{
  "type": "bundle",
  "id": "bundle--e6a2c16c-5240-5ad6-8a4e-bb3d659501c7",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "created": "2026-08-30T00:00:00.000Z",
      "modified": "2026-08-30T00:00:00.000Z",
      "name": "phishunt",
      "description": "Real-time phishing intelligence feed (phishunt.io): active suspicious phishing domains scored by an explainable 5-layer detection engine.",
      "identity_class": "organization",
      "contact_information": "https://phishunt.io/contact/"
    },
    {
      "type": "marking-definition",
      "spec_version": "2.1",
      "id": "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487",
      "created": "2022-10-01T00:00:00.000Z",
      "name": "TLP:CLEAR",
      "extensions": {
        "extension-definition--60a3c5c5-0d10-413e-aab3-9e08dde9e88d": {
          "extension_type": "property-extension",
          "tlp_2_0": "clear"
        }
      }
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3bb04286-97a0-5b08-ab5d-68c01109f1c1",
      "created": "2026-09-05T11:01:31.000Z",
      "modified": "2026-09-05T11:01:31.000Z",
      "valid_from": "2026-09-05T11:01:31.000Z",
      "name": "roblox.com.am",
      "description": "Suspicious phishing domain impersonating Roblox, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'roblox.com.am']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/roblox/ebc8915f-946c-470f-b107-7b01d94f1c1e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "roblox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea2b983a-7316-5716-b917-f56e03ff82fe",
      "created": "2026-03-27T01:01:47.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-03-27T01:01:47.000Z",
      "name": "register-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'register-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/8a6eca16-d8b0-420e-ade6-6ee178c13c78/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--72547ffa-9cd9-50b3-ae73-3d7e8e747195",
      "created": "2026-03-28T01:01:37.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-03-28T01:01:37.000Z",
      "name": "office365.internal-alerts.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'office365.internal-alerts.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/7e1b0fba-bc4d-475b-ba61-b7876519c68f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--555c02eb-ebb6-55a4-9d09-f516bc03a07a",
      "created": "2026-03-28T07:32:22.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-03-28T07:32:22.000Z",
      "name": "amazonbookawards.com",
      "description": "Suspicious phishing domain impersonating Amazon, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'amazonbookawards.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/amazon/c72a9648-33a9-4b66-bce4-b97b23a3aae3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "amazon"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3774f09b-c10d-5064-86a7-a31d80691300",
      "created": "2026-03-28T13:01:22.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-03-28T13:01:22.000Z",
      "name": "support.m365-microsoft.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 18/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'support.m365-microsoft.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 18,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/4484f1cb-d3da-4757-83a3-5596fb6c36a2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dbff08e1-218b-5608-8909-b2fefe0c2653",
      "created": "2026-03-30T13:01:17.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-03-30T13:01:17.000Z",
      "name": "security.email-microsoft.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'security.email-microsoft.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/6436eaa9-620c-4127-a8f7-04fd8fab6a30/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--001838a0-10a4-50e2-aa04-a91291df7f68",
      "created": "2026-04-03T01:02:32.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-03T01:02:32.000Z",
      "name": "login-facebook-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'login-facebook-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/b80bb03f-c63c-4b96-baa2-c2e1b16636da/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fec7fdd7-b338-5c15-8cd6-689a5da8af43",
      "created": "2026-04-03T13:02:09.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-03T13:02:09.000Z",
      "name": "instagramchatsview999.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramchatsview999.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/b4747511-2c0f-4eaa-a2c2-90b6b078de4a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--79d1ee18-9512-5e05-af08-08b7440f16ea",
      "created": "2026-04-06T00:17:28.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-06T00:17:28.000Z",
      "name": "mail.google.com.drive.pratham.vincacybertechltd.myshn.net",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mail.google.com.drive.pratham.vincacybertechltd.myshn.net']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/e0fc0d6a-30eb-44e5-95e7-c9de5f1c71a2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53d343e8-b4a5-56b6-b52e-2d4df7c2b270",
      "created": "2026-04-06T00:19:10.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-06T00:19:10.000Z",
      "name": "appengine.google.com.drive.pratham.vincacybertechltd.myshn.net",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'appengine.google.com.drive.pratham.vincacybertechltd.myshn.net']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/ce027a28-bd07-4893-824d-8748649c05f7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8082e0a-ea8e-54e7-9a34-2ea992fc1221",
      "created": "2026-04-06T00:19:47.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-06T00:19:47.000Z",
      "name": "sites.google.com.drive.pratham.vincacybertechltd.myshn.net",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'sites.google.com.drive.pratham.vincacybertechltd.myshn.net']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/32d0540f-7b1d-443b-b729-3e572b09ec46/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e066dc5e-8c9d-55a0-83c7-993aa7752cb0",
      "created": "2026-04-06T19:16:59.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-06T19:16:59.000Z",
      "name": "google28.m4ntapaset.ink",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'google28.m4ntapaset.ink']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/49b95987-c97d-42f3-9934-eac843863e8e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b3c4d136-59b3-599c-9105-2200042f3b68",
      "created": "2026-04-07T08:06:51.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-07T08:06:51.000Z",
      "name": "netflix.gafiatechnologies.com",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflix.gafiatechnologies.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/a160a3d1-c6c6-4f43-8bad-85b3c9cabaf4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6017a993-af0e-5c04-b13f-bab6ce76ef23",
      "created": "2026-04-08T16:57:32.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-08T16:57:32.000Z",
      "name": "netflix.vpnuse.eu.org",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflix.vpnuse.eu.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/2ebcd388-fb85-408d-8bca-f8a462d22450/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fb6c5835-3342-5f18-b2a8-9c066ef211de",
      "created": "2026-04-09T10:48:53.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-09T10:48:53.000Z",
      "name": "google32.m4ntapaset.ink",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'google32.m4ntapaset.ink']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/44db2d27-f552-4451-ba9a-eac868a76b2e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--693cade1-4f13-5f68-ad64-e5c1713ad059",
      "created": "2026-04-10T13:00:48.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-10T13:00:48.000Z",
      "name": "www-google.cn",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'www-google.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/7a8456b0-f824-4119-b55b-66853add26e0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--20294497-8b0d-500d-9684-b6e9f4655349",
      "created": "2026-04-11T23:42:20.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-11T23:42:20.000Z",
      "name": "metamaskrewards.com",
      "description": "Suspicious phishing domain impersonating MetaMask, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'metamaskrewards.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/metamask/797a38d3-6cf2-4702-8a8a-8bf6d02e4274/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "metamask"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--461bae38-4c71-58d2-bed4-c19d0ed08138",
      "created": "2026-04-12T06:13:52.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-12T06:13:52.000Z",
      "name": "google29.m4ntapaset.ink",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'google29.m4ntapaset.ink']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/c4ce9464-81df-4160-be3b-fc295b05b1ab/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f517b2e-3ba0-5016-8a48-1833180ce80d",
      "created": "2026-04-14T17:31:32.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-14T17:31:32.000Z",
      "name": "googlepartners.net",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googlepartners.net']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/0e63d647-c1a8-4989-aeb9-9e9d6dee5118/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc53fa02-dc0c-58fc-aa80-ccbc44dba1eb",
      "created": "2026-04-14T19:15:44.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-14T19:15:44.000Z",
      "name": "www2-facebook.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 19/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'www2-facebook.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 19,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/d4e38cf6-76dd-44c4-9fb3-6cab6f74e8b2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ce6c8486-8a5f-51dc-9d8c-f1bb3195263a",
      "created": "2026-04-15T01:01:26.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-15T01:01:26.000Z",
      "name": "facebooktechnicalsupportnumber123.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooktechnicalsupportnumber123.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/75c26e14-e3a1-4e6b-82a4-e3f06369532a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6a4877c2-b026-52b0-8dd6-deb4072f5a86",
      "created": "2026-04-15T01:01:38.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-15T01:01:38.000Z",
      "name": "facebook-faq.se",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-faq.se']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/68ac2d26-7bbd-412d-80d1-89c400bcd7db/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b9ffd729-caa0-535b-bb54-67f79e4725c4",
      "created": "2026-04-15T13:05:01.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-15T13:05:01.000Z",
      "name": "metamaskwallett.blogspot.com",
      "description": "Suspicious phishing domain impersonating MetaMask, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'metamaskwallett.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/metamask/4ddb55e0-5e97-444b-b0e5-575de9079e2c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "metamask"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e3b55e7b-1aa0-5156-81f5-10549ed66e56",
      "created": "2026-04-15T13:05:36.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-15T13:05:36.000Z",
      "name": "barcelona-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'barcelona-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/2a0d0cb6-bf4b-4f09-a2f1-1f7dcd5a4884/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--74189061-9f4e-5d1b-8390-5dcfa2f810ae",
      "created": "2026-04-16T03:19:07.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-16T03:19:07.000Z",
      "name": "dropbox-online.at",
      "description": "Suspicious phishing domain impersonating Dropbox, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'dropbox-online.at']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dropbox/0e472d44-44a7-46e4-ab06-c2005153428a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dropbox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2ba8217b-f048-5f87-84fb-a66b6fca876c",
      "created": "2026-04-16T13:02:26.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-16T13:02:26.000Z",
      "name": "login-facebookaccount.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'login-facebookaccount.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/0333b97b-a734-490f-ae64-ef5f044e774c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--af7cb17c-b659-584d-9af5-cb36122831ce",
      "created": "2026-04-19T05:13:05.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-19T05:13:05.000Z",
      "name": "wwww-linkedin.be",
      "description": "Suspicious phishing domain impersonating LinkedIn, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'wwww-linkedin.be']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/linkedin/a65acfa6-028d-460a-a0ed-40999c638a76/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "linkedin"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d87afaf8-6546-56e5-ab17-8d8678337ba6",
      "created": "2026-04-20T01:01:08.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-20T01:01:08.000Z",
      "name": "reactivar-microsoft-live.iceiy.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'reactivar-microsoft-live.iceiy.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/eb4c633a-da19-40fb-a686-744a9b51c8e9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0d7bfb12-b4ff-5272-a064-6aec30841a0c",
      "created": "2026-04-20T13:01:03.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-20T13:01:03.000Z",
      "name": "instagramusicabrasilinstagram.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramusicabrasilinstagram.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/b4a247ca-c7f4-4d3c-9e86-c4d3c7134c3e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d8551c5e-afa7-5b12-a4e3-196596c1312e",
      "created": "2026-04-21T08:01:36.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-21T08:01:36.000Z",
      "name": "metamaskcasino.de.com",
      "description": "Suspicious phishing domain impersonating MetaMask, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'metamaskcasino.de.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/metamask/7c89960e-42f8-4ffa-a9b3-df06b8ebd969/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "metamask"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b17563a-a9e7-50b2-b0a0-874b6b8ed264",
      "created": "2026-04-24T13:03:07.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-24T13:03:07.000Z",
      "name": "instagram-analytics.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-analytics.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/32e0de89-7d72-48cf-82a3-4a7758a839ac/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8864738-e49b-5ac2-b889-29c9f662cb4f",
      "created": "2026-04-26T13:00:40.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-26T13:00:40.000Z",
      "name": "cn-hsbc.foryour.review",
      "description": "Suspicious phishing domain impersonating HSBC, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'cn-hsbc.foryour.review']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/hsbc/62f33f52-975e-4787-a209-16a935e7a3db/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "hsbc"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b66d5041-1618-5f11-b95f-289324be2bee",
      "created": "2026-04-27T01:00:52.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-27T01:00:52.000Z",
      "name": "metamaskchromeextensionn.blogspot.com",
      "description": "Suspicious phishing domain impersonating MetaMask, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'metamaskchromeextensionn.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/metamask/c16ea253-83ee-43f3-b8e6-ec7deed57e9e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "metamask"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--68702e04-a08d-5875-b91c-a6152bf31caf",
      "created": "2026-04-27T17:28:14.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-27T17:28:14.000Z",
      "name": "netflix.surf",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflix.surf']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/9bc927e8-5168-4d9d-9b7b-6039503f3dad/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f3403270-9cfb-580b-83da-c87948344f9a",
      "created": "2026-04-29T04:57:15.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-29T04:57:15.000Z",
      "name": "mirror-google.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mirror-google.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/8accba84-7f36-4d6d-9da6-bec85059ca03/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--90a72f29-80f8-5452-9531-f0ed57bcb235",
      "created": "2026-04-29T13:00:56.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-29T13:00:56.000Z",
      "name": "netflixquebec.blogspot.com",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflixquebec.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/077cb309-7161-4cbc-bf56-455efb9c7b03/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2350b3a0-6cdc-5479-82d8-5f829f05a252",
      "created": "2026-04-30T01:01:21.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-30T01:01:21.000Z",
      "name": "trustwalletsupport.dev",
      "description": "Suspicious phishing domain impersonating Trust Wallet, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'trustwalletsupport.dev']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/trustwallet/57b747ea-d78d-4f32-8c5f-1d5579eefa34/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "trustwallet"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da7b3727-45ab-5b39-b4c0-6358cc3dc3c2",
      "created": "2026-04-30T21:44:28.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-04-30T21:44:28.000Z",
      "name": "googlelogos.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googlelogos.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/7d7a9fb0-4cad-4f9d-a54a-28881c88321b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--192e6103-8e3b-5530-b419-8ad1600ad754",
      "created": "2026-05-01T01:01:07.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-01T01:01:07.000Z",
      "name": "paypal-logiin.blogspot.com",
      "description": "Suspicious phishing domain impersonating PayPal, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'paypal-logiin.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/paypal/6e1c5536-f5b2-4416-93be-43b00952d7fd/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "paypal"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f109517-6a11-52e4-a35c-c5962ad60201",
      "created": "2026-05-01T03:28:24.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-01T03:28:24.000Z",
      "name": "hot-binance.com.cn",
      "description": "Suspicious phishing domain impersonating Binance, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'hot-binance.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/binance/2ee88ac9-fa57-425d-9a65-e8a82e947d0c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "binance"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9655dcb6-29d3-516d-8c16-e5e29f881738",
      "created": "2026-05-01T09:49:31.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-01T09:49:31.000Z",
      "name": "facebooktotranscript.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooktotranscript.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/e721ebaa-595f-4e39-a0bf-4bf3026fbc9f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--61c966ba-82e9-549c-bebc-da648770279a",
      "created": "2026-05-01T21:31:38.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-01T21:31:38.000Z",
      "name": "zelleria.shop",
      "description": "Suspicious phishing domain impersonating Zelle, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'zelleria.shop']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/zelle/61a4fa9e-c2b5-4dd1-904f-6e93a11a77f1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "zelle"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cde3e421-4c0d-5c2f-a051-1b89601b1f5e",
      "created": "2026-05-05T13:02:59.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-05T13:02:59.000Z",
      "name": "outlook.webaccess-alert.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'outlook.webaccess-alert.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/d15fc3b0-a9e7-4d75-bab2-2649389605c1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3a38341d-bc51-5c54-9612-736f279e165a",
      "created": "2026-05-06T13:03:34.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-06T13:03:34.000Z",
      "name": "instagram-login-user.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-login-user.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/c6a7381e-f34b-4c06-82f7-f5e544fb63c4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b82bc075-2d09-5efe-83ec-0f273f7e03b6",
      "created": "2026-05-10T09:44:25.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-10T09:44:25.000Z",
      "name": "microsoft-se.us",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoft-se.us']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/30c841f6-3b6b-454c-a357-beb8a4f0538d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f6c005d4-24eb-5564-a502-e4c46ef8dbe2",
      "created": "2026-05-10T18:26:51.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-10T18:26:51.000Z",
      "name": "facebookpagemanagement.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookpagemanagement.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/7b43c3f0-cd50-41d8-a527-ce2f2bd49999/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e9525892-fe39-5714-a1e1-d2fad120922c",
      "created": "2026-05-10T19:21:43.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-10T19:21:43.000Z",
      "name": "hsbc.dev",
      "description": "Suspicious phishing domain impersonating HSBC, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'hsbc.dev']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/hsbc/c9fb55c3-5023-4688-bf63-49db5cbc9bca/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "hsbc"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--91d56ee9-158b-5184-a6e3-0612ee171b0b",
      "created": "2026-05-12T10:55:45.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-12T10:55:45.000Z",
      "name": "admin.santandercitas.com",
      "description": "Suspicious phishing domain impersonating Banco Santander, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'admin.santandercitas.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/santander/5598e82b-8927-43fb-820b-74166b4d8b30/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "santander"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eab58c6b-53ef-5fce-a396-4ac7a8088801",
      "created": "2026-05-13T01:01:06.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-13T01:01:06.000Z",
      "name": "facebook-facebook45sr.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-facebook45sr.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/4b0c0da4-8b6a-4710-8c34-b341b903abac/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--65886790-167e-551f-9f30-bfad8cc94e52",
      "created": "2026-05-13T09:07:54.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-13T09:07:54.000Z",
      "name": "metamaskcasino.de",
      "description": "Suspicious phishing domain impersonating MetaMask, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'metamaskcasino.de']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/metamask/32d09389-a6b6-4b7d-a623-fdff85b87450/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "metamask"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e74c1fdb-291d-5850-89a0-ec74e94f86b1",
      "created": "2026-05-13T13:05:07.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-13T13:05:07.000Z",
      "name": "microsoft.account.trustedentity.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoft.account.trustedentity.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/73b4c145-55d6-4fa2-a656-04693699e177/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bdc59e59-1b15-58aa-80aa-c8959647fdd9",
      "created": "2026-05-14T21:20:02.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-14T21:20:02.000Z",
      "name": "netflixvoid.org",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflixvoid.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/312894ae-59b1-47fb-aad4-a563b4f71f0d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fc9fd9bf-9425-58aa-bb8f-a1e72cfc7df1",
      "created": "2026-05-15T12:28:28.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-15T12:28:28.000Z",
      "name": "ch-google.cc",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ch-google.cc']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/fe4d9962-ca12-4441-a826-73e9d6685428/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dbac8fa8-393d-52e7-98dd-dd023d453009",
      "created": "2026-05-15T13:01:41.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-15T13:01:41.000Z",
      "name": "microsoft.authorised-support.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoft.authorised-support.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/35cf8842-624d-4ec3-9c77-8fc11370fa98/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--12462eb4-33d2-5d9f-a31d-40f025033ddf",
      "created": "2026-05-18T20:16:35.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-18T20:16:35.000Z",
      "name": "netflixandchiffres.com",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflixandchiffres.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/6bef9e46-76a5-429d-a18f-73179ea7462e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8e6cfa7f-26d3-5bae-b286-71ea53e37b38",
      "created": "2026-05-20T21:10:29.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-20T21:10:29.000Z",
      "name": "binanceaa.com",
      "description": "Suspicious phishing domain impersonating Binance, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'binanceaa.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/binance/7d576ea9-ddd4-4ee0-856b-87a6d5edc67f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "binance"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ca85b11-38d9-520c-9416-6ff1e3e08e74",
      "created": "2026-05-20T21:10:59.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-20T21:10:59.000Z",
      "name": "binanceii.com",
      "description": "Suspicious phishing domain impersonating Binance, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'binanceii.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/binance/0d8aeff8-712a-448f-af11-bb2b3b7669e9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "binance"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f6813c0a-816c-5e44-8c12-a02ba4622f9f",
      "created": "2026-05-20T21:11:30.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-20T21:11:30.000Z",
      "name": "binancenn.com",
      "description": "Suspicious phishing domain impersonating Binance, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'binancenn.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/binance/a370eb2c-a522-4ed2-920e-a86bb1afc60b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "binance"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e7093180-18bf-5819-9813-c8dd719ec420",
      "created": "2026-05-24T16:25:41.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-24T16:25:41.000Z",
      "name": "hsbcpress.com",
      "description": "Suspicious phishing domain impersonating HSBC, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'hsbcpress.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/hsbc/15ac3363-2d93-423e-b5a6-063f1069c490/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "hsbc"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0151da00-a7f5-5ab4-9b15-a279a56434bf",
      "created": "2026-05-26T06:44:34.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-26T06:44:34.000Z",
      "name": "business-dropbox.me",
      "description": "Suspicious phishing domain impersonating Dropbox, detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'business-dropbox.me']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dropbox/12a13552-7405-46e2-a392-8cb82f667d58/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dropbox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e03cde66-4dc1-5883-8c64-8a13db0a0fdb",
      "created": "2026-05-26T08:35:15.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-26T08:35:15.000Z",
      "name": "dropboxbiz.com",
      "description": "Suspicious phishing domain impersonating Dropbox, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'dropboxbiz.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dropbox/55ab06a2-304f-4984-a73d-911575c56f2c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dropbox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd144008-bf04-5ad4-8ba1-a4c17f16d675",
      "created": "2026-05-30T08:31:28.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-30T08:31:28.000Z",
      "name": "dropbox-online.net",
      "description": "Suspicious phishing domain impersonating Dropbox, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'dropbox-online.net']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dropbox/d0d96e4b-23c6-47db-8409-b2c4bfca0581/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dropbox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--63866830-b3bb-5934-86f1-5e6f4f6935bc",
      "created": "2026-05-30T10:08:11.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-30T10:08:11.000Z",
      "name": "netflixtunisie.com.tn",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflixtunisie.com.tn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/379fa87e-860f-429e-acba-9a8540dea351/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--39e7ab7a-fbbc-5a5c-950c-0906ee0f01a8",
      "created": "2026-05-31T00:35:23.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-31T00:35:23.000Z",
      "name": "www-hk-google.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'www-hk-google.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/a9fb5cc4-c17c-4df1-b5ad-ea7986423a71/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0efd2edd-c94c-5a19-a3ef-b5bb415f86d0",
      "created": "2026-05-31T03:57:14.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-31T03:57:14.000Z",
      "name": "openai-coin.com",
      "description": "Suspicious phishing domain impersonating ChatGPT, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'openai-coin.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/chatgpt/50c32c94-c40a-4803-85a0-64163d17b77d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "chatgpt"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0d234ef-380f-505c-afaa-e27a1c7d3742",
      "created": "2026-05-31T06:52:47.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-05-31T06:52:47.000Z",
      "name": "best-credit-card-for-facebook-ads.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'best-credit-card-for-facebook-ads.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/75a6045c-89f1-4633-a1c6-6f1bb0bba206/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--568f0ad2-5752-554b-990a-5b8ed52edd30",
      "created": "2026-06-02T07:31:37.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-02T07:31:37.000Z",
      "name": "mobile-google.cn",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mobile-google.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/e3181001-316d-416f-833a-2332736b6d6a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--52a925ec-07e8-5b70-99c4-a858e86dc9cb",
      "created": "2026-06-02T13:02:34.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-02T13:02:34.000Z",
      "name": "netflix-uat.dblxhosting.co.uk",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflix-uat.dblxhosting.co.uk']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/2557c989-e4c6-4e41-b3b6-4259c4ccbf8f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--66a3f5b5-cb6f-5167-a5a7-6d7b187ba364",
      "created": "2026-06-05T18:48:29.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-05T18:48:29.000Z",
      "name": "netflixseeker.com",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflixseeker.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/b3d0ee43-c5de-43cb-95d1-2ad0ffda8ab3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--afeea8e5-17e2-56b0-8216-3543dac53622",
      "created": "2026-06-06T01:02:06.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-06T01:02:06.000Z",
      "name": "security.m365-microsoft.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'security.m365-microsoft.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/d5cb6a39-23cf-49f4-a25e-0ffd83801c0f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2709e2ba-11a4-5414-b4b5-61e919a35b68",
      "created": "2026-06-08T13:01:32.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-08T13:01:32.000Z",
      "name": "programme-hup.m365-microsoft.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'programme-hup.m365-microsoft.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/872fb8e2-403a-45ce-b2dc-518ebacf7fab/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aafe32ff-a07f-590c-bf35-c6668ba658fa",
      "created": "2026-06-09T15:34:09.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-09T15:34:09.000Z",
      "name": "hsbc-sec.com",
      "description": "Suspicious phishing domain impersonating HSBC, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'hsbc-sec.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/hsbc/65d1e6ec-962a-4743-a2fd-cedbf57bb9ed/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "hsbc"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a9c2df01-ba19-532f-bfca-b84657d24a9b",
      "created": "2026-06-10T13:02:03.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-10T13:02:03.000Z",
      "name": "binancelivetrade.blogspot.com",
      "description": "Suspicious phishing domain impersonating Binance, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'binancelivetrade.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/binance/c6f65415-24ff-4272-bc15-0ad191ccf02b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "binance"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8efdbee6-7000-5392-a667-fe7767f7f408",
      "created": "2026-06-12T01:01:41.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-12T01:01:41.000Z",
      "name": "a2zapk.co",
      "description": "Suspicious phishing domain impersonating Spotify, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'a2zapk.co']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/spotify/3de207bc-7431-4f8a-bb71-2e6de6865202/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "spotify"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c29b12aa-a5e4-54ec-9bf9-1b7fdf97edf9",
      "created": "2026-06-13T01:03:15.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-13T01:03:15.000Z",
      "name": "profil-facebook-saya.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'profil-facebook-saya.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/9ae63765-78b0-497b-9c07-7aa584237f4b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b9773bbe-907b-5b5d-b7bd-9474de82c40c",
      "created": "2026-06-13T13:01:33.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-13T13:01:33.000Z",
      "name": "facebook-networks.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-networks.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/91922a27-129c-4ca9-a003-63456945b7ed/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8473492-dc5d-50d6-b06c-ea7f5241ba7a",
      "created": "2026-06-13T13:02:25.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-13T13:02:25.000Z",
