{
  "type": "bundle",
  "id": "bundle--e6a2c16c-5240-5ad6-8a4e-bb3d659501c7",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "created": "2026-08-30T00:00:00.000Z",
      "modified": "2026-08-30T00:00:00.000Z",
      "name": "phishunt",
      "description": "Real-time phishing intelligence feed (phishunt.io): active suspicious phishing domains scored by an explainable 5-layer detection engine.",
      "identity_class": "organization",
      "contact_information": "https://phishunt.io/contact/"
    },
    {
      "type": "marking-definition",
      "spec_version": "2.1",
      "id": "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487",
      "created": "2022-10-01T00:00:00.000Z",
      "name": "TLP:CLEAR",
      "extensions": {
        "extension-definition--60a3c5c5-0d10-413e-aab3-9e08dde9e88d": {
          "extension_type": "property-extension",
          "tlp_2_0": "clear"
        }
      }
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c4e952d-cf56-5a62-8f7a-fada9750f354",
      "created": "2026-09-01T17:24:27.000Z",
      "modified": "2026-09-01T17:24:27.000Z",
      "valid_from": "2026-09-01T17:24:27.000Z",
      "name": "pop.debt-bankofamerica.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'pop.debt-bankofamerica.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/312b022b-f559-41b3-8323-3839ae2b483e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb23ff3c-bf3d-54e0-9ec4-d2aac4d81b65",
      "created": "2026-09-01T17:24:27.000Z",
      "modified": "2026-09-01T17:24:27.000Z",
      "valid_from": "2026-09-01T17:24:27.000Z",
      "name": "smtp.bankofamericacanadastore.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'smtp.bankofamericacanadastore.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/26e23209-11a5-4cd6-9593-5d5cfffb620b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--42e1d4f0-5a22-5fcf-a943-1a40e28bddb7",
      "created": "2026-09-01T17:24:27.000Z",
      "modified": "2026-09-01T17:24:27.000Z",
      "valid_from": "2026-09-01T17:24:27.000Z",
      "name": "mx.bankofamericana.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mx.bankofamericana.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/4bdd100c-8c70-4d26-b32f-7b587453eb29/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe70c504-9ace-54b3-9336-25e8090940b5",
      "created": "2026-09-01T17:24:27.000Z",
      "modified": "2026-09-01T17:24:27.000Z",
      "valid_from": "2026-09-01T17:24:27.000Z",
      "name": "autodiscover.bankofamericamerchantservices.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'autodiscover.bankofamericamerchantservices.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/c1a50c41-f9d9-4367-bb3b-f97db228f970/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2ed6d08-45f3-5193-a287-5ad1ae7c0d15",
      "created": "2026-09-01T17:24:26.000Z",
      "modified": "2026-09-01T17:24:26.000Z",
      "valid_from": "2026-09-01T17:24:26.000Z",
      "name": "autodiscover.bankofamerica-unauthorized.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'autodiscover.bankofamerica-unauthorized.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/e2fafd79-f125-4655-9d5f-498a7088096a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9e245143-45b3-569f-b1f1-b6f86d315566",
      "created": "2026-09-01T17:24:26.000Z",
      "modified": "2026-09-01T17:24:26.000Z",
      "valid_from": "2026-09-01T17:24:26.000Z",
      "name": "pop.bankofamericacanadastore.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'pop.bankofamericacanadastore.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/c43de70d-1996-4903-b192-ec5fd4fc34db/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--97b3f0fe-9344-5cb0-9184-7476f09c4701",
      "created": "2026-09-01T17:24:26.000Z",
      "modified": "2026-09-01T17:24:26.000Z",
      "valid_from": "2026-09-01T17:24:26.000Z",
      "name": "outlook.bankofamericana.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'outlook.bankofamericana.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/b73726e1-f8e8-45ba-a182-f2ff5d24c4e2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7809fcfc-847a-5fc5-ab5e-e330d1a7b529",
      "created": "2026-09-01T17:24:26.000Z",
      "modified": "2026-09-01T17:24:26.000Z",
      "valid_from": "2026-09-01T17:24:26.000Z",
      "name": "smtp.bankofamericasecured.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'smtp.bankofamericasecured.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/042a4094-302d-43f7-885f-102d915d8deb/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c8467f7f-6931-561b-b4a0-c4030e1a7052",
      "created": "2026-09-01T17:24:26.000Z",
      "modified": "2026-09-01T17:24:26.000Z",
      "valid_from": "2026-09-01T17:24:26.000Z",
      "name": "smtp.debt-bankofamerica.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'smtp.debt-bankofamerica.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/bdf14cb7-c8ca-4fd6-a50c-708838614e1e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8b7d2ff9-f0e6-50f5-874d-26e0114e2876",
      "created": "2026-09-01T17:24:25.000Z",
      "modified": "2026-09-01T17:24:25.000Z",
      "valid_from": "2026-09-01T17:24:25.000Z",
      "name": "outlook.bankofamericasecured.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'outlook.bankofamericasecured.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/817cbec3-c910-4e7a-aafd-8794236795b6/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8498d368-5a79-5e0d-b139-99dd6f44229f",
      "created": "2026-09-01T17:24:25.000Z",
      "modified": "2026-09-01T17:24:25.000Z",
      "valid_from": "2026-09-01T17:24:25.000Z",
      "name": "mx.debt-bankofamerica.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mx.debt-bankofamerica.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/8131e80f-9d66-457d-ac75-d9c24bf31239/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d9b33ad-a9d4-5ed3-bcfc-517e8bb5eda9",
      "created": "2026-09-01T17:24:25.000Z",
      "modified": "2026-09-01T17:24:25.000Z",
      "valid_from": "2026-09-01T17:24:25.000Z",
      "name": "outlook.bankofamerica-unauthorized.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'outlook.bankofamerica-unauthorized.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/6258ce93-fe5b-4272-945b-017ce2359c62/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--91bdabfc-1d69-51c1-b30a-8f3721674648",
      "created": "2026-09-01T17:24:25.000Z",
      "modified": "2026-09-01T17:24:25.000Z",
      "valid_from": "2026-09-01T17:24:25.000Z",
      "name": "autodiscover.debt-bankofamerica.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'autodiscover.debt-bankofamerica.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/8a766d7d-756c-42eb-b4ce-fafb6df8c7a1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--75d19329-9ae3-5454-9b98-a64c04ebbea5",
      "created": "2026-09-01T17:24:24.000Z",
      "modified": "2026-09-01T17:24:24.000Z",
      "valid_from": "2026-09-01T17:24:24.000Z",
      "name": "autoconfig.bankofamericamerchantservices.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'autoconfig.bankofamericamerchantservices.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/15d094e1-d19f-4032-8676-6738fdfb3ad1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--70fc6219-6c22-5436-bf5a-2ae0aba5ce38",
      "created": "2026-09-01T17:24:24.000Z",
      "modified": "2026-09-01T17:24:24.000Z",
      "valid_from": "2026-09-01T17:24:24.000Z",
      "name": "mx.bankofamericamerchantservices.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mx.bankofamericamerchantservices.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/e1386a2f-aa4d-4e41-8e98-386c394a7e82/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--22727d85-f13c-5d89-9d76-bad0a4e661ed",
      "created": "2026-09-01T17:24:23.000Z",
      "modified": "2026-09-01T17:24:23.000Z",
      "valid_from": "2026-09-01T17:24:23.000Z",
      "name": "autoconfig.bankofamericacanadastore.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'autoconfig.bankofamericacanadastore.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/53cc8da7-7467-44d4-8e19-51952737cac5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9ec5510b-1956-562a-9425-bbb6de404e0d",
      "created": "2026-09-01T17:24:23.000Z",
      "modified": "2026-09-01T17:24:23.000Z",
      "valid_from": "2026-09-01T17:24:23.000Z",
      "name": "mx.bankofamericasecured.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mx.bankofamericasecured.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/433440f5-2099-4460-82e3-69641431b3e8/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9dfd93a7-313d-5642-af09-976ee918fac8",
      "created": "2026-09-01T17:24:23.000Z",
      "modified": "2026-09-01T17:24:23.000Z",
      "valid_from": "2026-09-01T17:24:23.000Z",
      "name": "autodiscover.bankofamericacanadastore.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'autodiscover.bankofamericacanadastore.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/d518a11f-89dd-4a5f-ad08-2363934f933e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--abf8eae6-0ea4-5432-ab38-11645911b229",
      "created": "2026-09-01T17:24:22.000Z",
      "modified": "2026-09-01T17:24:22.000Z",
      "valid_from": "2026-09-01T17:24:22.000Z",
