98a0-0550-447e-99f6-fd790d6a0c67",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-28310",
      "pattern": "[vulnerability:name = 'CVE-2021-28310']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-28310 \u2014 Microsoft Win32k Privilege Escala",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--29fc76b9-79e2-4ad2-b230-ee5f00ce5e1f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-28663",
      "pattern": "[vulnerability:name = 'CVE-2021-28663']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-28664 \u2014 Arm Mali Graphics Processing Unit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-28663 \u2014 Arm Mali Graphics Processing Unit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e11008f6-169b-47aa-8324-b3a4fd228513",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-28664",
      "pattern": "[vulnerability:name = 'CVE-2021-28664']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-28664 \u2014 Arm Mali Graphics Processing Unit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e9200100-cf6b-4805-b7f0-cd50b6d40bb1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-3007",
      "pattern": "[vulnerability:name = 'CVE-2021-3007']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-7961 \u2014 Liferay Portal Deserialization of ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dcfe7cc6-7c79-4b6d-b6e6-567046c10a64",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30116",
      "pattern": "[vulnerability:name = 'CVE-2021-30116']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30116 \u2014 Kaseya Virtual System/Server Admi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fd71e8fb-a6b0-4566-815d-653a2292288b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30551",
      "pattern": "[vulnerability:name = 'CVE-2021-30551']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30551 \u2014 Google Chromium V8 Type Confusion",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a67c3db6-72ea-43bd-9a8a-2db4f8e2d4d7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30554",
      "pattern": "[vulnerability:name = 'CVE-2021-30554']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30554 \u2014 Google Chromium WebGL Use-After-F",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d1a4caa-2753-40c5-9c58-ddf279241f9c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30563",
      "pattern": "[vulnerability:name = 'CVE-2021-30563']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30563 \u2014 Google Chromium V8 Type Confusion",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fee37c7f-acf5-4529-b14b-1d2997e5f04f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30632",
      "pattern": "[vulnerability:name = 'CVE-2021-30632']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30632 \u2014 Google Chromium V8 Out-of-Bounds ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c5660ba0-cd01-4a3f-a3e7-1a3efe64732d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30633",
      "pattern": "[vulnerability:name = 'CVE-2021-30633']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30632 \u2014 Google Chromium V8 Out-of-Bounds ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-30633 \u2014 Google Chromium Indexed DB API Us",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8972b939-9bcf-4dea-98ea-5d3814ee23a9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30657",
      "pattern": "[vulnerability:name = 'CVE-2021-30657']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30657 \u2014 Apple macOS Unspecified Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c990c13d-df4a-4934-9e06-eea7c2794f9f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30661",
      "pattern": "[vulnerability:name = 'CVE-2021-30661']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30661 \u2014 Apple Multiple Products WebKit St",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--51a97802-e6fb-4ce9-8916-8df2d39234a6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30663",
      "pattern": "[vulnerability:name = 'CVE-2021-30663']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30663 \u2014 Apple Multiple Products WebKit In",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb6aafa3-a37f-4fa3-a598-662520c4b5eb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30665",
      "pattern": "[vulnerability:name = 'CVE-2021-30665']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30665 \u2014 Apple Multiple Products WebKit Me",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2368bff7-8c2c-4226-9434-787c72dd4caa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30666",
      "pattern": "[vulnerability:name = 'CVE-2021-30666']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30666 \u2014 Apple iOS WebKit Buffer Overflow ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-30761 \u2014 Apple iOS WebKit Memory Corruptio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fbadd010-b332-4532-9cb0-e3b56c066ad6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30713",
      "pattern": "[vulnerability:name = 'CVE-2021-30713']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d4e1950a-0614-4e8a-83b0-93c58b16053a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30761",
      "pattern": "[vulnerability:name = 'CVE-2021-30761']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30761 \u2014 Apple iOS WebKit Memory Corruptio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--83303d1b-9f3f-47c4-93a1-5380a201cce9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30762",
      "pattern": "[vulnerability:name = 'CVE-2021-30762']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30762 \u2014 Apple iOS WebKit Use-After-Free V",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--20087df7-a6f6-42ac-b251-907ab5b40b43",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30807",
      "pattern": "[vulnerability:name = 'CVE-2021-30807']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30807 \u2014 Apple Multiple Products Memory Co",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--842b71e5-0d2d-46b1-b0f9-76656d5e3324",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30858",
      "pattern": "[vulnerability:name = 'CVE-2021-30858']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30858 \u2014 Apple iOS, iPadOS, macOS Use-Afte",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ceb58a17-57b6-451a-8777-b9b59970a88f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30860",
      "pattern": "[vulnerability:name = 'CVE-2021-30860']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30860 \u2014 Apple Multiple Products Integer O",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-30665 \u2014 Apple Multiple Products WebKit Me",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--05606b21-ef8f-4169-a19b-0f081e6bbe3a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-30869",
      "pattern": "[vulnerability:name = 'CVE-2021-30869']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--20195111-8915-41b1-b971-62f19e08aed0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-31207",
      "pattern": "[vulnerability:name = 'CVE-2021-31207']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34523 \u2014 Microsoft Exchange Server Privile",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31207 \u2014 Microsoft Exchange Server Securit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b1085d54-3e7f-43f4-b825-03237e159bea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-31755",
      "pattern": "[vulnerability:name = 'CVE-2021-31755']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31755 \u2014 Tenda AC11 Router Stack Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9257e102-9f0f-4f38-849f-7b480fe98eaa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-31955",
      "pattern": "[vulnerability:name = 'CVE-2021-31955']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31955 \u2014 Microsoft Windows Kernel Informat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31956 \u2014 Microsoft Windows NTFS Privilege ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0191dce3-d956-436e-ab89-d9fad0d2c313",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-31956",
      "pattern": "[vulnerability:name = 'CVE-2021-31956']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31955 \u2014 Microsoft Windows Kernel Informat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31956 \u2014 Microsoft Windows NTFS Privilege ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b5e8ea14-9160-4a69-ad9d-7269d6729249",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-31979",
      "pattern": "[vulnerability:name = 'CVE-2021-31979']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31979 \u2014 Microsoft Windows Kernel Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7948fc4c-02f4-4958-9fbb-3725a29f754f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-33739",
      "pattern": "[vulnerability:name = 'CVE-2021-33739']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-33739 \u2014 Microsoft Desktop Window Manager ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c63f4933-8c1c-4575-805b-592bec31b910",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-33742",
      "pattern": "[vulnerability:name = 'CVE-2021-33742']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-33742 \u2014 Microsoft Windows MSHTML Platform",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--72de5d71-52c8-4714-86d1-9ae70be2f2c3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-33771",
      "pattern": "[vulnerability:name = 'CVE-2021-33771']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-33771 \u2014 Microsoft Windows Kernel Privileg",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c3d98a46-ebe3-40f0-ba97-ff13a2ac6662",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-34448",
      "pattern": "[vulnerability:name = 'CVE-2021-34448']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34448 \u2014 Microsoft Windows Scripting Engin",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--49310974-46a0-4b25-ac92-3e2d0c5474d6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-34473",
      "pattern": "[vulnerability:name = 'CVE-2021-34473']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34523 \u2014 Microsoft Exchange Server Privile",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31207 \u2014 Microsoft Exchange Server Securit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8b542d6c-bbcc-4ac4-bc33-1cac12aeb769",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-34523",
      "pattern": "[vulnerability:name = 'CVE-2021-34523']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34523 \u2014 Microsoft Exchange Server Privile",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31207 \u2014 Microsoft Exchange Server Securit",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d3f19044-a741-468b-aed7-94a15ff4a788",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-34527",
      "pattern": "[vulnerability:name = 'CVE-2021-34527']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34527 \u2014 Microsoft Windows Print Spooler R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7f8f2b54-597a-40ac-8e1b-240f7932f269",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-35211",
      "pattern": "[vulnerability:name = 'CVE-2021-35211']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-35211 \u2014 SolarWinds Serv-U Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5be887da-bf90-4066-864d-5205215c5987",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-35395",
      "pattern": "[vulnerability:name = 'CVE-2021-35395']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-35395 \u2014 Realtek AP-Router SDK Buffer Over",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b3ab17b4-440d-48f6-bdae-45ff0f1527ef",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-35464",
      "pattern": "[vulnerability:name = 'CVE-2021-35464']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-35464 \u2014 ForgeRock Access Management (AM) ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9f012f04-f6ed-496d-a698-b34c0bfcdca4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-36741",
      "pattern": "[vulnerability:name = 'CVE-2021-36741']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-36741 \u2014 Trend Micro Multiple Products Imp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e61606dc-e0b9-4688-b5d9-b36e62763d3d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-36742",
      "pattern": "[vulnerability:name = 'CVE-2021-36742']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-36742 \u2014 Trend Micro Multiple Products Imp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-36741 \u2014 Trend Micro Multiple Products Imp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6a2f9237-f5ed-41ee-a523-eb08d43195d4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-36955",
      "pattern": "[vulnerability:name = 'CVE-2021-36955']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-36955 \u2014 Microsoft Windows Common Log File",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--27e937b9-4464-444e-99b9-6f732e9d6370",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-37973",
      "pattern": "[vulnerability:name = 'CVE-2021-37973']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-37973 \u2014 Google Chromium Portals Use-After",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--00d0078b-8ab7-4280-97fa-6174942dd70e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-37975",
      "pattern": "[vulnerability:name = 'CVE-2021-37975']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-37975 \u2014 Google Chromium V8 Use-After-Free",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eafb5538-a639-4d84-aeef-fdb8250a3993",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-37976",
      "pattern": "[vulnerability:name = 'CVE-2021-37976']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-37976 \u2014 Google Chromium Information Discl",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e4f30983-7944-4712-a859-c2d09d6ca6dc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-38000",
      "pattern": "[vulnerability:name = 'CVE-2021-38000']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-38000 \u2014 Google Chromium Intents Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--18bc9016-ed07-4e9f-913a-61b044ec0b1d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-38003",
      "pattern": "[vulnerability:name = 'CVE-2021-38003']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-38000 \u2014 Google Chromium Intents Improper ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-38003 \u2014 Google Chromium V8 Memory Corrupt",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c8a71e60-0996-4ddd-9fef-fb3952690e07",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-38645",
      "pattern": "[vulnerability:name = 'CVE-2021-38645']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-38645 \u2014 Microsoft Open Management Infrast",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a0205221-7f8a-441b-b099-246fa10c1a97",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-38647",
      "pattern": "[vulnerability:name = 'CVE-2021-38647']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-38647 \u2014 Microsoft Open Management Infrast",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-38645 \u2014 Microsoft Open Management Infrast",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-38649 \u2014 Microsoft Open Management Infrast",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f2d74e90-1b40-41f6-8b8f-579004808e7a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-38648",
      "pattern": "[vulnerability:name = 'CVE-2021-38648']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-38645 \u2014 Microsoft Open Management Infrast",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-38648 \u2014 Microsoft Open Management Infrast",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7aec165b-723b-4b4e-ba71-b353fde66141",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-38649",