      "name": "facebook-profile-login.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-profile-login.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/746e1f33-2b40-4553-836c-250a9fc582a5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eadd3244-230a-5df6-bfad-83699a1e65dc",
      "created": "2026-06-15T13:02:34.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-15T13:02:34.000Z",
      "name": "chatgpt0005.eu.org",
      "description": "Suspicious phishing domain impersonating ChatGPT, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'chatgpt0005.eu.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/chatgpt/4c262625-576b-4c6c-9cdc-19a6b6e1efbc/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "chatgpt"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f7a139ea-7ff0-593a-902d-bf6497104daf",
      "created": "2026-06-16T08:30:25.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-16T08:30:25.000Z",
      "name": "393bet-facebook.sa.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '393bet-facebook.sa.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3903b5ce-15fc-4265-8673-cfd37c11db8a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8360f59e-6c12-5c6b-b4ae-c9ee4e43885e",
      "created": "2026-06-17T01:06:27.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-17T01:06:27.000Z",
      "name": "office365.rricrosoft-offices.org",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 17/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'office365.rricrosoft-offices.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 17,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/935697ea-6413-4c0c-b711-21baf1e8d028/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9a5e215e-c26f-54ab-a85b-9c6145daa662",
      "created": "2026-06-17T13:01:02.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-17T13:01:02.000Z",
      "name": "spotify-modapk.com",
      "description": "Suspicious phishing domain impersonating Spotify, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'spotify-modapk.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/spotify/9e7ca879-4a15-440a-aa7d-342cb1677655/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "spotify"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c1ea151d-c3cb-58fc-b225-78bba7e7b2c8",
      "created": "2026-06-22T13:00:58.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-22T13:00:58.000Z",
      "name": "interbank.protected-request.com",
      "description": "Suspicious phishing domain impersonating Interbank, detected by phishunt.io (score 18/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'interbank.protected-request.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 18,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/interbank/313179bb-c525-4cde-89a3-1b5250130e13/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "interbank"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7873cf3a-2fbb-5f1e-b1f5-433ffa198390",
      "created": "2026-06-23T02:00:34.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-23T02:00:34.000Z",
      "name": "googleplaydown.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googleplaydown.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/fa8dd605-6316-4ade-a08f-5042b15f3025/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c0d8e7d3-645a-56a3-ae2b-b01b960b93c8",
      "created": "2026-06-23T13:00:57.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-23T13:00:57.000Z",
      "name": "iniciamazon.com.br",
      "description": "Suspicious phishing domain impersonating Amazon, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'iniciamazon.com.br']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/amazon/866b92f0-db6e-45b9-ac06-cc35e6885e01/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "amazon"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--66cba592-c692-57c5-a5ff-b37a4d91c948",
      "created": "2026-06-24T13:02:03.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-24T13:02:03.000Z",
      "name": "my-facebook-blog.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'my-facebook-blog.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/067e2e22-fba5-4dd0-997d-31116b888e00/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--13247417-8473-5fc4-a514-0244d5a0d949",
      "created": "2026-06-25T01:01:38.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-25T01:01:38.000Z",
      "name": "correosprepago.bnext.es",
      "description": "Suspicious phishing domain impersonating Correos, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'correosprepago.bnext.es']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/correos/c28cb635-85de-4b87-8a55-c985f49fd5b3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "correos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--58443963-55f5-5c06-9b28-021e1dc466eb",
      "created": "2026-06-25T05:54:49.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-25T05:54:49.000Z",
      "name": "microsoftjk.eu.org",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoftjk.eu.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/4cef2ef8-eb5a-4536-8328-f692a8c4c350/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e74fb6fb-db6f-5d47-9cd8-07338928c45f",
      "created": "2026-06-25T13:01:23.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-25T13:01:23.000Z",
      "name": "microsoft-login-securitylogin.jimdofree.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoft-login-securitylogin.jimdofree.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/c4a2f81e-f2b3-41a5-8a56-9968bb8ff0e9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--04d75b80-41e9-502c-b307-79bfee2f3ab1",
      "created": "2026-06-25T13:01:31.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-25T13:01:31.000Z",
      "name": "outlook.verifytoken.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'outlook.verifytoken.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/efa8482f-552c-4f11-95de-4f96eb842791/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--56ab4ea1-987a-5094-902f-e1c85519de78",
      "created": "2026-06-26T01:01:52.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-26T01:01:52.000Z",
      "name": "facebookpage-noreplycenter.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookpage-noreplycenter.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/6628370d-31de-4efd-9e30-0721c7b101e8/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--11ce033d-79d8-5703-9835-3aa456ae92f9",
      "created": "2026-06-26T01:01:59.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-26T01:01:59.000Z",
      "name": "onedrive.at-us.therelayservice.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 19/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'onedrive.at-us.therelayservice.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 19,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/0fb7d6c7-9891-450b-8cef-f0fe730025c5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f1b9738-a942-5152-8b5c-462da43f907d",
      "created": "2026-06-27T01:01:31.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-27T01:01:31.000Z",
      "name": "ctia-outlook-2026.s1.yapla.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ctia-outlook-2026.s1.yapla.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/9fe477d6-026a-4435-b793-043ce1128b7a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff882705-3ce2-56a4-86d6-8f75ef1a044f",
      "created": "2026-06-27T01:02:06.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-27T01:02:06.000Z",
      "name": "accounts.binanceuz.co",
      "description": "Suspicious phishing domain impersonating Binance, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'accounts.binanceuz.co']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/binance/55c4f70b-a1a3-443b-8881-4c3cc69c6ccc/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "binance"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--012b1613-ff44-5e2e-9e5c-80c02e3e6154",
      "created": "2026-06-28T13:00:56.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-28T13:00:56.000Z",
      "name": "facebookaccountsmanager.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookaccountsmanager.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/1cc6789a-f402-4455-ae92-c081c30ed3b3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--55738aa4-a19d-5cf4-a5e8-80e9e332864e",
      "created": "2026-06-29T01:01:24.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-29T01:01:24.000Z",
      "name": "dropbox.rev.it",
      "description": "Suspicious phishing domain impersonating Dropbox, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'dropbox.rev.it']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dropbox/aaad6147-bd2e-4bdd-8ce0-2485cf1bee33/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dropbox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ab7cf1a7-97ee-5149-94ab-f9d843c2568c",
      "created": "2026-06-29T01:02:14.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-29T01:02:14.000Z",
      "name": "paypal-signin.blogspot.com",
      "description": "Suspicious phishing domain impersonating PayPal, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'paypal-signin.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/paypal/3f27a26c-323a-47fc-88fc-f471670ae530/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "paypal"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fd329dd0-44f9-5bf6-bd38-41e86cffc712",
      "created": "2026-06-30T01:01:33.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-30T01:01:33.000Z",
      "name": "facebooklogin-page.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin-page.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/4c930f97-8b09-48dd-8303-ff370d1e772b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3a289a04-469e-5a28-865b-ea77314a5dda",
      "created": "2026-06-30T01:01:40.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-30T01:01:40.000Z",
      "name": "facebook-login-help.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-login-help.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/be23a83e-e18e-4464-9c5b-3698af913d4e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--83d57d8f-548d-5476-bf57-e1cc3697a1f5",
      "created": "2026-06-30T13:01:07.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-30T13:01:07.000Z",
      "name": "barclays-grads.twineapp.com",
      "description": "Suspicious phishing domain impersonating Barclays, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'barclays-grads.twineapp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/barclays/7c3cdb2c-9316-415d-bdbd-597b52ee9285/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "barclays"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--274bf19c-fcec-51ca-bf01-721501a65660",
      "created": "2026-06-30T13:01:19.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-06-30T13:01:19.000Z",
      "name": "facebookloginpage2.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginpage2.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/aae47088-ee01-497b-89ec-0ec437bcbbad/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fbbb77cf-5eb9-5a61-9e1f-a710f0c678b8",
      "created": "2026-07-01T01:01:39.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-01T01:01:39.000Z",
      "name": "barclays-grads.twinehr.com",
      "description": "Suspicious phishing domain impersonating Barclays, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'barclays-grads.twinehr.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/barclays/b54a63fc-58ad-470e-b386-0e5ea8de3dc4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "barclays"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3388853c-c5c7-51ea-93b2-48d6618d250d",
      "created": "2026-07-01T16:46:30.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-01T16:46:30.000Z",
      "name": "netflix6.com",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflix6.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/734bbba7-7f04-4bb1-bd45-03269854b487/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87c47f48-f1fa-5d68-b4e5-f20c8c974eca",
      "created": "2026-07-02T01:02:18.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-02T01:02:18.000Z",
      "name": "forsakens-crew-teman-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'forsakens-crew-teman-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/5c41e70b-fd5e-495e-8295-0a41437ac95f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d0977715-62ac-512f-8240-57a48172b30b",
      "created": "2026-07-02T13:00:45.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-02T13:00:45.000Z",
      "name": "facebookprofilelinks.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookprofilelinks.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/1f191046-d288-465a-aeaf-aaef3a03a730/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d0ac43a5-9675-5ba8-b526-4f2ab484795f",
      "created": "2026-07-04T01:01:14.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-04T01:01:14.000Z",
      "name": "uspsaunitedworkforce.com",
      "description": "Suspicious phishing domain impersonating USPS, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'uspsaunitedworkforce.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/usps/06871f43-deaa-4811-a2f1-e82cd8764593/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "usps"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc934cdc-e48f-54a9-ab48-738757fa9aae",
      "created": "2026-07-04T13:01:14.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-04T13:01:14.000Z",
      "name": "netflixfeitoaqui.com.br",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflixfeitoaqui.com.br']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/719d4201-c686-4bf8-94c8-748202e55be6/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e65668cc-9a58-5a7d-b3b1-3e968764d93c",
      "created": "2026-07-05T01:02:16.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-05T01:02:16.000Z",
      "name": "netflixhasnohomepage.com",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflixhasnohomepage.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/13a88bbb-e831-42e4-9343-a888f00f47b3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e1b2599d-6bce-5fc2-b969-2a17a63602c7",
      "created": "2026-07-05T10:33:18.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-05T10:33:18.000Z",
      "name": "ggzh-google.com.cn",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ggzh-google.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/c4ad994c-be5c-4092-9012-9a23e2efa1ad/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c7b02b73-bf49-5150-a96f-c989f06099c8",
      "created": "2026-07-06T12:07:04.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-06T12:07:04.000Z",
      "name": "spotifyzonepro-dl.fwh.is",
      "description": "Suspicious phishing domain impersonating Spotify, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'spotifyzonepro-dl.fwh.is']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/spotify/b9cf6e3c-1c3e-4c76-82f0-e484bc2c8d4f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "spotify"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5ade31cc-5f30-5af2-b5df-b4bf918615de",
      "created": "2026-07-06T12:07:07.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-06T12:07:07.000Z",
      "name": "spotifysvotingslink.ct.ws",
      "description": "Suspicious phishing domain impersonating Spotify, detected by phishunt.io (score 21/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'spotifysvotingslink.ct.ws']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 21,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/spotify/c1479453-b303-4f32-908b-c1f240fd17a5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "spotify"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--12aa3b80-7dd8-5db0-b809-8baacd511f58",
      "created": "2026-07-08T13:00:59.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-08T13:00:59.000Z",
      "name": "facebook-seks-32.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-seks-32.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c883d791-422e-4cab-a04b-4300ff09d7d5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--861ba7aa-e9dd-5c5a-8d11-ed2c7b13696c",
      "created": "2026-07-09T13:01:50.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-09T13:01:50.000Z",
      "name": "facebook-login-pages.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-login-pages.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/a0ce4b87-ad9f-4a4b-a08b-bf4ba88f05e2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a4c7284a-7e95-5624-b263-03f62b3011c1",
      "created": "2026-07-09T13:01:55.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-09T13:01:55.000Z",
      "name": "test-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'test-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/45e96f70-861f-4611-8441-d1177adadd94/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6160c1cc-3b17-5726-b6ab-acab5304fba7",
      "created": "2026-07-09T13:01:57.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-09T13:01:57.000Z",
      "name": "facebook-seks-35.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-seks-35.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/54603dc9-a00d-47a2-bb20-1b14e4f558ea/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0de49a95-b9de-58bc-8353-eb6ec111908c",
      "created": "2026-07-09T13:02:04.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-09T13:02:04.000Z",
      "name": "s-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 's-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/efbd49f1-27d7-4ff9-b28e-001e7d2c11fc/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ec97f4f-e47d-5ceb-a39e-5e0ce8650e9f",
      "created": "2026-07-09T13:02:17.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-09T13:02:17.000Z",
      "name": "berbagi-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'berbagi-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/9d22f15f-4019-45d9-b131-cb5ebd54e52f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4822a7e2-a403-5256-ae98-2cdf4dadb789",
      "created": "2026-07-09T13:02:18.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-09T13:02:18.000Z",
      "name": "facebook-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/0ccb315b-5189-4564-bf62-c44c5f147870/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--49126807-35c5-5c9c-ab75-e0deb554cd4d",
      "created": "2026-07-09T13:02:21.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-09T13:02:21.000Z",
      "name": "network-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'network-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/243ea18e-54e1-442b-9694-077ee5dc6cb4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--31f05c1a-0496-5a58-b0f7-c94f0d6fb8da",
      "created": "2026-07-10T01:01:22.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-10T01:01:22.000Z",
      "name": "facebook-fake.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-fake.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/0cb5a7de-8102-44b9-83fa-704fa22c0f1c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--182c4409-0ceb-5cec-a86a-2c9f2f4d3e4c",
      "created": "2026-07-10T01:01:43.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-10T01:01:43.000Z",
      "name": "free-facebook-page-likes.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'free-facebook-page-likes.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/7f2050f8-e48b-4e5b-9e77-201aa3f06504/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1450a77a-3500-53c2-8808-62394fa20ad9",
      "created": "2026-07-10T01:01:45.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-10T01:01:45.000Z",
      "name": "facebook-prime.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-prime.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/d27131a8-4a89-4631-b7e4-e6b0c900310d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6cc6638e-fd23-51de-a00f-aa95dff45f32",
      "created": "2026-07-10T01:02:03.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-10T01:02:03.000Z",
      "name": "facebook-alpha.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-alpha.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/04389915-cf92-4c87-bbb0-34f423eca564/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--874da8c1-daf8-596b-a1b1-d5bf56a32034",
      "created": "2026-07-10T01:02:08.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-10T01:02:08.000Z",
      "name": "facebook-video-share.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-video-share.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/330d8b69-2865-4a04-a132-795fd49ed88b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53b7735e-4481-56f5-84d0-f0c53a54ddfe",
      "created": "2026-07-10T13:02:51.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-10T13:02:51.000Z",
      "name": "facebook-photo5.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-photo5.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/92cc5618-7491-44a1-94db-45804d3aa6b2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--109caf92-0736-5338-a538-d21b1ecf5bce",
      "created": "2026-07-10T13:02:52.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-10T13:02:52.000Z",
      "name": "facebookloginconfirm.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginconfirm.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/e0304d91-e069-418e-a00b-41ab7e63a468/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8cf34259-4095-5a1c-9869-bcdc99830643",
      "created": "2026-07-10T13:03:00.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-10T13:03:00.000Z",
      "name": "facebooklogin123.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin123.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/9b0d7ce5-88e8-4803-96fc-8152961d36eb/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3f0845a6-2238-51f8-b118-63f27fc42291",
      "created": "2026-07-10T13:04:27.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-10T13:04:27.000Z",
      "name": "ml-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ml-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c6f5028d-441a-403a-b45c-53f8318cb928/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1e20afef-1d6b-5b44-8b42-40b94d2eb756",
      "created": "2026-07-10T13:05:12.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-10T13:05:12.000Z",
      "name": "facebook-seks-44.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-seks-44.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/becb947e-f649-4ccc-a012-e0de425bbe54/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4c9845e0-b707-54ba-a526-5b015e980a46",
      "created": "2026-07-11T01:01:27.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-11T01:01:27.000Z",
      "name": "facebookmail-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookmail-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/e54e2f0a-4fc5-49b0-a9f6-3625f6c3cd13/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--974bc968-7e49-5a82-895a-68d90e254516",
      "created": "2026-07-11T01:01:53.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-11T01:01:53.000Z",
      "name": "cz-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'cz-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/da5846e9-fcad-4207-bf32-664565c99c68/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c081ed4-0cea-5178-8da4-6e8d2fccbd13",
      "created": "2026-07-11T13:03:28.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-11T13:03:28.000Z",
      "name": "facebook-seks-27.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-seks-27.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/194e057b-cbc4-456f-aa46-8a94af00a764/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d8daa440-1b2c-5eaf-be7f-48265ba2a3aa",
      "created": "2026-07-11T13:03:35.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-11T13:03:35.000Z",
      "name": "facebook-system.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-system.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/84d069be-13aa-4361-a8d1-6da4f4ae969b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ee944fc5-da8f-5308-bcd1-3a6655411019",
      "created": "2026-07-11T13:04:00.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-11T13:04:00.000Z",
      "name": "facebookloginf.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginf.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/9a2f0c44-3d27-4619-96ba-14db85ec0138/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8119ccd-77ff-5b1c-a5c5-a5a1c3791e38",
      "created": "2026-07-11T13:04:08.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-11T13:04:08.000Z",
      "name": "facebook-carol.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-carol.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/263a7ce5-27df-45c3-95b3-dfd6c3bec3f1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c3451ae9-8f45-5fa0-97e2-32e56e65b320",
      "created": "2026-07-11T13:04:09.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-11T13:04:09.000Z",
      "name": "facebook-logo.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-logo.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/193564d5-c343-43ef-b213-c67247cbe41d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--34fd1bde-5544-571f-a3cc-0ac6fdf039c5",
      "created": "2026-07-11T13:04:21.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-11T13:04:21.000Z",
      "name": "facebookcomfacebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookcomfacebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/5a939c28-4ff9-47ab-8a45-5db3fd517b09/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b9d1ae5-36bd-5d82-8bef-776585716464",
      "created": "2026-07-11T19:51:26.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-11T19:51:26.000Z",
      "name": "play.googleplaety.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'play.googleplaety.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/ddba8628-a2cb-4d98-830e-98fd9ef45f2b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e9073567-6272-537d-a8c3-a6c7b55bfd48",
      "created": "2026-07-11T19:51:26.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-11T19:51:26.000Z",
      "name": "ingdirect-cliente-gestion.com",
      "description": "Suspicious phishing domain impersonating ING Espa\u00f1a, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ingdirect-cliente-gestion.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ingspain/cf141307-2c57-44bb-bdf6-f1cc5639af50/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ingspain"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3ae8277a-44be-51ad-844d-b29d940b9480",
      "created": "2026-07-12T01:02:21.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-12T01:02:21.000Z",
      "name": "app81-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'app81-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/945ed8a4-192c-4c36-a89d-e9591a57ebac/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--949d11cc-308c-5188-a57d-bc2f6ef4e271",
      "created": "2026-07-12T01:02:55.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-12T01:02:55.000Z",
      "name": "pe-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'pe-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/201e4501-6dfd-4eda-baed-200cdc85547b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--71445875-90a3-550d-8f92-844381589dc4",
      "created": "2026-07-12T01:02:59.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-12T01:02:59.000Z",
      "name": "facebook-verification-system3.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-verification-system3.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/1f33ee25-77ee-4a72-b6aa-989fbdd78797/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c60cfa4a-64d7-55a2-9416-e990dbecc330",
      "created": "2026-07-12T01:03:06.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-12T01:03:06.000Z",
      "name": "metamasklskog.gitbook.io",
      "description": "Suspicious phishing domain impersonating MetaMask, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'metamasklskog.gitbook.io']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/metamask/f0c7c137-c905-495b-bba7-25f07c30a2c5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "metamask"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c728e095-9f0b-5a14-b87e-29c1ec73099e",
      "created": "2026-07-12T13:01:31.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-12T13:01:31.000Z",
      "name": "mb-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mb-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3563f3a1-cd54-4deb-bc94-f94482855ef1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9917d971-3974-5ccc-b8dc-5492e24391f7",
      "created": "2026-07-12T13:01:38.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-12T13:01:38.000Z",
      "name": "facebook-new-security.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-new-security.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/7a255b02-374d-4855-b3e9-ddcf7b2d8291/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--54d523b4-ef55-5bc4-9c77-f03106ef7e21",
      "created": "2026-07-12T13:01:41.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-12T13:01:41.000Z",
      "name": "facebook--br.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook--br.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3594fa2f-3031-4b6d-9a44-9f366f8ae90a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--baafccbb-926e-5d08-b604-444cf5153884",
      "created": "2026-07-12T13:01:51.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-12T13:01:51.000Z",
      "name": "click-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'click-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3c227bb5-1e31-400c-bf22-c4205ec2c13c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c11914f-0b51-5190-96cd-ebd274bf23b0",
      "created": "2026-07-12T13:01:52.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-12T13:01:52.000Z",
      "name": "online-facebook-privacy.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'online-facebook-privacy.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/735913fc-d4d3-4ad1-b2d7-33c9bb6555a4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d18fe183-8d73-5daf-8a28-8ae92622ac81",
      "created": "2026-07-12T15:41:21.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-12T15:41:21.000Z",
      "name": "click5.microsoftsupportcenter.digital",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'click5.microsoftsupportcenter.digital']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/1da42bf9-a9be-4b92-b23b-cbe979eee023/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--48580561-6d6c-564f-81e5-6ce419954b78",
      "created": "2026-07-12T15:41:21.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-12T15:41:21.000Z",
      "name": "ingdirect-alerta-clientes.com",
      "description": "Suspicious phishing domain impersonating ING Espa\u00f1a, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ingdirect-alerta-clientes.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ingspain/13b037cb-a3c8-4cca-8053-f481f2720efa/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ingspain"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f8f42792-a506-55e2-9c99-c775f86ab829",
      "created": "2026-07-12T15:41:21.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-12T15:41:21.000Z",
      "name": "ingdirect-gestiones-incidencia.com",
      "description": "Suspicious phishing domain impersonating ING Espa\u00f1a, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ingdirect-gestiones-incidencia.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ingspain/eb5aaa78-6688-4685-939c-7b6debe3995c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ingspain"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--952fc023-a831-5328-9185-31b3dfe32b2f",
      "created": "2026-07-12T15:41:22.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-12T15:41:22.000Z",
      "name": "bb.google77bd.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 21/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bb.google77bd.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 21,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/2cc9f36e-9c2d-42c7-8452-d0e8ee863ca0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fcfba7e4-6842-5c9f-81fb-8eb6825e74da",
      "created": "2026-07-12T15:41:23.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-12T15:41:23.000Z",
      "name": "googlebusiness.xyz",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googlebusiness.xyz']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/23a7c852-6d1f-4bb7-bf1a-58fdf18b6eca/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2aaf73a3-6ebb-5780-b5fb-8cc8833fc805",
      "created": "2026-07-12T15:41:23.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-12T15:41:23.000Z",
      "name": "ingdirect-usuario-soporte.com",
      "description": "Suspicious phishing domain impersonating ING Espa\u00f1a, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ingdirect-usuario-soporte.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ingspain/b75cdb17-191a-41ae-84da-076d97475730/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ingspain"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d234ea1-178c-5eba-bd54-8eb106082ed2",
      "created": "2026-07-12T15:41:24.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-12T15:41:24.000Z",
      "name": "ingdirect-clientes-alerta.com",
      "description": "Suspicious phishing domain impersonating ING Espa\u00f1a, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ingdirect-clientes-alerta.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ingspain/c4f0a746-1867-489c-be4d-f7c5b6c204ee/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ingspain"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4a84549-34d8-5a16-af09-e8953046657c",
      "created": "2026-07-12T15:41:24.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-12T15:41:24.000Z",
      "name": "ingdirect-web-validado.com",
      "description": "Suspicious phishing domain impersonating ING Espa\u00f1a, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ingdirect-web-validado.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ingspain/c76ab4b3-c1ea-497d-91fe-6ce2027faf4d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ingspain"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d53e3707-2a29-5de4-ae2e-565599577471",
      "created": "2026-07-12T15:41:24.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-12T15:41:24.000Z",
      "name": "openai-online.net",
      "description": "Suspicious phishing domain impersonating ChatGPT, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'openai-online.net']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/chatgpt/4e85d5c8-48e8-4ab1-9195-c1799bf9fc11/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "chatgpt"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1456d639-123e-5ac4-9ca2-ea4135f4cf93",
      "created": "2026-07-12T15:41:25.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-12T15:41:25.000Z",
      "name": "ingdirect-ingreso-usuarios.com",
      "description": "Suspicious phishing domain impersonating ING Espa\u00f1a, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ingdirect-ingreso-usuarios.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ingspain/9295692d-118f-40f1-9a83-23291e5d97d2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ingspain"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--434f0cf1-05db-5fe0-8d6e-2163d0c0fbc4",
      "created": "2026-07-12T15:41:26.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-12T15:41:26.000Z",