      "name": "mail.bankofamericasecured.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mail.bankofamericasecured.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/8817f5f0-39e6-4558-a54f-39113dd374b0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--45357fb0-95cb-5a54-bd84-1f99cb40de51",
      "created": "2026-09-01T17:24:22.000Z",
      "modified": "2026-09-01T17:24:22.000Z",
      "valid_from": "2026-09-01T17:24:22.000Z",
      "name": "secure-apple-id.com",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 18/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'secure-apple-id.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 18,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/96fc8651-3da6-4826-9e23-2d63012b08ab/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--216ab2d7-b7e3-5a9b-a8ab-101ded8e7010",
      "created": "2026-09-01T17:24:21.000Z",
      "modified": "2026-09-01T17:24:21.000Z",
      "valid_from": "2026-09-01T17:24:21.000Z",
      "name": "sec-whatsapp.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 21/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'sec-whatsapp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 21,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/bf248048-9722-4e7a-8706-aa4c8b711f7e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f8ccc89-a930-53c7-871a-bed49ae38691",
      "created": "2026-09-01T17:24:21.000Z",
      "modified": "2026-09-01T17:24:21.000Z",
      "valid_from": "2026-09-01T17:24:21.000Z",
      "name": "mydhl-verifn.help",
      "description": "Suspicious phishing domain impersonating DHL, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mydhl-verifn.help']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dhl/735be2bb-8846-4369-8cc4-85031403b75f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dhl"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9cc5b0e6-971d-5806-aad1-43d1f42aa847",
      "created": "2026-09-01T17:24:20.000Z",
      "modified": "2026-09-01T17:24:20.000Z",
      "valid_from": "2026-09-01T17:24:20.000Z",
      "name": "business-premier-google.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'business-premier-google.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/5c71a501-ecbf-4208-a691-876a150f8647/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53f390ab-60bf-5b6d-ad53-4a2f11c51451",
      "created": "2026-09-01T16:01:38.000Z",
      "modified": "2026-09-01T16:01:38.000Z",
      "valid_from": "2026-09-01T16:01:38.000Z",
      "name": "allegrolokalnie.pl-109772.cfd",
      "description": "Suspicious phishing domain impersonating Allegro, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'allegrolokalnie.pl-109772.cfd']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/allegro/5c81f575-140f-4c29-81e6-36353dc458d1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "allegro"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--77be119b-f1c0-5926-bc63-d76eb0eca1f2",
      "created": "2026-09-01T16:01:25.000Z",
      "modified": "2026-09-01T16:01:25.000Z",
      "valid_from": "2026-09-01T16:01:25.000Z",
      "name": "allegrolokalnie.pl-loka.shop",
      "description": "Suspicious phishing domain impersonating Allegro, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'allegrolokalnie.pl-loka.shop']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/allegro/cacdb0c0-ef30-4d30-807f-1a523925e103/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "allegro"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea2b983a-7316-5716-b917-f56e03ff82fe",
      "created": "2026-03-27T01:01:47.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-03-27T01:01:47.000Z",
      "name": "register-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'register-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/8a6eca16-d8b0-420e-ade6-6ee178c13c78/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--72547ffa-9cd9-50b3-ae73-3d7e8e747195",
      "created": "2026-03-28T01:01:37.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-03-28T01:01:37.000Z",
      "name": "office365.internal-alerts.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'office365.internal-alerts.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/7e1b0fba-bc4d-475b-ba61-b7876519c68f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--555c02eb-ebb6-55a4-9d09-f516bc03a07a",
      "created": "2026-03-28T07:32:22.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-03-28T07:32:22.000Z",
      "name": "amazonbookawards.com",
      "description": "Suspicious phishing domain impersonating Amazon, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'amazonbookawards.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/amazon/c72a9648-33a9-4b66-bce4-b97b23a3aae3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "amazon"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3774f09b-c10d-5064-86a7-a31d80691300",
      "created": "2026-03-28T13:01:22.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-03-28T13:01:22.000Z",
      "name": "support.m365-microsoft.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 19/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'support.m365-microsoft.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 19,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/4484f1cb-d3da-4757-83a3-5596fb6c36a2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dbff08e1-218b-5608-8909-b2fefe0c2653",
      "created": "2026-03-30T13:01:17.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-03-30T13:01:17.000Z",
      "name": "security.email-microsoft.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'security.email-microsoft.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/6436eaa9-620c-4127-a8f7-04fd8fab6a30/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--001838a0-10a4-50e2-aa04-a91291df7f68",
      "created": "2026-04-03T01:02:32.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-03T01:02:32.000Z",
      "name": "login-facebook-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'login-facebook-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/b80bb03f-c63c-4b96-baa2-c2e1b16636da/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fec7fdd7-b338-5c15-8cd6-689a5da8af43",
      "created": "2026-04-03T13:02:09.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-03T13:02:09.000Z",
      "name": "instagramchatsview999.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramchatsview999.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/b4747511-2c0f-4eaa-a2c2-90b6b078de4a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--79d1ee18-9512-5e05-af08-08b7440f16ea",
      "created": "2026-04-06T00:17:28.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-06T00:17:28.000Z",
      "name": "mail.google.com.drive.pratham.vincacybertechltd.myshn.net",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 21/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mail.google.com.drive.pratham.vincacybertechltd.myshn.net']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 21,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/e0fc0d6a-30eb-44e5-95e7-c9de5f1c71a2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53d343e8-b4a5-56b6-b52e-2d4df7c2b270",
      "created": "2026-04-06T00:19:10.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-06T00:19:10.000Z",
      "name": "appengine.google.com.drive.pratham.vincacybertechltd.myshn.net",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'appengine.google.com.drive.pratham.vincacybertechltd.myshn.net']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/ce027a28-bd07-4893-824d-8748649c05f7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8082e0a-ea8e-54e7-9a34-2ea992fc1221",
      "created": "2026-04-06T00:19:47.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-06T00:19:47.000Z",
      "name": "sites.google.com.drive.pratham.vincacybertechltd.myshn.net",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'sites.google.com.drive.pratham.vincacybertechltd.myshn.net']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/32d0540f-7b1d-443b-b729-3e572b09ec46/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0651e8f5-f8c1-5e49-a916-76f762834c1f",
      "created": "2026-04-06T00:21:19.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-06T00:21:19.000Z",
      "name": "docs.google.com.drive.pratham.vincacybertechltd.myshn.net",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'docs.google.com.drive.pratham.vincacybertechltd.myshn.net']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/ddb5da5a-d8ba-4020-acce-d1768d092ea9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e066dc5e-8c9d-55a0-83c7-993aa7752cb0",
      "created": "2026-04-06T19:16:59.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-06T19:16:59.000Z",
      "name": "google28.m4ntapaset.ink",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'google28.m4ntapaset.ink']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/49b95987-c97d-42f3-9934-eac843863e8e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b3c4d136-59b3-599c-9105-2200042f3b68",
      "created": "2026-04-07T08:06:51.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-07T08:06:51.000Z",
      "name": "netflix.gafiatechnologies.com",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflix.gafiatechnologies.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/a160a3d1-c6c6-4f43-8bad-85b3c9cabaf4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6017a993-af0e-5c04-b13f-bab6ce76ef23",