      "pattern": "[vulnerability:name = 'CVE-2021-38649']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-38645 \u2014 Microsoft Open Management Infrast",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-38649 \u2014 Microsoft Open Management Infrast",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--368209bf-c360-4e0a-8866-64e89ef29f37",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-40444",
      "pattern": "[vulnerability:name = 'CVE-2021-40444']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-40444 \u2014 Microsoft MSHTML Remote Code Exec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--26c45c05-7e02-4b12-8573-21d9a4e2b962",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-41773",
      "pattern": "[vulnerability:name = 'CVE-2021-41773']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-42013 \u2014 Apache HTTP Server Path Traversal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cfc9ef4f-83ba-451f-9473-dc56706a9e70",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-42013",
      "pattern": "[vulnerability:name = 'CVE-2021-42013']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-42013 \u2014 Apache HTTP Server Path Traversal",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de1f41fd-96e0-49ad-8f7c-369b16f1e2e5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-42258",
      "pattern": "[vulnerability:name = 'CVE-2021-42258']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-42258 \u2014 BQE BillQuick Web Suite SQL Injec",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--655c1154-58dd-4e5c-9639-a1b01fac82d3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: acne-school.ru",
      "pattern": "[domain-name:value = 'acne-school.ru']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-9978 \u2014 WordPress Social Warfare Plugin Cr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--02cf69b8-34c9-41bf-bcbb-0cfd01b44cf6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ado-read-parser.com",
      "pattern": "[domain-name:value = 'ado-read-parser.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31201 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--98b622ff-e7f0-4b61-b4cb-a62733ab2efa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: adoberelations.com",
      "pattern": "[domain-name:value = 'adoberelations.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--afc98e48-f83b-408f-9996-73ca2fa47dad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: adobestats.com",
      "pattern": "[domain-name:value = 'adobestats.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--efcfce86-8d4f-4afd-abf8-fef64ec48cfe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: apple-webservice.com",
      "pattern": "[domain-name:value = 'apple-webservice.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c2dcf2f8-2bc9-4f60-bd51-ddfd726616e1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: appleid-server.com",
      "pattern": "[domain-name:value = 'appleid-server.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ad364388-28c8-4d6b-b98e-fa7d856fdc5f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: atecasec.com",
      "pattern": "[domain-name:value = 'atecasec.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a4096e5b-3319-408f-9e70-e7cb6079c1ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: avsvmcloud.com",
      "pattern": "[domain-name:value = 'avsvmcloud.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-10148 \u2014 SolarWinds Orion Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eddf30f9-b5a8-4c93-9951-e27c59a30a26",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: cmd.irannetworkteam.org",
      "pattern": "[domain-name:value = 'cmd.irannetworkteam.org']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-19781 \u2014 Citrix ADC, Gateway, and SD-WAN W",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--333880a0-f743-4225-9236-442594da2ba0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: customcoverinc.com",
      "pattern": "[domain-name:value = 'customcoverinc.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-9978 \u2014 WordPress Social Warfare Plugin Cr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--777000a2-1c2f-4a58-8007-20e6707d240b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: debugmex.dsirflabs.eu",
      "pattern": "[domain-name:value = 'debugmex.dsirflabs.eu']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d9351619-9c7c-47c3-9837-836b711410d3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: exchange.dumb1.com",
      "pattern": "[domain-name:value = 'exchange.dumb1.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f72f70af-322d-4079-95ea-d51654601795",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: findmymacs.com",
      "pattern": "[domain-name:value = 'findmymacs.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--db026f11-e087-465b-b287-919375a520cc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: flixprice.com",
      "pattern": "[domain-name:value = 'flixprice.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d08af384-1974-4760-9c79-6bc68330f345",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: gxbrowser.net",
      "pattern": "[domain-name:value = 'gxbrowser.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-7961 \u2014 Liferay Portal Deserialization of ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7dfc0072-65ef-44ba-9f6d-f87336f1dffc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: icloudserv.com",
      "pattern": "[domain-name:value = 'icloudserv.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--08573e47-816e-49de-a41f-70f934b503b3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: iotlmao.xyz",
      "pattern": "[domain-name:value = 'iotlmao.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f2324bb-6223-4487-acba-04ff7656a72d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: irc.hoaxcalls.pw",
      "pattern": "[domain-name:value = 'irc.hoaxcalls.pw']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-8515 \u2014 Multiple DrayTek Vigor Routers Web",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b390a97c-7b9a-42e5-b54e-5d649be270b2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: linebrand.xyz",
      "pattern": "[domain-name:value = 'linebrand.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fbebb6ae-fc90-47f5-9e3d-5d0eee0dc836",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: mantrucks.xyz",
      "pattern": "[domain-name:value = 'mantrucks.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--310de640-46ef-4360-a71a-8419ccd2c13c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: media-seoengine.com",
      "pattern": "[domain-name:value = 'media-seoengine.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31955 \u2014 Microsoft Windows Kernel Informat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31956 \u2014 Microsoft Windows NTFS Privilege ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--23ebe6f7-a677-4088-8dcb-e5776466423a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: monotel.xyz",
      "pattern": "[domain-name:value = 'monotel.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--484905e1-752b-48b9-9a3d-ed2653f6782e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: netlabs.gr",
      "pattern": "[domain-name:value = 'netlabs.gr']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-9978 \u2014 WordPress Social Warfare Plugin Cr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5617af0f-c1b0-4f76-a0ae-ee76fffe4781",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: nodeline.xyz",
      "pattern": "[domain-name:value = 'nodeline.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b7876d14-a0a8-4620-aadc-0f24ff5fd0dd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: ntpserver.tk",
      "pattern": "[domain-name:value = 'ntpserver.tk']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c8b44972-3cc9-405c-b227-5964bfbf69e9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: postgre.tk",
      "pattern": "[domain-name:value = 'postgre.tk']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2753d02-bed5-424e-b2b2-011c48e5f212",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sidelink.xyz",
      "pattern": "[domain-name:value = 'sidelink.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--70d2635a-c117-4c3c-bdf3-b8f347df1162",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: sophosfirewallupdate.com",
      "pattern": "[domain-name:value = 'sophosfirewallupdate.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-12271 \u2014 Sophos SFOS SQL Injection Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--36fb8a6a-5d02-4581-9cbf-58bb9b3383c6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: statsmag.com",
      "pattern": "[domain-name:value = 'statsmag.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--56f54c43-dc22-4762-ad9b-e72388f14871",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: statsmag.xyz",
      "pattern": "[domain-name:value = 'statsmag.xyz']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a1b3bc41-85a0-4884-9b2a-e9ade8313595",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: support-box.com",
      "pattern": "[domain-name:value = 'support-box.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cf25d186-6939-4389-8460-ac52d4953aae",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: supportversion.yourlinkforplaceforupgrading.info",
      "pattern": "[domain-name:value = 'supportversion.yourlinkforplaceforupgrading.info']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30657 \u2014 Apple macOS Unspecified Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b831f61-d82e-4d80-a7c3-adb7bad48448",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: szstaging.dsirflabs.eu",
      "pattern": "[domain-name:value = 'szstaging.dsirflabs.eu']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1f793007-2c81-4298-8569-b47bdf85fba4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: tcp.symantecserver.co",
      "pattern": "[domain-name:value = 'tcp.symantecserver.co']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--828c99f7-73e1-441b-a6da-e1dfb67101a4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: tekmat.net",
      "pattern": "[domain-name:value = 'tekmat.net']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-9978 \u2014 WordPress Social Warfare Plugin Cr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--34bc20c1-3d6e-46c2-bc45-34419f86c020",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: titiez.com",
      "pattern": "[domain-name:value = 'titiez.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--965ffdb1-d1f9-4659-af99-20f9e7d4e5b5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: trendmicronano.com",
      "pattern": "[domain-name:value = 'trendmicronano.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76d2ea82-9eb9-4786-86d9-aefb171824b9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: viamarkt.hu",
      "pattern": "[domain-name:value = 'viamarkt.hu']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-9978 \u2014 WordPress Social Warfare Plugin Cr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e82cd1aa-d2a1-4ef4-9003-1f7db72c7a9c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: www.1588-2040.co.kr",
      "pattern": "[domain-name:value = 'www.1588-2040.co.kr']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-4878 \u2014 Adobe Flash Player Use-After-Free ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7a7daf3b-85a8-48de-b2c3-e13a9e19525f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: www.dylboiler.co.kr",
      "pattern": "[domain-name:value = 'www.dylboiler.co.kr']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-4878 \u2014 Adobe Flash Player Use-After-Free ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5e08257f-7ef7-4392-acc6-4fd9253db7cd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: www.korea-tax.info",
      "pattern": "[domain-name:value = 'www.korea-tax.info']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-4878 \u2014 Adobe Flash Player Use-After-Free ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4437d20d-4f99-4352-92f5-818c9f90dbdc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: zx.ado-read-parser.com",
      "pattern": "[domain-name:value = 'zx.ado-read-parser.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31201 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5701b399-4386-474c-96df-03ecee5635b9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 103.255.44.56",
      "pattern": "[ipv4-addr:value = '103.255.44.56']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c30ef35-ee70-4201-8378-5127b11a1137",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 104.248.238.198",
      "pattern": "[ipv4-addr:value = '104.248.238.198']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c4cd352-0f61-4478-8149-aeb46c757b62",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 117.79.132.174",
      "pattern": "[ipv4-addr:value = '117.79.132.174']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8fa681f0-5631-44d3-a4b6-e6f799b1f0da",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 121.196.25.170",
      "pattern": "[ipv4-addr:value = '121.196.25.170']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b81f9cae-18a3-4e6a-bae5-eac2db0f1c03",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 122.9.48.250",
      "pattern": "[ipv4-addr:value = '122.9.48.250']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1dd246cc-6a70-48cf-b25f-4b2ea528ef2d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 123.1.170.152",
      "pattern": "[ipv4-addr:value = '123.1.170.152']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3beed879-7926-4c38-9d79-fb1296563fcb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 13.66.185.182",
      "pattern": "[ipv4-addr:value = '13.66.185.182']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c841690c-3903-4a6e-bba1-30a652792eb0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 13.82.220.36",
      "pattern": "[ipv4-addr:value = '13.82.220.36']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a5ba3fd2-2b18-4e4f-8496-5341b2ccc300",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 13.85.84.182",
      "pattern": "[ipv4-addr:value = '13.85.84.182']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d7e32ac-2034-43e8-a60d-a5b1440ac72e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 141.98.83.139",
      "pattern": "[ipv4-addr:value = '141.98.83.139']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--873a54a2-8feb-4ccc-aebb-a068db9a7cea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 144.34.179.162",
      "pattern": "[ipv4-addr:value = '144.34.179.162']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-35211 \u2014 SolarWinds Serv-U Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e88bc979-c928-40a2-9305-72201bfe1885",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 148.251.71.182",
      "pattern": "[ipv4-addr:value = '148.251.71.182']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a08428b1-895b-46b6-ba05-24346e8b4a00",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 149.28.85.17",
      "pattern": "[ipv4-addr:value = '149.28.85.17']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b211f120-4df8-41ef-ac84-433f6401c84d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 155.94.160.40",
      "pattern": "[ipv4-addr:value = '155.94.160.40']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--029d52cb-718e-4dd4-aa68-c5c333e171ea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 160.20.147.136",