      "name": "click6.microsoftsupportcenter.digital",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'click6.microsoftsupportcenter.digital']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/26e74f36-d9b6-418b-b32d-5d2b065b7208/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--272f5c1e-4150-5419-adcc-9e87d4c478a0",
      "created": "2026-07-13T01:01:20.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-13T01:01:20.000Z",
      "name": "accounts-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'accounts-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/ef756b22-f225-491b-a58f-a1bd193cc308/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f07b61a5-dfd8-528c-a942-c22583c26630",
      "created": "2026-07-13T01:01:34.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-13T01:01:34.000Z",
      "name": "facebook-www.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-www.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/167f459a-da90-4a14-942b-e5678e587e26/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd26582c-a3fd-5fa6-b166-a0b7e9a6dc54",
      "created": "2026-07-13T01:01:37.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-13T01:01:37.000Z",
      "name": "home-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'home-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/d25b1b8f-af34-4c5f-8c97-e7328ed3bd07/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--52cf2682-c28d-5e5b-900b-157cc2318db5",
      "created": "2026-07-13T01:01:39.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-13T01:01:39.000Z",
      "name": "facebook-login-login.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-login-login.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/d805b229-2383-43d2-bdc2-7580386b8ca7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c8a1499b-385b-5200-af2c-9fef8af362b8",
      "created": "2026-07-13T01:01:42.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-13T01:01:42.000Z",
      "name": "uk-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'uk-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/6ff1ddcd-4cba-4fe0-a003-3f26a48c58c0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6a84545d-673c-549e-983b-26f18b065141",
      "created": "2026-07-13T05:46:50.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-13T05:46:50.000Z",
      "name": "googleplty.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googleplty.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/244e8248-2926-40b9-b004-cfaf28e719fa/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--89dacec2-ef10-559f-8896-587eb6f96634",
      "created": "2026-07-13T05:47:11.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-13T05:47:11.000Z",
      "name": "rberthelette.com",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'rberthelette.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//bfe3b071-b9a6-4d65-b9a5-18119c3acbec/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--acc426d8-4f77-5f7b-9603-662029e9e530",
      "created": "2026-07-13T13:01:48.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-13T13:01:48.000Z",
      "name": "facebook-th.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-th.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/9918b10a-9389-44a6-b217-28463d18010b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5b78d2bb-f845-51cc-b30d-d8194cd0b892",
      "created": "2026-07-13T13:01:53.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-13T13:01:53.000Z",
      "name": "facebook-us.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-us.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/ad9625b9-6e0f-4b0c-80c6-95806c77ce01/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--21fac35b-f0ea-574b-8141-2502d7c28a3d",
      "created": "2026-07-13T13:01:55.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-13T13:01:55.000Z",
      "name": "facebook-ca.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-ca.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/f7f34949-aea8-461e-be34-44b3de17bb35/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--71df1a48-e279-5279-8a9e-816347b4be0b",
      "created": "2026-07-13T13:01:58.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-13T13:01:58.000Z",
      "name": "fake-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'fake-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/5db340d4-c4b1-408a-beed-d310d69bbe10/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4cc237c5-d191-5da2-85a6-b182245bc275",
      "created": "2026-07-13T13:02:00.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-13T13:02:00.000Z",
      "name": "sena-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'sena-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c0473ceb-47ca-4ec0-ae9d-06a1e63609c1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2d36c1fb-5a41-5092-8121-399a63dd139d",
      "created": "2026-07-13T13:02:02.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-13T13:02:02.000Z",
      "name": "facebook-sa.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-sa.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/befabd16-6d45-404c-acd9-a9715b89fe6d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--62729d87-d2a4-5656-bda6-5c5614f3ca55",
      "created": "2026-07-13T13:02:10.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-13T13:02:10.000Z",
      "name": "vn-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'vn-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/b072b8b0-d893-4e45-9a05-21f9754245b2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0c92a39e-4de2-51b9-9d4d-8f20e5559aeb",
      "created": "2026-07-13T13:02:13.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-13T13:02:13.000Z",
      "name": "facebooklogin1234.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin1234.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/a7f28f6c-db2a-46d3-a746-754684b6e49c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--69fcbe7e-3ae9-544a-bc98-3c9a697fc76d",
      "created": "2026-07-13T13:02:16.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-13T13:02:16.000Z",
      "name": "facebook-mx.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-mx.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/ef5a8cb2-7e0c-4ef1-8682-c3d96047b506/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9ee4575c-af42-55e6-835a-aec9b4a9e7a4",
      "created": "2026-07-13T13:02:20.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-13T13:02:20.000Z",
      "name": "facebook-official-page.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-official-page.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/aad9e123-dd97-4e54-84f9-22a8913fcc3e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7f15adee-1b4c-55ba-ab2a-1e7937fdb8d8",
      "created": "2026-07-13T13:02:21.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-13T13:02:21.000Z",
      "name": "facebook-vn.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-vn.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/5c20abff-4d68-4aa7-acfe-21b1f21496f5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f62e8fc-8667-5427-b447-cf0dccc52521",
      "created": "2026-07-14T01:02:06.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-14T01:02:06.000Z",
      "name": "facebooklogin13.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin13.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/480276f6-e7fd-4433-bd74-40ab032d080a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d720b3c4-72e0-5be6-a646-7e17c951ded0",
      "created": "2026-07-14T01:02:16.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-14T01:02:16.000Z",
      "name": "facebook-vn-com.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-vn-com.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/711bbb58-dffc-46c8-9d61-66225c47e3b8/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--61b35bf4-78e6-579c-a8f6-317293b5a0c1",
      "created": "2026-07-14T13:02:24.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-14T13:02:24.000Z",
      "name": "r-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'r-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c8a06548-614a-418d-b7ad-75fdf094b59b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--777026f0-af78-57fc-8df4-a5e95a55c0d4",
      "created": "2026-07-14T13:02:31.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-14T13:02:31.000Z",
      "name": "ww-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ww-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/8e474612-4766-4efd-aa4b-9798b0103a0c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2cece366-8fd8-5ab8-94c8-8ea633c9a8f3",
      "created": "2026-07-14T13:02:32.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-14T13:02:32.000Z",
      "name": "meme-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'meme-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/374604a3-290c-4fb4-a645-6a258424b302/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eeb0b571-3413-5b7e-9208-d4386854fd02",
      "created": "2026-07-14T13:02:35.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-14T13:02:35.000Z",
      "name": "facebook-22.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-22.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/0f30d905-81be-4e3f-8601-d7d74c1737b7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--54d1fc22-9571-545e-af98-6c2f24395902",
      "created": "2026-07-14T13:02:40.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-14T13:02:40.000Z",
      "name": "facebook-5645464.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-5645464.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/7d058dc2-9038-40c7-a448-555ef38b9ab7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e9765c06-0322-5da8-862c-316ab572d941",
      "created": "2026-07-14T13:03:00.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-14T13:03:00.000Z",
      "name": "facebook-seks-45.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-seks-45.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/5cf95b60-46aa-41be-9eb1-5b6e8f447a4c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d3e0e5ed-9216-561d-873f-683d3db939b7",
      "created": "2026-07-14T13:03:03.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-14T13:03:03.000Z",
      "name": "facebook-channel.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-channel.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/603dd38f-3c34-4a3a-b79a-3aaf93caa98e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6bd080c9-42e6-5b65-9ce2-529af5e5b9c2",
      "created": "2026-07-14T13:03:05.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-14T13:03:05.000Z",
      "name": "facebook-ng.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-ng.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/966b534e-ef0a-4555-adaa-fdb7a20914a7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--01fabf06-4987-537f-8963-e7bc4ce5ce6b",
      "created": "2026-07-14T13:03:11.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-14T13:03:11.000Z",
      "name": "instagramaccounthacks.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramaccounthacks.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/760388a4-ecd2-4c0c-9680-aeb95d658fa0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a1be505c-66c1-5789-b916-31165fb96a47",
      "created": "2026-07-14T13:03:13.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-14T13:03:13.000Z",
      "name": "facebookloginapps.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginapps.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/2d1fe52a-3b2b-4a3d-ac25-3c232ee58160/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--12fe52a0-ed58-5818-a917-5db0e638f01b",
      "created": "2026-07-14T21:00:40.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-14T21:00:40.000Z",
      "name": "microsoft.updata.net.cn",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoft.updata.net.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/3e9b9685-7b3c-4c65-b646-842441c00c51/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f86bd026-49e7-514a-aeed-6d9193f2af20",
      "created": "2026-07-15T01:01:03.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-15T01:01:03.000Z",
      "name": "secutury-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'secutury-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/dd8d457d-f8cb-4567-9ba5-fd3c37435447/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--63c6304c-05dd-5bfe-a5bb-d264bdaf3106",
      "created": "2026-07-15T01:01:09.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-15T01:01:09.000Z",
      "name": "jwb-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'jwb-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/6dbacaad-9107-47e2-a7d5-da587fcf63a9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--03f3a5a9-3d52-511e-900a-aee3162aecbb",
      "created": "2026-07-15T01:01:14.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-15T01:01:14.000Z",
      "name": "facebook-account-login-page.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-account-login-page.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/166bea03-7616-43e7-a17f-d2791d020e18/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da5af006-35a9-5e0d-b4f5-c61e3277d6cc",
      "created": "2026-07-15T13:01:08.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-15T13:01:08.000Z",
      "name": "nw-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'nw-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/7ad0b839-f509-4cbf-ad85-52d86d5744a2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b2ea749b-4e8d-5d25-b25d-4640d8d0b629",
      "created": "2026-07-16T00:38:22.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-16T00:38:22.000Z",
      "name": "www-app-google.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'www-app-google.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/bf2b9c5b-9e90-4256-85f1-720f2d238e51/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5992ae52-1cd2-5e56-9574-ec0f2b3036b4",
      "created": "2026-07-16T01:01:13.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-16T01:01:13.000Z",
      "name": "facebook-eu.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-eu.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/bf7d718f-50eb-42fb-ac92-30fb3db9804f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3f6e4ede-0aec-5643-a581-9795b76f52d2",
      "created": "2026-07-16T01:01:15.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-16T01:01:15.000Z",
      "name": "facebook-qa.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-qa.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/2e736496-d79e-45dc-ab12-748aaf3ac60b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9314af17-c68c-5ae8-841a-773ee9523816",
      "created": "2026-07-16T13:01:03.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-16T13:01:03.000Z",
      "name": "facebooklogin17.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin17.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/a3cb513b-4e49-4304-9014-c9f5e073d8cb/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fa9c0b8d-d9f5-5928-befb-82cda3a3b11a",
      "created": "2026-07-17T01:03:03.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-17T01:03:03.000Z",
      "name": "facebookloginuser.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginuser.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/53ea55da-e98f-41cf-aa8c-474548f367ab/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--879d3d94-f171-5411-8825-a84577e8e88a",
      "created": "2026-07-17T01:04:26.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-17T01:04:26.000Z",
      "name": "facebook-help-m.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-help-m.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/5c8ea14e-83ec-4229-a95c-938615e7799d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e7e67fa-8786-585e-a1de-7ac58aeebc7b",
      "created": "2026-07-17T13:01:07.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-17T13:01:07.000Z",
      "name": "facebook-pt.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-pt.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/f648ac2f-7604-4e57-933e-714eefa435cc/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6c625479-19ec-5913-b669-62e21576a7ae",
      "created": "2026-07-17T13:01:10.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-17T13:01:10.000Z",
      "name": "facebook-login-page.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-login-page.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/484862d0-19f2-4cfe-9f54-c3160a2d6a12/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b0c898d-203c-5dc6-b5c6-2eb2a89d2c22",
      "created": "2026-07-17T13:01:12.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-17T13:01:12.000Z",
      "name": "brad-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'brad-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/66108f28-dce0-45c0-8228-9a739fad3f4d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b7cfa5b-cc42-5225-9e8b-2cba54b1fca5",
      "created": "2026-07-17T13:01:13.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-17T13:01:13.000Z",
      "name": "su-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'su-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/40a7120e-fb28-42be-a199-2bf8a301e67a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ab3430f2-5d51-503d-9165-4b00d44237ee",
      "created": "2026-07-18T01:03:09.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-18T01:03:09.000Z",
      "name": "facebook-login0.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-login0.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/01bf3029-d5fc-46d4-a1fb-25f468cafa80/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aeff0036-6a62-54d4-8e1d-66611fa2667a",
      "created": "2026-07-18T13:01:47.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-18T13:01:47.000Z",
      "name": "facebook-cdn.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-cdn.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/6dc03801-92d2-45d0-b055-01f9f9113a73/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eafb5ed9-b8b6-573d-943d-e685e18a9983",
      "created": "2026-07-18T13:01:51.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-18T13:01:51.000Z",
      "name": "ly-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ly-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/34c89fda-234d-470c-95e0-f35031da2301/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd5101c5-46e5-5a3b-88b0-65dc48bbc079",
      "created": "2026-07-18T13:02:37.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-18T13:02:37.000Z",
      "name": "services-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'services-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/bcef11a1-3c7d-4c67-81b6-be782fe81a32/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4df6ee2d-74a7-526c-9a60-968f4fc33b2e",
      "created": "2026-07-18T13:02:39.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-18T13:02:39.000Z",
      "name": "facebooklogin18.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin18.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/860ec897-3b26-425a-b304-fa667b564061/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4179a01b-b9cc-5e8a-a625-fe281d76c266",
      "created": "2026-07-18T13:02:41.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-18T13:02:41.000Z",
      "name": "empresas-hsbc.com",
      "description": "Suspicious phishing domain impersonating HSBC, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'empresas-hsbc.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/hsbc/656cdf99-a953-4192-8ab7-8cf0962606bc/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "hsbc"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4ce06b4a-02de-5f8e-a0c7-261a11e16f12",
      "created": "2026-07-19T01:02:16.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-19T01:02:16.000Z",
      "name": "sk-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'sk-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c8e24f42-b925-4619-8520-af00c106e94f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a09cd08e-3373-5c43-be9f-30da829d58eb",
      "created": "2026-07-19T01:02:21.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-19T01:02:21.000Z",
      "name": "facebook-9.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-9.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/a5c06203-6af5-496a-aaa2-87b9279ca826/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--567af8eb-069f-51f4-8039-277f9c68e45e",
      "created": "2026-07-19T08:11:29.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-19T08:11:29.000Z",
      "name": "microsoftai.pl",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoftai.pl']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/7c104beb-6cbd-4c2d-aad5-0fa2603ff03e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a684c6fb-8b64-55c2-9fa9-545058603e57",
      "created": "2026-07-19T13:01:27.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-19T13:01:27.000Z",
      "name": "facebook-find.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-find.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/22856948-8aa0-4fda-a06f-0457168467f6/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0e64ad3b-7c22-59ac-b96a-600ce97c1e2f",
      "created": "2026-07-19T13:01:29.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-19T13:01:29.000Z",
      "name": "ani-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ani-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/a860de31-8dc1-4598-936f-ef911a89318f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b4249cde-4df5-5df2-863a-bf463841cdb8",
      "created": "2026-07-19T13:01:41.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-19T13:01:41.000Z",
      "name": "usacrazyseller.com",
      "description": "Suspicious phishing domain impersonating LinkedIn, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'usacrazyseller.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/linkedin/10a3b0d9-7de8-4a52-97cb-b31b9fc35e08/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "linkedin"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c196acfe-d901-5856-a16c-4bf8684b6002",
      "created": "2026-07-20T01:01:39.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-20T01:01:39.000Z",
      "name": "facebooklogini.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogini.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/52954f4c-5d51-4eaf-a731-7048dbfcc5cf/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3fb456d4-9b4a-5fd5-bbd1-bdc79837a622",
      "created": "2026-07-20T12:34:47.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-20T12:34:47.000Z",
      "name": "uspssmartpackagelockers.com",
      "description": "Suspicious phishing domain impersonating USPS, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'uspssmartpackagelockers.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/usps/6f1e7fe2-188d-4f2c-b76d-680c46e66afe/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "usps"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--86cfff79-fc76-5dfd-bb7b-b8eab2d5dc2a",
      "created": "2026-07-20T13:02:12.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-20T13:02:12.000Z",
      "name": "facebook-login-web.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-login-web.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/97417ee6-49b4-4492-ba03-6caf7839989f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e54e8504-eb6d-53e4-93f7-9a803be878a5",
      "created": "2026-07-20T13:02:21.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-20T13:02:21.000Z",
      "name": "facebooksecurityhelp.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooksecurityhelp.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/fc5bc47b-8b86-4eac-beea-bcd87c789b44/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a8230f1-9134-5e5c-b7fc-c3b09d27799e",
      "created": "2026-07-20T13:02:37.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-20T13:02:37.000Z",
      "name": "info-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'info-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3604834e-7b07-4001-a991-006ffd3d4db5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d682ecb7-ed17-5679-bc46-a719b3c91d54",
      "created": "2026-07-20T13:02:53.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-20T13:02:53.000Z",
      "name": "facebook-groups-new.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-groups-new.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/4eb25870-e3e2-4a9d-9473-b7cc65a5e9da/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc165c6f-5dca-527c-a732-3b108abdf462",
      "created": "2026-07-20T18:15:31.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-20T18:15:31.000Z",
      "name": "netflix520.com",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflix520.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/56f4d4bb-687e-45dd-b08d-402358b197db/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c1d1b78-744e-5136-a5e0-995622d6be3c",
      "created": "2026-07-21T01:01:17.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-21T01:01:17.000Z",
      "name": "bbvalues.uk",
      "description": "Suspicious phishing domain impersonating BBVA, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bbvalues.uk']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bbva/23e87ca8-5181-42e4-8742-0ea639f64232/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bbva"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--befd0fae-b5da-5ab1-9b96-c254d6007f4d",
      "created": "2026-07-21T13:01:12.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-21T13:01:12.000Z",
      "name": "love-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'love-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/17f81f25-a053-4a0f-be44-2f77ac578947/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb379430-a85b-5131-bc54-86c1892c426c",
      "created": "2026-07-21T13:01:15.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-21T13:01:15.000Z",
      "name": "facebookdatingonfacebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookdatingonfacebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/250a46e9-85b5-46eb-b2f2-6e50d22d37da/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b178e69e-2a96-5634-92d8-995f12803389",
      "created": "2026-07-21T13:01:22.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-21T13:01:22.000Z",
      "name": "bbva-hiring-paperless.appspot.com",
      "description": "Suspicious phishing domain impersonating BBVA, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bbva-hiring-paperless.appspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bbva/483241bc-0edd-4151-bb15-9fe871cb34db/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bbva"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b90fc462-383f-5412-9301-eab9620c2e7f",
      "created": "2026-07-22T01:03:03.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-22T01:03:03.000Z",
      "name": "facebok-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebok-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/d8d1b4a6-9096-413d-9c5e-bbfe01073e94/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87432734-bd72-55a3-8b31-d485878fb409",
      "created": "2026-07-22T01:03:10.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-22T01:03:10.000Z",
      "name": "jo-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'jo-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/4799078c-a0fa-4c29-824f-1622671828df/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e0534b31-5f6f-51bf-8e52-9f2350cc9bf2",
      "created": "2026-07-22T01:03:14.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-22T01:03:14.000Z",
      "name": "facebook-gamehacks.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-gamehacks.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/b3bec619-a1d4-4a86-944d-bfcab851c86b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5146bd40-09c6-5ed9-b5b4-f9b79cb10762",
      "created": "2026-07-22T01:03:18.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-22T01:03:18.000Z",
      "name": "facebook-q.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-q.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/dcda95f4-7761-4639-ba28-c9a29dbca884/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d7253dfa-e0b7-501f-bfef-6a43dd3f54e8",
      "created": "2026-07-22T01:03:26.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-22T01:03:26.000Z",
      "name": "facebook-account-manager.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-account-manager.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/f57bd13d-5a17-471e-9b66-737656906dea/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da7e298d-a997-5356-8b16-dc7c101add4a",
      "created": "2026-07-22T05:48:09.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-22T05:48:09.000Z",
      "name": "play-google.cam",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'play-google.cam']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/8d9dd06a-6225-46c4-9317-2b83312e7807/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b8c69314-0eb9-553f-a5a5-84769e4e9c34",
      "created": "2026-07-22T13:01:54.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-22T13:01:54.000Z",
      "name": "facebook-vu.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-vu.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/ee5b415b-06a8-430c-a7d7-088bcaa0dcbb/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b3ab1bf7-01d2-550c-81ca-ac59fc06eaa2",
      "created": "2026-07-22T13:01:58.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-22T13:01:58.000Z",
      "name": "facebooklogin333.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin333.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/1ca0d6ed-c768-4b41-8676-62afd1057ec2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--357473de-d32f-5178-9ac7-bd8a051016be",
      "created": "2026-07-22T13:02:02.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-22T13:02:02.000Z",
      "name": "instagramcoverrbrasilinstagram.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramcoverrbrasilinstagram.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/46a65d94-9e22-48d4-a602-127e3018433e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--17196182-12b3-58c6-959a-345ff3633063",
      "created": "2026-07-22T13:02:08.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-22T13:02:08.000Z",
      "name": "facebook-int.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-int.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/a02eff5d-c116-405e-9b2f-e555bcf3f933/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--83fe4b8d-8714-5cfd-8a01-0abbc5799892",
      "created": "2026-07-22T13:02:13.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-22T13:02:13.000Z",
      "name": "facebookloginfriends.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginfriends.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/4d5f10ad-bf1a-4a02-9112-b59a31526d55/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--327ecd9a-e47b-5e52-bf2d-485b941fd835",
      "created": "2026-07-22T13:02:15.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-22T13:02:15.000Z",
      "name": "facebook7-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook7-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/ac9c74de-0bf7-4dd4-a9a1-fe0b0eb6b9b5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b2edefcb-a43a-5dfe-975e-00fd886f92b8",
      "created": "2026-07-22T13:02:17.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-22T13:02:17.000Z",
      "name": "facebook-facebook1.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-facebook1.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/56669579-785c-4741-9d50-dbfe53cd0e3d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c65c930-f28d-508d-9214-5cc5632d4d52",
      "created": "2026-07-22T13:02:20.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-22T13:02:20.000Z",
      "name": "help-instagram.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'help-instagram.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/2ba75fcd-f685-419f-a1fb-5ab94a426600/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8b0202da-9157-5db1-8762-6ea7261cf56f",
      "created": "2026-07-22T13:02:23.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-22T13:02:23.000Z",
      "name": "facebook-fb-com.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-fb-com.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/dda3d97a-abde-47eb-98d4-cc5a03dddfad/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--75af4664-352d-5d5c-9bd6-cc429c16a661",
      "created": "2026-07-22T17:20:19.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-22T17:20:19.000Z",
      "name": "bbvaglobalwealthadvisors.com",
      "description": "Suspicious phishing domain impersonating BBVA, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bbvaglobalwealthadvisors.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bbva/323dfc8c-089e-416f-a4c1-42ab52899060/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bbva"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a800d822-35bd-5090-bc7d-e98f218b2a1a",
      "created": "2026-07-22T23:04:16.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-22T23:04:16.000Z",
      "name": "ebay-app.com",
      "description": "Suspicious phishing domain impersonating eBay, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ebay-app.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ebay/3f7de289-508f-4a07-a152-78467a1f30ae/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ebay"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--78d456ff-19cc-5d89-95d4-aa55dc1f3514",
      "created": "2026-07-23T01:01:20.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-23T01:01:20.000Z",
      "name": "tara-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'tara-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/cc2d2240-ec33-4ee5-93fd-0cad356e5745/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--201072f5-e925-514b-a734-349c0f631958",
      "created": "2026-07-23T01:01:27.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-23T01:01:27.000Z",
      "name": "instagramcheck.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramcheck.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/5e1c7733-3cc6-493c-85a7-8100de840fef/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--696197c5-2c88-5f69-a616-0b96a8e59a2f",
      "created": "2026-07-23T01:01:32.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-23T01:01:32.000Z",
      "name": "lovefive-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'lovefive-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/310840fe-8db1-4c59-8c42-c7e1a6c8f0d2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e4ae3c29-f620-55b4-a3cb-82bb433d0cb2",
      "created": "2026-07-23T01:01:35.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-23T01:01:35.000Z",
      "name": "facebook-supports.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-supports.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/1f6f36f1-e706-41ad-92fe-9e1592d8dd64/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--628bb3ca-daa1-5d17-b3bd-0ee42e550f15",
      "created": "2026-07-23T01:01:41.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-23T01:01:41.000Z",
      "name": "emailnotifications.m365-microsoft.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'emailnotifications.m365-microsoft.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/cd267dfc-abf2-428a-8266-fdeb1382bc4f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--01998a41-f2cc-57f2-944c-e676d98182ba",