      "created": "2026-04-08T16:57:32.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-08T16:57:32.000Z",
      "name": "netflix.vpnuse.eu.org",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflix.vpnuse.eu.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/2ebcd388-fb85-408d-8bca-f8a462d22450/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fb6c5835-3342-5f18-b2a8-9c066ef211de",
      "created": "2026-04-09T10:48:53.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-09T10:48:53.000Z",
      "name": "google32.m4ntapaset.ink",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'google32.m4ntapaset.ink']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/44db2d27-f552-4451-ba9a-eac868a76b2e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--693cade1-4f13-5f68-ad64-e5c1713ad059",
      "created": "2026-04-10T13:00:48.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-10T13:00:48.000Z",
      "name": "www-google.cn",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 21/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'www-google.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 21,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/7a8456b0-f824-4119-b55b-66853add26e0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--20294497-8b0d-500d-9684-b6e9f4655349",
      "created": "2026-04-11T23:42:20.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-11T23:42:20.000Z",
      "name": "metamaskrewards.com",
      "description": "Suspicious phishing domain impersonating MetaMask, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'metamaskrewards.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/metamask/797a38d3-6cf2-4702-8a8a-8bf6d02e4274/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "metamask"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--461bae38-4c71-58d2-bed4-c19d0ed08138",
      "created": "2026-04-12T06:13:52.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-12T06:13:52.000Z",
      "name": "google29.m4ntapaset.ink",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'google29.m4ntapaset.ink']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/c4ce9464-81df-4160-be3b-fc295b05b1ab/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f517b2e-3ba0-5016-8a48-1833180ce80d",
      "created": "2026-04-14T17:31:32.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-14T17:31:32.000Z",
      "name": "googlepartners.net",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googlepartners.net']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/0e63d647-c1a8-4989-aeb9-9e9d6dee5118/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc53fa02-dc0c-58fc-aa80-ccbc44dba1eb",
      "created": "2026-04-14T19:15:44.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-14T19:15:44.000Z",
      "name": "www2-facebook.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'www2-facebook.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/d4e38cf6-76dd-44c4-9fb3-6cab6f74e8b2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ce6c8486-8a5f-51dc-9d8c-f1bb3195263a",
      "created": "2026-04-15T01:01:26.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-15T01:01:26.000Z",
      "name": "facebooktechnicalsupportnumber123.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooktechnicalsupportnumber123.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/75c26e14-e3a1-4e6b-82a4-e3f06369532a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6a4877c2-b026-52b0-8dd6-deb4072f5a86",
      "created": "2026-04-15T01:01:38.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-15T01:01:38.000Z",
      "name": "facebook-faq.se",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-faq.se']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/68ac2d26-7bbd-412d-80d1-89c400bcd7db/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b9ffd729-caa0-535b-bb54-67f79e4725c4",
      "created": "2026-04-15T13:05:01.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-15T13:05:01.000Z",
      "name": "metamaskwallett.blogspot.com",
      "description": "Suspicious phishing domain impersonating MetaMask, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'metamaskwallett.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/metamask/4ddb55e0-5e97-444b-b0e5-575de9079e2c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "metamask"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e3b55e7b-1aa0-5156-81f5-10549ed66e56",
      "created": "2026-04-15T13:05:36.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-15T13:05:36.000Z",
      "name": "barcelona-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'barcelona-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/2a0d0cb6-bf4b-4f09-a2f1-1f7dcd5a4884/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--74189061-9f4e-5d1b-8390-5dcfa2f810ae",
      "created": "2026-04-16T03:19:07.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-16T03:19:07.000Z",
      "name": "dropbox-online.at",
      "description": "Suspicious phishing domain impersonating Dropbox, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'dropbox-online.at']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dropbox/0e472d44-44a7-46e4-ab06-c2005153428a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dropbox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2ba8217b-f048-5f87-84fb-a66b6fca876c",
      "created": "2026-04-16T13:02:26.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-16T13:02:26.000Z",
      "name": "login-facebookaccount.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'login-facebookaccount.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/0333b97b-a734-490f-ae64-ef5f044e774c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--af7cb17c-b659-584d-9af5-cb36122831ce",
      "created": "2026-04-19T05:13:05.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-19T05:13:05.000Z",
      "name": "wwww-linkedin.be",
      "description": "Suspicious phishing domain impersonating LinkedIn, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'wwww-linkedin.be']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/linkedin/a65acfa6-028d-460a-a0ed-40999c638a76/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "linkedin"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d87afaf8-6546-56e5-ab17-8d8678337ba6",
      "created": "2026-04-20T01:01:08.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-20T01:01:08.000Z",
      "name": "reactivar-microsoft-live.iceiy.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'reactivar-microsoft-live.iceiy.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/eb4c633a-da19-40fb-a686-744a9b51c8e9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0d7bfb12-b4ff-5272-a064-6aec30841a0c",
      "created": "2026-04-20T13:01:03.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-20T13:01:03.000Z",
      "name": "instagramusicabrasilinstagram.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramusicabrasilinstagram.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/b4a247ca-c7f4-4d3c-9e86-c4d3c7134c3e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d8551c5e-afa7-5b12-a4e3-196596c1312e",
      "created": "2026-04-21T08:01:36.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-21T08:01:36.000Z",
      "name": "metamaskcasino.de.com",
      "description": "Suspicious phishing domain impersonating MetaMask, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'metamaskcasino.de.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/metamask/7c89960e-42f8-4ffa-a9b3-df06b8ebd969/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "metamask"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0b17563a-a9e7-50b2-b0a0-874b6b8ed264",
      "created": "2026-04-24T13:03:07.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-24T13:03:07.000Z",
      "name": "instagram-analytics.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-analytics.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/32e0de89-7d72-48cf-82a3-4a7758a839ac/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8864738-e49b-5ac2-b889-29c9f662cb4f",
      "created": "2026-04-26T13:00:40.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-26T13:00:40.000Z",
      "name": "cn-hsbc.foryour.review",
      "description": "Suspicious phishing domain impersonating HSBC, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'cn-hsbc.foryour.review']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/hsbc/62f33f52-975e-4787-a209-16a935e7a3db/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "hsbc"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b66d5041-1618-5f11-b95f-289324be2bee",
      "created": "2026-04-27T01:00:52.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-27T01:00:52.000Z",
      "name": "metamaskchromeextensionn.blogspot.com",
      "description": "Suspicious phishing domain impersonating MetaMask, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'metamaskchromeextensionn.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/metamask/c16ea253-83ee-43f3-b8e6-ec7deed57e9e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "metamask"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--68702e04-a08d-5875-b91c-a6152bf31caf",
      "created": "2026-04-27T17:28:14.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-27T17:28:14.000Z",