      "pattern": "[ipv4-addr:value = '160.20.147.136']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4b603c3d-0b9c-494d-864f-e64b2dada049",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 161.35.90.11",
      "pattern": "[ipv4-addr:value = '161.35.90.11']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a08bcf51-e2f4-4917-8103-73b668019731",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 164.132.92.180",
      "pattern": "[ipv4-addr:value = '164.132.92.180']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-8515 \u2014 Multiple DrayTek Vigor Routers Web",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d99a9d7c-54ce-45da-84d0-03dce817341e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 169.40.2.68",
      "pattern": "[ipv4-addr:value = '169.40.2.68']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31201 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1e6a603a-5262-4039-a043-753f3150b1d4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 176.113.115.89",
      "pattern": "[ipv4-addr:value = '176.113.115.89']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--84f39f50-91e0-4ab8-be84-d2d92bb0fc04",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 178.170.117.50",
      "pattern": "[ipv4-addr:value = '178.170.117.50']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ffdf0fb4-7910-4032-bc62-d21676f30d64",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 178.32.148.5",
      "pattern": "[ipv4-addr:value = '178.32.148.5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-8515 \u2014 Multiple DrayTek Vigor Routers Web",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--83fe6074-4d0e-44c7-a036-270173718196",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 18.182.153.49",
      "pattern": "[ipv4-addr:value = '18.182.153.49']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--438fb6b5-ce20-4ecb-81fb-a43a72499e11",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 18.185.109.135",
      "pattern": "[ipv4-addr:value = '18.185.109.135']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-8515 \u2014 Multiple DrayTek Vigor Routers Web",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe1ebc2f-b27b-4992-afd5-c511c40bb933",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 18.207.224.249",
      "pattern": "[ipv4-addr:value = '18.207.224.249']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--883017dc-eb2c-4f7f-9b5e-9408f1c5e5ce",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 18.207.254.243",
      "pattern": "[ipv4-addr:value = '18.207.254.243']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7597fb25-7198-47b4-82e7-a0a419287394",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 18.220.190.151",
      "pattern": "[ipv4-addr:value = '18.220.190.151']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--92b63ac1-530a-4e4b-b531-9cf95c1d2303",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 18.221.115.241",
      "pattern": "[ipv4-addr:value = '18.221.115.241']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de1aa36b-c5ef-4b90-b1e8-dc330f588d75",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.141.24.222",
      "pattern": "[ipv4-addr:value = '185.141.24.222']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0171 \u2014 Cisco IOS and IOS XE Software Smar",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c49aeebe-f2cc-41c3-be18-416ee9b1c310",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.141.24.28",
      "pattern": "[ipv4-addr:value = '185.141.24.28']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0171 \u2014 Cisco IOS and IOS XE Software Smar",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b1e6fe6d-5336-4b1b-919e-0a70451442f2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.239.242.63",
      "pattern": "[ipv4-addr:value = '185.239.242.63']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ae4f6638-02c9-4c09-96c1-7878f3168ab3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.82.200.181",
      "pattern": "[ipv4-addr:value = '185.82.200.181']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0171 \u2014 Cisco IOS and IOS XE Software Smar",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--84ccaf28-692f-4e49-84a4-52ecc457084c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 185.82.202.34",
      "pattern": "[ipv4-addr:value = '185.82.202.34']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-0171 \u2014 Cisco IOS and IOS XE Software Smar",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--01eb3e4b-bab5-4b03-b3f7-334cd7484016",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 188.214.34.20",
      "pattern": "[ipv4-addr:value = '188.214.34.20']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31201 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b1d1ea89-6fe8-4c58-b2d2-02dee99418fb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.154.253.120",
      "pattern": "[ipv4-addr:value = '192.154.253.120']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--70211077-6f80-4c92-b0e5-64c307292138",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.3.45.185",
      "pattern": "[ipv4-addr:value = '192.3.45.185']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-8515 \u2014 Multiple DrayTek Vigor Routers Web",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c56a8fa-e4d7-42a9-ad78-2402affe49e2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.52.167.101",
      "pattern": "[ipv4-addr:value = '192.52.167.101']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd2fe24d-9bf7-42b6-962c-8efce6706d66",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.99.35.149",
      "pattern": "[ipv4-addr:value = '192.99.35.149']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-9978 \u2014 WordPress Social Warfare Plugin Cr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0435f58-e985-4c76-8796-0793901f33f8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 192.99.35.63",
      "pattern": "[ipv4-addr:value = '192.99.35.63']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-9978 \u2014 WordPress Social Warfare Plugin Cr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--df261f73-bc1b-487f-920b-60f3e3b45fc2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 193.27.229.26",
      "pattern": "[ipv4-addr:value = '193.27.229.26']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--73b55246-5ac3-4253-90e9-af2c4422f084",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 194.88.104.24",
      "pattern": "[ipv4-addr:value = '194.88.104.24']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--235baeb1-8f9c-4fe3-8a0f-cc816b2340ab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 198.144.189.74",
      "pattern": "[ipv4-addr:value = '198.144.189.74']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7794a7ce-39bc-42f8-ad63-1aafa4f7a2b6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 2.57.33.59",
      "pattern": "[ipv4-addr:value = '2.57.33.59']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c21382a-20ed-4efe-864b-30af48e8595e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 20.185.0.202",
      "pattern": "[ipv4-addr:value = '20.185.0.202']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ad8dcb12-48a5-486b-94f6-1ac777f455a6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 203.159.80.241",
      "pattern": "[ipv4-addr:value = '203.159.80.241']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f1b1a77-17e1-490b-ad57-bb375b416a04",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 207.148.102.208",
      "pattern": "[ipv4-addr:value = '207.148.102.208']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4add22fd-6ea9-4293-a68f-8afe5766bf85",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 208.113.35.58",
      "pattern": "[ipv4-addr:value = '208.113.35.58']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-35211 \u2014 SolarWinds Serv-U Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ce0ba817-46a9-45b5-bb1b-5741389c316c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 209.141.50.210",
      "pattern": "[ipv4-addr:value = '209.141.50.210']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c3d185d6-491b-48c3-ba1c-7f1d0d4c229d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 217.23.5.42",
      "pattern": "[ipv4-addr:value = '217.23.5.42']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ebe32856-a429-4fba-835b-a64c65b91108",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 221.168.37.77",
      "pattern": "[ipv4-addr:value = '221.168.37.77']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1ade7e4c-97e0-4b10-82c8-a5744e9e8f10",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 34.226.244.53",
      "pattern": "[ipv4-addr:value = '34.226.244.53']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aded36bd-2f2f-4b6f-bb13-f7fe71888a6e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 34.247.148.227",
      "pattern": "[ipv4-addr:value = '34.247.148.227']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ed820183-e2aa-4823-9d41-e6f5a0b6a4db",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 37.139.3.208",
      "pattern": "[ipv4-addr:value = '37.139.3.208']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--866814c3-8f21-465c-b0a2-9804174af4f8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 37.46.150.102",
      "pattern": "[ipv4-addr:value = '37.46.150.102']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--179db601-f40e-42b8-b07b-4a8b0e5cbee3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 37.59.35.206",
      "pattern": "[ipv4-addr:value = '37.59.35.206']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f06eacb0-d742-4c6a-a296-748ab824500a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 37.59.55.45",
      "pattern": "[ipv4-addr:value = '37.59.55.45']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-9978 \u2014 WordPress Social Warfare Plugin Cr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a44137d2-85cc-43f8-aec7-51e32edd69d5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 38.27.99.69",
      "pattern": "[ipv4-addr:value = '38.27.99.69']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-12271 \u2014 Sophos SFOS SQL Injection Vulnera",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c5455223-6e0e-412f-906b-830f6db5b95a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.133.1.133",
      "pattern": "[ipv4-addr:value = '45.133.1.133']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--388687df-c91c-4200-b4e9-8cd5db1649e4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 45.135.229.179",
      "pattern": "[ipv4-addr:value = '45.135.229.179']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b689c553-1c11-4633-86c9-7056936cd8dd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 46.30.189.6",
      "pattern": "[ipv4-addr:value = '46.30.189.6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-3452 \u2014 Cisco ASA and FTD Read-Only Path T",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--81ce4de3-9d6c-412c-8162-10988cca03b3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 51.11.136.167",
      "pattern": "[ipv4-addr:value = '51.11.136.167']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--19c83b2f-4302-4fd8-bbc3-6c7b84269f0e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 51.75.195.137",
      "pattern": "[ipv4-addr:value = '51.75.195.137']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de032da5-be51-4299-8082-73b0136bbb2b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 52.186.156.31",
      "pattern": "[ipv4-addr:value = '52.186.156.31']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a0086df-28c0-45fa-927e-526f4018aedf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 52.207.232.106",
      "pattern": "[ipv4-addr:value = '52.207.232.106']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--95f3d8b2-637d-450e-9d70-bb7093b07f8f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 54.197.4.10",
      "pattern": "[ipv4-addr:value = '54.197.4.10']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a91f4044-881e-47d3-bce4-2b35b110b40f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 66.42.98.220",
      "pattern": "[ipv4-addr:value = '66.42.98.220']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6b599e35-c88d-4dd4-99c3-2e75e76cc537",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 66.7.149.161",
      "pattern": "[ipv4-addr:value = '66.7.149.161']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c066629a-d5f9-41a0-bde1-ce91ae82119b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 68.235.178.32",
      "pattern": "[ipv4-addr:value = '68.235.178.32']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-35211 \u2014 SolarWinds Serv-U Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--49fb1566-cc63-4e1c-8483-e03c38658312",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 74.82.201.8",
      "pattern": "[ipv4-addr:value = '74.82.201.8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f05b750b-1c55-4386-a727-79a6ac8640a7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 77.71.115.52",
      "pattern": "[ipv4-addr:value = '77.71.115.52']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-11738 \u2014 WordPress Snap Creek Duplicator P",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ca9fb2c2-67d6-4433-a66f-d03421282bff",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 79.141.162.82",
      "pattern": "[ipv4-addr:value = '79.141.162.82']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0aede6fe-50a7-4d40-bf44-f3f6dfbd93de",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 8.47.64.2",
      "pattern": "[ipv4-addr:value = '8.47.64.2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-9978 \u2014 WordPress Social Warfare Plugin Cr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--470afc93-9896-473a-bc78-80a6529a4ee6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 82.221.136.27",
      "pattern": "[ipv4-addr:value = '82.221.136.27']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-1732 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5ce79770-7da6-4642-813b-5f5c11ab064e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 86.105.195.120",
      "pattern": "[ipv4-addr:value = '86.105.195.120']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--88dddbaf-d014-41fd-ab61-daa20bac14a4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 86.105.195.154",
      "pattern": "[ipv4-addr:value = '86.105.195.154']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d23635a-4330-4287-bf2e-e3fc813adb18",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 86.57.38.156",
      "pattern": "[ipv4-addr:value = '86.57.38.156']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f99716b-c61a-4b22-a57f-92a4176f1032",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 87.106.194.46",
      "pattern": "[ipv4-addr:value = '87.106.194.46']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ab7be929-f22f-4317-9b55-3863e7d3958d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 91.208.184.78",
      "pattern": "[ipv4-addr:value = '91.208.184.78']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7fcde480-7f4a-44af-8a2b-cac415fe1302",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 94.23.255.34",
      "pattern": "[ipv4-addr:value = '94.23.255.34']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-9978 \u2014 WordPress Social Warfare Plugin Cr",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e4906297-a36b-41fd-a037-9846b44aed3e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 97.77.97.58",
      "pattern": "[ipv4-addr:value = '97.77.97.58']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-35211 \u2014 SolarWinds Serv-U Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--93ebf639-5932-4150-ac59-4069dc4fd390",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 98.176.196.89",