      "created": "2026-07-23T12:01:00.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-23T12:01:00.000Z",
      "name": "paypal-refund.com",
      "description": "Suspicious phishing domain impersonating PayPal, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'paypal-refund.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/paypal/83c47439-fc31-473d-8855-85e31d1fffd3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "paypal"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e070180d-b41b-5a57-8c35-4e087a9c4967",
      "created": "2026-07-23T13:01:51.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-23T13:01:51.000Z",
      "name": "instagram-change-password.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-change-password.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/a0a36105-eb57-45c7-a820-4df8fb019108/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--724578ca-ee93-5598-b3d5-782e86920b8d",
      "created": "2026-07-23T13:01:54.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-23T13:01:54.000Z",
      "name": "facebook-verify.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-verify.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/eb9a6da1-63e9-45ba-a052-599a5778efde/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ba9e6e13-0131-5e4e-8f48-3c29043b3974",
      "created": "2026-07-23T13:01:57.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-23T13:01:57.000Z",
      "name": "instagram-jennifer.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-jennifer.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/ec26a484-faa3-431d-a5c7-8e92d63b7854/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8899f101-858d-534d-92a0-e1bef928d4d8",
      "created": "2026-07-23T13:02:11.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-23T13:02:11.000Z",
      "name": "dj-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'dj-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/b8baa040-0cc0-4513-ad83-5066bb11c6df/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a7c57d85-bbbb-57bf-86cb-8dd0cd8c0bc8",
      "created": "2026-07-23T13:02:22.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-23T13:02:22.000Z",
      "name": "faceb00klogin.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'faceb00klogin.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/094de6a9-0272-4365-8ee7-8202d3ace25f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c9e3e1ef-5e72-5382-a211-3c78c26a2fa1",
      "created": "2026-07-23T13:02:35.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-23T13:02:35.000Z",
      "name": "app-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'app-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/026c60bf-afb2-43a1-bb07-18a3eebb7cde/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c4788152-1dff-5fef-837c-d95118b6869d",
      "created": "2026-07-23T13:02:40.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-23T13:02:40.000Z",
      "name": "facebooksociallink.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooksociallink.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3773a35b-b319-4282-a02b-97e8742125e9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9d468b87-0d9d-5cbb-ac43-d2b2626412e4",
      "created": "2026-07-23T13:02:44.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-23T13:02:44.000Z",
      "name": "facebookcustomersupportnumber25.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookcustomersupportnumber25.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/efc3cb5c-1cb9-43a6-9b25-0290a38ca71d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--850076da-4b8e-506d-b978-2109c3cd5c85",
      "created": "2026-07-23T13:02:48.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-23T13:02:48.000Z",
      "name": "facebookpageslinkk.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookpageslinkk.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/0a4d4691-3929-4b26-a505-cf447b52515e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e7dee465-cff9-537a-9793-727abd2f1aa4",
      "created": "2026-07-24T01:02:03.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-24T01:02:03.000Z",
      "name": "bet-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bet-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/44ee93b6-e0ca-457a-9055-2e15956fd11a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1899fa31-ab6a-594e-ac59-9fbf6db0974f",
      "created": "2026-07-24T01:02:13.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-24T01:02:13.000Z",
      "name": "tb-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'tb-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/fb0f2ee1-d0a7-49b3-b411-4657252a20b3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--024c4891-9998-547b-ada0-9f75f6ad86c0",
      "created": "2026-07-24T05:49:01.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-24T05:49:01.000Z",
      "name": "google-verify.email",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'google-verify.email']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/6b2cbe41-61e9-4cd5-a362-b4791a896d7f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--66f81287-19c5-547c-86cc-700ae35909eb",
      "created": "2026-07-24T11:00:44.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-24T11:00:44.000Z",
      "name": "googlepodstream.unaux.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googlepodstream.unaux.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/e9c56b3a-f572-42d6-85fe-97559174a969/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--df0fad2b-e59d-5816-8997-dd7e2b1a00d2",
      "created": "2026-07-24T13:01:24.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-24T13:01:24.000Z",
      "name": "123-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '123-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/a4913c12-f71a-4534-b9c7-741421b31858/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--10399bd7-72f9-575b-9530-d6bc775ad622",
      "created": "2026-07-24T13:01:38.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-24T13:01:38.000Z",
      "name": "instagramloginpage111.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramloginpage111.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/e45d0422-f9a5-4781-96a8-18af1563ae60/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ae7334e4-6bec-5db1-82ab-43f7c866ef3c",
      "created": "2026-07-24T13:01:40.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-24T13:01:40.000Z",
      "name": "facebook-do.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-do.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/270da7cd-f622-4e0b-9a08-58351640bcc4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--db1589fc-9c03-59d9-8b1c-8392821c0052",
      "created": "2026-07-24T13:01:43.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-24T13:01:43.000Z",
      "name": "login-page-instagram.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'login-page-instagram.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/c49093d0-2045-4741-a948-711c40a5cdd7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9b1facb8-b6bf-56ab-8f51-2aefcb96cd30",
      "created": "2026-07-25T01:02:05.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-25T01:02:05.000Z",
      "name": "facebook-hack-accounts.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-hack-accounts.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/f89073c6-2491-42a9-b9d7-da14865a61ab/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--baea8658-bd78-5803-9d50-1fdd4c4396ed",
      "created": "2026-07-25T01:02:13.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-25T01:02:13.000Z",
      "name": "facebook-verification-system5.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-verification-system5.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/5633b0ab-4b97-46de-8357-a8d92e21d1b8/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--225cd160-b52e-530a-9b5b-3b429fdea90b",
      "created": "2026-07-25T01:02:16.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-25T01:02:16.000Z",
      "name": "facebooklogin99999.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin99999.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/790c921e-d7cb-4634-aebc-d32c5f2befce/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--734b4cac-6e64-5136-b3b5-0b172107ebd4",
      "created": "2026-07-25T01:02:25.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-25T01:02:25.000Z",
      "name": "facebook-mark.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-mark.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/bbd003f4-9659-4c3c-9e3a-3fec438f331e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e2773b66-954f-5a5d-8b2e-17cf1be815d0",
      "created": "2026-07-25T01:02:36.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-25T01:02:36.000Z",
      "name": "facebook-247-support.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 44/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-247-support.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 44,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3aeedbee-358e-4620-a8cf-3bb682363f4c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7ecdda70-49da-528e-a942-a4103c632f6f",
      "created": "2026-07-25T01:03:29.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-25T01:03:29.000Z",
      "name": "facebook-trk.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-trk.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/afb4462e-8dbe-470d-9500-84f056e7573f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b7854958-9787-5a7b-900b-4cd64ae7dc75",
      "created": "2026-07-25T01:04:05.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-25T01:04:05.000Z",
      "name": "facebookloginss.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginss.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3af8f0b7-efd4-4770-b3ed-6ec8499159d9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e0d4de3e-c908-5cbd-8210-d2ab95363ea5",
      "created": "2026-07-25T01:04:19.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-25T01:04:19.000Z",
      "name": "facebook-di.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-di.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/b41a25e6-96bd-4667-9b8d-179b7483889c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a0a43656-7f11-55bf-8128-a4e6a8b92422",
      "created": "2026-07-25T01:05:48.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-25T01:05:48.000Z",
      "name": "facebookloginguidance.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginguidance.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/86296e06-df28-4a67-83cd-1975258f5cb2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0914c6c5-27b4-5526-98b2-4a0bce451d9d",
      "created": "2026-07-25T13:01:37.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-25T13:01:37.000Z",
      "name": "facebooklogin01.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin01.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/6859fc30-2d6e-4fb2-979c-e179e0ff418a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--402f4405-37ea-590f-a739-96958d58c230",
      "created": "2026-07-25T13:01:40.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-25T13:01:40.000Z",
      "name": "instagramlogin99.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramlogin99.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/f5b9d7e1-45da-45ac-9cb5-1e111b259370/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--95a58394-4bf0-5332-8386-d7fc9fdd4854",
      "created": "2026-07-25T13:01:42.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-25T13:01:42.000Z",
      "name": "facebook-login-be.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-login-be.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/2b61a5dd-394d-4015-b008-92b47a1d55a9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2d1bbda-7754-581c-a366-8d2452b8a373",
      "created": "2026-07-25T13:01:46.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-25T13:01:46.000Z",
      "name": "facebook-benjamin.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-benjamin.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/9f10fe8a-c098-44bd-89ad-396a26cead96/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--794198ae-184b-5e42-9fe2-ed0cb060d7c0",
      "created": "2026-07-25T13:01:49.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-25T13:01:49.000Z",
      "name": "facebookloginapp.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginapp.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/81427d41-7a30-48e3-9ba5-7570c6882273/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--72275b62-2c4b-58b9-9baf-f940c49faa3d",
      "created": "2026-07-25T13:01:52.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-25T13:01:52.000Z",
      "name": "instagramlogin24.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramlogin24.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/1323e5ee-020a-49ba-84bd-5adbb0185079/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e1c686c1-bc41-517b-9eb5-a381107d5183",
      "created": "2026-07-25T13:01:55.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-25T13:01:55.000Z",
      "name": "facebooksecure.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooksecure.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/6d4931be-51a8-4339-856d-2100cdebb27c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76289843-fec9-5abe-a1d5-759976dce540",
      "created": "2026-07-25T13:01:56.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-25T13:01:56.000Z",
      "name": "facebookverifyyouraccount.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookverifyyouraccount.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/834d1298-453d-4e02-a7a1-f8b93705e5e5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c940df39-730e-5e2a-a9c5-b40a7cb49271",
      "created": "2026-07-25T13:01:58.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-25T13:01:58.000Z",
      "name": "instagramlogin77.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramlogin77.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/e81d4311-0ce9-4855-8b65-e2eb630b60af/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5000706-4aeb-51ea-acad-aeb8ca24a768",
      "created": "2026-07-25T13:02:02.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-25T13:02:02.000Z",
      "name": "instagramlogin124.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramlogin124.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/ed52cac4-4db8-4455-b3d2-ed25f261a853/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--675f6bff-2a4d-5ae0-a58f-54606ba46822",
      "created": "2026-07-25T13:02:09.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-25T13:02:09.000Z",
      "name": "facebook-community.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-community.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c4691c76-4192-4c5a-8906-6ac42fc8b0e6/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc160ec3-c114-5869-8aa0-fc6753d5a9af",
      "created": "2026-07-25T13:02:12.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-25T13:02:12.000Z",
      "name": "facebooke-login.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooke-login.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/08068293-0500-46b8-9331-6e24be342cbf/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32bb359d-88f9-53fd-a099-9dc8022105b2",
      "created": "2026-07-26T01:03:21.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-26T01:03:21.000Z",
      "name": "facebook-pi.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-pi.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/2fb86d0c-4bee-4989-88ef-6d1fe66d92d1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6a6e554d-28e1-56b7-93b1-36b70fad3a0e",
      "created": "2026-07-26T01:03:24.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-26T01:03:24.000Z",
      "name": "instagram-baittouts-login.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-baittouts-login.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/d3ba1276-9019-477b-a373-d5d134907842/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ca0907ee-2cc3-5eb6-bfee-ecdf500e52ef",
      "created": "2026-07-26T01:03:28.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-26T01:03:28.000Z",
      "name": "neda-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'neda-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/954f7510-6600-44e9-8e1d-7e7564eca341/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e837b735-9bda-58e0-bc95-731fa0afb7b1",
      "created": "2026-07-26T01:03:31.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-26T01:03:31.000Z",
      "name": "instagramlogin68.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramlogin68.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/ef228d45-10dd-4741-a33d-0cdd74c45545/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c9052113-4de4-5402-9309-a5ad94a272fc",
      "created": "2026-07-26T01:03:36.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-26T01:03:36.000Z",
      "name": "z-instagram.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'z-instagram.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/77f717b0-9b2a-40f7-8178-ef422c660496/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6bca90bd-4353-52e1-aab9-c6530fc284c8",
      "created": "2026-07-26T01:03:37.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-26T01:03:37.000Z",
      "name": "facebookbfacebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookbfacebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c80af9b9-3ba5-45c6-8737-d79afc86bf36/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--80408013-45ad-5a06-806f-a6aadde2689f",
      "created": "2026-07-26T01:03:46.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-26T01:03:46.000Z",
      "name": "facebookloginsignub.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginsignub.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/15497459-c0ab-4c98-851b-9d06dc01e2f0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ce20c916-43df-5201-b9db-68636dee5004",
      "created": "2026-07-26T01:03:48.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-26T01:03:48.000Z",
      "name": "facebook-login-it.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-login-it.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/176c7a1e-4e82-4ce0-ade8-991414ff634c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--12aa58a2-6487-5fa3-a638-a9fb7add67b1",
      "created": "2026-07-26T01:04:01.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-26T01:04:01.000Z",
      "name": "instagram-login.hashnode.dev",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-login.hashnode.dev']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/74bd5cbb-85a6-4396-b0ca-f8ef93d9c493/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6cf43233-3b21-5c7f-bb64-59c98d1127b7",
      "created": "2026-07-26T01:04:08.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-26T01:04:08.000Z",
      "name": "instagramfollowers146.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramfollowers146.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/5dd55974-c01b-4537-b417-07a1e7ac7f70/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f7e7bf90-941a-54a0-99ab-d69eed334fd3",
      "created": "2026-07-26T01:04:16.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-26T01:04:16.000Z",
      "name": "facebookloginnew.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginnew.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/48224f19-0ebf-44da-bcf3-918c8e88b069/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ac0deeda-e5dc-59eb-9d66-71f4d4f9305c",
      "created": "2026-07-26T13:01:22.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-26T13:01:22.000Z",
      "name": "facebookuseraccount.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookuseraccount.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/8d07e50b-66d4-4743-9a56-77d0ce58eec0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d746bd0f-6230-5a0f-bb77-eeba7e89f7fb",
      "created": "2026-07-26T13:01:26.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-26T13:01:26.000Z",
      "name": "facebook-0-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-0-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c17e85bb-f2e9-45fb-9f44-4db1f7f3aea1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b9f5101e-bca5-5c25-b3ff-b834a9ce8b3a",
      "created": "2026-07-26T13:01:36.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-26T13:01:36.000Z",
      "name": "facebook-source.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-source.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/9704af42-f5d5-4ce7-a866-ea95cd70cc6e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--17872549-9cc7-5b95-9194-62d3cce10b9c",
      "created": "2026-07-27T00:04:05.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-27T00:04:05.000Z",
      "name": "mi-santander.com",
      "description": "Suspicious phishing domain impersonating Banco Santander, detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mi-santander.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/santander/60341f53-919a-40d3-bd09-2a6e393cbf1c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "santander"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4c3c89eb-1074-5d0b-a73d-606877446aba",
      "created": "2026-07-27T00:04:09.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-27T00:04:09.000Z",
      "name": "steamcommunity.ing",
      "description": "Suspicious phishing domain impersonating Steam, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'steamcommunity.ing']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/steam/313f67ab-4a8f-45bb-9541-895ecd934014/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "steam"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fad3e773-ca9b-564d-ab9c-d1e884f4b5e2",
      "created": "2026-07-27T00:04:16.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-27T00:04:16.000Z",
      "name": "santanderbank.shop",
      "description": "Suspicious phishing domain impersonating Banco Santander, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'santanderbank.shop']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/santander/a41863d8-6c4a-4f9b-8a94-bad456ce923d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "santander"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--31ec3430-51bf-5dc5-be3a-2b74abe49fe5",
      "created": "2026-07-27T01:01:23.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-27T01:01:23.000Z",
      "name": "instagramfollowers7894.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramfollowers7894.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/79a0819e-9425-411f-8c04-d076a48ae2f0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1e720f4f-332c-5c49-afb1-6bf7d14cdd83",
      "created": "2026-07-27T01:01:49.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-27T01:01:49.000Z",
      "name": "facebook-services-login.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-services-login.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/70138f6a-ba13-46da-b7d1-e6d134c60524/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--acaa7d49-45ef-5273-aaa3-d832de3abc87",
      "created": "2026-07-27T01:01:54.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-27T01:01:54.000Z",
      "name": "instagramlikescheap.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramlikescheap.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/5acafb8a-41c8-4d33-85b6-adb84cc56595/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3112503c-0f19-5561-a2d3-fa3678a58043",
      "created": "2026-07-27T01:01:56.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-27T01:01:56.000Z",
      "name": "instagram-verifications.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-verifications.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/334763eb-cbab-4a4e-b88f-9882e77b3b29/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e91840b1-c365-59c8-a0b7-3ed9c3e64cfb",
      "created": "2026-07-27T01:01:58.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-27T01:01:58.000Z",
      "name": "facebooklogincc.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogincc.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/b19c7c76-9286-4574-945d-b592e1f986a9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--42585b56-f9fb-5314-97ca-64f3232f930d",
      "created": "2026-07-27T05:04:31.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-27T05:04:31.000Z",
      "name": "invreceiptslinkedin.com",
      "description": "Suspicious phishing domain impersonating LinkedIn, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'invreceiptslinkedin.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/linkedin/3608123f-e170-4687-83cd-7e6dfde6099c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "linkedin"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0ff13522-7092-5551-aa6c-568dd6dc3cca",
      "created": "2026-07-27T05:04:48.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-27T05:04:48.000Z",
      "name": "receipts-andy-linkedin.com",
      "description": "Suspicious phishing domain impersonating LinkedIn, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'receipts-andy-linkedin.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/linkedin/68a187e0-d129-424a-8353-b9cadb7547a9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "linkedin"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f1f94d73-4822-52d9-890a-40907b5d3c87",
      "created": "2026-07-27T05:04:59.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-27T05:04:59.000Z",
      "name": "receiptslinkedin.com",
      "description": "Suspicious phishing domain impersonating LinkedIn, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'receiptslinkedin.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/linkedin/975bd679-992b-4f7e-a6c8-22c617c83296/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "linkedin"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5e699768-5dd2-5479-b924-e9912b2b8cd9",
      "created": "2026-07-27T05:05:05.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-27T05:05:05.000Z",
      "name": "facebookshops.best",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookshops.best']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/86d42b79-c24a-441d-b210-2b501a36423f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f5d3b07b-4864-5685-bfc8-86e8d65d1bff",
      "created": "2026-07-27T13:02:24.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-27T13:02:24.000Z",
      "name": "zeta-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'zeta-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3563406b-dbe8-4051-bdd4-b78e8bf95f50/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d3953e0-4f84-5326-ad4d-a70de681b6f5",
      "created": "2026-07-27T13:02:27.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-27T13:02:27.000Z",
      "name": "instagram-open.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-open.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/f6b975d4-5ea6-4117-b7c2-f578f4722bed/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6c5da20d-e800-5340-bafb-c18fd820e10c",
      "created": "2026-07-27T13:02:30.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-27T13:02:30.000Z",
      "name": "facebook-ana.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-ana.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/058fc690-89cc-45b1-90e3-28100c74610a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9f5e55db-5f83-5080-826b-2c1a9fcbcac9",
      "created": "2026-07-27T13:02:39.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-27T13:02:39.000Z",
      "name": "amazon-ae-relay.apps.prov.cx",
      "description": "Suspicious phishing domain impersonating Amazon, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'amazon-ae-relay.apps.prov.cx']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/amazon/52a2d664-efef-4b6c-af31-5001088d0ded/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "amazon"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f42cae60-da8a-5914-bcf2-f689d755f1d9",
      "created": "2026-07-27T13:02:44.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-27T13:02:44.000Z",
      "name": "instagramlogin-k.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramlogin-k.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/bca8a741-9f1a-46b0-b984-038b7e3bfaf1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--602f9ee8-2678-55af-8602-3f3a47172050",
      "created": "2026-07-27T13:02:51.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-27T13:02:51.000Z",
      "name": "instagram-users.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-users.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/eb88cc4f-407d-4a33-860f-076a8de7744f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d9f01c4b-a899-5fc8-88b9-c30b13e08983",
      "created": "2026-07-27T16:03:29.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-27T16:03:29.000Z",
      "name": "helpsecurity-microsoft.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'helpsecurity-microsoft.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/301d9f55-4ccb-496b-9e58-f7b6b134a669/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b321641c-79cd-5b44-ba11-8774d5a32eb2",
      "created": "2026-07-27T16:03:30.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-27T16:03:30.000Z",
      "name": "microsoft365businessbasic.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 21/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoft365businessbasic.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 21,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/c00c8349-6c13-44c8-ab8f-c74716786713/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ba82e2a0-242e-5cdd-b15a-e6cc43900626",
      "created": "2026-07-27T16:03:39.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-27T16:03:39.000Z",
      "name": "instagramaccount.info",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramaccount.info']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/66ae3b8d-c194-45b5-a371-e2ce13827a82/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--48c677fd-77ae-5917-8286-69f7c91ebf76",
      "created": "2026-07-28T00:19:03.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-28T00:19:03.000Z",
      "name": "fifa-store.shop",
      "description": "Suspicious phishing domain impersonating FIFA World Cup, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'fifa-store.shop']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/fifa/88fc08ba-c884-40a6-b5ac-b5e1ee97f166/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "fifa"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc23b757-e193-5fe8-a2ec-8e38c0af6e7c",
      "created": "2026-07-28T00:44:30.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-28T00:44:30.000Z",
      "name": "facebookcustomer-service.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookcustomer-service.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/af047a57-435b-4c2c-bc32-726566fc4188/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f96b1f60-adce-540d-b5c6-315eebd5d984",
      "created": "2026-07-28T01:02:28.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-28T01:02:28.000Z",
      "name": "facebook-notification.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-notification.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/530da9c3-56d8-42e6-9e06-eac94370780a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d346a170-e4aa-59e2-8bca-f35fa3e09e80",
      "created": "2026-07-28T01:02:37.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-28T01:02:37.000Z",
      "name": "facebook-in.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-in.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/ad8a1853-941d-4a93-bb84-1441b35327c8/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2c306eb3-4b66-5252-b644-f38b7f034a92",
      "created": "2026-07-28T01:02:39.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-28T01:02:39.000Z",
      "name": "trust-wallet.daservglobal.com",
      "description": "Suspicious phishing domain impersonating Trust Wallet, detected by phishunt.io (score 13/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'trust-wallet.daservglobal.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 13,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/trustwallet/1a853a99-08c0-4585-ab04-68c929ecc554/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "trustwallet"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--71e7d146-ef98-5a81-b918-ed604bffe502",
      "created": "2026-07-28T03:04:56.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-28T03:04:56.000Z",
      "name": "premio-instagram.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'premio-instagram.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/12a4d469-24d2-40e9-b811-441ebbbffc03/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b2c491e1-33c4-585a-bffe-c52b3bdc721c",
      "created": "2026-07-28T03:05:14.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-28T03:05:14.000Z",
      "name": "saque-instagram.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'saque-instagram.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/a3656af7-0774-493e-a776-959f78db627c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da20f073-8f0b-5be2-bba3-66bc36ccd98a",
      "created": "2026-07-28T03:05:15.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-28T03:05:15.000Z",
      "name": "noreply-icloud.app",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'noreply-icloud.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/3fd21102-4478-4caf-a6a6-d4fdedd25cad/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e239307a-ebea-5911-89e3-7cde54900f89",
      "created": "2026-07-28T05:49:24.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-28T05:49:24.000Z",
      "name": "a1-kraken.com",
      "description": "Suspicious phishing domain impersonating Kraken, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'a1-kraken.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/kraken/2239ae2f-33e8-4d74-8e38-39dbe5eae7b4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "kraken"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a0cbe85c-f3df-5187-baf6-c2fb926c2477",
      "created": "2026-07-28T13:01:29.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-28T13:01:29.000Z",
      "name": "facebooklogin21.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin21.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/9dfc64a0-1743-4127-b0c4-47d02d064858/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0945430-16d8-5206-ae21-03229a56bd47",
      "created": "2026-07-28T13:01:32.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-28T13:01:32.000Z",
      "name": "facebooklogin239.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin239.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/bccef171-ea7f-44d9-9c40-4be8ff1d0fdf/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0a37f890-cc36-58f8-b509-3d3b6990d8b4",
      "created": "2026-07-28T18:05:50.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-28T18:05:50.000Z",
      "name": "office365licensingsupport.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'office365licensingsupport.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/c69639c2-f6a3-4077-8381-01427010e537/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a46e5612-8ff1-599b-b988-20a9502049e4",
      "created": "2026-07-28T18:06:11.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-28T18:06:11.000Z",