      "name": "netflix.surf",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflix.surf']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/9bc927e8-5168-4d9d-9b7b-6039503f3dad/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f3403270-9cfb-580b-83da-c87948344f9a",
      "created": "2026-04-29T04:57:15.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-29T04:57:15.000Z",
      "name": "mirror-google.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mirror-google.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/8accba84-7f36-4d6d-9da6-bec85059ca03/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--90a72f29-80f8-5452-9531-f0ed57bcb235",
      "created": "2026-04-29T13:00:56.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-29T13:00:56.000Z",
      "name": "netflixquebec.blogspot.com",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflixquebec.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/077cb309-7161-4cbc-bf56-455efb9c7b03/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2350b3a0-6cdc-5479-82d8-5f829f05a252",
      "created": "2026-04-30T01:01:21.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-30T01:01:21.000Z",
      "name": "trustwalletsupport.dev",
      "description": "Suspicious phishing domain impersonating Trust Wallet, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'trustwalletsupport.dev']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/trustwallet/57b747ea-d78d-4f32-8c5f-1d5579eefa34/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "trustwallet"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da7b3727-45ab-5b39-b4c0-6358cc3dc3c2",
      "created": "2026-04-30T21:44:28.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-04-30T21:44:28.000Z",
      "name": "googlelogos.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googlelogos.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/7d7a9fb0-4cad-4f9d-a54a-28881c88321b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--192e6103-8e3b-5530-b419-8ad1600ad754",
      "created": "2026-05-01T01:01:07.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-01T01:01:07.000Z",
      "name": "paypal-logiin.blogspot.com",
      "description": "Suspicious phishing domain impersonating PayPal, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'paypal-logiin.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/paypal/6e1c5536-f5b2-4416-93be-43b00952d7fd/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "paypal"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f109517-6a11-52e4-a35c-c5962ad60201",
      "created": "2026-05-01T03:28:24.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-01T03:28:24.000Z",
      "name": "hot-binance.com.cn",
      "description": "Suspicious phishing domain impersonating Binance, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'hot-binance.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/binance/2ee88ac9-fa57-425d-9a65-e8a82e947d0c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "binance"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9655dcb6-29d3-516d-8c16-e5e29f881738",
      "created": "2026-05-01T09:49:31.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-01T09:49:31.000Z",
      "name": "facebooktotranscript.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooktotranscript.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/e721ebaa-595f-4e39-a0bf-4bf3026fbc9f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--61c966ba-82e9-549c-bebc-da648770279a",
      "created": "2026-05-01T21:31:38.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-01T21:31:38.000Z",
      "name": "zelleria.shop",
      "description": "Suspicious phishing domain impersonating Zelle, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'zelleria.shop']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/zelle/61a4fa9e-c2b5-4dd1-904f-6e93a11a77f1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "zelle"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cde3e421-4c0d-5c2f-a051-1b89601b1f5e",
      "created": "2026-05-05T13:02:59.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-05T13:02:59.000Z",
      "name": "outlook.webaccess-alert.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'outlook.webaccess-alert.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/d15fc3b0-a9e7-4d75-bab2-2649389605c1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3a38341d-bc51-5c54-9612-736f279e165a",
      "created": "2026-05-06T13:03:34.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-06T13:03:34.000Z",
      "name": "instagram-login-user.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-login-user.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/c6a7381e-f34b-4c06-82f7-f5e544fb63c4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b82bc075-2d09-5efe-83ec-0f273f7e03b6",
      "created": "2026-05-10T09:44:25.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-10T09:44:25.000Z",
      "name": "microsoft-se.us",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoft-se.us']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/30c841f6-3b6b-454c-a357-beb8a4f0538d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f6c005d4-24eb-5564-a502-e4c46ef8dbe2",
      "created": "2026-05-10T18:26:51.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-10T18:26:51.000Z",
      "name": "facebookpagemanagement.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookpagemanagement.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/7b43c3f0-cd50-41d8-a527-ce2f2bd49999/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e9525892-fe39-5714-a1e1-d2fad120922c",
      "created": "2026-05-10T19:21:43.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-10T19:21:43.000Z",
      "name": "hsbc.dev",
      "description": "Suspicious phishing domain impersonating HSBC, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'hsbc.dev']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/hsbc/c9fb55c3-5023-4688-bf63-49db5cbc9bca/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "hsbc"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--91d56ee9-158b-5184-a6e3-0612ee171b0b",
      "created": "2026-05-12T10:55:45.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-12T10:55:45.000Z",
      "name": "admin.santandercitas.com",
      "description": "Suspicious phishing domain impersonating Banco Santander, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'admin.santandercitas.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/santander/5598e82b-8927-43fb-820b-74166b4d8b30/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "santander"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eab58c6b-53ef-5fce-a396-4ac7a8088801",
      "created": "2026-05-13T01:01:06.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-13T01:01:06.000Z",
      "name": "facebook-facebook45sr.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-facebook45sr.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/4b0c0da4-8b6a-4710-8c34-b341b903abac/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--65886790-167e-551f-9f30-bfad8cc94e52",
      "created": "2026-05-13T09:07:54.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-13T09:07:54.000Z",
      "name": "metamaskcasino.de",
      "description": "Suspicious phishing domain impersonating MetaMask, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'metamaskcasino.de']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/metamask/32d09389-a6b6-4b7d-a623-fdff85b87450/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "metamask"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e74c1fdb-291d-5850-89a0-ec74e94f86b1",
      "created": "2026-05-13T13:05:07.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-13T13:05:07.000Z",
      "name": "microsoft.account.trustedentity.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoft.account.trustedentity.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/73b4c145-55d6-4fa2-a656-04693699e177/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bdc59e59-1b15-58aa-80aa-c8959647fdd9",
      "created": "2026-05-14T21:20:02.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-14T21:20:02.000Z",
      "name": "netflixvoid.org",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflixvoid.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/312894ae-59b1-47fb-aad4-a563b4f71f0d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fc9fd9bf-9425-58aa-bb8f-a1e72cfc7df1",
      "created": "2026-05-15T12:28:28.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-15T12:28:28.000Z",
      "name": "ch-google.cc",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ch-google.cc']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/fe4d9962-ca12-4441-a826-73e9d6685428/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dbac8fa8-393d-52e7-98dd-dd023d453009",
      "created": "2026-05-15T13:01:41.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-15T13:01:41.000Z",
      "name": "microsoft.authorised-support.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoft.authorised-support.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/35cf8842-624d-4ec3-9c77-8fc11370fa98/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--12462eb4-33d2-5d9f-a31d-40f025033ddf",
      "created": "2026-05-18T20:16:35.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-18T20:16:35.000Z",