      "pattern": "[ipv4-addr:value = '98.176.196.89']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-35211 \u2014 SolarWinds Serv-U Remote Code Exe",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--144315a4-8cfa-4c21-b056-6f65834fb244",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "IPV4: 98.239.93.20",
      "pattern": "[ipv4-addr:value = '98.239.93.20']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--df6cbe4d-6773-404f-9ed7-7321e13973b2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 09a5055db44fc1c9e3add608efff038c",
      "pattern": "[file:hashes.MD5 = '09a5055db44fc1c9e3add608efff038c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31955 \u2014 Microsoft Windows Kernel Informat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31956 \u2014 Microsoft Windows NTFS Privilege ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0b1ac8b-3f04-4756-a5d0-b390b7630af0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 25a16b0fca9acd71450e02a341064c8d",
      "pattern": "[file:hashes.MD5 = '25a16b0fca9acd71450e02a341064c8d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-1732 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b9bd0b23-f05d-4b1e-aa5e-c81b9c88d911",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 2798c0e836b907e8224520e7e6e4bb42",
      "pattern": "[file:hashes.MD5 = '2798c0e836b907e8224520e7e6e4bb42']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ced18ef7-f5bf-4f51-ba0e-4ad131e591a4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 31f05b4ee52f0512c96d0cc6f158e083",
      "pattern": "[file:hashes.MD5 = '31f05b4ee52f0512c96d0cc6f158e083']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bcab6935-7c5f-4738-b7d3-1b8b40b47b43",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 3375fe67827671e121d049f9aabefc3e",
      "pattern": "[file:hashes.MD5 = '3375fe67827671e121d049f9aabefc3e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--63ff0002-a830-4382-8cdf-bf0d7baba31a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 34623dc70d274157dbc6e08b21154a3f",
      "pattern": "[file:hashes.MD5 = '34623dc70d274157dbc6e08b21154a3f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--22282739-4384-44ef-b7f8-0204797f2274",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 3e6a16bcf7a9e9e0be25ae28551150f5",
      "pattern": "[file:hashes.MD5 = '3e6a16bcf7a9e9e0be25ae28551150f5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-14558 \u2014 Tenda AC7, AC9, and AC10 Routers ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cf3a6b5b-6c02-4aa3-9652-71b9448ad1b8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 3e856162c36b532925c8226b4ed3481c",
      "pattern": "[file:hashes.MD5 = '3e856162c36b532925c8226b4ed3481c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7f4336fb-3631-41ee-ba16-910cf475b97a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 4a7bf7f013cc2297d62627b2b78c5b0b",
      "pattern": "[file:hashes.MD5 = '4a7bf7f013cc2297d62627b2b78c5b0b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb8db017-5c5e-41d2-ac90-3b116edd2634",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 4ee942a0153ed74eb9a98f7ad321ec97",
      "pattern": "[file:hashes.MD5 = '4ee942a0153ed74eb9a98f7ad321ec97']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-14558 \u2014 Tenda AC7, AC9, and AC10 Routers ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2ef873a6-3b39-4dd1-94b4-edc81edc3d4a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 522cda0c18b410daa033dc66c48eb75a",
      "pattern": "[file:hashes.MD5 = '522cda0c18b410daa033dc66c48eb75a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31201 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--835d0142-c671-4f33-bbcc-ee46d6ef44b2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 5909983db4d9023e4098e56361c96a6f",
      "pattern": "[file:hashes.MD5 = '5909983db4d9023e4098e56361c96a6f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--792c1952-9f35-4584-9ebf-0c8243f47e9a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 6078c8a0c32f4e634f2952e3ebac2430",
      "pattern": "[file:hashes.MD5 = '6078c8a0c32f4e634f2952e3ebac2430']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4dda17d4-8a28-4299-b0ae-f77477aee339",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 659bd19b562059f3f0cc978e15624fd9",
      "pattern": "[file:hashes.MD5 = '659bd19b562059f3f0cc978e15624fd9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7f09d834-84b2-46be-8a6f-8abf8205c30e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 6bff8b6fd606e795385b84437d1e1e0a",
      "pattern": "[file:hashes.MD5 = '6bff8b6fd606e795385b84437d1e1e0a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-14558 \u2014 Tenda AC7, AC9, and AC10 Routers ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e963024d-ae8f-4df5-a835-0b8ac8aea4a6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 733f71eb6cfca905e8904d0fb785fb43",
      "pattern": "[file:hashes.MD5 = '733f71eb6cfca905e8904d0fb785fb43']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-14558 \u2014 Tenda AC7, AC9, and AC10 Routers ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--11895121-3f35-4070-b518-fa0dde2deda1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 73ffd45ab46415b41831faee138f306e",
      "pattern": "[file:hashes.MD5 = '73ffd45ab46415b41831faee138f306e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-14558 \u2014 Tenda AC7, AC9, and AC10 Routers ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a9adbb62-b5b0-4c36-a635-7f57bbac587a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 75259ee2db52d038efea5f939f68f122",
      "pattern": "[file:hashes.MD5 = '75259ee2db52d038efea5f939f68f122']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9b447b2b-1865-4449-a937-fbc422171c4d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 7966c2c546b71e800397a67f942858d0",
      "pattern": "[file:hashes.MD5 = '7966c2c546b71e800397a67f942858d0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a85fd7c7-899c-4296-acdd-38af85865b45",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 7c2b567b659246d2b278da500daa9abe",
      "pattern": "[file:hashes.MD5 = '7c2b567b659246d2b278da500daa9abe']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7cfd9073-3608-420f-a60d-d0be74343e89",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 8cc2b831e29dc9f4832a162e9f425649",
      "pattern": "[file:hashes.MD5 = '8cc2b831e29dc9f4832a162e9f425649']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--701e645b-2cce-47c6-b0eb-0296fd83b418",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 911e417b9bc8689a3eed828f0b39f579",
      "pattern": "[file:hashes.MD5 = '911e417b9bc8689a3eed828f0b39f579']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87202f3a-8f9c-45d1-baee-4728331c8952",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: a43ad8a740081f0b5a89e219fe8475a3",
      "pattern": "[file:hashes.MD5 = 'a43ad8a740081f0b5a89e219fe8475a3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--68e985a4-94b8-4e39-beaf-ffb641551bb0",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: a89cefdf71f2fced35fba8612ad07174",
      "pattern": "[file:hashes.MD5 = 'a89cefdf71f2fced35fba8612ad07174']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-14558 \u2014 Tenda AC7, AC9, and AC10 Routers ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c0eeb6f1-9f68-4ae4-915a-9b37b83426b2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: a8eb59396d698bda5840c8b73c34a03b",
      "pattern": "[file:hashes.MD5 = 'a8eb59396d698bda5840c8b73c34a03b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c985bdcb-2b1b-480c-be81-8ce68aacef66",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: bdfd11b1b092b7c61ce5f02ffc5ad55a",
      "pattern": "[file:hashes.MD5 = 'bdfd11b1b092b7c61ce5f02ffc5ad55a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1aa7d4e6-2d35-4e67-af85-cbb2bef7caa7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: bf8a7b199f3293852c7f2b3578e8c0ae",
      "pattern": "[file:hashes.MD5 = 'bf8a7b199f3293852c7f2b3578e8c0ae']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fedaeb06-0de1-4260-b3fc-7b5cf8cdb961",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: c5cb2b438ba6d809f1f71c776376d293",
      "pattern": "[file:hashes.MD5 = 'c5cb2b438ba6d809f1f71c776376d293']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-14558 \u2014 Tenda AC7, AC9, and AC10 Routers ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c1021119-de0a-40c4-8d50-4d579f70240b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: cfc0f745941ce1ec024cb86b1fd244f3",
      "pattern": "[file:hashes.MD5 = 'cfc0f745941ce1ec024cb86b1fd244f3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-14558 \u2014 Tenda AC7, AC9, and AC10 Routers ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e78c7618-4f24-42e7-bd77-6ea57666daf3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: d4a55e486f5e28168bc4554cffa64ea0",
      "pattern": "[file:hashes.MD5 = 'd4a55e486f5e28168bc4554cffa64ea0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--10d4ad2c-132c-4582-b6cc-8f743f826839",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: d6b850c950379d5ee0f254f7164833e8",
      "pattern": "[file:hashes.MD5 = 'd6b850c950379d5ee0f254f7164833e8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31955 \u2014 Microsoft Windows Kernel Informat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31956 \u2014 Microsoft Windows NTFS Privilege ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--18164b84-04f7-4be7-89eb-85d7c232c886",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: f0551696774f66ad3485445d9e3f7214",
      "pattern": "[file:hashes.MD5 = 'f0551696774f66ad3485445d9e3f7214']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and D",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b331fd38-a15a-4381-8edd-cd02ae76648b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 085a136c03f8b024a173068768c67b1a5ad928c1",
      "pattern": "[file:hashes.'SHA-1' = '085a136c03f8b024a173068768c67b1a5ad928c1']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30657 \u2014 Apple macOS Unspecified Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cd58c51a-21c5-4e5b-bf31-f559e370f57d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 0902181D1B9433B5616763646A089B1BDF428262",
      "pattern": "[file:hashes.'SHA-1' = '0902181D1B9433B5616763646A089B1BDF428262']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5206f917-e439-43ff-8062-94c4812696fe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 0AB00045D0D403F2D8F8865120C1089C09BA4FEE",
      "pattern": "[file:hashes.'SHA-1' = '0AB00045D0D403F2D8F8865120C1089C09BA4FEE']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--962b2f4a-8a3c-423a-afa2-de3894255d44",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 11D7694987A32A91FB766BA221F9A2DE3C06D173",
      "pattern": "[file:hashes.'SHA-1' = '11D7694987A32A91FB766BA221F9A2DE3C06D173']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f35911c8-e3d2-4a2b-8e1d-ca6623a8303c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 20ac95c44549710a434902267394525333e96c0b",
      "pattern": "[file:hashes.'SHA-1' = '20ac95c44549710a434902267394525333e96c0b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30657 \u2014 Apple macOS Unspecified Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--db096640-cad6-4f5a-b314-c5dc530bf458",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 31721AE37835F792EE792D8324E307BA423277AE",
      "pattern": "[file:hashes.'SHA-1' = '31721AE37835F792EE792D8324E307BA423277AE']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a32fedd2-03c7-4aab-ba5e-15d524dddd27",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 3664e6e27fb2784f44f6dba6105ac8b90793032a",
      "pattern": "[file:hashes.'SHA-1' = '3664e6e27fb2784f44f6dba6105ac8b90793032a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3039d915-6398-44dd-a748-e4bb339b282b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 37D4CC67351B2BD8067AB99973C4AFD7090DB1E9",
      "pattern": "[file:hashes.'SHA-1' = '37D4CC67351B2BD8067AB99973C4AFD7090DB1E9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ee86546a-e575-4600-a7dc-359eadd68d58",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 52413AE19BBCDB9339D38A6F305E040FE83DEE1B",
      "pattern": "[file:hashes.'SHA-1' = '52413AE19BBCDB9339D38A6F305E040FE83DEE1B']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b2b99604-ab76-4c42-8214-b85500841370",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 55869270ed20956e5c3e5533fb4472e4eb533dc2",
      "pattern": "[file:hashes.'SHA-1' = '55869270ed20956e5c3e5533fb4472e4eb533dc2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30657 \u2014 Apple macOS Unspecified Vulnerabi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1afb7d19-6562-4e4a-a7cc-8c17e7581a1d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 76640508b1e7759e548771a5359eaed353bf1eec",
      "pattern": "[file:hashes.'SHA-1' = '76640508b1e7759e548771a5359eaed353bf1eec']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-10148 \u2014 SolarWinds Orion Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1d7394c7-058a-4ea3-8a57-014f4a82e3e8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 83d21bb502b73016ec0ad7d6c725d71aaffa0f6d",
      "pattern": "[file:hashes.'SHA-1' = '83d21bb502b73016ec0ad7d6c725d71aaffa0f6d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a9c5d995-3d95-4eeb-8c0a-438652f2657b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 9FCB3943660203E99C348F17A8801BA077F7CB40",
      "pattern": "[file:hashes.'SHA-1' = '9FCB3943660203E99C348F17A8801BA077F7CB40']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3e6ea647-aff7-43af-a66d-38d9dc89e444",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: A0BC6EA2BFA1D3D895FE8E706737D490D5FE3987",
      "pattern": "[file:hashes.'SHA-1' = 'A0BC6EA2BFA1D3D895FE8E706737D490D5FE3987']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Ov",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc630278-b462-4a80-b72c-3fea55053cb3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: bffa4462901b74dbfbfffaa3a3db27daa61211412",
      "pattern": "[file:hashes.'SHA-1' = 'bffa4462901b74dbfbfffaa3a3db27daa61211412']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31955 \u2014 Microsoft Windows Kernel Informat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31956 \u2014 Microsoft Windows NTFS Privilege ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--17942fab-c07a-49e9-9325-2186fdeacdea",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: dafd571da1df72fb53bcd250e8b901103b51d6e4",
      "pattern": "[file:hashes.'SHA-1' = 'dafd571da1df72fb53bcd250e8b901103b51d6e4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31201 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b4dae36b-d627-4a54-9b86-b8845fa68eca",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: e63ed3b56a5f9a1ea5c92d3d2444196ea13be94b",
      "pattern": "[file:hashes.'SHA-1' = 'e63ed3b56a5f9a1ea5c92d3d2444196ea13be94b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31955 \u2014 Microsoft Windows Kernel Informat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31956 \u2014 Microsoft Windows NTFS Privilege ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--21b7e039-c3f5-447b-a26f-787451e40617",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: ef949770ae46bb58918b0fe127bec0ec300b18a9",
      "pattern": "[file:hashes.'SHA-1' = 'ef949770ae46bb58918b0fe127bec0ec300b18a9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--01fd9fce-dd96-454a-94cb-d7ac4ceba192",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 02ac3a4f1cfb2723c20f3c7678b62c340c7974b95f8d9320941641d5c6fd2fee",
      "pattern": "[file:hashes.'SHA-256' = '02ac3a4f1cfb2723c20f3c7678b62c340c7974b95f8d9320941641d5c6fd2fee']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f754a651-6384-4a21-af93-5fcea0e57010",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 03bfec4e039805091fe30fa978d5ec7f28431bb0fca4b137e075257b3e1c0dd4",