      "name": "icloud-network.com",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 21/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'icloud-network.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 21,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/c954789c-9e62-4746-ad39-de61f285aa9a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5b6493e5-377e-5c8c-ba5a-993da405da0c",
      "created": "2026-07-28T18:06:30.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-28T18:06:30.000Z",
      "name": "assign-icloud.com",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 19/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'assign-icloud.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 19,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/30581b1a-6c8a-4908-8caa-578c225c586b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--074e2ced-3867-592d-b7ed-44dcce662bb5",
      "created": "2026-07-28T18:06:38.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-28T18:06:38.000Z",
      "name": "outlookmail.social",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 17/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'outlookmail.social']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 17,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/abcc9681-d61f-47c6-9034-20dd13655fdf/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2c561a76-4649-5ce5-bc69-788f431181a2",
      "created": "2026-07-28T18:06:57.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-28T18:06:57.000Z",
      "name": "steamcommunity.blog",
      "description": "Suspicious phishing domain impersonating Steam, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'steamcommunity.blog']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/steam/828fed5d-1fd1-4474-94f7-2c36de53a517/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "steam"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--29f0ad8a-cf99-5cd6-972e-88f5c81e4e24",
      "created": "2026-07-29T01:01:34.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-29T01:01:34.000Z",
      "name": "login-my-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'login-my-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/f587fc58-489d-4ccd-afd5-d91bb1dbd467/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--412e5d0d-9779-52a3-b244-d256e3b6d1be",
      "created": "2026-07-29T01:01:42.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-29T01:01:42.000Z",
      "name": "jj-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'jj-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/782bea7b-506d-41cb-ab96-efbfa8507676/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--684a3357-3f2d-51ac-a66e-a402b0e99706",
      "created": "2026-07-29T01:01:46.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-29T01:01:46.000Z",
      "name": "rama-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'rama-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/0adf392d-1c67-408e-9286-fb080024732f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9471e6d8-c519-5839-844d-f6fb09eb5bec",
      "created": "2026-07-29T01:02:30.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-29T01:02:30.000Z",
      "name": "facebookloginpage2025.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginpage2025.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/352af64d-5010-4db0-bd3a-e1675fdb8ab9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2348c75a-8fc8-50ab-a66a-e817b193d72f",
      "created": "2026-07-29T05:48:30.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-29T05:48:30.000Z",
      "name": "microsoft365updates.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoft365updates.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/003cde31-66bf-4247-94a9-3a6fff361e87/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b31f387b-32d9-5040-b336-4d0f2edad306",
      "created": "2026-07-29T13:01:59.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-29T13:01:59.000Z",
      "name": "instagramrecovery.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramrecovery.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/78e16f99-d44c-4366-93f9-99851ed4fb7a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4271bdce-c5c5-5d21-a373-c1ef18418d62",
      "created": "2026-07-29T13:02:05.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-29T13:02:05.000Z",
      "name": "facebook-germany.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-germany.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c3ac9ca1-2311-49eb-bbc9-2cc5f4e12850/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2902886e-7b6e-5546-93ef-ce3b99b3d462",
      "created": "2026-07-29T13:03:24.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-29T13:03:24.000Z",
      "name": "facebookuserlogin.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookuserlogin.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/f19dc248-d203-43c5-a57f-f6b2ebfb4678/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea657705-95cb-5018-b678-a73b8e877469",
      "created": "2026-07-29T20:24:34.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-29T20:24:34.000Z",
      "name": "netflixreviewflix.com",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflixreviewflix.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/8c6ef71b-2f60-4f27-ae69-6fb25a10bebc/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--412b199c-c7a2-5f4a-a781-81cd75cd4d90",
      "created": "2026-07-29T20:33:01.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-29T20:33:01.000Z",
      "name": "googleplaiby.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googleplaiby.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/a7586c12-bb04-46ff-8b30-4789b37d1f34/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6394e82e-d2d3-5dfd-89bc-372ac2a377e9",
      "created": "2026-07-30T01:01:03.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-30T01:01:03.000Z",
      "name": "paypalcorp.blogspot.com",
      "description": "Suspicious phishing domain impersonating PayPal, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'paypalcorp.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/paypal/7ff8be0a-cc0b-4431-a13d-026275bccd63/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "paypal"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e441d90f-b0d1-58d0-8a87-8314df33e6f7",
      "created": "2026-07-30T13:02:00.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-30T13:02:00.000Z",
      "name": "facebookk.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookk.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c625b3e8-a095-420d-b383-41e5e2c2996d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--af2df56a-4d2a-5388-a4e0-9b858fc98c7c",
      "created": "2026-07-30T13:02:05.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-30T13:02:05.000Z",
      "name": "facebookahla.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookahla.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/0414fecd-ccc9-4571-9327-66446d6ab1dd/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--377b7ae3-837f-57f4-bda1-aab7c6ca12f9",
      "created": "2026-07-30T13:02:08.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-30T13:02:08.000Z",
      "name": "facebook1019key.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook1019key.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/1fbf7b6d-7515-4bc3-b6fe-35b36159bff2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fc4270c0-20f9-5a95-98e9-f9b96b690921",
      "created": "2026-07-30T13:02:16.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-30T13:02:16.000Z",
      "name": "instagramsnp.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramsnp.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/a01eb744-16c9-41ed-96ef-e98208378436/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c9a7f110-4b76-5884-beac-a9551b489360",
      "created": "2026-07-30T13:23:59.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-30T13:23:59.000Z",
      "name": "google1107.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'google1107.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/b22515f2-4aa2-4063-be79-83e2fb2d44fd/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bae7c543-66e4-5c21-9c68-1c24679f5230",
      "created": "2026-07-31T01:01:11.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-31T01:01:11.000Z",
      "name": "facebooknenys.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooknenys.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/9e0857d7-8f9b-4c17-8c71-e803cf0ee159/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6af537f5-d181-5fbc-843a-dc7426c98182",
      "created": "2026-07-31T05:46:08.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-31T05:46:08.000Z",
      "name": "googleepway.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googleepway.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/aac2278b-0aa1-43d1-acdb-88c1073ea391/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--21f94b72-7fb1-58fe-9bf5-efa2d629b17e",
      "created": "2026-07-31T05:46:09.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-31T05:46:09.000Z",
      "name": "app.googleoa.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 45/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'app.googleoa.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 45,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/9e538a2b-ddf7-4f94-8324-7ae9866fbd2f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0124055a-89e6-5f6d-8150-f86b8ec7f180",
      "created": "2026-07-31T05:46:11.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-31T05:46:11.000Z",
      "name": "microsoft-sharepoint.fr",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoft-sharepoint.fr']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/3330b4e8-0014-4140-986a-5f568a20d334/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--03a75c01-be5d-56ef-9329-42b52e3d70e0",
      "created": "2026-07-31T07:09:17.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-31T07:09:17.000Z",
      "name": "googlepeey.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googlepeey.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/887b795e-4e51-4db4-9f35-ecb4673cf05a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--691ef5fc-2131-56a6-8529-33b74307656c",
      "created": "2026-07-31T13:01:47.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-31T13:01:47.000Z",
      "name": "eu-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'eu-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/fb59902c-6086-446c-9172-d7ebaabc59c9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ac1c56fb-466a-5a11-b6af-bf461badcd2f",
      "created": "2026-08-01T01:01:31.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-01T01:01:31.000Z",
      "name": "facebooklogin19.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin19.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/433c8d9b-55a7-4344-9f08-f5cac5b05c02/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--05f80b19-e901-5f03-83ec-775d1fc93465",
      "created": "2026-08-01T01:01:51.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-01T01:01:51.000Z",
      "name": "bankofamericamailcompte.blogspot.com",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bankofamericamailcompte.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/ad8b0b9d-3408-4974-853a-7e2c75993ead/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--43067483-329b-5f37-be66-63364aa3b93d",
      "created": "2026-08-01T01:01:54.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-01T01:01:54.000Z",
      "name": "instagram-register.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-register.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/ffed60d9-1ad3-4bea-9982-e7e0c6fee77d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c24754b1-3e01-52e5-a3c9-1e0f7c1baec9",
      "created": "2026-08-01T07:01:27.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-01T07:01:27.000Z",
      "name": "google1208.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'google1208.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/f7c499f2-3d40-40be-83f6-26e3617d3a86/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9120ed74-a5fc-5692-850b-42f771278535",
      "created": "2026-08-01T10:28:41.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-01T10:28:41.000Z",
      "name": "googlepllry.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googlepllry.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/c23ea5ab-ab49-4f15-84e2-194a90773bc4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ae375cad-4bb8-55a0-a382-590c5218ba91",
      "created": "2026-08-01T13:01:30.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-01T13:01:30.000Z",
      "name": "trackingnumbers.org",
      "description": "Suspicious phishing domain impersonating FedEx, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'trackingnumbers.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/fedex/88975cb3-0c45-486f-9f7d-1348b221ca53/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "fedex"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6989e665-0926-5e8b-ae3f-0d4964a14f5f",
      "created": "2026-08-01T13:02:40.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-01T13:02:40.000Z",
      "name": "z-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'z-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/9ac05aa6-b5e4-4c8d-9d1e-bb3357b271ef/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7045b70d-13e9-5e6a-ac84-41fda9b42ec1",
      "created": "2026-08-01T13:02:44.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-01T13:02:44.000Z",
      "name": "trackingnumbers.org",
      "description": "Suspicious phishing domain impersonating USPS, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'trackingnumbers.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/usps/68555614-a607-4cfa-82e8-5cd3f93d1801/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "usps"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b1ea7436-e87d-5be1-8019-3a1b967cc04c",
      "created": "2026-08-01T13:02:49.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-01T13:02:49.000Z",
      "name": "facebookwebsite9.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookwebsite9.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/4160086c-ae15-4c53-9fd5-92e9e7223087/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2024789-1740-523e-aa43-ad603390dda4",
      "created": "2026-08-02T01:02:35.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-02T01:02:35.000Z",
      "name": "facebook-rus.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-rus.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c165624f-39ce-44b5-a480-41e486e2496b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4509dfc1-801d-5624-835f-c1ef47c03b2a",
      "created": "2026-08-02T01:02:42.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-02T01:02:42.000Z",
      "name": "facebookfakepage.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookfakepage.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/ac005a29-85eb-4bd7-80d5-8a7db2b163de/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--65f3bf6f-40f1-5cc5-8658-a47f198d3073",
      "created": "2026-08-02T01:40:43.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-02T01:40:43.000Z",
      "name": "googlepepy.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googlepepy.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/4aa4bd5c-7c69-4c4f-a287-b89881b0f783/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6b728c9f-735a-5ff2-81d0-6a8db8e353c2",
      "created": "2026-08-02T04:16:59.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-02T04:16:59.000Z",
      "name": "googlepemy.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googlepemy.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/36ad3c2a-c030-4e10-88b6-4fe082768e58/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b18f2fe2-07e9-5820-9d56-ce2e0337cc96",
      "created": "2026-08-02T05:43:20.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-02T05:43:20.000Z",
      "name": "microsoftuk.co",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoftuk.co']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/3690fadf-3111-4434-b66d-d6a1c6ac27bb/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea9f700a-ab35-5cbe-9032-176e9b9e0831",
      "created": "2026-08-02T09:53:52.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-02T09:53:52.000Z",
      "name": "googleplrzy.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googleplrzy.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/f8ef7760-00de-4c4d-86d7-59c64c2eb067/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--47ec162f-003f-53d3-9328-a0e4e58bfc53",
      "created": "2026-08-02T11:43:48.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-02T11:43:48.000Z",
      "name": "fedexinterviewprep.com",
      "description": "Suspicious phishing domain impersonating FedEx, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'fedexinterviewprep.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/fedex/17671297-3f0a-43a9-8dcb-9e138804d137/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "fedex"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--89870221-d581-5bcb-95ab-c3db8bfa74ff",
      "created": "2026-08-02T13:01:44.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-02T13:01:44.000Z",
      "name": "metamaskextensionnn.gitbook.io",
      "description": "Suspicious phishing domain impersonating MetaMask, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'metamaskextensionnn.gitbook.io']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/metamask/61f6e500-4ea1-4aa5-ae84-6967f2acb023/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "metamask"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53071ed0-8984-52bc-a649-ed307726ddf8",
      "created": "2026-08-02T13:01:56.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-02T13:01:56.000Z",
      "name": "faceb0k-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'faceb0k-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/9193f058-089f-4c69-a550-cd613db05679/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0814fdf-d116-5bb6-8139-e4535a8d1c2f",
      "created": "2026-08-02T13:02:20.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-02T13:02:20.000Z",
      "name": "facebookfakelogin.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookfakelogin.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/a0657687-64f2-42b4-886a-28b154c78554/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--44ef304f-db05-52bc-b4b2-e5d223f872cc",
      "created": "2026-08-04T01:00:43.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-04T01:00:43.000Z",
      "name": "instagram-tip.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-tip.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/75d0ed8b-9254-48ca-89cd-60fe3fc09170/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d918e32-17e9-56bf-8df5-f04c1852dde1",
      "created": "2026-08-04T05:24:57.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-04T05:24:57.000Z",
      "name": "ebay-wholesale.com",
      "description": "Suspicious phishing domain impersonating eBay, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ebay-wholesale.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ebay/c55dc147-70fc-4413-a070-10ebe58c25b2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ebay"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb0155cb-8a2d-5d67-b117-65bbd4ddd9b8",
      "created": "2026-08-04T13:02:02.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-04T13:02:02.000Z",
      "name": "santander2026.dothome.co.kr",
      "description": "Suspicious phishing domain impersonating Banco Santander, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'santander2026.dothome.co.kr']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/santander/03d2d72c-3b3f-4bcd-8399-3294d49c42ff/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "santander"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4b24e4c6-66a0-5f0c-9034-52a992f0e375",
      "created": "2026-08-05T05:27:31.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-05T05:27:31.000Z",
      "name": "ewlpnkrg.login.wccheck-0209014e-ext.santander.bimp-bot.duckdns.org",
      "description": "Suspicious phishing domain impersonating Banco Santander, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ewlpnkrg.login.wccheck-0209014e-ext.santander.bimp-bot.duckdns.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/santander/d371b197-ebdd-467d-8a2b-dcac979b46c2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "santander"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ddaa6fef-7188-5b9d-bad7-3e2525ed8942",
      "created": "2026-08-05T05:27:31.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-05T05:27:31.000Z",
      "name": "ewlpnkrg.www.login.wccheck-0209014e-ext.santander.bimp-bot.duckdns.org",
      "description": "Suspicious phishing domain impersonating Banco Santander, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ewlpnkrg.www.login.wccheck-0209014e-ext.santander.bimp-bot.duckdns.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/santander/9c728943-8728-4102-a4ab-b806081e4bd4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "santander"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4e1aa287-13f8-57e2-8b92-9bbc8a9f717c",
      "created": "2026-08-05T10:34:09.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-05T10:34:09.000Z",
      "name": "netflix-games.click",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflix-games.click']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/9e9b5105-b33a-4ae4-84d8-45f76d274552/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--af524f88-f57a-5389-ada5-d9e11feb9788",
      "created": "2026-08-05T13:01:15.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-05T13:01:15.000Z",
      "name": "amazon.biowikiweb.com",
      "description": "Suspicious phishing domain impersonating Amazon, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'amazon.biowikiweb.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/amazon/be52dde9-23ca-43cc-b75b-e691fa4dd3f4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "amazon"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c25535a-bcae-54d3-825f-e55f32884ccf",
      "created": "2026-08-05T13:01:17.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-05T13:01:17.000Z",
      "name": "proteccion-outlook2026.iceiy.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'proteccion-outlook2026.iceiy.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/786d71cd-f6e5-47b2-a8b6-13f9a22983bc/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--018a55d2-7a12-55d9-b248-a5a3e2de043e",
      "created": "2026-08-05T17:26:58.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-05T17:26:58.000Z",
      "name": "paypal.com-websppsc-verification.epsilons.co",
      "description": "Suspicious phishing domain impersonating PayPal, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'paypal.com-websppsc-verification.epsilons.co']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/paypal/0c02bd9a-9cad-4ba6-98eb-241c2156a393/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "paypal"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1afe0d90-0282-5e4f-adb3-d8ff01d85836",
      "created": "2026-08-06T05:26:45.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-06T05:26:45.000Z",
      "name": "gateareis.vu",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'gateareis.vu']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//81e42650-1d0c-40f8-aaf6-ceea99c1e421/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--52e4c95f-245d-55a9-bf9e-fd397fff88d3",
      "created": "2026-08-06T05:26:45.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-06T05:26:45.000Z",
      "name": "munimventures.com",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'munimventures.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//eb274379-7b2a-49e5-9074-512ee201c371/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--64708955-6f40-5baf-a620-182aeafbe009",
      "created": "2026-08-07T01:01:18.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-07T01:01:18.000Z",
      "name": "trezor-login-us-auth-start.typedream.app",
      "description": "Suspicious phishing domain impersonating Trezor, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'trezor-login-us-auth-start.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/trezor/73ac3f6d-0b65-47ff-9eb9-12215eef4cac/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "trezor"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2135e80b-62df-5123-9a8b-8a486e8d5e18",
      "created": "2026-08-07T01:01:35.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-07T01:01:35.000Z",
      "name": "facebook-developers.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-developers.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/e9768ca8-3fc5-4c12-8c74-420c2c0e89a7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f407e93d-15fc-5017-b65a-f7986389770c",
      "created": "2026-08-07T01:01:47.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-07T01:01:47.000Z",
      "name": "facebooklogininfo.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogininfo.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/992cf1ef-6dff-453f-b9a9-ace798ae6294/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--62f78516-7b4d-5497-8d86-279bb0c1abf9",
      "created": "2026-08-07T10:29:04.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-07T10:29:04.000Z",
      "name": "netflixtoto.xyz",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflixtoto.xyz']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/51d1a433-258a-448a-a25e-2edb7e76b3fe/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2079b5b9-9b37-515a-8c85-c0448faa1731",
      "created": "2026-08-07T17:27:20.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-07T17:27:20.000Z",
      "name": "login.rmdbwskx.santander.bimp-bot.duckdns.org",
      "description": "Suspicious phishing domain impersonating Banco Santander, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'login.rmdbwskx.santander.bimp-bot.duckdns.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/santander/4466ee66-95d8-4787-aa29-9987c06d1e34/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "santander"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--374af4f9-dfaa-5591-afbf-ba9ee40961d8",
      "created": "2026-08-07T17:27:25.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-07T17:27:25.000Z",
      "name": "login.wccheck-b18ca936-a.santander.bimp-bot.duckdns.org",
      "description": "Suspicious phishing domain impersonating Banco Santander, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'login.wccheck-b18ca936-a.santander.bimp-bot.duckdns.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/santander/eae29de0-315e-41e6-9cf7-46d7dcf32858/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "santander"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5e3f74a6-c0e7-50b4-b620-b01bfa1ebce1",
      "created": "2026-08-07T17:27:29.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-07T17:27:29.000Z",
      "name": "plugins.sugar-outlook.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 16/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'plugins.sugar-outlook.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 16,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/4f73247b-82f4-487f-9dc2-ee3e7ef99b2e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e23b376a-6554-50b9-8b13-133e9445fc46",
      "created": "2026-08-07T23:13:32.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-07T23:13:32.000Z",
      "name": "googleplouy.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googleplouy.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/5f320075-1cbd-48c7-9474-9490b3c58167/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--52706451-0d55-575c-bf59-7afa15732201",
      "created": "2026-08-08T01:02:19.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-08T01:02:19.000Z",
      "name": "outlooksereguri365.hstn.me",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'outlooksereguri365.hstn.me']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/68e9f160-6b3f-4377-b074-1267b4b88d10/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--395c7767-c1bc-5b85-b470-9dd748f6be58",
      "created": "2026-08-08T01:02:24.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-08T01:02:24.000Z",
      "name": "docs-google.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 14/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'docs-google.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 14,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/c66902dc-fa0a-4dd1-b87d-11a9e847bbeb/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e5228dd-b22b-59a0-8da7-bcb8dddd9b2d",
      "created": "2026-08-08T01:02:28.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-08T01:02:28.000Z",
      "name": "login-east3.cashappps.com",
      "description": "Suspicious phishing domain impersonating Cash App, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'login-east3.cashappps.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/cashapp/8e74bf82-2f08-4eb4-b614-a09631847cb3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "cashapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53ed3931-e534-5845-a2b4-f7c97a14ba9f",
      "created": "2026-08-08T05:27:31.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-08T05:27:31.000Z",
      "name": "erutjhpk.login.dwmnhsqa.wccheck-6b3c4826-a.santandertelephony-yfcowbeta.bimp-bot.duckdns.org",
      "description": "Suspicious phishing domain impersonating Banco Santander, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'erutjhpk.login.dwmnhsqa.wccheck-6b3c4826-a.santandertelephony-yfcowbeta.bimp-bot.duckdns.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/santander/c0e09d5a-8c3d-45bd-985c-dd44008ad503/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "santander"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0da17f3e-48d5-51a1-884e-ded0c7349d89",
      "created": "2026-08-08T05:27:36.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-08T05:27:36.000Z",
      "name": "lkgrazsl.login.5b55bakaizeipheexooz.bckwsbem.santander.bimp-bot.duckdns.org",
      "description": "Suspicious phishing domain impersonating Banco Santander, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'lkgrazsl.login.5b55bakaizeipheexooz.bckwsbem.santander.bimp-bot.duckdns.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/santander/9a303b31-c9bf-4144-bfa6-05113726db44/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "santander"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--881a4b3f-81e6-536f-99a1-3ea117f41041",
      "created": "2026-08-08T05:27:54.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-08T05:27:54.000Z",
      "name": "deluxxe.com.br",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'deluxxe.com.br']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//7d611647-69a0-40c9-8244-63777bc41cf9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b256ebb-47ea-5e03-8d8e-af5b5f1348a1",
      "created": "2026-08-08T13:01:39.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-08T13:01:39.000Z",
      "name": "instagram-demo.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-demo.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/8162cf24-aa2c-4060-b3b3-58f2d370b5a5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--62cf7a84-7ecd-5254-9be1-7f1b8998c304",
      "created": "2026-08-08T13:01:41.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-08T13:01:41.000Z",
      "name": "facebook-verification-system4.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-verification-system4.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/24730bfa-9f5c-4e65-9834-f06e49aa9cc3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe2400b1-f070-511a-94fe-c6a61cb4a757",
      "created": "2026-08-08T13:01:59.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-08T13:01:59.000Z",
      "name": "facebookbigeronline.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookbigeronline.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/fba6a261-1c2d-4acd-b0db-0bc6a648443f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--25cc414b-502a-5eae-ad29-8be211396451",
      "created": "2026-08-08T13:03:00.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-08T13:03:00.000Z",
      "name": "instagram-instagram.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-instagram.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/7d2801f2-90d7-45f6-be1a-f52beb7780dc/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3f81be2d-56af-5906-bd77-f11ef12851d5",
      "created": "2026-08-08T13:03:03.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-08T13:03:03.000Z",
      "name": "binance-register.blogspot.com",
      "description": "Suspicious phishing domain impersonating Binance, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'binance-register.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/binance/10383449-d039-4cbf-b53e-4864fdf6049d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "binance"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d43c4dd3-b596-5bdb-a433-38651cb2b82b",
      "created": "2026-08-08T17:29:35.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-08T17:29:35.000Z",
      "name": "rec-netflix.com",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 17/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'rec-netflix.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 17,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/8d6927f7-5399-4656-bb51-a2c6a1d68c8a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f2b5892b-0144-554d-a500-dc2417a0232d",
      "created": "2026-08-09T01:02:25.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-09T01:02:25.000Z",
      "name": "facebookloginreview.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginreview.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/873ee835-e761-4a8e-a218-244cac34d3b0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5cb92bd9-b3bb-5e0a-bc65-cc148207d272",
      "created": "2026-08-09T05:25:57.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-09T05:25:57.000Z",
      "name": "microsoft.vpn-update.org",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 21/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoft.vpn-update.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 21,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/b502902a-e5e4-4cbf-b958-ca816cb59d87/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc8858ea-7153-5982-aa2e-8b4a1e290a3f",
      "created": "2026-08-09T07:58:03.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-09T07:58:03.000Z",
      "name": "hotmail143.net",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'hotmail143.net']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/4df56670-68d7-4de7-a5ca-8a0e6e49ce90/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--449483fa-865f-5321-bd37-9fa72f80f05e",
      "created": "2026-08-09T13:01:39.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-09T13:01:39.000Z",
      "name": "facebook-linkedin.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-linkedin.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/098798a2-b137-4ced-9464-782f965d50f9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--33711ef9-e11a-5cd6-8f35-42d1c5a706ca",
      "created": "2026-08-09T13:01:44.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-09T13:01:44.000Z",