      "name": "netflixandchiffres.com",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflixandchiffres.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/6bef9e46-76a5-429d-a18f-73179ea7462e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8e6cfa7f-26d3-5bae-b286-71ea53e37b38",
      "created": "2026-05-20T21:10:29.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-20T21:10:29.000Z",
      "name": "binanceaa.com",
      "description": "Suspicious phishing domain impersonating Binance, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'binanceaa.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/binance/7d576ea9-ddd4-4ee0-856b-87a6d5edc67f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "binance"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ca85b11-38d9-520c-9416-6ff1e3e08e74",
      "created": "2026-05-20T21:10:59.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-20T21:10:59.000Z",
      "name": "binanceii.com",
      "description": "Suspicious phishing domain impersonating Binance, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'binanceii.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/binance/0d8aeff8-712a-448f-af11-bb2b3b7669e9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "binance"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f6813c0a-816c-5e44-8c12-a02ba4622f9f",
      "created": "2026-05-20T21:11:30.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-20T21:11:30.000Z",
      "name": "binancenn.com",
      "description": "Suspicious phishing domain impersonating Binance, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'binancenn.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/binance/a370eb2c-a522-4ed2-920e-a86bb1afc60b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "binance"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e7093180-18bf-5819-9813-c8dd719ec420",
      "created": "2026-05-24T16:25:41.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-24T16:25:41.000Z",
      "name": "hsbcpress.com",
      "description": "Suspicious phishing domain impersonating HSBC, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'hsbcpress.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/hsbc/15ac3363-2d93-423e-b5a6-063f1069c490/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "hsbc"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0151da00-a7f5-5ab4-9b15-a279a56434bf",
      "created": "2026-05-26T06:44:34.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-26T06:44:34.000Z",
      "name": "business-dropbox.me",
      "description": "Suspicious phishing domain impersonating Dropbox, detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'business-dropbox.me']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dropbox/12a13552-7405-46e2-a392-8cb82f667d58/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dropbox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e03cde66-4dc1-5883-8c64-8a13db0a0fdb",
      "created": "2026-05-26T08:35:15.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-26T08:35:15.000Z",
      "name": "dropboxbiz.com",
      "description": "Suspicious phishing domain impersonating Dropbox, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'dropboxbiz.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dropbox/55ab06a2-304f-4984-a73d-911575c56f2c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dropbox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd144008-bf04-5ad4-8ba1-a4c17f16d675",
      "created": "2026-05-30T08:31:28.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-30T08:31:28.000Z",
      "name": "dropbox-online.net",
      "description": "Suspicious phishing domain impersonating Dropbox, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'dropbox-online.net']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dropbox/d0d96e4b-23c6-47db-8409-b2c4bfca0581/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dropbox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--63866830-b3bb-5934-86f1-5e6f4f6935bc",
      "created": "2026-05-30T10:08:11.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-30T10:08:11.000Z",
      "name": "netflixtunisie.com.tn",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflixtunisie.com.tn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/379fa87e-860f-429e-acba-9a8540dea351/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--39e7ab7a-fbbc-5a5c-950c-0906ee0f01a8",
      "created": "2026-05-31T00:35:23.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-31T00:35:23.000Z",
      "name": "www-hk-google.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'www-hk-google.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/a9fb5cc4-c17c-4df1-b5ad-ea7986423a71/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0efd2edd-c94c-5a19-a3ef-b5bb415f86d0",
      "created": "2026-05-31T03:57:14.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-31T03:57:14.000Z",
      "name": "openai-coin.com",
      "description": "Suspicious phishing domain impersonating ChatGPT, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'openai-coin.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/chatgpt/50c32c94-c40a-4803-85a0-64163d17b77d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "chatgpt"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0d234ef-380f-505c-afaa-e27a1c7d3742",
      "created": "2026-05-31T06:52:47.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-05-31T06:52:47.000Z",
      "name": "best-credit-card-for-facebook-ads.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'best-credit-card-for-facebook-ads.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/75a6045c-89f1-4633-a1c6-6f1bb0bba206/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--568f0ad2-5752-554b-990a-5b8ed52edd30",
      "created": "2026-06-02T07:31:37.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-02T07:31:37.000Z",
      "name": "mobile-google.cn",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mobile-google.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/e3181001-316d-416f-833a-2332736b6d6a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--52a925ec-07e8-5b70-99c4-a858e86dc9cb",
      "created": "2026-06-02T13:02:34.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-02T13:02:34.000Z",
      "name": "netflix-uat.dblxhosting.co.uk",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflix-uat.dblxhosting.co.uk']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/2557c989-e4c6-4e41-b3b6-4259c4ccbf8f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--66a3f5b5-cb6f-5167-a5a7-6d7b187ba364",
      "created": "2026-06-05T18:48:29.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-05T18:48:29.000Z",
      "name": "netflixseeker.com",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflixseeker.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/b3d0ee43-c5de-43cb-95d1-2ad0ffda8ab3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--afeea8e5-17e2-56b0-8216-3543dac53622",
      "created": "2026-06-06T01:02:06.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-06T01:02:06.000Z",
      "name": "security.m365-microsoft.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'security.m365-microsoft.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/d5cb6a39-23cf-49f4-a25e-0ffd83801c0f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2709e2ba-11a4-5414-b4b5-61e919a35b68",
      "created": "2026-06-08T13:01:32.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-08T13:01:32.000Z",
      "name": "programme-hup.m365-microsoft.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'programme-hup.m365-microsoft.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/872fb8e2-403a-45ce-b2dc-518ebacf7fab/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aafe32ff-a07f-590c-bf35-c6668ba658fa",
      "created": "2026-06-09T15:34:09.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-09T15:34:09.000Z",
      "name": "hsbc-sec.com",
      "description": "Suspicious phishing domain impersonating HSBC, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'hsbc-sec.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/hsbc/65d1e6ec-962a-4743-a2fd-cedbf57bb9ed/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "hsbc"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a9c2df01-ba19-532f-bfca-b84657d24a9b",
      "created": "2026-06-10T13:02:03.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-10T13:02:03.000Z",
      "name": "binancelivetrade.blogspot.com",
      "description": "Suspicious phishing domain impersonating Binance, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'binancelivetrade.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/binance/c6f65415-24ff-4272-bc15-0ad191ccf02b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "binance"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8efdbee6-7000-5392-a667-fe7767f7f408",
      "created": "2026-06-12T01:01:41.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-12T01:01:41.000Z",
      "name": "a2zapk.co",
      "description": "Suspicious phishing domain impersonating Spotify, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'a2zapk.co']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/spotify/3de207bc-7431-4f8a-bb71-2e6de6865202/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "spotify"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c29b12aa-a5e4-54ec-9bf9-1b7fdf97edf9",
      "created": "2026-06-13T01:03:15.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-13T01:03:15.000Z",