      "pattern": "[file:hashes.'SHA-256' = '03bfec4e039805091fe30fa978d5ec7f28431bb0fca4b137e075257b3e1c0dd4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3a5c70a4-ed36-40aa-9b97-481da3a6a6a5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 051baaabf205c7c0f5fd455ac5775447f9f3df0cc9bc5f66f6d386f368520581",
      "pattern": "[file:hashes.'SHA-256' = '051baaabf205c7c0f5fd455ac5775447f9f3df0cc9bc5f66f6d386f368520581']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8557b6d-4cae-4233-8d52-3d5a946fd72c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 05908f2a1325c130e3a877a32dfdf1c9596d156d031d0eaa54473fe342206a65",
      "pattern": "[file:hashes.'SHA-256' = '05908f2a1325c130e3a877a32dfdf1c9596d156d031d0eaa54473fe342206a65']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-7961 \u2014 Liferay Portal Deserialization of ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--84c5fc40-1437-40f2-9076-b2ee08a884e2",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 0747988a77c89c1267a882b663fbd4168e25aed239fb1553e65bb4ac74ecda67",
      "pattern": "[file:hashes.'SHA-256' = '0747988a77c89c1267a882b663fbd4168e25aed239fb1553e65bb4ac74ecda67']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3a78387d-6db1-4b45-b8a4-0e3bc813cadb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 097549cf7d0f76f0d99edf8b2d91c60977fd6a96e4b8c3c94b0b1733dc026d3e",
      "pattern": "[file:hashes.'SHA-256' = '097549cf7d0f76f0d99edf8b2d91c60977fd6a96e4b8c3c94b0b1733dc026d3e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26857 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9076c510-c3ab-45d7-9b30-c960277e921f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1900e09983acf7ddc658b860be7875a527bc914cbffcf0aaff0b4182ecef047b",
      "pattern": "[file:hashes.'SHA-256' = '1900e09983acf7ddc658b860be7875a527bc914cbffcf0aaff0b4182ecef047b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6c00f369-ffeb-4c81-a858-ea0268ce506f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 1cf9ac9150d59de25ca5ac1f855fadf1b03f13b4e9ced63a12acef9c8292a648",
      "pattern": "[file:hashes.'SHA-256' = '1cf9ac9150d59de25ca5ac1f855fadf1b03f13b4e9ced63a12acef9c8292a648']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f87d55db-467b-4a66-aa1c-ca1efc610bfd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 26b3c9a5077232c1bbb5c5b4fc5513e3e0b54a735c32ae90a6d6c1e1d7e4cc0f",
      "pattern": "[file:hashes.'SHA-256' = '26b3c9a5077232c1bbb5c5b4fc5513e3e0b54a735c32ae90a6d6c1e1d7e4cc0f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-1732 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bfa61355-9082-40b5-9bf0-43f34b51098c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2a09719254934fe8ee8f200a0a7537d35a293fe1f8d0e396e23374e9b209f273",
      "pattern": "[file:hashes.'SHA-256' = '2a09719254934fe8ee8f200a0a7537d35a293fe1f8d0e396e23374e9b209f273']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8574a323-944f-4ed5-97ed-a9e70bcca706",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 2e0df09fa37eabcae645302d9865913b818ee0993199a6d904728f3093ff48c7",
      "pattern": "[file:hashes.'SHA-256' = '2e0df09fa37eabcae645302d9865913b818ee0993199a6d904728f3093ff48c7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--977ceedc-f391-41f6-b378-e990c4d60a6e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 32519b85c0b422e4656de6e6c41878e95fd95026267daab4215ee59c107d6c77",
      "pattern": "[file:hashes.'SHA-256' = '32519b85c0b422e4656de6e6c41878e95fd95026267daab4215ee59c107d6c77']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-10148 \u2014 SolarWinds Orion Authentication B",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ec5f801-113f-4764-94cb-af9f878ff75b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 372ab5c1c23d198b594353239a96d6cf620cc56588f5fdf5dfb32919dd019020",
      "pattern": "[file:hashes.'SHA-256' = '372ab5c1c23d198b594353239a96d6cf620cc56588f5fdf5dfb32919dd019020']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8e8294f9-79f9-4176-9b2c-6e8e07294510",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 39b6d72101adae2b71815328599f8e67ee27955849dfb3825c5b2731d504696b",
      "pattern": "[file:hashes.'SHA-256' = '39b6d72101adae2b71815328599f8e67ee27955849dfb3825c5b2731d504696b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8d11970-bdb6-42f5-a0be-c7215ffcf59a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 3b1395f620e428c5f68c6497a2338da0c4f749feb64e8f12e4c5b1288cc57a1c",
      "pattern": "[file:hashes.'SHA-256' = '3b1395f620e428c5f68c6497a2338da0c4f749feb64e8f12e4c5b1288cc57a1c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-4878 \u2014 Adobe Flash Player Use-After-Free ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1965d308-d89b-470c-b635-916a475ee75d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 41ef0133acaca395ea957e796dc1b939b9825b1414541c616b8ca8bdfadb8d16",
      "pattern": "[file:hashes.'SHA-256' = '41ef0133acaca395ea957e796dc1b939b9825b1414541c616b8ca8bdfadb8d16']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-8515 \u2014 Multiple DrayTek Vigor Routers Web",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--98b32042-00d5-4b2b-845a-72defbfc1f4a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 4ff21e69b11566336f4fd56ac2829cdcf215182e8ff807f8e744c0a2b08f726f",
      "pattern": "[file:hashes.'SHA-256' = '4ff21e69b11566336f4fd56ac2829cdcf215182e8ff807f8e744c0a2b08f726f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87385720-99c1-495b-9dba-a141cd2fd81d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 54077a5b15638e354fa02318623775b7a1cc0e8c21e59bcbab333035369e377f",
      "pattern": "[file:hashes.'SHA-256' = '54077a5b15638e354fa02318623775b7a1cc0e8c21e59bcbab333035369e377f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31201 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1d0a0adb-cf5d-47b9-b3cf-e61e4961dc46",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 554bee9f896a7a013804485894875348ff760b08ff7b0ae14c210e2b37da75f6",
      "pattern": "[file:hashes.'SHA-256' = '554bee9f896a7a013804485894875348ff760b08ff7b0ae14c210e2b37da75f6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bcb61ea0-a591-4208-845a-dfb4232a39cf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5f1e0e3cc38f7888b89a9adddb745a341c5f65165dadc311ca389789cc9c6889",
      "pattern": "[file:hashes.'SHA-256' = '5f1e0e3cc38f7888b89a9adddb745a341c5f65165dadc311ca389789cc9c6889']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9fa77fbe-b282-4e7c-8584-876e1c258702",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 5fa2b9546770241da7305356d6427847598288290866837626f621d794692c1b",
      "pattern": "[file:hashes.'SHA-256' = '5fa2b9546770241da7305356d6427847598288290866837626f621d794692c1b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injectio",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulne",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8b19dc9d-4f2a-49eb-af62-58f76b7274c3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 60d22223625c86d7f3deb20f41aec40bc8e1df3ab02cf379d95554df05edf55c",
      "pattern": "[file:hashes.'SHA-256' = '60d22223625c86d7f3deb20f41aec40bc8e1df3ab02cf379d95554df05edf55c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ca96885c-0404-43fa-9645-b8b3e351fc5b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 65dca34b04416f9a113f09718cbe51e11fd58e7287b7863e37f393ed4d25dde7",
      "pattern": "[file:hashes.'SHA-256' = '65dca34b04416f9a113f09718cbe51e11fd58e7287b7863e37f393ed4d25dde7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31201 \u2014 Microsoft Enhanced Cryptographic ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--532dd2ba-8de8-4e87-8f2e-a88405631361",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 667640d293e4ce2287546fc2e0056ee14f414868bf5b77f72078096c516a9fb0",
      "pattern": "[file:hashes.'SHA-256' = '667640d293e4ce2287546fc2e0056ee14f414868bf5b77f72078096c516a9fb0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--535e4c1e-67ef-4121-8880-6d9c9845b7d7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 66ea76a427b69f153486f962baff29d4a68393e985c7d88c94d773b25ad4964a",
      "pattern": "[file:hashes.'SHA-256' = '66ea76a427b69f153486f962baff29d4a68393e985c7d88c94d773b25ad4964a']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f3e387b3-0b51-4629-b4f5-056019f62030",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 68132010d9a543a6a2a9ea61e771cf2c041cea259cc76affdfe663e20c130a45",
      "pattern": "[file:hashes.'SHA-256' = '68132010d9a543a6a2a9ea61e771cf2c041cea259cc76affdfe663e20c130a45']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--09dd5f9a-abdc-4b51-b140-56d182a50b23",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 695a0b2ef0d46027d2f106c060dade52b34e3bb7342a8eae906c7d2b15a99fc3",
      "pattern": "[file:hashes.'SHA-256' = '695a0b2ef0d46027d2f106c060dade52b34e3bb7342a8eae906c7d2b15a99fc3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-8515 \u2014 Multiple DrayTek Vigor Routers Web",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cd6237df-aa14-4dfd-a2c7-35e0b5268ca8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6ae71f71db042e43077941abe4d56753e0947b9464eac4e03567ec5356d9a22b",
      "pattern": "[file:hashes.'SHA-256' = '6ae71f71db042e43077941abe4d56753e0947b9464eac4e03567ec5356d9a22b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-11652 \u2014 SaltStack Salt Path Traversal Vul",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2020-11651 \u2014 SaltStack Salt Authentication Byp",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67f753c3-5994-4323-8f63-fbf85e2f1e0c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6e25ad03103a1a972b78c642bac09060fa79c460011dc5748cbb433cc459938b",
      "pattern": "[file:hashes.'SHA-256' = '6e25ad03103a1a972b78c642bac09060fa79c460011dc5748cbb433cc459938b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a4d3189-04c8-456b-867c-3fc643589a92",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 6f191f598589b7708b1890d56b374b45c6eb41610d34f976f0b4cfde8d5731af",
      "pattern": "[file:hashes.'SHA-256' = '6f191f598589b7708b1890d56b374b45c6eb41610d34f976f0b4cfde8d5731af']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34527 \u2014 Microsoft Windows Print Spooler R",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e7c7b900-1e30-47b9-995c-fb8337b5dc47",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 72492605815c59579170adef1519231a5e3f17ada26428d20bd7948041c812a3",
      "pattern": "[file:hashes.'SHA-256' = '72492605815c59579170adef1519231a5e3f17ada26428d20bd7948041c812a3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-8515 \u2014 Multiple DrayTek Vigor Routers Web",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--856baaf8-6231-47c9-8c18-b6ffa8a72fce",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 77b4f7f0d66a0333d756116eaae567a8540392f558c49d507bf6da10bd047fe3",
      "pattern": "[file:hashes.'SHA-256' = '77b4f7f0d66a0333d756116eaae567a8540392f558c49d507bf6da10bd047fe3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--276a1143-0b30-438b-b177-d6eb403f56ec",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7b64a739836c6b436c179eac37c446fee5ba5abc6c96206cf8e454744a0cd5f2",
      "pattern": "[file:hashes.'SHA-256' = '7b64a739836c6b436c179eac37c446fee5ba5abc6c96206cf8e454744a0cd5f2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-1732 \u2014 Microsoft Win32k Privilege Escalat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bdfa7496-b7ea-4695-867b-a068d332ae6c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 7c7273d0ac2aaba3116c3021530c1c868dc848b6fdd2aafa1deecac216131779",
      "pattern": "[file:hashes.'SHA-256' = '7c7273d0ac2aaba3116c3021530c1c868dc848b6fdd2aafa1deecac216131779']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-7961 \u2014 Liferay Portal Deserialization of ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aeed7b20-ef49-442b-9efe-255882dbfb84",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 80cd13bfcc2fc29096abf18525d17766700a6d25a9806e55c7b7de776cba0302",
      "pattern": "[file:hashes.'SHA-256' = '80cd13bfcc2fc29096abf18525d17766700a6d25a9806e55c7b7de776cba0302']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a739e034-28b6-4725-b256-a8165a74fdf5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 80fb66c6b1191954c31734355a236b7342dc3fd074ead47f9c1ed465561c6e8c",
      "pattern": "[file:hashes.'SHA-256' = '80fb66c6b1191954c31734355a236b7342dc3fd074ead47f9c1ed465561c6e8c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b8948745-6035-4a9a-bce9-0bcb4fe11663",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 84448ee487010d6fed918febe230b71a8ec1266e300f85933014db2566645857",
      "pattern": "[file:hashes.'SHA-256' = '84448ee487010d6fed918febe230b71a8ec1266e300f85933014db2566645857']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e54cfefc-e7fa-4656-88d4-dabce1d2e18b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 88ddd8a1b77477aaffd1bb163b9770d72a77bf29bfca226e79c28d15bef983ed",
      "pattern": "[file:hashes.'SHA-256' = '88ddd8a1b77477aaffd1bb163b9770d72a77bf29bfca226e79c28d15bef983ed']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d66a80e2-47b6-45fa-ac0c-e01a60279c71",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8a17279ba26c8fbe6966ea3300fdefb1adae1b3ed68f76a7fc81413bd8c1a5f6",
      "pattern": "[file:hashes.'SHA-256' = '8a17279ba26c8fbe6966ea3300fdefb1adae1b3ed68f76a7fc81413bd8c1a5f6']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31955 \u2014 Microsoft Windows Kernel Informat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31956 \u2014 Microsoft Windows NTFS Privilege ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eca2b121-ca17-431f-b37a-ecb0fb47138a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8b5810e07cf21ebb1c2ff23c13ce88022c1dd5bc2df32f4d7e5480b4ddb82de2",
      "pattern": "[file:hashes.'SHA-256' = '8b5810e07cf21ebb1c2ff23c13ce88022c1dd5bc2df32f4d7e5480b4ddb82de2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cf5e25a6-7024-49d4-b7bc-161c223e7d26",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8dd620d9aeb35960bb766458c8890ede987c33d239cf730f93fe49d90ae759dd",
      "pattern": "[file:hashes.'SHA-256' = '8dd620d9aeb35960bb766458c8890ede987c33d239cf730f93fe49d90ae759dd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30116 \u2014 Kaseya Virtual System/Server Admi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d40a6876-868e-44e4-89ef-a1dd7053060e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8fae0d5860aa44b5c7260ef7a0b277bcddae8c02cea7d3a9c19f1a40388c223f",
      "pattern": "[file:hashes.'SHA-256' = '8fae0d5860aa44b5c7260ef7a0b277bcddae8c02cea7d3a9c19f1a40388c223f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0669d151-0fce-45fb-ad27-12ec56f1befe",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 94f02ea10b4546da71bd46916f0fe260b40c8ed4deccf0588687e62ca3819ad7",
      "pattern": "[file:hashes.'SHA-256' = '94f02ea10b4546da71bd46916f0fe260b40c8ed4deccf0588687e62ca3819ad7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c866fbb-eb79-454b-9aec-2dad08db7bb5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 982f7c4700c75b81833d5d59ad29147c392b20c760fe36b200b541a0f841c8a9",
      "pattern": "[file:hashes.'SHA-256' = '982f7c4700c75b81833d5d59ad29147c392b20c760fe36b200b541a0f841c8a9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-31955 \u2014 Microsoft Windows Kernel Informat",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "source_name": "CISA KEV: CVE-2021-31956 \u2014 Microsoft Windows NTFS Privilege ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--168eea4f-455d-4a43-8266-306fbdfea9e8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 98ccde0e1a5e6c7071623b8b294df53d8e750ff2fa22070b19a88faeaa3d32b0",