      "name": "instagramloginpassword.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramloginpassword.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/ec274c28-c16d-4cbc-8459-c21bef552293/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ac7d6b01-4fb4-5fc1-98b3-18ba9336fe14",
      "created": "2026-08-09T13:01:46.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-09T13:01:46.000Z",
      "name": "facebook-login-redirect.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-login-redirect.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/1a5e591a-b95f-4e9c-9baa-2a761f179322/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a3f4e70c-9310-5b52-bb4c-374ded47b9e3",
      "created": "2026-08-09T14:10:18.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-09T14:10:18.000Z",
      "name": "site.outlookindia.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'site.outlookindia.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/8e1b3f68-ea34-4784-84ec-7e453d0c1806/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--38c354ac-e38b-568f-b1c5-83c6e0b5655a",
      "created": "2026-08-10T01:01:21.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-10T01:01:21.000Z",
      "name": "facebook-fansdanssapage.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-fansdanssapage.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/ab7ead5f-ce4c-47f2-a947-c8c570058620/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--defe0138-8c6d-5a6f-9e48-0f53ae136ec9",
      "created": "2026-08-10T01:01:27.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-10T01:01:27.000Z",
      "name": "facebooksuporteolaine.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooksuporteolaine.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/2919cd6a-3ace-459e-90ca-9a6126d1ac82/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b943e52-8b62-52ab-b053-6e7cee103836",
      "created": "2026-08-10T01:01:33.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-10T01:01:33.000Z",
      "name": "instagramfollowersfake.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 44/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramfollowersfake.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 44,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/d3a8db48-4003-4946-85c7-b96df63f2482/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1494adcf-597d-5e25-8413-f6398037d3a5",
      "created": "2026-08-10T01:01:36.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-10T01:01:36.000Z",
      "name": "instagramsupportverify.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramsupportverify.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/78d25570-614a-4457-97f6-92b30f68bea5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--397cc13c-674f-5d3a-b2fe-adb77e7bcabf",
      "created": "2026-08-10T05:28:05.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-10T05:28:05.000Z",
      "name": "short.googleadsense.com.tr",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'short.googleadsense.com.tr']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/4c99201c-2ad9-4157-a7df-65893fa82ab3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6bb1e0f7-2f8e-5ab0-b048-6c94d4f3905a",
      "created": "2026-08-10T13:01:02.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-10T13:01:02.000Z",
      "name": "facebooklivepage.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklivepage.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/0de5a27f-d424-4978-ab6c-5744639ed122/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--55cef9e2-0309-500d-bf08-b17435a1eb91",
      "created": "2026-08-10T15:03:12.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-10T15:03:12.000Z",
      "name": "www-microsoft.com.cn",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'www-microsoft.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/24638ba6-d041-4826-963d-91ddb02fa6c9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c4307dc0-af9b-50be-8672-b2981af540ee",
      "created": "2026-08-11T01:01:30.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-11T01:01:30.000Z",
      "name": "facebook-2022.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-2022.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c8bad0a3-916c-4541-b110-3db533b24ee4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9e5ce915-1862-528c-97cd-90655308c268",
      "created": "2026-08-11T09:27:47.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-11T09:27:47.000Z",
      "name": "secure-dropbox.ist",
      "description": "Suspicious phishing domain impersonating Dropbox, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'secure-dropbox.ist']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dropbox/14e1304d-f0c9-4171-9426-3a5dd7859400/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dropbox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--27122d68-0cd2-5f16-a52e-f81d7f02648b",
      "created": "2026-08-11T10:22:58.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-11T10:22:58.000Z",
      "name": "googlepelay.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googlepelay.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/5073adfc-7955-4090-adbb-418c41b28c73/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--81636038-81d0-591c-bc42-dcf41e871c7e",
      "created": "2026-08-11T13:01:29.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-11T13:01:29.000Z",
      "name": "facebookloginid.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginid.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3db4e53a-628b-48d1-b789-3a2a1b4494f9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--114f905b-8fa5-5d47-8d46-9fa54038ebfe",
      "created": "2026-08-12T00:09:04.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-12T00:09:04.000Z",
      "name": "google1308.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'google1308.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/bfcd443d-0ad1-42ff-8062-d1e57c8a1fe6/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8b11bc22-06ea-5ae7-ac53-4e2e4b1035e7",
      "created": "2026-08-12T00:14:38.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-12T00:14:38.000Z",
      "name": "google1302.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'google1302.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/0b2f2c33-e609-45c3-b56a-deca25d016e7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ecd72d18-1dbb-5091-982a-3508d372741d",
      "created": "2026-08-12T01:01:43.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-12T01:01:43.000Z",
      "name": "facebook-auto-liker.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-auto-liker.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/5b70c512-af2e-4e61-9131-0dba6e66187b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e81edb7e-5d0b-563f-af27-e74dcf312e12",
      "created": "2026-08-12T05:24:41.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-12T05:24:41.000Z",
      "name": "googleww.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googleww.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/5daf0342-1061-447d-966b-edf3459588ad/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c5b5efb8-6a6b-5023-ab14-85e22561f810",
      "created": "2026-08-12T05:25:55.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-12T05:25:55.000Z",
      "name": "gpcconcrete.co.nz",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'gpcconcrete.co.nz']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//3e8fcb48-0af8-4b7b-ba88-e0cb70f2a48b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b4998db8-1936-5d53-91bb-d893949e97ef",
      "created": "2026-08-12T17:26:22.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-12T17:26:22.000Z",
      "name": "confirm-your-account-informations-paypal.com.ifotografix.co.uk",
      "description": "Suspicious phishing domain impersonating PayPal, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'confirm-your-account-informations-paypal.com.ifotografix.co.uk']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/paypal/fb18b8f7-70b2-4819-b376-6d4e4a115210/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "paypal"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67616d5b-9af1-5a7f-8535-68f4f69b305a",
      "created": "2026-08-12T17:28:12.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-12T17:28:12.000Z",
      "name": "api-41829387-44817741.google-cloud.services",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 16/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'api-41829387-44817741.google-cloud.services']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 16,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/7d1c6e5a-3b02-46de-a168-ce42efa1f0fd/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--50cbcdff-80af-550f-ae49-b051b324996b",
      "created": "2026-08-13T01:02:18.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-13T01:02:18.000Z",
      "name": "pay.paykmc.com",
      "description": "Suspicious phishing domain impersonating PayPal, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'pay.paykmc.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/paypal/2e28b2a2-1e5e-4417-b5a7-eafc9310a3bb/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "paypal"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d4b926e9-ef2b-54e3-8e90-021a669bddaa",
      "created": "2026-08-13T01:02:29.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-13T01:02:29.000Z",
      "name": "2017-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '2017-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/90b06bb9-b94f-4f09-bed1-2b4c362054de/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6a025135-d1bf-5cf2-ad01-6c8c1de2f7c7",
      "created": "2026-08-13T05:26:00.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-13T05:26:00.000Z",
      "name": "rcb.cuj.temporary.site",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'rcb.cuj.temporary.site']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//2a1ab1d2-aef2-424a-8901-979e369d31e3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8790d1d8-a0cd-538d-ac9a-f7c3e7e07b9c",
      "created": "2026-08-13T13:02:39.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-13T13:02:39.000Z",
      "name": "ledgrelivapp--crome.typedream.app",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ledgrelivapp--crome.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/28b026ed-8f92-4ead-878f-fcf5c6b67db7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--31745858-4c78-5275-a2b1-848a58da8db4",
      "created": "2026-08-13T13:02:43.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-13T13:02:43.000Z",
      "name": "ledger-live-download-sso-conect.typedream.app",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ledger-live-download-sso-conect.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/2b2bcc96-b2d2-499a-8f24-08ff22af2a4e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0581e5d-e566-5a95-98a1-bf3113efb6fd",
      "created": "2026-08-13T13:02:49.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-13T13:02:49.000Z",
      "name": "ledger-live-wallet-start-conect-us-en.typedream.app",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ledger-live-wallet-start-conect-us-en.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/2e7035af-c99a-4654-a399-fdc3ac2d1478/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5cf14737-616f-5463-bb1c-2b35f70b6842",
      "created": "2026-08-13T13:03:27.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-13T13:03:27.000Z",
      "name": "binancewallett.blogspot.com",
      "description": "Suspicious phishing domain impersonating Binance, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'binancewallett.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/binance/3ad31d68-66dc-4066-9ad0-48968422d61f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "binance"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff916300-2cca-55e7-beb5-bc60731a0b8e",
      "created": "2026-08-13T17:52:34.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-13T17:52:34.000Z",
      "name": "xfinitywindowfilms.com",
      "description": "Suspicious phishing domain impersonating Xfinity (Comcast), detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'xfinitywindowfilms.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/xfinity/4846d944-1b67-48ef-bc77-021d08ff8627/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "xfinity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--92bb6ab5-c218-5932-9042-3a01daba6652",
      "created": "2026-08-14T13:01:35.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-14T13:01:35.000Z",
      "name": "uspsglobal.delivery",
      "description": "Suspicious phishing domain impersonating USPS, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'uspsglobal.delivery']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/usps/46496331-3805-4e0a-a7ff-3d420999cbf0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "usps"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e11e5fa-5330-5770-ac05-d3471b70fa0e",
      "created": "2026-08-14T14:00:49.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-14T14:00:49.000Z",
      "name": "facebookteamhelp.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookteamhelp.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c1a2327b-b0c9-4ecf-aab5-41776a8e5669/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a7d72dcc-924d-5cfb-a197-273853867bc1",
      "created": "2026-07-07T01:45:37.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-07T01:45:37.000Z",
      "name": "securedsupport-coinbase.com",
      "description": "Suspicious phishing domain impersonating Coinbase, detected by phishunt.io (score 19/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'securedsupport-coinbase.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 19,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/coinbase/5ab1b47f-1ff3-4b2f-baba-1b0059fca080/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "coinbase"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f2ea96b4-43dc-5865-9416-88f5a7b8f895",
      "created": "2026-07-28T18:07:05.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-07-28T18:07:05.000Z",
      "name": "coinbasebackoffice.exchange",
      "description": "Suspicious phishing domain impersonating Coinbase, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'coinbasebackoffice.exchange']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/coinbase/75df3c6a-708c-4aff-a85d-f43d3c30a7b2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "coinbase"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3e331a14-f1bb-55c2-8e4d-83321bc95c11",
      "created": "2026-08-13T05:25:51.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-13T05:25:51.000Z",
      "name": "164196-coinbase.com",
      "description": "Suspicious phishing domain impersonating Coinbase, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '164196-coinbase.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/coinbase/cfb42cf8-cbf5-4e85-a0fc-021728463ca1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "coinbase"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--93bd685a-0e32-5b0a-8916-e13cf131b230",
      "created": "2026-08-17T01:03:19.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-17T01:03:19.000Z",
      "name": "coinbaseinvestors.ai",
      "description": "Suspicious phishing domain impersonating Coinbase, detected by phishunt.io (score 51/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'coinbaseinvestors.ai']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 51,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/coinbase/988a2c90-1247-44e0-a5cf-7941984c8d0c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "coinbase"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b615d135-90ab-52fd-8ff5-17aa6d978c57",
      "created": "2026-08-22T01:07:05.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-22T01:07:05.000Z",
      "name": "center.metacreatormonetizationsupportsystem.click",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'center.metacreatormonetizationsupportsystem.click']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/b1265f48-0df4-4d32-ac1d-f1b0b5e916c5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--16b28b35-d567-5be3-ab82-a94376185cbf",
      "created": "2026-08-22T13:02:00.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-22T13:02:00.000Z",
      "name": "paypal-password.blogspot.com",
      "description": "Suspicious phishing domain impersonating PayPal, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'paypal-password.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/paypal/9f8f855d-d4a4-4566-b96e-6b0f083a7034/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "paypal"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--386180eb-1fc8-5cf2-878b-bc20dffa8cdb",
      "created": "2026-08-22T13:02:07.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-22T13:02:07.000Z",
      "name": "facebook-visitantes.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-visitantes.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/0864bbae-1670-4e17-bd74-e74896527d3e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--90daf712-c0f6-558f-a878-ddce61236da0",
      "created": "2026-08-22T17:37:57.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-22T17:37:57.000Z",
      "name": "alibaba66malaysia.app",
      "description": "Suspicious phishing domain impersonating Alibaba, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'alibaba66malaysia.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/alibaba/c6a94f9a-411b-4d75-b38e-ab0e995c7d2f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "alibaba"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cbf76f98-30d8-504d-aa71-ad0232cf778f",
      "created": "2026-08-22T17:38:10.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-22T17:38:10.000Z",
      "name": "alibaba33.pro",
      "description": "Suspicious phishing domain impersonating Alibaba, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'alibaba33.pro']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/alibaba/3abe296b-bfc4-434a-8c05-7dd67088ff6e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "alibaba"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1f612054-9a6d-5665-b67e-08beaef1ef41",
      "created": "2026-08-22T17:41:20.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-22T17:41:20.000Z",
      "name": "alibaba666.bet",
      "description": "Suspicious phishing domain impersonating Alibaba, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'alibaba666.bet']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/alibaba/fb624f42-0def-4e1e-8a12-ce3756dce3d8/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "alibaba"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c4f5f68-1cb5-5122-9954-24018c47c31c",
      "created": "2026-08-23T01:03:17.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-23T01:03:17.000Z",
      "name": "me.h5-whatsapp-zn.hl.cn",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'me.h5-whatsapp-zn.hl.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/c961c2e0-75d5-4458-9b43-cebfe349ce0c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--019b6e70-524d-5920-bacd-fe74f820c3c6",
      "created": "2026-08-23T01:03:56.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-23T01:03:56.000Z",
      "name": "xfinity101.duckdns.org",
      "description": "Suspicious phishing domain impersonating Xfinity (Comcast), detected by phishunt.io (score 45/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'xfinity101.duckdns.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 45,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/xfinity/4af36e08-3106-4535-a6b3-ffb3fc9aa52e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "xfinity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--347d7726-f2f3-5cdc-8fe9-e6157dfd951b",
      "created": "2026-08-23T13:03:37.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-23T13:03:37.000Z",
      "name": "whatsapp-tools.lateinos.com.br",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'whatsapp-tools.lateinos.com.br']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/a3e43a05-7829-4c29-8afe-93a5bcda4a7e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--725b6a12-751e-5fe2-8f8e-17123040e573",
      "created": "2026-08-23T17:24:00.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-23T17:24:00.000Z",
      "name": "authentication.citrix-sharing.com",
      "description": "Suspicious phishing domain impersonating Citrix, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'authentication.citrix-sharing.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/citrix/03db0f18-004b-481c-bd30-496fe517a54d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "citrix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c02a622a-f2a2-584b-aa3b-db563271bf14",
      "created": "2026-08-23T20:40:24.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-23T20:40:24.000Z",
      "name": "alibaba666.pro",
      "description": "Suspicious phishing domain impersonating Alibaba, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'alibaba666.pro']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/alibaba/52034821-31e7-4400-8117-b71586cfd4e1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "alibaba"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b684126-ea33-5125-a045-054310d175f7",
      "created": "2026-08-24T01:02:21.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-24T01:02:21.000Z",
      "name": "instagram.rents.ac",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram.rents.ac']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/6b9365f2-9012-4692-a96d-1536f08ee6e8/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a5931653-6a22-5b06-8df8-1a81d42f346b",
      "created": "2026-08-24T05:25:28.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-24T05:25:28.000Z",
      "name": "spotify-plus.com",
      "description": "Suspicious phishing domain impersonating Spotify, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'spotify-plus.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/spotify/4826a1db-d82d-4e58-b6ac-f7b5f1dc7d8f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "spotify"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--16e1afac-a198-52d7-a6d9-e24462531eb0",
      "created": "2026-08-24T13:01:53.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-24T13:01:53.000Z",
      "name": "lnk.ink",
      "description": "Suspicious phishing domain impersonating SEUR, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'lnk.ink']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/seur/91b6f4f6-d503-4d38-8274-6096d7ddcd66/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "seur"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b8e62251-c4b8-57f8-8026-8e06e0bd13c4",
      "created": "2026-08-24T13:01:57.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-24T13:01:57.000Z",
      "name": "livepc.h5-whatsapp-zn.hl.cn",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'livepc.h5-whatsapp-zn.hl.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/17c59491-da3c-405e-a74e-22ac945f0a11/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--28a32671-a9f5-581a-ab48-4ad841794daa",
      "created": "2026-08-24T22:02:35.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-24T22:02:35.000Z",
      "name": "roblox.com.gr",
      "description": "Suspicious phishing domain impersonating Roblox, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'roblox.com.gr']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/roblox/4def2b22-8304-4fcf-b815-eba710971e95/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "roblox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--65b2f90a-636f-561b-aa2e-c132ed8b746c",
      "created": "2026-08-24T22:03:08.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-24T22:03:08.000Z",
      "name": "roblox.com.bi",
      "description": "Suspicious phishing domain impersonating Roblox, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'roblox.com.bi']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/roblox/f9dd4b1f-e06b-4f38-b794-ab6c5fead730/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "roblox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--36453e59-ef4e-5c91-b363-d8de60339142",
      "created": "2026-08-24T22:03:41.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-24T22:03:41.000Z",
      "name": "roblox.com.bn",
      "description": "Suspicious phishing domain impersonating Roblox, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'roblox.com.bn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/roblox/f927080c-8f92-4892-814b-473d2d069ce3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "roblox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cdf825e8-6fd4-5141-bf7d-1af242bbd98f",
      "created": "2026-08-24T22:03:57.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-24T22:03:57.000Z",
      "name": "roblox.com.pt",
      "description": "Suspicious phishing domain impersonating Roblox, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'roblox.com.pt']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/roblox/ed9aa1fd-c50a-4958-9f4b-5601d237cb16/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "roblox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d8f7346e-11ce-509f-bb9e-11b3c124211c",
      "created": "2026-08-25T01:02:18.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-25T01:02:18.000Z",
      "name": "facebook-ba.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-ba.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/d4129abc-fe27-458c-b8bc-fa8aaab592b4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--699b0808-a691-5d21-b002-599c585aefe4",
      "created": "2026-08-25T01:02:29.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-25T01:02:29.000Z",
      "name": "facebook-hr.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-hr.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3a6a5d74-0def-4f6f-a281-29c91157f4ba/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e28ce511-6859-53f2-a512-3ddc79cbe65a",
      "created": "2026-08-25T01:44:59.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-25T01:44:59.000Z",
      "name": "movistar-recaudo-epayc.com",
      "description": "Suspicious phishing domain impersonating Movistar, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'movistar-recaudo-epayc.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/movistar/29aa00e3-6aee-4730-8ab7-2b7330e4d629/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "movistar"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0ea23719-f5d7-5d47-a707-54df78084b6e",
      "created": "2026-08-25T04:40:28.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-25T04:40:28.000Z",
      "name": "rekemonedasi-facebook.org",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'rekemonedasi-facebook.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/405f101b-c2c7-4281-8dba-e7ea3a13fe4b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0ac475e5-1012-5c95-a338-8f9b1ad95b30",
      "created": "2026-08-25T13:04:25.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-25T13:04:25.000Z",
      "name": "ledger-liveusa.zapier.app",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ledger-liveusa.zapier.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/3e0be6b7-9df2-436b-bfc3-90d2ff13348d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de3a7600-8071-580d-841f-a4ad80d22c73",
      "created": "2026-08-25T13:04:33.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-25T13:04:33.000Z",
      "name": "lovevivah.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 16/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'lovevivah.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 16,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/8a3c181b-636b-4ae3-a9f1-49b3949e48f9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--106afd27-12bb-5b0c-b6e8-cd913b366b61",
      "created": "2026-08-25T17:25:05.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-25T17:25:05.000Z",
      "name": "18493821-coinbase.com",
      "description": "Suspicious phishing domain impersonating Coinbase, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '18493821-coinbase.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/coinbase/e271dd57-dc7f-424a-96f1-ce271e16d7ed/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "coinbase"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--75e30c0e-45f4-5f6e-9551-abded7b85790",
      "created": "2026-08-26T01:02:28.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-26T01:02:28.000Z",
      "name": "11ec78d.netsolhost.com",
      "description": "Suspicious phishing domain impersonating SEUR, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '11ec78d.netsolhost.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/seur/57cfda4c-92da-4c95-9103-1d098e50fb92/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "seur"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--34a4c0d9-38a3-5368-8005-01b1f9835dcb",
      "created": "2026-08-26T01:02:29.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-26T01:02:29.000Z",
      "name": "file-whatsappn.hl.cn",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'file-whatsappn.hl.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/ec764242-29fc-4767-b6eb-3c0686476e68/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f05d221-fe7d-5e00-84ca-0109d7f53dd1",
      "created": "2026-08-26T05:24:34.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-26T05:24:34.000Z",
      "name": "dpdi.xyz",
      "description": "Suspicious phishing domain impersonating DPD, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'dpdi.xyz']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dpd/44c55560-88cc-4bb6-b4f8-89eca0e32acb/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dpd"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ba75fde-7a05-5b71-8188-7e6370799112",
      "created": "2026-08-26T05:24:35.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-26T05:24:35.000Z",
      "name": "googleplsey.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googleplsey.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/132f9033-e3a9-46ed-8f4e-a19a24fdc384/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87f35744-c7dd-52c7-9b14-ab3751574c15",
      "created": "2026-08-26T06:11:49.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-26T06:11:49.000Z",
      "name": "seureonline.shop",
      "description": "Suspicious phishing domain impersonating SEUR, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'seureonline.shop']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/seur/c650a1b7-f32b-455d-b7cd-acf26c7bf412/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "seur"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bec21446-701c-534e-a157-b42597a7ff20",
      "created": "2026-08-26T13:02:44.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-26T13:02:44.000Z",
      "name": "njj.standard.us-east-1.oortstorages.com",
      "description": "Suspicious phishing domain impersonating DocuSign, detected by phishunt.io (score 75/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'njj.standard.us-east-1.oortstorages.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 75,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/docusign/74c85fa5-5310-4984-b470-8ed47c8cd50b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "docusign"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd43a1ae-941b-58f7-aa3c-3b2164d62d57",
      "created": "2026-08-26T13:02:52.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-26T13:02:52.000Z",
      "name": "vodafone-form.mhmr.ro",
      "description": "Suspicious phishing domain impersonating Vodafone, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'vodafone-form.mhmr.ro']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/vodafone/05070343-3dff-4532-9a9a-3d92185a0a78/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "vodafone"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1bf92c1b-8f81-5066-b63c-7e082b0f0505",
      "created": "2026-08-26T13:03:05.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-26T13:03:05.000Z",
      "name": "reentrega-seur-envio.cloudaccess.host",
      "description": "Suspicious phishing domain impersonating SEUR, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'reentrega-seur-envio.cloudaccess.host']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/seur/ee4b5ef0-0aa1-42e5-8485-bd05e812d229/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "seur"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fca5a285-fba9-5fb2-b3b2-5eab4ba5f611",
      "created": "2026-08-27T01:04:05.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-27T01:04:05.000Z",
      "name": "facebook-7.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-7.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/1eb71ffa-96b7-4f84-b5bd-01c7a3fec1f0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c9b6633-0f22-595c-91e7-f6963a6a4906",
      "created": "2026-08-27T01:04:29.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-27T01:04:29.000Z",
      "name": "secure-trezor-en-io.typedream.app",
      "description": "Suspicious phishing domain impersonating Trezor, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'secure-trezor-en-io.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/trezor/bed946e5-8788-462e-b4f5-aa4cc279cae4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "trezor"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9cf3ae77-ecaa-5173-9734-8f9d4d630e9c",
      "created": "2026-08-27T01:05:25.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-27T01:05:25.000Z",
      "name": "instagramlogin08.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramlogin08.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/7465a3bd-17b2-4428-834e-501f3a56c6cb/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5ca25b3-35d3-5248-ba78-33c5df70366f",
      "created": "2026-08-27T01:05:48.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-27T01:05:48.000Z",
      "name": "whatsappfreewhatsapp.blogspot.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'whatsappfreewhatsapp.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/eaed4216-b59e-4506-87d4-d4af051cc1c7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5bb8d017-f824-5693-be9a-b28fcdcfa802",
      "created": "2026-08-27T01:07:10.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-27T01:07:10.000Z",
      "name": "facebook-seks-30.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-seks-30.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/18fed14e-e5eb-4c76-87ae-be95eeb96619/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0c29dbdb-f059-55a2-8981-eea7e6237f4a",
      "created": "2026-08-27T01:07:48.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-27T01:07:48.000Z",
      "name": "dhl-express-test.lobster-cloud.com",
      "description": "Suspicious phishing domain impersonating DHL, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'dhl-express-test.lobster-cloud.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dhl/31ea6339-1b1f-427a-a302-9e9182f72bfd/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dhl"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--557c3095-85c2-5f9f-95d7-6031b3d0ce3b",
      "created": "2026-08-27T01:08:01.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-27T01:08:01.000Z",
      "name": "id-kraken-controle.com",
      "description": "Suspicious phishing domain impersonating Kraken, detected by phishunt.io (score 45/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'id-kraken-controle.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 45,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/kraken/0103be07-698f-4056-99aa-319254882909/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "kraken"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c2b9290-8abe-514b-a2c3-2600dc7d0c2e",