      "name": "profil-facebook-saya.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'profil-facebook-saya.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/9ae63765-78b0-497b-9c07-7aa584237f4b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b9773bbe-907b-5b5d-b7bd-9474de82c40c",
      "created": "2026-06-13T13:01:33.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-13T13:01:33.000Z",
      "name": "facebook-networks.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-networks.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/91922a27-129c-4ca9-a003-63456945b7ed/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8473492-dc5d-50d6-b06c-ea7f5241ba7a",
      "created": "2026-06-13T13:02:25.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-13T13:02:25.000Z",
      "name": "facebook-profile-login.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-profile-login.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/746e1f33-2b40-4553-836c-250a9fc582a5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--755a82c9-4081-5846-bc98-8853d45f6161",
      "created": "2026-06-13T23:31:11.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-13T23:31:11.000Z",
      "name": "hsbcbankuk.ws",
      "description": "Suspicious phishing domain impersonating HSBC, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'hsbcbankuk.ws']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/hsbc/1ef59bcf-4fcc-4a25-8bb9-73a65cf87d4c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "hsbc"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eadd3244-230a-5df6-bfad-83699a1e65dc",
      "created": "2026-06-15T13:02:34.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-15T13:02:34.000Z",
      "name": "chatgpt0005.eu.org",
      "description": "Suspicious phishing domain impersonating ChatGPT, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'chatgpt0005.eu.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/chatgpt/4c262625-576b-4c6c-9cdc-19a6b6e1efbc/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "chatgpt"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f7a139ea-7ff0-593a-902d-bf6497104daf",
      "created": "2026-06-16T08:30:25.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-16T08:30:25.000Z",
      "name": "393bet-facebook.sa.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '393bet-facebook.sa.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3903b5ce-15fc-4265-8673-cfd37c11db8a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8360f59e-6c12-5c6b-b4ae-c9ee4e43885e",
      "created": "2026-06-17T01:06:27.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-17T01:06:27.000Z",
      "name": "office365.rricrosoft-offices.org",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 18/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'office365.rricrosoft-offices.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 18,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/935697ea-6413-4c0c-b711-21baf1e8d028/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9a5e215e-c26f-54ab-a85b-9c6145daa662",
      "created": "2026-06-17T13:01:02.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-17T13:01:02.000Z",
      "name": "spotify-modapk.com",
      "description": "Suspicious phishing domain impersonating Spotify, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'spotify-modapk.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/spotify/9e7ca879-4a15-440a-aa7d-342cb1677655/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "spotify"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c1ea151d-c3cb-58fc-b225-78bba7e7b2c8",
      "created": "2026-06-22T13:00:58.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-22T13:00:58.000Z",
      "name": "interbank.protected-request.com",
      "description": "Suspicious phishing domain impersonating Interbank, detected by phishunt.io (score 18/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'interbank.protected-request.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 18,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/interbank/313179bb-c525-4cde-89a3-1b5250130e13/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "interbank"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7873cf3a-2fbb-5f1e-b1f5-433ffa198390",
      "created": "2026-06-23T02:00:34.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-23T02:00:34.000Z",
      "name": "googleplaydown.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googleplaydown.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/fa8dd605-6316-4ade-a08f-5042b15f3025/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c0d8e7d3-645a-56a3-ae2b-b01b960b93c8",
      "created": "2026-06-23T13:00:57.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-23T13:00:57.000Z",
      "name": "iniciamazon.com.br",
      "description": "Suspicious phishing domain impersonating Amazon, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'iniciamazon.com.br']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/amazon/866b92f0-db6e-45b9-ac06-cc35e6885e01/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "amazon"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--66cba592-c692-57c5-a5ff-b37a4d91c948",
      "created": "2026-06-24T13:02:03.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-24T13:02:03.000Z",
      "name": "my-facebook-blog.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'my-facebook-blog.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/067e2e22-fba5-4dd0-997d-31116b888e00/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--13247417-8473-5fc4-a514-0244d5a0d949",
      "created": "2026-06-25T01:01:38.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-25T01:01:38.000Z",
      "name": "correosprepago.bnext.es",
      "description": "Suspicious phishing domain impersonating Correos, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'correosprepago.bnext.es']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/correos/c28cb635-85de-4b87-8a55-c985f49fd5b3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "correos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--58443963-55f5-5c06-9b28-021e1dc466eb",
      "created": "2026-06-25T05:54:49.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-25T05:54:49.000Z",
      "name": "microsoftjk.eu.org",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoftjk.eu.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/4cef2ef8-eb5a-4536-8328-f692a8c4c350/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e74fb6fb-db6f-5d47-9cd8-07338928c45f",
      "created": "2026-06-25T13:01:23.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-25T13:01:23.000Z",
      "name": "microsoft-login-securitylogin.jimdofree.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoft-login-securitylogin.jimdofree.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/c4a2f81e-f2b3-41a5-8a56-9968bb8ff0e9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--04d75b80-41e9-502c-b307-79bfee2f3ab1",
      "created": "2026-06-25T13:01:31.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-25T13:01:31.000Z",
      "name": "outlook.verifytoken.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'outlook.verifytoken.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/efa8482f-552c-4f11-95de-4f96eb842791/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--56ab4ea1-987a-5094-902f-e1c85519de78",
      "created": "2026-06-26T01:01:52.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-26T01:01:52.000Z",
      "name": "facebookpage-noreplycenter.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookpage-noreplycenter.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/6628370d-31de-4efd-9e30-0721c7b101e8/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--11ce033d-79d8-5703-9835-3aa456ae92f9",
      "created": "2026-06-26T01:01:59.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-26T01:01:59.000Z",
      "name": "onedrive.at-us.therelayservice.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 19/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'onedrive.at-us.therelayservice.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 19,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/0fb7d6c7-9891-450b-8cef-f0fe730025c5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f1b9738-a942-5152-8b5c-462da43f907d",
      "created": "2026-06-27T01:01:31.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-27T01:01:31.000Z",
      "name": "ctia-outlook-2026.s1.yapla.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ctia-outlook-2026.s1.yapla.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/9fe477d6-026a-4435-b793-043ce1128b7a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff882705-3ce2-56a4-86d6-8f75ef1a044f",
      "created": "2026-06-27T01:02:06.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-27T01:02:06.000Z",
      "name": "accounts.binanceuz.co",
      "description": "Suspicious phishing domain impersonating Binance, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'accounts.binanceuz.co']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/binance/55c4f70b-a1a3-443b-8881-4c3cc69c6ccc/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "binance"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--012b1613-ff44-5e2e-9e5c-80c02e3e6154",