      "pattern": "[file:hashes.'SHA-256' = '98ccde0e1a5e6c7071623b8b294df53d8e750ff2fa22070b19a88faeaa3d32b0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5568298-5df7-471b-a4cd-455032d92f12",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 994889422b24a5b4759eda30265f1b933a458e15927b4f7949d4a3ba79eb43ca",
      "pattern": "[file:hashes.'SHA-256' = '994889422b24a5b4759eda30265f1b933a458e15927b4f7949d4a3ba79eb43ca']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e8803087-a5b5-4b47-89de-14302e387fa5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 99d06d1c82af244b1533c1173ca10da7f29bfbf753073f20f5dc7a0016152a4c",
      "pattern": "[file:hashes.'SHA-256' = '99d06d1c82af244b1533c1173ca10da7f29bfbf753073f20f5dc7a0016152a4c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b64bda14-0970-4181-8016-8436d481b9f4",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a447bb67be310702807ff148f53f2b4c64ddba0c37f92caf6acabdfaa9ad6603",
      "pattern": "[file:hashes.'SHA-256' = 'a447bb67be310702807ff148f53f2b4c64ddba0c37f92caf6acabdfaa9ad6603']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4f5bd536-1bfc-475c-8c9c-f8e10d2d2269",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a68ab806c8e111e98ba46d5bfdabd9091a68839dd39dfe81e887361bd4994a62",
      "pattern": "[file:hashes.'SHA-256' = 'a68ab806c8e111e98ba46d5bfdabd9091a68839dd39dfe81e887361bd4994a62']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--05caf52b-de8a-4881-a954-cc6b126614b7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: a7373fa18b367edbcd4462345a5da087821e34734bdf05d1c4060a7694868c5e",
      "pattern": "[file:hashes.'SHA-256' = 'a7373fa18b367edbcd4462345a5da087821e34734bdf05d1c4060a7694868c5e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--066cf36a-3957-4881-a005-3f4dd7a3575c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ab671fc0c68ed1c249c2bb52b28ae3d70df8bd1614d86f6d6a3f4c21d7841d72",
      "pattern": "[file:hashes.'SHA-256' = 'ab671fc0c68ed1c249c2bb52b28ae3d70df8bd1614d86f6d6a3f4c21d7841d72']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--42fe53e1-7e38-4d04-a8f7-806230c63390",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ac4f2e74a7b90b772afb920f10b789415355451c79b3ed359ccad1976c1857a8",
      "pattern": "[file:hashes.'SHA-256' = 'ac4f2e74a7b90b772afb920f10b789415355451c79b3ed359ccad1976c1857a8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-7961 \u2014 Liferay Portal Deserialization of ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--94438ca3-a189-4832-b0d5-cdca6b201e2e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ac6818140883e0f8bf5cef9b5f965861ff64cebfe181ff025e1f0aee9c72506c",
      "pattern": "[file:hashes.'SHA-256' = 'ac6818140883e0f8bf5cef9b5f965861ff64cebfe181ff025e1f0aee9c72506c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-7961 \u2014 Liferay Portal Deserialization of ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2f786f15-8129-4565-a053-6222d59aa0bd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b2122c5a9c738d964fa770760db40d6708de377e2e671feccb836054ceda2f47",
      "pattern": "[file:hashes.'SHA-256' = 'b2122c5a9c738d964fa770760db40d6708de377e2e671feccb836054ceda2f47']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c546a1a-2b87-4fbd-8ba0-9ef244c25954",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b4cb04709f613b5363514e75984084ef1d3eaba7c50638b2a5a284680831b992",
      "pattern": "[file:hashes.'SHA-256' = 'b4cb04709f613b5363514e75984084ef1d3eaba7c50638b2a5a284680831b992']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3646bfa7-6e95-4d1d-956d-9c71d8342fee",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: b75f163ca9b9240bf4b37ad92bc7556b40a17e27c2b8ed5c8991385fe07d17d0",
      "pattern": "[file:hashes.'SHA-256' = 'b75f163ca9b9240bf4b37ad92bc7556b40a17e27c2b8ed5c8991385fe07d17d0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-26857 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e5b97cbd-a0c8-49b1-918c-7303cd9c6faa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: bd72be4f7d64795b902f352e47b1654eaee6b5a71cddfaf2c245dba1b2d602eb",
      "pattern": "[file:hashes.'SHA-256' = 'bd72be4f7d64795b902f352e47b1654eaee6b5a71cddfaf2c245dba1b2d602eb']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--649e7dae-61f7-417c-bcfa-182b6727bffa",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: beb0b7178b242f2dba21c3d91abf80e8738847b8086d2a42e9352738c83542b5",
      "pattern": "[file:hashes.'SHA-256' = 'beb0b7178b242f2dba21c3d91abf80e8738847b8086d2a42e9352738c83542b5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f1ca29ca-97a3-41d7-adc7-4a26f1a39545",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c379139347470254f19041f05e19f5454750e052f04f6d377ec8df19ce959519",
      "pattern": "[file:hashes.'SHA-256' = 'c379139347470254f19041f05e19f5454750e052f04f6d377ec8df19ce959519']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--141fb01c-bda9-4e31-9306-d4d3a47d4006",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: cbbfd767774de9fecc4f8d2bdc4c23595c804113a3f6246ec4dfe2b47cb4d34c",
      "pattern": "[file:hashes.'SHA-256' = 'cbbfd767774de9fecc4f8d2bdc4c23595c804113a3f6246ec4dfe2b47cb4d34c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--948bc2a7-8b10-4199-a5ab-1e9df340cd08",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: cf172b4629e321e4c78a1d0717130bbb693392712a86d3d85d035bae1f377dbd",
      "pattern": "[file:hashes.'SHA-256' = 'cf172b4629e321e4c78a1d0717130bbb693392712a86d3d85d035bae1f377dbd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0e26a85d-62db-45c4-9e10-1f941780e569",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: cf5edcff4053e29cb236d3ed1fe06ca93ae6f64f26e25117d68ee130b9bc60c8",
      "pattern": "[file:hashes.'SHA-256' = 'cf5edcff4053e29cb236d3ed1fe06ca93ae6f64f26e25117d68ee130b9bc60c8']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c088df91-b9eb-4378-9870-c87c93f2894c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d55f983c994caa160ec63a59f6b4250fe67fb3e8c43a388aec60a4a6978e9f1e",
      "pattern": "[file:hashes.'SHA-256' = 'd55f983c994caa160ec63a59f6b4250fe67fb3e8c43a388aec60a4a6978e9f1e']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30116 \u2014 Kaseya Virtual System/Server Admi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc529d85-0113-4337-a6b3-61e5ff0c3724",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: d854f775ab1071eebadc0eb44d8571c387567c233a71d2e26242cd9a80e67309",
      "pattern": "[file:hashes.'SHA-256' = 'd854f775ab1071eebadc0eb44d8571c387567c233a71d2e26242cd9a80e67309']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0fa2f1d0-58e7-4b15-94ba-62974443707d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: dc4186dd9b3a4af8565f87a9a799644fce8af25e3ee8777d90ae660d48497a04",
      "pattern": "[file:hashes.'SHA-256' = 'dc4186dd9b3a4af8565f87a9a799644fce8af25e3ee8777d90ae660d48497a04']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9143c78b-f5c6-4fff-86f3-298fbc06d1ba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: dd603db3e2c0800d5eaa262b6b8553c68deaa486b545d4965df5dc43217cc839",
      "pattern": "[file:hashes.'SHA-256' = 'dd603db3e2c0800d5eaa262b6b8553c68deaa486b545d4965df5dc43217cc839']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2ef6a16b-aa08-4f7d-9ec4-ae1502bbba48",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: de9ef08a148305963accb8a64eb22117916aa42ab0eddf60ccb8850468a194fc",
      "pattern": "[file:hashes.'SHA-256' = 'de9ef08a148305963accb8a64eb22117916aa42ab0eddf60ccb8850468a194fc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5dacbb8e-a7da-4b98-bfb9-5fa095cde792",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: dec56b06e03665d2c656b530d3b6f90ca0ec2925bec4559d8a2cec5da3a7700b",
      "pattern": "[file:hashes.'SHA-256' = 'dec56b06e03665d2c656b530d3b6f90ca0ec2925bec4559d8a2cec5da3a7700b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f8da2471-4e84-41a4-8ff7-f7ba69f8e3d6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ded23c3f5f2950257d8cfb215c40d5f54b28fde23c02f61ce1eb746843f43397",
      "pattern": "[file:hashes.'SHA-256' = 'ded23c3f5f2950257d8cfb215c40d5f54b28fde23c02f61ce1eb746843f43397']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--01baf823-a548-45fb-a839-aeb46681cbd7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: def1959fae2d8a3dfe606126ceb9d5403deae97a4b4e216dc8e60354980eeac4",
      "pattern": "[file:hashes.'SHA-256' = 'def1959fae2d8a3dfe606126ceb9d5403deae97a4b4e216dc8e60354980eeac4']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Inj",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0404497-7bb4-4c3e-b132-028e4e179982",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: df5b588f555cccdf4bbf695158b10b5d3a5f463da7e36d26bdf8b7ba0f8ed144",
      "pattern": "[file:hashes.'SHA-256' = 'df5b588f555cccdf4bbf695158b10b5d3a5f463da7e36d26bdf8b7ba0f8ed144']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--462e035e-864d-4913-85cf-62d50f02c4b8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e1546323dc746ed2f7a5c973dcecc79b014b68bdd8a6230239283b4f775f4bbd",
      "pattern": "[file:hashes.'SHA-256' = 'e1546323dc746ed2f7a5c973dcecc79b014b68bdd8a6230239283b4f775f4bbd']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-4878 \u2014 Adobe Flash Player Use-After-Free ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d38ef337-035c-45a5-a84a-a2e461069c41",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e2a24ab94f865caeacdf2c3ad015f31f23008ac6db8312c2cbfb32e4a5466ea2",
      "pattern": "[file:hashes.'SHA-256' = 'e2a24ab94f865caeacdf2c3ad015f31f23008ac6db8312c2cbfb32e4a5466ea2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30116 \u2014 Kaseya Virtual System/Server Admi",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f9c4508-bae8-4275-89bd-48d7b9b86bb1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e3eac25c3beb77ffed609c53b447a81ec8a0e20fb94a6442a51d72ca9e6f7cd2",
      "pattern": "[file:hashes.'SHA-256' = 'e3eac25c3beb77ffed609c53b447a81ec8a0e20fb94a6442a51d72ca9e6f7cd2']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e63f9596-727e-4a30-b73c-95ded829dc38",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ef2a6b37568e14dacd5d8894ce2e4bbc593ffd58e197827a052d2c2f0a756949",
      "pattern": "[file:hashes.'SHA-256' = 'ef2a6b37568e14dacd5d8894ce2e4bbc593ffd58e197827a052d2c2f0a756949']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7e4b9bb0-d02e-4029-958b-6aefe49da5e9",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f0b12413c9d291e3b9edd1ed1496af7712184a63c066e1d5b2bb528376d66ebc",
      "pattern": "[file:hashes.'SHA-256' = 'f0b12413c9d291e3b9edd1ed1496af7712184a63c066e1d5b2bb528376d66ebc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ccd94dc0-3fc2-4169-9dce-2403d149e806",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f1c5bed9560a1afe9d5575e923e480e7e8030e10bc3d7c0d842b1a64f49f8794",
      "pattern": "[file:hashes.'SHA-256' = 'f1c5bed9560a1afe9d5575e923e480e7e8030e10bc3d7c0d842b1a64f49f8794']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Rem",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--829f74f9-dc37-4b88-9919-115efe6e5765",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f30bb52c0e32dfe524fc0dfda1724a1ffb88647c39c33a66dfd66109fecceec7",
      "pattern": "[file:hashes.'SHA-256' = 'f30bb52c0e32dfe524fc0dfda1724a1ffb88647c39c33a66dfd66109fecceec7']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cfc65c77-0c76-46cd-8703-c2b4377301f6",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: f91f2a7e1944734371562f18b066f193605e07223aab90bd1e8925e23bbeaa1c",
      "pattern": "[file:hashes.'SHA-256' = 'f91f2a7e1944734371562f18b066f193605e07223aab90bd1e8925e23bbeaa1c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b7e98aec-ec78-4ac4-b108-2919b95619b8",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: fa7575bd0cd2a83995ea34d8d008eb07c2062a843e5e155e2e8d8b35a0cf7901",
      "pattern": "[file:hashes.'SHA-256' = 'fa7575bd0cd2a83995ea34d8d008eb07c2062a843e5e155e2e8d8b35a0cf7901']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--92688879-836e-43be-a8f6-d6c49faad2b1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: fd63b9c7e9dce51348d9600f67139ea8959fdbbca84d505b5e9317bbdca74016",
      "pattern": "[file:hashes.'SHA-256' = 'fd63b9c7e9dce51348d9600f67139ea8959fdbbca84d505b5e9317bbdca74016']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c8d7c338-c5fe-498d-9090-ecb95ff00374",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: fec71b8479f3a416fa58580ae76a8c731c2294c24663c601a1267e0e5c2678a0",
      "pattern": "[file:hashes.'SHA-256' = 'fec71b8479f3a416fa58580ae76a8c731c2294c24663c601a1267e0e5c2678a0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2018-4878 \u2014 Adobe Flash Player Use-After-Free ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--391a6861-3f87-49ae-9852-c5c74deed936",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: fed0f0d3e9d990f8a83b86d29e586d46e7cac54efb0eae2f07112d61afb9b885",
      "pattern": "[file:hashes.'SHA-256' = 'fed0f0d3e9d990f8a83b86d29e586d46e7cac54efb0eae2f07112d61afb9b885']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code ",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "CISA KEV"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--360f8703-7b4b-4958-a271-9ca7c95d1054",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-20162",
      "pattern": "[vulnerability:name = 'CVE-2017-20162']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Plugins to put Node.js application security and observabilit",
          "url": "https://snyk.io/blog/lightrun-snyk-plugins-node-js-application-security-observability-ide/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8af7ca3d-94c4-4b49-afcf-44ba485a5e2f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-9484",
      "pattern": "[vulnerability:name = 'CVE-2020-9484']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "How Snyk Social Trends help you fix essential security vulne",
          "url": "https://snyk.io/blog/snyk-social-trends-fix-security-vulnerabilities/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5e79e836-9211-4cb2-8b11-76c145ab6635",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-8184",
      "pattern": "[vulnerability:name = 'CVE-2020-8184']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Better Ruby Gemfile security: A step-by-step guide using Sny",
          "url": "https://snyk.io/blog/better-ruby-gemfile-security-step-by-step-guide-snyk/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b99d2564-7e80-4642-8443-c4cd4217615f",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-26291",
      "pattern": "[vulnerability:name = 'CVE-2021-26291']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Why you should upgrade to Maven version 3.8.1",
          "url": "https://snyk.io/blog/why-you-should-upgrade-to-maven-version-3-8-1/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fb26b5d0-425d-465d-b372-94f287fb5a78",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "DOMAIN: dreamslab.com",
      "pattern": "[domain-name:value = 'dreamslab.com']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "SnykCon 2021 excitement is starting, but the CFP is ending (",
          "url": "https://snyk.io/blog/snykcon-2021-excitement-starting-cfp-ending/"
        }
      ],
      "x_severity": "med",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ecdc254a-dd39-4b9f-9755-de5eeb423753",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-11253",
      "pattern": "[vulnerability:name = 'CVE-2019-11253']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hardening Amazon EKS security with RBAC, secure IMDS, and au",
          "url": "https://snyk.io/blog/hardening-aws-eks-security-rbac-secure-imds-audit-logging/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f84163ab-79a8-4e3a-89fb-7d5d231d5c33",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-8559",