      "created": "2026-08-27T01:09:31.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-27T01:09:31.000Z",
      "name": "cvmac.id",
      "description": "Suspicious phishing domain impersonating DocuSign, detected by phishunt.io (score 19/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'cvmac.id']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 19,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/docusign/89f7d3aa-3534-48ac-afa0-d7d130bef32a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "docusign"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aaaec739-984d-5a1a-9137-bcdf54222d3e",
      "created": "2026-08-27T13:02:08.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-27T13:02:08.000Z",
      "name": "sso-ledger-live-strt-ledger-support-cdn.typedream.app",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'sso-ledger-live-strt-ledger-support-cdn.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/fa1617d5-29f3-4b4c-9262-d423310c8246/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b6cd5175-e1f0-52b7-90b0-9b16f69b889d",
      "created": "2026-08-28T01:02:15.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-28T01:02:15.000Z",
      "name": "login-yahoo-verify.blogspot.com",
      "description": "Suspicious phishing domain impersonating Yahoo, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'login-yahoo-verify.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/yahoo/6429bd71-98d1-4699-8aa8-acf2dc892290/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "yahoo"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--92438f33-c97c-5cfe-9bea-b11ae766ed2a",
      "created": "2026-08-28T01:02:53.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-28T01:02:53.000Z",
      "name": "facebook-links.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-links.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3dd7002e-fdda-410e-bec2-a636a3605630/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fffbfae5-78ca-5fd0-810d-0d6b84d0449e",
      "created": "2026-08-28T01:02:55.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-28T01:02:55.000Z",
      "name": "icloud.trienkhaiweb.com",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'icloud.trienkhaiweb.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/bf597b67-2acc-4efe-802b-4057b005eeb5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--590f58e9-42f0-592f-a51d-2e6780d8a26c",
      "created": "2026-08-28T01:03:00.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-28T01:03:00.000Z",
      "name": "metamasklogniox.gitbook.io",
      "description": "Suspicious phishing domain impersonating MetaMask, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'metamasklogniox.gitbook.io']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/metamask/9c6b6cb8-1522-4a99-8099-0134f05f9ab8/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "metamask"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a46237e4-fd87-5dd0-8d06-0d03ef82d199",
      "created": "2026-08-28T04:17:22.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-28T04:17:22.000Z",
      "name": "ebay-c.com",
      "description": "Suspicious phishing domain impersonating eBay, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ebay-c.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ebay/fd5640f9-21ad-46b4-b760-d7368aaf83b0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ebay"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--458d7f58-baeb-52c4-ac4b-2878103ddede",
      "created": "2026-08-28T05:24:56.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-28T05:24:56.000Z",
      "name": "ebayfoll.store",
      "description": "Suspicious phishing domain impersonating eBay, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ebayfoll.store']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ebay/40cff67c-d784-4ad1-914f-dada27388d0a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ebay"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c524bcb9-1631-5ccc-98b3-d73a23355137",
      "created": "2026-08-28T05:24:58.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-28T05:24:58.000Z",
      "name": "asif.me",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'asif.me']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//a935dfce-772f-4488-abc9-2e9dbda718bd/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cc9d42b3-740c-5448-8eb2-289262fc6531",
      "created": "2026-08-28T05:26:55.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-28T05:26:55.000Z",
      "name": "prizebond.net.pk",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'prizebond.net.pk']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//d6cb7d4f-5755-4f9d-9793-7c66ed3a58d9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9fcee453-d798-5d11-a8c3-2e0976f866ad",
      "created": "2026-08-28T10:52:03.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-28T10:52:03.000Z",
      "name": "alibaba66.co",
      "description": "Suspicious phishing domain impersonating Alibaba, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'alibaba66.co']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/alibaba/7a79df0d-c668-4011-a6a4-63fad0585375/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "alibaba"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2225b230-91f5-5dd3-9365-ec1d2ca197fe",
      "created": "2026-08-28T13:15:35.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-28T13:15:35.000Z",
      "name": "web-conect-us-ledger-live-wallet.typedream.app",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'web-conect-us-ledger-live-wallet.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/2711ec30-a33d-4ad0-9ed6-3f3653110f91/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--be0770eb-ff7b-5a61-8eae-abc90841cc24",
      "created": "2026-08-28T13:15:46.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-28T13:15:46.000Z",
      "name": "trezor-io-start-us-help-access.typedream.app",
      "description": "Suspicious phishing domain impersonating Trezor, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'trezor-io-start-us-help-access.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/trezor/5f530f42-a7ba-43d4-806d-9518b1d7fec0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "trezor"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2ffff4f6-c2f0-5f45-b7d3-c039665a99c9",
      "created": "2026-08-28T13:16:39.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-28T13:16:39.000Z",
      "name": "support-ledgrcom-start-web.typedream.app",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'support-ledgrcom-start-web.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/74c1c412-8196-4331-ba59-28bc79518616/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--56ba3bd8-213e-5ca7-9078-01e9d338d542",
      "created": "2026-08-28T15:04:02.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-28T15:04:02.000Z",
      "name": "loja.amazon-promos.shop",
      "description": "Suspicious phishing domain impersonating Amazon, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'loja.amazon-promos.shop']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/amazon/b8aaa8f4-d578-42ee-9569-7dd6319508ea/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "amazon"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6459caef-3e2f-554e-ba8b-90d84ec5375a",
      "created": "2026-08-28T17:24:53.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-28T17:24:53.000Z",
      "name": "shoppingonamazon.net",
      "description": "Suspicious phishing domain impersonating Amazon, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'shoppingonamazon.net']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/amazon/1f3fc203-f91e-4aa0-a893-f725683970d2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "amazon"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32385953-f2bd-53ea-85bb-09df2d7cd45f",
      "created": "2026-08-28T17:43:26.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-28T17:43:26.000Z",
      "name": "alibaba66slot.app",
      "description": "Suspicious phishing domain impersonating Alibaba, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'alibaba66slot.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/alibaba/efb91061-f898-469d-bd05-7a7e631c9bd9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "alibaba"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5dbe882e-9ec6-5a79-84af-a0e0f66a6411",
      "created": "2026-08-28T22:01:37.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-28T22:01:37.000Z",
      "name": "roblox.com.mu",
      "description": "Suspicious phishing domain impersonating Roblox, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'roblox.com.mu']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/roblox/4cbb35ce-4ad6-4a9f-935c-011c86df94b2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "roblox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4270f0c3-a5ff-5412-848d-e29a78a0c085",
      "created": "2026-08-29T01:02:26.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-29T01:02:26.000Z",
      "name": "trezor-io-start-conect-auth.typedream.app",
      "description": "Suspicious phishing domain impersonating Trezor, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'trezor-io-start-conect-auth.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/trezor/9f1a698d-511b-4b23-baf7-ebd259ebbec5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "trezor"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fdd894d3-3202-5e08-8087-87a61afdf494",
      "created": "2026-08-29T01:02:32.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-29T01:02:32.000Z",
      "name": "trezrstartpublic-com-en-auths.typedream.app",
      "description": "Suspicious phishing domain impersonating Trezor, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'trezrstartpublic-com-en-auths.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/trezor/bfc6b96e-0d62-4c56-b360-cb7152107f9f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "trezor"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--edc34c04-9342-5e87-b1eb-9d310c9f77fa",
      "created": "2026-08-29T01:02:43.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-29T01:02:43.000Z",
      "name": "windows-ledger-live.typedream.app",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'windows-ledger-live.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/7241dbbd-1eba-4a72-a95b-a1b6d7c2d09c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--44aff663-2696-59d3-bd67-cf8c5d870a27",
      "created": "2026-08-29T01:03:10.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-29T01:03:10.000Z",
      "name": "start-web-en-ledger-live-login.typedream.app",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'start-web-en-ledger-live-login.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/22b0df35-b50a-4419-9f8c-dcef0fd1b8ce/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f700012d-d3c2-5805-b15e-08538dd1a3f4",
      "created": "2026-08-29T01:03:32.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-29T01:03:32.000Z",
      "name": "exodus-wallet.global.ssl.fastly.net",
      "description": "Suspicious phishing domain impersonating Exodus, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'exodus-wallet.global.ssl.fastly.net']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/exodus/d65694ce-deb5-4d2a-92cb-19348f2bcee5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "exodus"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4eed084-b56a-588d-ac4c-6d41960f9f2b",
      "created": "2026-08-29T01:03:40.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-29T01:03:40.000Z",
      "name": "pub-d68525cbc6144dcaaac2fc0354aa17dd.r2.dev",
      "description": "Suspicious phishing domain impersonating DocuSign, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'pub-d68525cbc6144dcaaac2fc0354aa17dd.r2.dev']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/docusign/23a5b426-9cc1-4b63-894f-2ec1b860699c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "docusign"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bdbf1b08-aacf-5ba5-9d6a-57487b71ac05",
      "created": "2026-08-29T05:24:56.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-29T05:24:56.000Z",
      "name": "fmi-icloud.pro",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'fmi-icloud.pro']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/4d7e18d1-a72a-439d-85df-0a59fc66d14f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--899dcf48-f73d-5fe1-8c1a-0972de8ccca2",
      "created": "2026-08-29T05:24:56.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-29T05:24:56.000Z",
      "name": "steuerquimica.cl",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'steuerquimica.cl']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//6a59ee2b-f142-4c1d-aad0-33386036ac7f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--487425a8-50f4-5b63-ad9e-be4834c85fca",
      "created": "2026-08-29T05:25:20.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-29T05:25:20.000Z",
      "name": "icloud-sharedalbum.com",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'icloud-sharedalbum.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/171888d5-fea9-4adb-b324-842a14b22398/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ec86b0b-f447-555c-8deb-3e849245a7d6",
      "created": "2026-08-29T13:05:12.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-29T13:05:12.000Z",
      "name": "netflix-login.blogspot.com",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflix-login.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/536bcb6c-b61d-4c92-b984-e1c863b83b94/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d3279c9a-0d10-5c7c-a765-de0493da7335",
      "created": "2026-08-29T13:06:25.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-29T13:06:25.000Z",
      "name": "ledger-lives-desktop.square.site",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ledger-lives-desktop.square.site']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/6cc47c8a-77c1-475e-ada7-9783f02f030f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d7dfc1c1-8ed4-53d5-8565-a4b3bbd7aa36",
      "created": "2026-08-29T13:08:44.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-29T13:08:44.000Z",
      "name": "facebook-login-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-login-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/f3c63666-478e-49fa-b48e-f4d487a3d7f3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de2935f6-3ccf-5aee-991b-ffd694b09f28",
      "created": "2026-08-29T13:09:29.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-29T13:09:29.000Z",
      "name": "loginfacebook-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'loginfacebook-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c1a271b3-38e4-4c68-bee2-225ca642ed80/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6287f130-a901-51b8-8b47-2d51d3c0a74c",
      "created": "2026-08-29T13:11:22.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-29T13:11:22.000Z",
      "name": "vi-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'vi-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c11f5e12-4353-4bd8-82ec-c62082620ae2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b2959481-f465-563f-b8b7-e2abf4a0b618",
      "created": "2026-08-29T13:12:00.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-29T13:12:00.000Z",
      "name": "whatsapp.dir.com.my",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'whatsapp.dir.com.my']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/d019f376-a20b-4d51-b330-b6dff020df39/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5dff034d-429a-5993-969d-8fe4e9264ce7",
      "created": "2026-08-29T13:12:51.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-29T13:12:51.000Z",
      "name": "trustwallet-login.blogspot.com",
      "description": "Suspicious phishing domain impersonating Trust Wallet, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'trustwallet-login.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/trustwallet/765b1f40-8289-4413-b52b-cef7206e11ad/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "trustwallet"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fa186554-4eee-55e2-b7f7-669c313b4e05",
      "created": "2026-08-29T13:14:33.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-29T13:14:33.000Z",
      "name": "facebook-astuces-news.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-astuces-news.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/e5beef27-73de-403b-84df-09dc65aaaa4a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a15d986d-d205-526e-b10f-e178adb079df",
      "created": "2026-08-29T13:16:25.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-29T13:16:25.000Z",
      "name": "ledger-live-login-web.square.site",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ledger-live-login-web.square.site']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/ff2fd97b-1277-4309-bbf6-020af76f6973/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fcff8394-557e-5af5-ada4-0b6c2880587e",
      "created": "2026-08-29T13:17:45.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-29T13:17:45.000Z",
      "name": "whatsapp-verify.blogspot.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'whatsapp-verify.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/15595635-1b7f-44fd-adbd-d9f5c1f3c958/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f88ab2d1-5b02-5c71-a4ff-869badd67ec5",
      "created": "2026-08-29T13:18:44.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-29T13:18:44.000Z",
      "name": "home-ledgrreliveapp.typedream.app",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'home-ledgrreliveapp.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/af0f53fc-14ac-45cd-84c2-d68a7d7fef32/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--755df61b-dc1a-554c-800f-aabbe579674a",
      "created": "2026-08-29T17:25:01.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-29T17:25:01.000Z",
      "name": "googleuserlogin.cam",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googleuserlogin.cam']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/f0c3a0b8-b351-4553-bfc0-40be5777decd/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a5ab3e2-5105-5206-be28-6f08ee3bfdfe",
      "created": "2026-08-30T00:01:32.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-30T00:01:32.000Z",
      "name": "usps.us-nqzqo.life",
      "description": "Suspicious phishing domain impersonating USPS, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'usps.us-nqzqo.life']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/usps/edee3660-19e6-4705-b574-d5c37bfd8bec/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "usps"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2e327d53-17df-5d91-92f5-8ce7912df22d",
      "created": "2026-08-30T00:33:04.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-30T00:33:04.000Z",
      "name": "alibaba66a.net",
      "description": "Suspicious phishing domain impersonating Alibaba, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'alibaba66a.net']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/alibaba/df8483e8-a334-4dc4-8bfb-e44d1f7a1366/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "alibaba"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a88c2ebb-d240-5ce2-8ae7-153ce81a2346",
      "created": "2026-08-30T01:02:11.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-30T01:02:11.000Z",
      "name": "facebook-loging.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-loging.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/37eb177a-e453-4480-8f48-307ccbdaca88/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--08d420a3-6809-545b-8bbf-bf724075b1de",
      "created": "2026-08-30T01:02:19.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-30T01:02:19.000Z",
      "name": "trezor-io-lernnu.typedream.app",
      "description": "Suspicious phishing domain impersonating Trezor, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'trezor-io-lernnu.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/trezor/6dbc4b4e-83cf-4b5a-acff-0124e552d68b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "trezor"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5166a791-d4cf-5297-b419-9269540a36fb",
      "created": "2026-08-30T13:03:49.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-30T13:03:49.000Z",
      "name": "start-ledgren.zapier.app",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'start-ledgren.zapier.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/894da4c8-359b-43ba-a290-1db9cba5722f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--62998a49-67e5-5b84-8f23-3c3813541746",
      "created": "2026-08-30T13:04:31.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-30T13:04:31.000Z",
      "name": "roblox.com.bz",
      "description": "Suspicious phishing domain impersonating Roblox, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'roblox.com.bz']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/roblox/44f846dc-f536-4bcb-bce8-1e7f863906f9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "roblox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--40a5b9c7-e1c4-57ed-a23f-f331dee0ea70",
      "created": "2026-08-30T13:05:23.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-30T13:05:23.000Z",
      "name": "on.instagram-g.com.cn",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'on.instagram-g.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/ce96ec60-1c1f-46f5-bb96-858b6bcb0f67/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1dc5ab7a-3d96-5e31-aa88-2190a723c7aa",
      "created": "2026-08-30T13:05:39.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-30T13:05:39.000Z",
      "name": "cm.instagram-g.com.cn",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'cm.instagram-g.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/4e3424d7-2b4e-4f9b-ac50-e5d74be4c228/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--22446f3c-3eab-535c-aa30-1458ce7f60c1",
      "created": "2026-08-30T13:06:02.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-30T13:06:02.000Z",
      "name": "login.authorised-support.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 45/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'login.authorised-support.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 45,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/15cc6a85-bcbd-4d85-b02c-97aa8ac16f75/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5cba6e4a-7e4a-54bc-8362-6cbb20900a76",
      "created": "2026-08-30T13:06:13.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-30T13:06:13.000Z",
      "name": "ebay-phone-number.blogspot.com",
      "description": "Suspicious phishing domain impersonating eBay, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ebay-phone-number.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ebay/820fa749-5366-4d37-9e6f-b64c8b4fdcb1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ebay"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0083b153-2c3f-577c-af49-c07e77b2a0f9",
      "created": "2026-08-30T13:07:31.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-30T13:07:31.000Z",
      "name": "dpd.hhvka.club",
      "description": "Suspicious phishing domain impersonating DPD, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'dpd.hhvka.club']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dpd/40e549e7-12a8-4ed2-a6e2-eee281058684/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dpd"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--316b3824-b4a5-54c5-8dd3-43743fb09c48",
      "created": "2026-08-30T13:07:47.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-30T13:07:47.000Z",
      "name": "dpd.oovra.club",
      "description": "Suspicious phishing domain impersonating DPD, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'dpd.oovra.club']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dpd/8f0c24e9-933a-4c2c-a426-c73e211ade0c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dpd"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--687934f6-d86c-53d2-af9d-6e0c12294338",
      "created": "2026-08-30T13:08:46.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-30T13:08:46.000Z",
      "name": "dpd.ffmka.club",
      "description": "Suspicious phishing domain impersonating DPD, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'dpd.ffmka.club']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dpd/aae6b094-d51e-47c8-8fdb-2965fb67e05a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dpd"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff5c01c2-9422-5b73-bc34-cf475f6feca3",
      "created": "2026-08-30T17:25:14.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-30T17:25:14.000Z",
      "name": "support.zoom.us.pro.kaisarstore.dpdns.org",
      "description": "Suspicious phishing domain impersonating Zoom, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'support.zoom.us.pro.kaisarstore.dpdns.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/zoom/12a84c24-2590-4722-98f8-79ae0c5f2949/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "zoom"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0b2e21c-914f-5a4b-af38-5d425306fbc3",
      "created": "2026-08-30T17:25:26.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-30T17:25:26.000Z",
      "name": "support.zoom.us.vip.kaisarstore.dpdns.org",
      "description": "Suspicious phishing domain impersonating Zoom, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'support.zoom.us.vip.kaisarstore.dpdns.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/zoom/2c1f937d-dbec-4ca1-87ad-eac111516f25/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "zoom"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--790ef169-1f21-512f-9b10-50772e2ac516",
      "created": "2026-08-30T17:25:28.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-30T17:25:28.000Z",
      "name": "case185366-coinbase.com",
      "description": "Suspicious phishing domain impersonating Coinbase, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'case185366-coinbase.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/coinbase/ab1b63d6-d119-4718-9162-995a28a43c99/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "coinbase"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e3c8f387-9b9c-5d03-8583-579567b58cf7",
      "created": "2026-08-31T04:43:21.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-31T04:43:21.000Z",
      "name": "alibaba188.org",
      "description": "Suspicious phishing domain impersonating Alibaba, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'alibaba188.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/alibaba/ecdbc638-e3bb-4a4d-8729-f08beaf7c844/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "alibaba"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--39ea4c7a-96ca-5e70-8af6-317f1112f9fb",
      "created": "2026-08-31T05:24:38.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-31T05:24:38.000Z",
      "name": "googleplsmy.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googleplsmy.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/b2992209-4f37-4f5b-b116-a5ae29f508c5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ddf7adfa-26eb-5068-a3b1-de215f3f68b1",
      "created": "2026-08-31T05:26:28.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-31T05:26:28.000Z",
      "name": "misilabario.cl",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'misilabario.cl']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//864430ec-a961-45b9-bc3a-0e8c6e80c986/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--27c0e531-d8ed-5554-9bb3-d59e2e847198",
      "created": "2026-08-31T05:26:29.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-31T05:26:29.000Z",
      "name": "kenhoward.com",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'kenhoward.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//dfd0a0fb-8a26-49a0-b074-83ef29887b40/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4bf30dde-961f-504e-bd79-7bf2800efa3f",
      "created": "2026-08-31T13:01:46.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-31T13:01:46.000Z",
      "name": "instagram-e.com.cn",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-e.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/67ac04a3-9c31-41ff-863a-268ac8043659/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e8ea25f5-4e15-590e-9260-d049a1f7faff",
      "created": "2026-08-31T17:24:15.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-31T17:24:15.000Z",
      "name": "54893-coinbase.com",
      "description": "Suspicious phishing domain impersonating Coinbase, detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '54893-coinbase.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/coinbase/86b4a42a-daa7-4dcf-9368-f52ca218a478/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "coinbase"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ca512fee-5398-56c9-8e09-626978f74061",
      "created": "2026-08-31T17:24:16.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-31T17:24:16.000Z",
      "name": "978489-coinbase.com",
      "description": "Suspicious phishing domain impersonating Coinbase, detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '978489-coinbase.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/coinbase/94317a86-0c28-4487-8bf8-08e39ea2a9a2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "coinbase"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67834b75-0d16-5a96-a56b-3352b31dcc0e",
      "created": "2026-08-31T17:24:18.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-31T17:24:18.000Z",
      "name": "online.accounts-google-com-id29902wavx-ssl-k-emailrenew55.codes566ghhhbvnnjui.srpska-banka.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'online.accounts-google-com-id29902wavx-ssl-k-emailrenew55.codes566ghhhbvnnjui.srpska-banka.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/f32035b5-08b8-4ccf-86cf-c6548abcf6ac/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dca7700a-b3b3-5287-ade7-5d3f4b998ed0",
      "created": "2026-08-31T17:24:18.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-31T17:24:18.000Z",
      "name": "accounts-google-com-id29902wavx-ssl-k-emailrenew55.srpska-banka.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'accounts-google-com-id29902wavx-ssl-k-emailrenew55.srpska-banka.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/242b12c6-c117-4f10-bbbc-aa8bd187d9c1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c125f96-e9ca-583d-ad1b-a33f7f7f7277",
      "created": "2026-08-31T17:24:18.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-31T17:24:18.000Z",
      "name": "accounts-google-com.srpska-banka.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'accounts-google-com.srpska-banka.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/8e6f0cef-f412-4cd4-b7e9-ff2812f7d689/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6cf811b-20c9-5823-a4e7-6e482079e2a4",
      "created": "2026-08-31T17:24:19.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-31T17:24:19.000Z",
      "name": "metamask88.com",
      "description": "Suspicious phishing domain impersonating MetaMask, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'metamask88.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/metamask/0f83aa77-b3ce-4e5e-8d15-8f404f2bc6a0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "metamask"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6bc84cf2-ce2b-5c15-988d-021d65b4da54",
      "created": "2026-08-31T17:26:56.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-31T17:26:56.000Z",
      "name": "11.alibaba-taobaol.cn",
      "description": "Suspicious phishing domain impersonating Alibaba, detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '11.alibaba-taobaol.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/alibaba/517c4434-5618-4f43-8ee8-c4cf4494a53b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "alibaba"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f9cd05ad-8860-55b8-89ae-4713ce3c8963",
      "created": "2026-08-31T17:26:56.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-08-31T17:26:56.000Z",
      "name": "22.alibaba-taobaol.cn",
      "description": "Suspicious phishing domain impersonating Alibaba, detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '22.alibaba-taobaol.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/alibaba/c4b3802f-a0e7-49e3-9ab5-2c669829e1fa/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "alibaba"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ec1dea71-fb7e-5c4a-a62f-1f2a8771ba8a",
      "created": "2026-09-01T01:02:11.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-01T01:02:11.000Z",
      "name": "microsoftwordob.blogspot.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoftwordob.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/4a2c971a-7668-4b8d-adf3-fe2c8306099d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f5d9fcf-c509-5ba1-ba23-0ac7bfd7a82d",
      "created": "2026-09-01T01:03:21.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-01T01:03:21.000Z",
      "name": "swanhui.com",
      "description": "Suspicious phishing domain impersonating USPS, detected by phishunt.io (score 45/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'swanhui.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 45,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/usps/e956dc36-cfc7-4584-a657-38dd43ba8aad/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "usps"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6361c275-a5fa-5792-a6a9-ab6061f3f44a",
      "created": "2026-09-01T05:24:22.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-01T05:24:22.000Z",
      "name": "correosiicr.cc",
      "description": "Suspicious phishing domain impersonating Correos, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'correosiicr.cc']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/correos/2c775544-dc9a-47cb-9e08-9c196ee9dc17/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "correos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f8ccc89-a930-53c7-871a-bed49ae38691",
      "created": "2026-09-01T17:24:21.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-01T17:24:21.000Z",
      "name": "mydhl-verifn.help",
      "description": "Suspicious phishing domain impersonating DHL, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mydhl-verifn.help']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dhl/735be2bb-8846-4369-8cc4-85031403b75f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dhl"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5e2bf37-803c-577e-a26c-67d71ee4a5a1",
      "created": "2026-09-02T02:59:26.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-02T02:59:26.000Z",
      "name": "siyarata-assets-workbench.whatsappapk.org",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'siyarata-assets-workbench.whatsappapk.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/57297f77-9590-4863-8e56-f20e4c74eddf/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--727b120f-e27f-596a-b6df-63ce4c5b31a0",
      "created": "2026-09-02T05:24:54.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-02T05:24:54.000Z",
      "name": "steamcommunity-balanceworkshop.shop",
      "description": "Suspicious phishing domain impersonating Steam, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'steamcommunity-balanceworkshop.shop']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/steam/c4749e87-cff4-45a5-9164-c90808420d27/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "steam"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--147717b5-0071-5266-9198-6f329d149af6",