      "created": "2026-06-28T13:00:56.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-28T13:00:56.000Z",
      "name": "facebookaccountsmanager.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookaccountsmanager.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/1cc6789a-f402-4455-ae92-c081c30ed3b3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--55738aa4-a19d-5cf4-a5e8-80e9e332864e",
      "created": "2026-06-29T01:01:24.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-29T01:01:24.000Z",
      "name": "dropbox.rev.it",
      "description": "Suspicious phishing domain impersonating Dropbox, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'dropbox.rev.it']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dropbox/aaad6147-bd2e-4bdd-8ce0-2485cf1bee33/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dropbox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ab7cf1a7-97ee-5149-94ab-f9d843c2568c",
      "created": "2026-06-29T01:02:14.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-29T01:02:14.000Z",
      "name": "paypal-signin.blogspot.com",
      "description": "Suspicious phishing domain impersonating PayPal, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'paypal-signin.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/paypal/3f27a26c-323a-47fc-88fc-f471670ae530/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "paypal"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fd329dd0-44f9-5bf6-bd38-41e86cffc712",
      "created": "2026-06-30T01:01:33.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-30T01:01:33.000Z",
      "name": "facebooklogin-page.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin-page.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/4c930f97-8b09-48dd-8303-ff370d1e772b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3a289a04-469e-5a28-865b-ea77314a5dda",
      "created": "2026-06-30T01:01:40.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-30T01:01:40.000Z",
      "name": "facebook-login-help.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-login-help.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/be23a83e-e18e-4464-9c5b-3698af913d4e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--83d57d8f-548d-5476-bf57-e1cc3697a1f5",
      "created": "2026-06-30T13:01:07.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-30T13:01:07.000Z",
      "name": "barclays-grads.twineapp.com",
      "description": "Suspicious phishing domain impersonating Barclays, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'barclays-grads.twineapp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/barclays/7c3cdb2c-9316-415d-bdbd-597b52ee9285/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "barclays"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--274bf19c-fcec-51ca-bf01-721501a65660",
      "created": "2026-06-30T13:01:19.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-06-30T13:01:19.000Z",
      "name": "facebookloginpage2.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginpage2.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/aae47088-ee01-497b-89ec-0ec437bcbbad/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fbbb77cf-5eb9-5a61-9e1f-a710f0c678b8",
      "created": "2026-07-01T01:01:39.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-01T01:01:39.000Z",
      "name": "barclays-grads.twinehr.com",
      "description": "Suspicious phishing domain impersonating Barclays, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'barclays-grads.twinehr.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/barclays/b54a63fc-58ad-470e-b386-0e5ea8de3dc4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "barclays"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3388853c-c5c7-51ea-93b2-48d6618d250d",
      "created": "2026-07-01T16:46:30.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-01T16:46:30.000Z",
      "name": "netflix6.com",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflix6.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/734bbba7-7f04-4bb1-bd45-03269854b487/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87c47f48-f1fa-5d68-b4e5-f20c8c974eca",
      "created": "2026-07-02T01:02:18.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-02T01:02:18.000Z",
      "name": "forsakens-crew-teman-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'forsakens-crew-teman-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/5c41e70b-fd5e-495e-8295-0a41437ac95f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d0977715-62ac-512f-8240-57a48172b30b",
      "created": "2026-07-02T13:00:45.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-02T13:00:45.000Z",
      "name": "facebookprofilelinks.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookprofilelinks.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/1f191046-d288-465a-aeaf-aaef3a03a730/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d0ac43a5-9675-5ba8-b526-4f2ab484795f",
      "created": "2026-07-04T01:01:14.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-04T01:01:14.000Z",
      "name": "uspsaunitedworkforce.com",
      "description": "Suspicious phishing domain impersonating USPS, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'uspsaunitedworkforce.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/usps/06871f43-deaa-4811-a2f1-e82cd8764593/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "usps"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc934cdc-e48f-54a9-ab48-738757fa9aae",
      "created": "2026-07-04T13:01:14.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-04T13:01:14.000Z",
      "name": "netflixfeitoaqui.com.br",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflixfeitoaqui.com.br']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/719d4201-c686-4bf8-94c8-748202e55be6/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8014971e-54aa-5213-acd3-ccf434b39e80",
      "created": "2026-07-04T13:01:34.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-04T13:01:34.000Z",
      "name": "fifaworldcupgiveaway.com",
      "description": "Suspicious phishing domain impersonating FIFA World Cup, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'fifaworldcupgiveaway.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/fifa/18097bc0-ede8-40aa-9576-2d0f98535be3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "fifa"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e65668cc-9a58-5a7d-b3b1-3e968764d93c",
      "created": "2026-07-05T01:02:16.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-05T01:02:16.000Z",
      "name": "netflixhasnohomepage.com",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflixhasnohomepage.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/13a88bbb-e831-42e4-9343-a888f00f47b3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e1b2599d-6bce-5fc2-b969-2a17a63602c7",
      "created": "2026-07-05T10:33:18.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-05T10:33:18.000Z",
      "name": "ggzh-google.com.cn",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ggzh-google.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/c4ad994c-be5c-4092-9012-9a23e2efa1ad/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c7b02b73-bf49-5150-a96f-c989f06099c8",
      "created": "2026-07-06T12:07:04.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-06T12:07:04.000Z",
      "name": "spotifyzonepro-dl.fwh.is",
      "description": "Suspicious phishing domain impersonating Spotify, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'spotifyzonepro-dl.fwh.is']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/spotify/b9cf6e3c-1c3e-4c76-82f0-e484bc2c8d4f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "spotify"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5ade31cc-5f30-5af2-b5df-b4bf918615de",
      "created": "2026-07-06T12:07:07.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-06T12:07:07.000Z",
      "name": "spotifysvotingslink.ct.ws",
      "description": "Suspicious phishing domain impersonating Spotify, detected by phishunt.io (score 21/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'spotifysvotingslink.ct.ws']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 21,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/spotify/c1479453-b303-4f32-908b-c1f240fd17a5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "spotify"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--12aa3b80-7dd8-5db0-b809-8baacd511f58",
      "created": "2026-07-08T13:00:59.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-08T13:00:59.000Z",
      "name": "facebook-seks-32.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-seks-32.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c883d791-422e-4cab-a04b-4300ff09d7d5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--861ba7aa-e9dd-5c5a-8d11-ed2c7b13696c",
      "created": "2026-07-09T13:01:50.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-09T13:01:50.000Z",
      "name": "facebook-login-pages.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-login-pages.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/a0ce4b87-ad9f-4a4b-a08b-bf4ba88f05e2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a4c7284a-7e95-5624-b263-03f62b3011c1",
      "created": "2026-07-09T13:01:55.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-09T13:01:55.000Z",