      "pattern": "[vulnerability:name = 'CVE-2020-8559']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Hardening Amazon EKS security with RBAC, secure IMDS, and au",
          "url": "https://snyk.io/blog/hardening-aws-eks-security-rbac-secure-imds-audit-logging/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f991484a-c09a-404a-b855-c7d55e9918ad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-12120",
      "pattern": "[vulnerability:name = 'CVE-2018-12120']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk uncovers supply chain security vulnerabilities in Visua",
          "url": "https://snyk.io/blog/vulnerable-visual-studio-code-extensions-marketplace/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--577c6e32-b7b6-4ec6-a9d9-b6950f1a8ab3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-13567",
      "pattern": "[vulnerability:name = 'CVE-2019-13567']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk uncovers supply chain security vulnerabilities in Visua",
          "url": "https://snyk.io/blog/vulnerable-visual-studio-code-extensions-marketplace/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--64104954-1b2a-464e-879c-3e85db476954",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-8801",
      "pattern": "[vulnerability:name = 'CVE-2020-8801']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "SuiteCRM: PHAR deserialization vulnerability to code executi",
          "url": "https://snyk.io/blog/suitecrm-phar-deserialization-vulnerability-to-code-execution/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b3b53f4d-c893-4b0b-b34a-e3cd89ad139c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 6b8f472cd174d02167bc0a0c908ec9e0",
      "pattern": "[file:hashes.MD5 = '6b8f472cd174d02167bc0a0c908ec9e0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "SuiteCRM: PHAR deserialization vulnerability to code executi",
          "url": "https://snyk.io/blog/suitecrm-phar-deserialization-vulnerability-to-code-execution/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ffb1c6d7-9084-4b97-b878-dddb1a22285d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 571cbfa209da4c8280a5359f301115de25b4c6e3",
      "pattern": "[file:hashes.'SHA-1' = '571cbfa209da4c8280a5359f301115de25b4c6e3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "SuiteCRM: PHAR deserialization vulnerability to code executi",
          "url": "https://snyk.io/blog/suitecrm-phar-deserialization-vulnerability-to-code-execution/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--728702d5-4aaa-42f2-9d5b-8cca9f977d59",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: c365dec0cfdf64d8cfd43ebd8f2bcd534cfe7b71849796dfb3030b4fe5ff7f93",
      "pattern": "[file:hashes.'SHA-256' = 'c365dec0cfdf64d8cfd43ebd8f2bcd534cfe7b71849796dfb3030b4fe5ff7f93']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Developer driven workflows: Dockerfile image scanning, prior",
          "url": "https://snyk.io/blog/dockerfile-optimization-and-docker-image-security-scanning/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--06379485-8050-41d8-a785-6c34b8c3af4d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-8554",
      "pattern": "[vulnerability:name = 'CVE-2020-8554']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Snyk IaC scanning enhancements include Azure and AWS infrast",
          "url": "https://snyk.io/blog/snyk-iac-scanning-enhancements-include-aws-infrastructure-as-code/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f76ee8e4-b5ae-4321-ac01-0c66248da5dd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: adae6cf9abdb84b63919cc27c2ecafcb",
      "pattern": "[file:hashes.MD5 = 'adae6cf9abdb84b63919cc27c2ecafcb']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "AWS vulnerability scanning using the Snyk integration",
          "url": "https://snyk.io/blog/aws-vulnerability-scanning-using-the-snyk-integration/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--08ad9be1-1ca9-4e11-b19f-67f4831f5547",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: ca6c19e25b4d7917769ee535f0b073e04e8ddc32ead83493c03abc65e82e5e6c",
      "pattern": "[file:hashes.'SHA-256' = 'ca6c19e25b4d7917769ee535f0b073e04e8ddc32ead83493c03abc65e82e5e6c']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "AWS vulnerability scanning using the Snyk integration",
          "url": "https://snyk.io/blog/aws-vulnerability-scanning-using-the-snyk-integration/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5476c7dc-b6f0-4cf6-a02c-d6425b204f14",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: cd100d7c505ced1f5c4f4eb6fbd7ac83a623f9bb483db1e828fb4cd3b3c01bd9",
      "pattern": "[file:hashes.'SHA-256' = 'cd100d7c505ced1f5c4f4eb6fbd7ac83a623f9bb483db1e828fb4cd3b3c01bd9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "AWS vulnerability scanning using the Snyk integration",
          "url": "https://snyk.io/blog/aws-vulnerability-scanning-using-the-snyk-integration/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8cb9b500-f491-4be7-a1d7-e5e25a5323cb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-28473",
      "pattern": "[vulnerability:name = 'CVE-2020-28473']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cache poisoning in popular open source packages",
          "url": "https://snyk.io/blog/cache-poisoning-in-popular-open-source-packages/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c20baa65-7bf1-4f94-87e3-8aa052ed84e3",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2021-23336",
      "pattern": "[vulnerability:name = 'CVE-2021-23336']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Cache poisoning in popular open source packages",
          "url": "https://snyk.io/blog/cache-poisoning-in-popular-open-source-packages/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6300d1b7-6f8e-4fb4-bbe0-248e3636c509",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-7308",
      "pattern": "[vulnerability:name = 'CVE-2017-7308']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Kernel privilege escalation: how Kubernetes container isolat",
          "url": "https://snyk.io/blog/kernel-privilege-escalation/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e5d18834-f9b5-4298-b86b-204e778b5347",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 01a2038b20d165ab7df81934f9849bdfbc59bd6f6322c5d11e341504f66ec266",
      "pattern": "[file:hashes.'SHA-256' = '01a2038b20d165ab7df81934f9849bdfbc59bd6f6322c5d11e341504f66ec266']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Container image formats under the hood",
          "url": "https://snyk.io/blog/container-image-formats/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--177a8f5e-0e27-4913-a34d-2e3d32b4e980",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 171857c49d0f5e2ebf623e6cb36a8bcad585ed0c2aa99c87a055df034c1e5848",
      "pattern": "[file:hashes.'SHA-256' = '171857c49d0f5e2ebf623e6cb36a8bcad585ed0c2aa99c87a055df034c1e5848']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Container image formats under the hood",
          "url": "https://snyk.io/blog/container-image-formats/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f5a9b9ff-ff7c-4b7c-af27-384f58e17506",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 33a51d09088285451e7a7525d4bd64fc15563264afe5a91ef84a8b3042018899",
      "pattern": "[file:hashes.'SHA-256' = '33a51d09088285451e7a7525d4bd64fc15563264afe5a91ef84a8b3042018899']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Container image formats under the hood",
          "url": "https://snyk.io/blog/container-image-formats/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1fda4371-92c5-4375-876c-225fecad5f89",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 419640447d267f068d2f84a093cb13a56ce77e130877f5b8bdb4294f4a90a84f",
      "pattern": "[file:hashes.'SHA-256' = '419640447d267f068d2f84a093cb13a56ce77e130877f5b8bdb4294f4a90a84f']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Container image formats under the hood",
          "url": "https://snyk.io/blog/container-image-formats/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2ecb797-3823-4259-b580-7dec98bd064a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 45c6f8f1b2fe15adaa72305616d69a6cd641169bc8b16886756919e7c01fa48b",
      "pattern": "[file:hashes.'SHA-256' = '45c6f8f1b2fe15adaa72305616d69a6cd641169bc8b16886756919e7c01fa48b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Container image formats under the hood",
          "url": "https://snyk.io/blog/container-image-formats/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bf320086-5d14-484b-92a4-76d99b3c1606",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 46076a325f0de3f745254638b8b0f0de343685b34e7ca6ec5cd0b6b7930eb7fa",
      "pattern": "[file:hashes.'SHA-256' = '46076a325f0de3f745254638b8b0f0de343685b34e7ca6ec5cd0b6b7930eb7fa']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Container image formats under the hood",
          "url": "https://snyk.io/blog/container-image-formats/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1df8824c-7151-459b-9f10-86748ce9cb8a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 468327b5cd7ce539db695bd0ef05dae8a4ff77b02870a8e823ed74dedad4bd55",
      "pattern": "[file:hashes.'SHA-256' = '468327b5cd7ce539db695bd0ef05dae8a4ff77b02870a8e823ed74dedad4bd55']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Container image formats under the hood",
          "url": "https://snyk.io/blog/container-image-formats/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bd8530e2-21b2-45e2-a4f4-6c715f5b6f90",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 56def654ec22f857f480cdcc640c474e2f84d4be2e549a9d16eaba3f397596e9",
      "pattern": "[file:hashes.'SHA-256' = '56def654ec22f857f480cdcc640c474e2f84d4be2e549a9d16eaba3f397596e9']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Container image formats under the hood",
          "url": "https://snyk.io/blog/container-image-formats/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--01cc2559-1e47-4394-886d-b0cb8ab9bc90",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 61e52f862619ab016d3bcfbd78e5c7aaaa1989b4c295e6dbcacddd2d7b93e1f5",
      "pattern": "[file:hashes.'SHA-256' = '61e52f862619ab016d3bcfbd78e5c7aaaa1989b4c295e6dbcacddd2d7b93e1f5']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Container image formats under the hood",
          "url": "https://snyk.io/blog/container-image-formats/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2e5a538-5547-49cc-b0b4-8cce5b3cd9de",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 8bf067b107a6f7444876e33c6ed85652355f679ac98ebab97ab3ebad63f0dff3",
      "pattern": "[file:hashes.'SHA-256' = '8bf067b107a6f7444876e33c6ed85652355f679ac98ebab97ab3ebad63f0dff3']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Container image formats under the hood",
          "url": "https://snyk.io/blog/container-image-formats/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--61651814-7a39-45fb-83f8-235970bebfbc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: afa93a8ce255ca452ca8c88f4b5c821a466cf0a3e0148a31d0d97dfdb91d9aef",
      "pattern": "[file:hashes.'SHA-256' = 'afa93a8ce255ca452ca8c88f4b5c821a466cf0a3e0148a31d0d97dfdb91d9aef']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Container image formats under the hood",
          "url": "https://snyk.io/blog/container-image-formats/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--58c07a66-5850-4bce-9fd4-4771bede3424",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: e80b8affb2361dc632c1fa8fcbf6b6514f750eb6ef99b7e7f825a55f849bfd89",
      "pattern": "[file:hashes.'SHA-256' = 'e80b8affb2361dc632c1fa8fcbf6b6514f750eb6ef99b7e7f825a55f849bfd89']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Container image formats under the hood",
          "url": "https://snyk.io/blog/container-image-formats/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ddd93d39-8538-4050-b12d-bce1ca4ad3cc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-7733",
      "pattern": "[vulnerability:name = 'CVE-2020-7733']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Regular Expression Denial of Service (REDoS) in UAParser.js",
          "url": "https://snyk.io/blog/regular-expression-denial-of-service-redos-in-uaparser-js/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--008d2fc3-104c-41ea-b02d-08acc6007e68",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-7729",
      "pattern": "[vulnerability:name = 'CVE-2020-7729']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Arbitrary code execution in Grunt",
          "url": "https://snyk.io/blog/arbitrary-code-execution-in-js-grunt/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e04d357d-5269-48b8-8288-68e66dc78bba",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-7699",
      "pattern": "[vulnerability:name = 'CVE-2020-7699']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Prototype pollution in express-fileupload",
          "url": "https://snyk.io/blog/prototype-pollution-in-express-fileupload/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2984ab96-505b-43ed-8be0-224b10e2360c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: 9329a7706dd43d6ed64d022ad0e7b13b",
      "pattern": "[file:hashes.MD5 = '9329a7706dd43d6ed64d022ad0e7b13b']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "SourMint malicious SDK research writeup",
          "url": "https://snyk.io/blog/sour-mint-malicious-sdk/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c9f6a181-4475-441a-9a4f-2d09d033e59a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-11981",
      "pattern": "[vulnerability:name = 'CVE-2020-11981']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Breaking out of message brokers",
          "url": "https://snyk.io/blog/message-brokers/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d25e2c54-238c-400c-bed9-771cc3c81ccd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-11982",
      "pattern": "[vulnerability:name = 'CVE-2020-11982']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Breaking out of message brokers",
          "url": "https://snyk.io/blog/message-brokers/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--48fbb67e-56f9-4ed9-adee-3bb1c0fc6f41",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-7667",
      "pattern": "[vulnerability:name = 'CVE-2020-7667']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Arbitrary File Write via Archive Extraction (Zip Slip) in go",
          "url": "https://snyk.io/blog/arbitrary-file-write-via-archive-extraction-in-go-rpmutils/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--042944a4-dc86-4396-940d-75eff16a48bd",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-16786",
      "pattern": "[vulnerability:name = 'CVE-2019-16786']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Demystifying HTTP request smuggling",
          "url": "https://snyk.io/blog/demystifying-http-request-smuggling/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--51d1749f-229c-4489-9f52-54c66836b673",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-12440",
      "pattern": "[vulnerability:name = 'CVE-2020-12440']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Demystifying HTTP request smuggling",
          "url": "https://snyk.io/blog/demystifying-http-request-smuggling/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--01afa432-46dc-4273-81b0-7eea11980575",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-7662",
      "pattern": "[vulnerability:name = 'CVE-2020-7662']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Regular Expression Denial-of-Service in websocket-extensions",
          "url": "https://snyk.io/blog/regular-expression-denial-of-service-in-websocket-extensions/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0f79610-276e-4dd0-b42a-2be4fe0d619b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-7663",