      "created": "2026-09-02T13:05:09.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-02T13:05:09.000Z",
      "name": "facebook.meweb.kz",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook.meweb.kz']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/4e23956f-3999-4112-91e3-0dcef2f7ccab/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ef1e4224-86ae-5c62-a641-6d24d6e59abe",
      "created": "2026-09-02T13:05:48.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-02T13:05:48.000Z",
      "name": "grupoimpaktu.ao",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'grupoimpaktu.ao']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/27427bb8-bc8c-4365-9a6b-bb8079e95b31/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e5362573-a713-5fc9-a3f8-791317c080db",
      "created": "2026-09-02T13:06:50.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-02T13:06:50.000Z",
      "name": "netflixcasino.co.it",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflixcasino.co.it']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/115a1f74-9305-45ca-9e54-bb15b53dbedb/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb650da1-ac5f-55da-be8a-b28ef574f61b",
      "created": "2026-09-02T13:07:14.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-02T13:07:14.000Z",
      "name": "bmb.adv.br",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bmb.adv.br']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/fa9847b5-9d4b-4357-bb40-17cfbe0e324e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--03ef6926-30db-559a-b1d9-4289ca851c92",
      "created": "2026-09-02T17:25:12.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-02T17:25:12.000Z",
      "name": "ebaymevip.com",
      "description": "Suspicious phishing domain impersonating eBay, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ebaymevip.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ebay/bcd703eb-769a-454f-9b20-1ed84a0edc5a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ebay"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eb47c52c-8f53-5472-b2a9-269c9ab1fc9a",
      "created": "2026-09-02T17:25:13.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-02T17:25:13.000Z",
      "name": "uspsecuredlogs.com",
      "description": "Suspicious phishing domain impersonating USPS, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'uspsecuredlogs.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/usps/535b829b-515c-4e1b-a6e4-ade104fc7761/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "usps"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9002fd95-af3b-5937-8ca8-7beedf0bc8f2",
      "created": "2026-09-03T01:03:17.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-03T01:03:17.000Z",
      "name": "zh.instagram-e.com.cn",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'zh.instagram-e.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/63fbd68a-b8cc-49f8-8d0e-8690752e7819/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--14a21324-ac71-5f46-8366-396ce7b8888d",
      "created": "2026-09-03T01:03:27.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-03T01:03:27.000Z",
      "name": "lm.instagram-f.com.cn",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'lm.instagram-f.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/6829bb77-5bfd-437a-ba7a-a9479441a428/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0d5b8b11-77d6-521c-976a-3d8c850ada4f",
      "created": "2026-09-03T01:03:34.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-03T01:03:34.000Z",
      "name": "pc.instagram-e.com.cn",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'pc.instagram-e.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/8664cbfd-a8cd-4745-99fd-1c9acca4dd1c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9cc9a5ac-0ca8-5f68-9edc-d20c4410da4d",
      "created": "2026-09-03T01:03:39.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-03T01:03:39.000Z",
      "name": "cm.instagram-f.com.cn",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'cm.instagram-f.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/69ac8f5e-3500-46f8-a176-d37c09c34406/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--789f9673-dca7-5942-87d3-24c726cfe7ba",
      "created": "2026-09-03T01:03:47.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-03T01:03:47.000Z",
      "name": "geotehnica.com",
      "description": "Suspicious phishing domain impersonating DocuSign, detected by phishunt.io (score 17/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'geotehnica.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 17,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/docusign/15c875c0-686e-45ba-a4fb-12741b98f722/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "docusign"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8201cd11-36d3-5c53-ad3f-8572c21d8eed",
      "created": "2026-09-03T01:05:30.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-03T01:05:30.000Z",
      "name": "instagramlogin74.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramlogin74.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/abe80fb5-b56c-45eb-971b-d6412f3141ff/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c0ada3a4-e473-5f31-8690-4f733cefedbd",
      "created": "2026-09-03T05:24:31.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-03T05:24:31.000Z",
      "name": "c-icloud.com",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'c-icloud.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/749ca0e1-2ba2-4437-a6dd-ac9c00d5e2f3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f62be7d-65a6-5a90-841d-5a9faae80cea",
      "created": "2026-09-03T05:24:31.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-03T05:24:31.000Z",
      "name": "down.c-icloud.com",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'down.c-icloud.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/c30d44b8-05d4-4eb4-816d-5a2360a89fca/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c5789ac8-c178-50c1-a674-445a8edadae8",
      "created": "2026-09-03T05:24:31.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-03T05:24:31.000Z",
      "name": "h5.c-icloud.com",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'h5.c-icloud.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/cf07f38e-74d7-431e-95af-0932720b01a7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3aa07bd9-b322-56db-ae82-49a4d7e7cc62",
      "created": "2026-09-03T05:24:31.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-03T05:24:31.000Z",
      "name": "m.c-icloud.com",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'm.c-icloud.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/4c43aea9-0cb6-4197-a866-a5ca5daa1a2e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--db3d4db2-bb41-5176-8f2a-ee71eedac41c",
      "created": "2026-09-03T05:24:31.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-03T05:24:31.000Z",
      "name": "wap.c-icloud.com",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'wap.c-icloud.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/fcd38cf5-9f67-435d-b79a-766a45b1cb56/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67280e26-f90d-5026-95cf-564beb5cbdeb",
      "created": "2026-09-03T13:02:56.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-03T13:02:56.000Z",
      "name": "carivo.vu",
      "description": "Suspicious phishing domain impersonating Adobe, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'carivo.vu']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/adobe/056cfbdf-fedd-4209-ae2a-0d60843cf2d8/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "adobe"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1dbcb7ab-2654-589a-b700-c80cd9af3517",
      "created": "2026-09-03T13:03:34.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-03T13:03:34.000Z",
      "name": "app.instagram-g.com.cn",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'app.instagram-g.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/1637bad6-87d5-4535-a402-804dac146ab3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e162e59c-489b-5f5b-ab92-1096eb772487",
      "created": "2026-09-03T13:04:06.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-03T13:04:06.000Z",
      "name": "app.instagram-f.com.cn",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'app.instagram-f.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/7b7ad30a-0e5a-4f74-b02a-f27d573a18a5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da4f336d-9815-5bad-8f26-e8846d622845",
      "created": "2026-09-03T13:04:45.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-03T13:04:45.000Z",
      "name": "outlookwebs.softr.app",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'outlookwebs.softr.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/6b332437-8492-4a7a-91b1-2725f39d04a3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--474d9603-66b4-55b2-b06b-8450294c7e6f",
      "created": "2026-09-03T13:05:53.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-03T13:05:53.000Z",
      "name": "roblox.com.ms",
      "description": "Suspicious phishing domain impersonating Roblox, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'roblox.com.ms']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/roblox/b81094da-3127-4443-bbd3-e564e2f0e693/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "roblox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--70b019d2-52d7-5e46-8ed7-2d7faf6b99d2",
      "created": "2026-09-03T13:07:23.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-03T13:07:23.000Z",
      "name": "pc.instagram-g.com.cn",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'pc.instagram-g.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/8505015a-b563-4963-89cc-316954916b45/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3c4f4dd4-6570-51ca-8da5-d2fb20009b44",
      "created": "2026-09-03T13:07:37.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-03T13:07:37.000Z",
      "name": "cn.instagram-f.com.cn",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'cn.instagram-f.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/77149b5a-f741-4f49-85c7-ff691023440c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2d1da9b3-183c-5085-a37b-e2cf7688fb48",
      "created": "2026-09-03T13:08:24.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-03T13:08:24.000Z",
      "name": "instagram-g.com.cn",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-g.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/c1f7a7d2-a68c-4a76-a08b-d1b3ed032bd8/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--078b4035-7982-5ed3-9c5d-08f9d56b7e9f",
      "created": "2026-09-03T13:09:04.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-03T13:09:04.000Z",
      "name": "cm.instagram-e.com.cn",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'cm.instagram-e.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/eea7167c-21e9-42b4-b17b-252e58698a85/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--97861225-d1c3-5662-ab0b-fe8face4bb1e",
      "created": "2026-09-03T17:26:16.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-03T17:26:16.000Z",
      "name": "whatsappq.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 17/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'whatsappq.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 17,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/3caeee27-d3ed-4660-ade5-323e121d296c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1b00375d-8a52-5cad-89ae-1ea54e40f72b",
      "created": "2026-09-04T01:02:20.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T01:02:20.000Z",
      "name": "kucoinloign.gitbook.io",
      "description": "Suspicious phishing domain impersonating KuCoin, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'kucoinloign.gitbook.io']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/kucoin/11e0cf02-0260-40a9-8fdf-8b4b0e8cccb5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "kucoin"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--157b2d7d-b029-555d-a3fd-f5318b004c3a",
      "created": "2026-09-04T01:03:33.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T01:03:33.000Z",
      "name": "facebookhints.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookhints.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/064e1703-f8e4-402e-b5a5-aed46e68b97a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb137ba4-5e9a-5840-bfc0-96b156c000ed",
      "created": "2026-09-04T01:04:20.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T01:04:20.000Z",
      "name": "comecome.click",
      "description": "Suspicious phishing domain impersonating Alibaba, detected by phishunt.io (score 45/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'comecome.click']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 45,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/alibaba/b371f872-b4b3-44ba-a2f1-e63e395b4020/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "alibaba"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2850c488-9bdb-5bfd-8ebe-09a895987baa",
      "created": "2026-09-04T01:04:27.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T01:04:27.000Z",
      "name": "metamask-portal.yzz.me",
      "description": "Suspicious phishing domain impersonating MetaMask, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'metamask-portal.yzz.me']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/metamask/9aa8361d-6511-451c-8701-4957b816fd95/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "metamask"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fb77451c-38e0-5012-97f9-fcce8ae6f047",
      "created": "2026-09-04T05:24:03.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T05:24:03.000Z",
      "name": "asset.static-whatsapp.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'asset.static-whatsapp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/3828ac56-cba7-4acc-8965-a1408108d78f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c7556260-df5b-5db0-a9cb-660213912b09",
      "created": "2026-09-04T05:25:39.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T05:25:39.000Z",
      "name": "modanix.digital",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'modanix.digital']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//98767629-34a0-4611-9d22-2efafbc52118/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--19fcfcd0-4fa2-5bb5-b3c5-e6e3f4b26393",
      "created": "2026-09-04T13:02:24.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T13:02:24.000Z",
      "name": "sso-trezor-com-start-x-auth.typedream.app",
      "description": "Suspicious phishing domain impersonating Trezor, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'sso-trezor-com-start-x-auth.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/trezor/ee4d59ff-666e-4993-a0fb-fb166c14ff5f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "trezor"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bfae5f14-1ecd-5b18-b8ef-69355e5b8419",
      "created": "2026-09-04T13:02:56.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T13:02:56.000Z",
      "name": "vodafone-on-line.it",
      "description": "Suspicious phishing domain impersonating Vodafone, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'vodafone-on-line.it']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/vodafone/a29e6716-477b-451b-9686-187bc1ab1058/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "vodafone"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7672822f-ec59-58b2-a545-95ac6dcd0640",
      "created": "2026-09-04T13:03:01.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T13:03:01.000Z",
      "name": "notifications.microsoft-ssl.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'notifications.microsoft-ssl.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/aed93857-cf79-4462-8e2e-65264bd19e8c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c82288a2-68e6-56f7-b70a-f39008a547dd",
      "created": "2026-09-04T13:03:41.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T13:03:41.000Z",
      "name": "lonato-cc-il-leone-shopping-center.vodafone-on-line.it",
      "description": "Suspicious phishing domain impersonating Vodafone, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'lonato-cc-il-leone-shopping-center.vodafone-on-line.it']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/vodafone/64d0913f-1914-47fa-a84e-8455dededa4f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "vodafone"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--34838dba-3f5a-5788-8d5a-2b28ca47d38b",
      "created": "2026-09-04T13:03:44.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T13:03:44.000Z",
      "name": "spotify-anniversary30th.com",
      "description": "Suspicious phishing domain impersonating Spotify, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'spotify-anniversary30th.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/spotify/45de2582-5f16-44a6-92c4-9e2b8b68d010/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "spotify"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--77e042db-e947-50b0-bbe4-dc3a6c00f8f8",
      "created": "2026-09-04T13:03:51.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T13:03:51.000Z",
      "name": "cn.instagram-g.com.cn",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'cn.instagram-g.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/634c8f44-ac13-4d0d-b387-4edcc972325a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ad4bf46-afde-5722-a0b5-bcef42fbc8c4",
      "created": "2026-09-04T17:24:47.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:24:47.000Z",
      "name": "build.comm-whatsapp.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'build.comm-whatsapp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/a89411a2-c065-4c3c-b4df-f458b7f3cbc3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d56adc68-4d6f-5052-8438-29f9c86ab80b",
      "created": "2026-09-04T17:24:47.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:24:47.000Z",
      "name": "local.comm-whatsapp.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'local.comm-whatsapp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/371526b6-b9aa-479e-9549-dadbdcce3a9f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8196a7f2-3b8e-5739-84a4-fcb577a7f368",
      "created": "2026-09-04T17:24:47.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:24:47.000Z",
      "name": "patch.comm-whatsapp.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'patch.comm-whatsapp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/caeab633-3a83-412c-8f3e-05fe4e10b9b1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7c17de63-a9dc-50e4-94b4-c598ea5cda89",
      "created": "2026-09-04T17:24:48.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:24:48.000Z",
      "name": "photo.comm-whatsapp.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'photo.comm-whatsapp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/6dc6f811-b49b-4246-b1f0-fcab40001c37/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--41cdcd5b-0acc-51c3-9906-6c56a8d6e2e3",
      "created": "2026-09-04T17:24:48.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:24:48.000Z",
      "name": "premium.comm-whatsapp.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'premium.comm-whatsapp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/e7ad0330-8052-4ecf-929f-fbf74f140415/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8790f54b-22ea-51bf-b862-213e1da6d81c",
      "created": "2026-09-04T17:24:48.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:24:48.000Z",
      "name": "private.comm-whatsapp.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'private.comm-whatsapp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/8e66aed0-3c4c-4fbf-9eb2-5c14ac20f181/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f23cb729-e739-545a-a771-03a709e2431a",
      "created": "2026-09-04T17:24:48.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:24:48.000Z",
      "name": "sandbox.comm-whatsapp.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'sandbox.comm-whatsapp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/0dc7a062-8183-47df-97c1-7c52fa72a1c1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0cd83610-873a-526f-b5a4-d3ecb9c8e3bc",
      "created": "2026-09-04T17:24:48.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:24:48.000Z",
      "name": "staging.comm-whatsapp.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'staging.comm-whatsapp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/3af3d897-a053-44ad-8686-8f2b131bc1e7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--084f3bad-cc30-5c0b-bb04-91249f43abee",
      "created": "2026-09-04T17:24:48.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:24:48.000Z",
      "name": "stream.comm-whatsapp.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'stream.comm-whatsapp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/2b150352-e8fc-456d-a672-ba7d3f5c30ba/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6700c64c-61d7-514e-b574-0f8917d08a3f",
      "created": "2026-09-04T17:24:48.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:24:48.000Z",
      "name": "works.comm-whatsapp.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'works.comm-whatsapp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/1af481a3-eeb3-4da8-b724-bcc3bfe5e257/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--75fbc14d-f1e7-5d9f-a727-099932db05cd",
      "created": "2026-09-04T17:24:49.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:24:49.000Z",
      "name": "calendar.scan-whatsapp.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'calendar.scan-whatsapp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/a3a20b82-0c24-4d47-bb2b-c97ef6ec10b1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1773b304-537f-5dd6-aba5-20a8b5ece53d",
      "created": "2026-09-04T17:24:49.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:24:49.000Z",
      "name": "desktop.scan-whatsapp.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'desktop.scan-whatsapp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/4eaa3c2b-ef3b-4f30-8b3a-28eb976a23e9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8e53a99d-8d87-513f-b891-4586015628c9",
      "created": "2026-09-04T17:24:49.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:24:49.000Z",
      "name": "docs.scan-whatsapp.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'docs.scan-whatsapp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/3c79f56e-36ac-44b1-9a9a-40562b9a773e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c05805b-0e19-5ca9-84bc-60a97d6acb6a",
      "created": "2026-09-04T17:24:49.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:24:49.000Z",
      "name": "job.scan-whatsapp.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'job.scan-whatsapp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/3b04720a-03f3-49db-8bf4-611f99631d7e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5a97aaa-a6e0-5d74-bef4-d2febaeb1257",
      "created": "2026-09-04T17:24:49.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:24:49.000Z",
      "name": "meet.scan-whatsapp.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'meet.scan-whatsapp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/d178a671-b184-45bc-9aee-7c98d722016a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4601cac3-4b80-56e3-9805-4f0621fb2c51",
      "created": "2026-09-04T17:24:53.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:24:53.000Z",
      "name": "283674-coinbase.com",
      "description": "Suspicious phishing domain impersonating Coinbase, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '283674-coinbase.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/coinbase/06fa55a3-abce-47e4-9c60-f5c09d0eed10/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "coinbase"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--47585937-8727-5cc0-b8e4-72fed68bc48b",
      "created": "2026-09-04T17:24:55.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:24:55.000Z",
      "name": "818144-kraken.com",
      "description": "Suspicious phishing domain impersonating Kraken, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '818144-kraken.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/kraken/0c123e9a-e124-4fcc-8a73-b25c566314aa/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "kraken"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fbdaaf85-7a80-5f36-ae48-5bd0ab03d7a8",
      "created": "2026-09-04T17:24:56.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:24:56.000Z",
      "name": "818920-kraken.com",
      "description": "Suspicious phishing domain impersonating Kraken, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '818920-kraken.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/kraken/9e13f4da-eb77-41a4-8122-332fb9e2ea84/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "kraken"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--58652e46-2aa2-5afb-ab7c-e3a6754c0cf0",
      "created": "2026-09-04T17:24:57.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:24:57.000Z",
      "name": "819283-kraken.com",
      "description": "Suspicious phishing domain impersonating Kraken, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '819283-kraken.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/kraken/6b02dc5f-f67f-40cd-be08-3db0d60e7daf/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "kraken"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--45295d71-ff25-57d8-9eb3-3faa63863933",
      "created": "2026-09-04T17:24:58.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:24:58.000Z",
      "name": "bankofamericanonline.com",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bankofamericanonline.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/0b4828e3-cf78-4086-9ea7-4bc806662648/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--07f5c247-b487-516b-8f27-b8abd1d9522f",
      "created": "2026-09-04T17:24:59.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:24:59.000Z",
      "name": "my-walletfix-id-apple.com",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'my-walletfix-id-apple.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/578cfda5-31a8-4485-bf82-7941e59b776d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1001ecb5-f444-59c2-aa5c-d021621807eb",
      "created": "2026-09-04T17:25:00.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:25:00.000Z",
      "name": "restoration-google.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'restoration-google.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/11a739df-7b73-487c-8f96-71f5bc154069/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bd2ff3cd-a7cd-525c-ba70-c43c8b547e93",
      "created": "2026-09-04T17:25:07.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:25:07.000Z",
      "name": "academy.ww12.coinbase.com.lc",
      "description": "Suspicious phishing domain impersonating Coinbase, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'academy.ww12.coinbase.com.lc']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/coinbase/30185d6e-b436-4436-9e4e-a6dc7ae83207/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "coinbase"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--631e2abf-50f8-53ae-85d1-61f31fb4526d",
      "created": "2026-09-04T17:25:14.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T17:25:14.000Z",
      "name": "whatsappcampaign.online",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'whatsappcampaign.online']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/943e6141-503c-49dc-a040-9fdfa16f192e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--81a1dd11-4bbf-5f89-b21a-bfb24e718fc9",
      "created": "2026-09-04T19:43:23.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T19:43:23.000Z",
      "name": "apk-google.cn",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'apk-google.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/3a9caf38-d5fe-4cf9-9b6f-702f5b135596/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d603a418-2f1d-5377-bf5b-2abb45ab2fce",
      "created": "2026-09-04T23:01:17.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-04T23:01:17.000Z",
      "name": "desktop-ledgrecdn.wixstudio.com",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'desktop-ledgrecdn.wixstudio.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/9069f224-5c2c-4ab6-b740-5c6dbc5b5a64/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--35f37f70-12a4-5011-beac-7215e1c93dc7",
      "created": "2026-09-05T01:02:45.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-05T01:02:45.000Z",
      "name": "ks-gov.us-onedrive.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ks-gov.us-onedrive.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/8c46ce6e-abca-4380-bf33-e8f48414af30/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e85aa274-9ee3-5c6b-a154-ecc8f870ac79",
      "created": "2026-09-05T01:02:59.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-05T01:02:59.000Z",
      "name": "web-spotify.cn",
      "description": "Suspicious phishing domain impersonating Spotify, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'web-spotify.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/spotify/80af6217-911d-49d5-9b40-2d43157fc9d3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "spotify"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--62a9159b-a56d-591a-b890-89b476eab75b",
      "created": "2026-09-05T01:03:04.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-05T01:03:04.000Z",
      "name": "facebookzaman.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookzaman.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/e231dbf8-53ea-4b02-ba8e-e070a3fa8d0f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6886650e-6660-5bf7-92fe-b762aa15174b",
      "created": "2026-09-05T01:03:15.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-05T01:03:15.000Z",
      "name": "start-faq-en-trezr-cdq.typedream.app",
      "description": "Suspicious phishing domain impersonating Trezor, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'start-faq-en-trezr-cdq.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/trezor/1f2eeb51-a4e4-4af0-8f74-e65f206b6959/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "trezor"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c028962-ac75-5219-afc6-9fbf4c3f53e3",
      "created": "2026-09-05T01:03:19.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-05T01:03:19.000Z",
      "name": "pc-spotify.cn",
      "description": "Suspicious phishing domain impersonating Spotify, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'pc-spotify.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/spotify/fd126730-e2c5-44d5-bd0e-f157b82b4cc1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "spotify"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--90b9d070-942d-5706-8665-53da2fdb6c1b",
      "created": "2026-09-05T01:04:29.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-05T01:04:29.000Z",
      "name": "cn-spotify.cn",
      "description": "Suspicious phishing domain impersonating Spotify, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'cn-spotify.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/spotify/1fc784b9-db41-463b-89e2-a94e9138ba68/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "spotify"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--43a09c8f-5726-52de-af91-e4d5f2096be8",
      "created": "2026-09-05T01:04:34.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-05T01:04:34.000Z",
      "name": "books-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'books-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/1d9e404e-dc78-4dcc-b01a-c9af5b8944b7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a11dba5f-f530-5667-8a14-5d859c380614",
      "created": "2026-09-05T01:04:38.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-05T01:04:38.000Z",
      "name": "admin-instagram.orderyuk.info",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 19/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'admin-instagram.orderyuk.info']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 19,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/3210627c-f732-4cdc-8315-b7429f611c09/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--14ff46e4-35e9-505e-980b-34c18952887f",
      "created": "2026-09-05T04:02:07.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-05T04:02:07.000Z",
      "name": "allegrolokalnie.26352717.xyz",
      "description": "Suspicious phishing domain impersonating Allegro, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'allegrolokalnie.26352717.xyz']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/allegro/070a15f4-bc04-46f4-b1e7-bb6bd54f0200/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "allegro"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f041df2a-70aa-5350-ae89-86d73946de0a",
      "created": "2026-09-05T05:24:35.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-05T05:24:35.000Z",
      "name": "web0-whatsapp.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'web0-whatsapp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/e04097a4-f12c-4330-a058-438c253a961e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6824693c-43af-560f-a2d6-f0b183ae8f4c",
      "created": "2026-09-05T05:24:42.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-05T05:24:42.000Z",
      "name": "benchmark.comm-whatsapp.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'benchmark.comm-whatsapp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/8055fda8-9662-4921-a5a7-d47c2eb31773/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d59c143f-15ca-5943-b63f-16e2f64dce05",
      "created": "2026-09-05T05:24:43.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-05T05:24:43.000Z",
      "name": "cart.comm-whatsapp.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'cart.comm-whatsapp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/91c8a12c-3c1d-4ec8-928e-0d132b2cd813/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--817463bb-b0bc-56ba-9e06-da41d6cdfb76",
      "created": "2026-09-05T05:24:45.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-05T05:24:45.000Z",
      "name": "wqg.ru.com",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'wqg.ru.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//bbe8aa29-c195-4ecd-be25-0c71d981f1a2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f2afeb87-0834-5597-a5da-5e03b2ddeeff",
      "created": "2026-09-05T05:24:56.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-05T05:24:56.000Z",
      "name": "prirural.account-paypal.antimoney-laundering.org",
      "description": "Suspicious phishing domain impersonating PayPal, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'prirural.account-paypal.antimoney-laundering.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/paypal/4e152f68-6815-492c-9fe3-7c6cb7ee0a8b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "paypal"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9577c8bf-a577-5d7f-8a1a-b4c7b3abadd6",
      "created": "2026-09-05T07:07:27.000Z",
      "modified": "2026-09-05T09:30:12.000Z",
      "valid_from": "2026-09-05T07:07:27.000Z",
      "name": "coinbase-fedex-claimshelpdesk.net.ph",
      "description": "Suspicious phishing domain impersonating FedEx, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'coinbase-fedex-claimshelpdesk.net.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/fedex/c394c08a-3dd8-4ce8-b128-8843cf7a9107/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "fedex"
      ]
    }
  ]
}