      "pattern": "[vulnerability:name = 'CVE-2020-7663']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Regular Expression Denial-of-Service in websocket-extensions",
          "url": "https://snyk.io/blog/regular-expression-denial-of-service-in-websocket-extensions/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--21467c10-a2a1-487f-a345-ee4d05ec7dfb",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-10777",
      "pattern": "[vulnerability:name = 'CVE-2019-10777']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Why do organizations trust Snyk to win the open source secur",
          "url": "https://snyk.io/blog/why-snyk-wins-open-source-security-battle/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--36278a04-7597-469f-abcd-c69390e100c1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-10795",
      "pattern": "[vulnerability:name = 'CVE-2019-10795']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Why do organizations trust Snyk to win the open source secur",
          "url": "https://snyk.io/blog/why-snyk-wins-open-source-security-battle/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e5f98fdc-e8f8-4c8d-8c8b-c65051bcab3c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-7599",
      "pattern": "[vulnerability:name = 'CVE-2020-7599']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Vulnerable Gradle plugin-publish plugin reveals sensitive in",
          "url": "https://snyk.io/blog/vulnerable-gradle-plugin/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--28e02a4d-25c4-4f4a-a68b-a9259c37668c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-11247",
      "pattern": "[vulnerability:name = 'CVE-2019-11247']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "March in review: State of Open Source Security survey, All.T",
          "url": "https://snyk.io/blog/march-in-review-security-news/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b7d3124d-759a-40c8-847d-ea579b01cbab",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-11249",
      "pattern": "[vulnerability:name = 'CVE-2019-11249']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "March in review: State of Open Source Security survey, All.T",
          "url": "https://snyk.io/blog/march-in-review-security-news/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe178b6d-5069-4e91-b94e-e743c2715305",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2020-7598",
      "pattern": "[vulnerability:name = 'CVE-2020-7598']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Exploring the minimist prototype pollution security vulnerab",
          "url": "https://snyk.io/blog/prototype-pollution-minimist/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--40e35d3c-7280-44a8-a38a-27c498578a9c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "MD5: c4fbb68607bcbb25407e0362dab0b2ea",
      "pattern": "[file:hashes.MD5 = 'c4fbb68607bcbb25407e0362dab0b2ea']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "What is a backdoor? Let\u2019s build one with Node.js",
          "url": "https://snyk.io/blog/what-is-a-backdoor/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f14ab8da-f873-4f14-bfe0-1377b3adf80c",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-15604",
      "pattern": "[vulnerability:name = 'CVE-2019-15604']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Node.js release fixes a critical HTTP security vulnerability",
          "url": "https://snyk.io/blog/node-js-release-fixes-a-critical-http-security-vulnerability/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--38286a87-b1b9-4bdc-b6a0-43d2a8ef9867",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-15605",
      "pattern": "[vulnerability:name = 'CVE-2019-15605']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Node.js release fixes a critical HTTP security vulnerability",
          "url": "https://snyk.io/blog/node-js-release-fixes-a-critical-http-security-vulnerability/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--373b4dfb-f0cf-428f-aa46-4a5dd1361f12",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-15606",
      "pattern": "[vulnerability:name = 'CVE-2019-15606']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Node.js release fixes a critical HTTP security vulnerability",
          "url": "https://snyk.io/blog/node-js-release-fixes-a-critical-http-security-vulnerability/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0cf838af-7078-472b-b444-8587786144b5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-10773",
      "pattern": "[vulnerability:name = 'CVE-2019-10773']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Understanding filesystem takeover vulnerabilities in npm Jav",
          "url": "https://snyk.io/blog/understanding-filesystem-takeover-vulnerabilities-in-npm-javascript-package-manager/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--71121093-f009-4add-a74e-86d82f136ef5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-16776",
      "pattern": "[vulnerability:name = 'CVE-2019-16776']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Understanding filesystem takeover vulnerabilities in npm Jav",
          "url": "https://snyk.io/blog/understanding-filesystem-takeover-vulnerabilities-in-npm-javascript-package-manager/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--df8b5714-6d45-4f6f-9d4a-69100cf1c482",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-16777",
      "pattern": "[vulnerability:name = 'CVE-2019-16777']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Understanding filesystem takeover vulnerabilities in npm Jav",
          "url": "https://snyk.io/blog/understanding-filesystem-takeover-vulnerabilities-in-npm-javascript-package-manager/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc1b12d3-a22b-447d-9fb3-1b58f1a9bbaf",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-2781",
      "pattern": "[vulnerability:name = 'CVE-2016-2781']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Showing application vulnerabilities in Kubernetes-native too",
          "url": "https://snyk.io/blog/showing-application-vulnerabilities-in-kubernetes-native-tooling/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d377127c-19cb-4f84-b412-b92940175ed1",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2005-2541",
      "pattern": "[vulnerability:name = 'CVE-2005-2541']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Uncharted territory - discovering vulnerabilities in public ",
          "url": "https://snyk.io/blog/uncharted-territory-discovering-vulnerabilities-in-public-helm-charts/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bbf92a2e-9812-4abc-81cf-c55d2e7a45b7",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-9619",
      "pattern": "[vulnerability:name = 'CVE-2019-9619']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Uncharted territory - discovering vulnerabilities in public ",
          "url": "https://snyk.io/blog/uncharted-territory-discovering-vulnerabilities-in-public-helm-charts/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a04659d0-8cfb-4b44-8de3-0076625a15df",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: fe8a0be91ee3e7dea812e8694491e1dde5b75e6d",
      "pattern": "[file:hashes.'SHA-1' = 'fe8a0be91ee3e7dea812e8694491e1dde5b75e6d']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Everything you wanted to know about addressing security vuln",
          "url": "https://snyk.io/blog/everything-you-wanted-to-know-about-addressing-security-vulnerabilities-in-linux-based-containers/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d4c065a4-56b1-4057-8ffa-2fa07578fa3b",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-10748",
      "pattern": "[vulnerability:name = 'CVE-2019-10748']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Sequelize ORM npm library found vulnerable to SQL Injection ",
          "url": "https://snyk.io/blog/sequelize-orm-npm-library-found-vulnerable-to-sql-injection-attacks/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a19ad686-df8a-4e08-9e6c-a43d77b8246a",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-10749",
      "pattern": "[vulnerability:name = 'CVE-2019-10749']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Sequelize ORM npm library found vulnerable to SQL Injection ",
          "url": "https://snyk.io/blog/sequelize-orm-npm-library-found-vulnerable-to-sql-injection-attacks/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--052f598b-50ee-4cc2-90d4-adb34aec3b98",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-10752",
      "pattern": "[vulnerability:name = 'CVE-2019-10752']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Sequelize ORM npm library found vulnerable to SQL Injection ",
          "url": "https://snyk.io/blog/sequelize-orm-npm-library-found-vulnerable-to-sql-injection-attacks/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e7005ea4-6be0-402a-98eb-e72bc7726351",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-14379",
      "pattern": "[vulnerability:name = 'CVE-2019-14379']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Jackson Deserialization Vulnerability",
          "url": "https://snyk.io/blog/jackson-deserialization-vulnerability/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5356070e-e0e2-4c99-9c5c-933dfa8ebd25",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-14439",
      "pattern": "[vulnerability:name = 'CVE-2019-14439']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Jackson Deserialization Vulnerability",
          "url": "https://snyk.io/blog/jackson-deserialization-vulnerability/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7795f86d-2654-4706-90ec-42bf59e65d4e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-10744",
      "pattern": "[vulnerability:name = 'CVE-2019-10744']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Staying ahead of security vulnerabilities with security patc",
          "url": "https://snyk.io/blog/staying-ahead-of-security-vulnerabilities-with-security-patches/"
        },
        {
          "source_name": "Snyk research team discovers severe prototype pollution secu",
          "url": "https://snyk.io/blog/snyk-research-team-discovers-severe-prototype-pollution-security-vulnerabilities-affecting-all-versions-of-lodash/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3a8ac264-2565-40ff-90e0-7a705ecb747e",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-13354",
      "pattern": "[vulnerability:name = 'CVE-2019-13354']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Concerns of supply-chain attacks amplify as remote code exec",
          "url": "https://snyk.io/blog/ruby-gem-strong_password-found-to-contain-remote-code-execution-code-in-a-malicious-version-further-strengthening-worries-of-growth-in-supply-chain-attacks/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--51d2e250-6036-4dca-8262-df2c6c57a5c5",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA256: 366d6162fe36fc81dadc114558b43c6c8890c8bcc7e90e2949ae6344d0785dc0",
      "pattern": "[file:hashes.'SHA-256' = '366d6162fe36fc81dadc114558b43c6c8890c8bcc7e90e2949ae6344d0785dc0']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Malicious remote code execution backdoor discovered in the p",
          "url": "https://snyk.io/blog/malicious-remote-code-execution-backdoor-discovered-in-the-popular-bootstrap-sass-ruby-gem/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0efa7d17-745d-4968-9554-2d616ba9b2ad",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2019-5736",
      "pattern": "[vulnerability:name = 'CVE-2019-5736']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "A serious security flaw in runC can result in root privilege",
          "url": "https://snyk.io/blog/a-serious-security-flaw-in-runc-can-result-in-root-privilege-escalation-in-docker-and-kubernetes/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ec0b754-8f7e-42ae-9cbf-53c9fc85d52d",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-1002105",
      "pattern": "[vulnerability:name = 'CVE-2018-1002105']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Critical Arbitrary Code Execution Vulnerability Found in Kub",
          "url": "https://snyk.io/blog/critical-arbitrary-code-execution-vulnerability-found-in-kubernetes/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff1aeea0-a35d-4b56-92f1-3394c75720dc",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-8008",
      "pattern": "[vulnerability:name = 'CVE-2018-8008']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Behind the disclosure: the Zip Slip vulnerability",
          "url": "https://snyk.io/blog/behind-the-disclosure-the-zip-slip-vulnerability/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5ad54c1d-7488-4654-a7db-8b2dc5392d42",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-8009",
      "pattern": "[vulnerability:name = 'CVE-2018-8009']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Behind the disclosure: the Zip Slip vulnerability",
          "url": "https://snyk.io/blog/behind-the-disclosure-the-zip-slip-vulnerability/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--769718cf-dfa5-4439-8fe6-5cf368558d35",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-0495",
      "pattern": "[vulnerability:name = 'CVE-2018-0495']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Container vulnerability management for developers",
          "url": "https://snyk.io/blog/container-vulnerability-management-for-developers/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2f0b511f-d311-4f9e-8759-a256b3f094af",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2018-1315",
      "pattern": "[vulnerability:name = 'CVE-2018-1315']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Attacking an FTP Client: MGETting more than you bargained fo",
          "url": "https://snyk.io/blog/attacking-an-ftp-client/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--41b862c3-c95b-4146-b43d-a7694a292f97",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 305f2ddcd4eff7cc7c518aca6bb2b2d2daad8fef",
      "pattern": "[file:hashes.'SHA-1' = '305f2ddcd4eff7cc7c518aca6bb2b2d2daad8fef']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Using the Snyk API to find and fix vulnerabilities",
          "url": "https://snyk.io/blog/using-the-snyk-api-to-find-and-fix-vulnerabilities/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eadc1fc4-885c-4687-bfc1-63e21757fd80",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2016-6037",
      "pattern": "[vulnerability:name = 'CVE-2016-6037']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "XSS Attacks: The Next Wave",
          "url": "https://snyk.io/blog/xss-attacks-the-next-wave/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--03c81eba-61f8-4bdd-8750-e75cc6aaca23",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "CVE: CVE-2017-8801",
      "pattern": "[vulnerability:name = 'CVE-2017-8801']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "XSS Attacks: The Next Wave",
          "url": "https://snyk.io/blog/xss-attacks-the-next-wave/"
        }
      ],
      "x_severity": "crit",
      "x_sources": [
        "Snyk"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--41152c45-1c25-4f7f-85e7-f194c1e72769",
      "created": "2026-08-18T12:38:30Z",
      "modified": "2026-08-18T12:38:30Z",
      "name": "SHA1: 1bfdedf6a6e345f322fe956d5df5bd08a8ce84dc",
      "pattern": "[file:hashes.'SHA-1' = '1bfdedf6a6e345f322fe956d5df5bd08a8ce84dc']",
      "pattern_type": "stix",
      "valid_from": "2026-08-18T12:38:30Z",
      "labels": [
        "malicious-activity"
      ],
      "external_references": [
        {
          "source_name": "Yarn is Micro Secure",
          "url": "https://snyk.io/blog/yarn-is-micro-secure/"
        }
      ],
      "x_severity": "high",
      "x_sources": [
        "Snyk"
      ]
    }
  ]
}