      "name": "test-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'test-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/45e96f70-861f-4611-8441-d1177adadd94/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6160c1cc-3b17-5726-b6ab-acab5304fba7",
      "created": "2026-07-09T13:01:57.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-09T13:01:57.000Z",
      "name": "facebook-seks-35.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-seks-35.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/54603dc9-a00d-47a2-bb20-1b14e4f558ea/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0de49a95-b9de-58bc-8353-eb6ec111908c",
      "created": "2026-07-09T13:02:04.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-09T13:02:04.000Z",
      "name": "s-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 's-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/efbd49f1-27d7-4ff9-b28e-001e7d2c11fc/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ec97f4f-e47d-5ceb-a39e-5e0ce8650e9f",
      "created": "2026-07-09T13:02:17.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-09T13:02:17.000Z",
      "name": "berbagi-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'berbagi-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/9d22f15f-4019-45d9-b131-cb5ebd54e52f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4822a7e2-a403-5256-ae98-2cdf4dadb789",
      "created": "2026-07-09T13:02:18.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-09T13:02:18.000Z",
      "name": "facebook-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/0ccb315b-5189-4564-bf62-c44c5f147870/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--49126807-35c5-5c9c-ab75-e0deb554cd4d",
      "created": "2026-07-09T13:02:21.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-09T13:02:21.000Z",
      "name": "network-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'network-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/243ea18e-54e1-442b-9694-077ee5dc6cb4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--31f05c1a-0496-5a58-b0f7-c94f0d6fb8da",
      "created": "2026-07-10T01:01:22.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-10T01:01:22.000Z",
      "name": "facebook-fake.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-fake.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/0cb5a7de-8102-44b9-83fa-704fa22c0f1c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--182c4409-0ceb-5cec-a86a-2c9f2f4d3e4c",
      "created": "2026-07-10T01:01:43.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-10T01:01:43.000Z",
      "name": "free-facebook-page-likes.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'free-facebook-page-likes.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/7f2050f8-e48b-4e5b-9e77-201aa3f06504/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1450a77a-3500-53c2-8808-62394fa20ad9",
      "created": "2026-07-10T01:01:45.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-10T01:01:45.000Z",
      "name": "facebook-prime.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-prime.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/d27131a8-4a89-4631-b7e4-e6b0c900310d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6cc6638e-fd23-51de-a00f-aa95dff45f32",
      "created": "2026-07-10T01:02:03.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-10T01:02:03.000Z",
      "name": "facebook-alpha.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-alpha.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/04389915-cf92-4c87-bbb0-34f423eca564/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--874da8c1-daf8-596b-a1b1-d5bf56a32034",
      "created": "2026-07-10T01:02:08.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-10T01:02:08.000Z",
      "name": "facebook-video-share.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-video-share.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/330d8b69-2865-4a04-a132-795fd49ed88b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53b7735e-4481-56f5-84d0-f0c53a54ddfe",
      "created": "2026-07-10T13:02:51.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-10T13:02:51.000Z",
      "name": "facebook-photo5.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-photo5.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/92cc5618-7491-44a1-94db-45804d3aa6b2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--109caf92-0736-5338-a538-d21b1ecf5bce",
      "created": "2026-07-10T13:02:52.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-10T13:02:52.000Z",
      "name": "facebookloginconfirm.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginconfirm.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/e0304d91-e069-418e-a00b-41ab7e63a468/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8cf34259-4095-5a1c-9869-bcdc99830643",
      "created": "2026-07-10T13:03:00.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-10T13:03:00.000Z",
      "name": "facebooklogin123.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin123.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/9b0d7ce5-88e8-4803-96fc-8152961d36eb/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3f0845a6-2238-51f8-b118-63f27fc42291",
      "created": "2026-07-10T13:04:27.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-10T13:04:27.000Z",
      "name": "ml-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ml-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c6f5028d-441a-403a-b45c-53f8318cb928/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1e20afef-1d6b-5b44-8b42-40b94d2eb756",
      "created": "2026-07-10T13:05:12.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-10T13:05:12.000Z",
      "name": "facebook-seks-44.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-seks-44.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/becb947e-f649-4ccc-a012-e0de425bbe54/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4c9845e0-b707-54ba-a526-5b015e980a46",
      "created": "2026-07-11T01:01:27.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-11T01:01:27.000Z",
      "name": "facebookmail-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookmail-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/e54e2f0a-4fc5-49b0-a9f6-3625f6c3cd13/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--974bc968-7e49-5a82-895a-68d90e254516",
      "created": "2026-07-11T01:01:53.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-11T01:01:53.000Z",
      "name": "cz-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'cz-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/da5846e9-fcad-4207-bf32-664565c99c68/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c081ed4-0cea-5178-8da4-6e8d2fccbd13",
      "created": "2026-07-11T13:03:28.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-11T13:03:28.000Z",
      "name": "facebook-seks-27.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-seks-27.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/194e057b-cbc4-456f-aa46-8a94af00a764/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d8daa440-1b2c-5eaf-be7f-48265ba2a3aa",
      "created": "2026-07-11T13:03:35.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-11T13:03:35.000Z",
      "name": "facebook-system.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-system.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/84d069be-13aa-4361-a8d1-6da4f4ae969b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ee944fc5-da8f-5308-bcd1-3a6655411019",
      "created": "2026-07-11T13:04:00.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-11T13:04:00.000Z",
      "name": "facebookloginf.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginf.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/9a2f0c44-3d27-4619-96ba-14db85ec0138/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8119ccd-77ff-5b1c-a5c5-a5a1c3791e38",
      "created": "2026-07-11T13:04:08.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-11T13:04:08.000Z",
      "name": "facebook-carol.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-carol.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/263a7ce5-27df-45c3-95b3-dfd6c3bec3f1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c3451ae9-8f45-5fa0-97e2-32e56e65b320",
      "created": "2026-07-11T13:04:09.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-11T13:04:09.000Z",
      "name": "facebook-logo.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-logo.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/193564d5-c343-43ef-b213-c67247cbe41d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--34fd1bde-5544-571f-a3cc-0ac6fdf039c5",
      "created": "2026-07-11T13:04:21.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-11T13:04:21.000Z",
      "name": "facebookcomfacebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookcomfacebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/5a939c28-4ff9-47ab-8a45-5db3fd517b09/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b9d1ae5-36bd-5d82-8bef-776585716464",
      "created": "2026-07-11T19:51:26.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-11T19:51:26.000Z",
      "name": "play.googleplaety.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'play.googleplaety.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/ddba8628-a2cb-4d98-830e-98fd9ef45f2b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e9073567-6272-537d-a8c3-a6c7b55bfd48",
      "created": "2026-07-11T19:51:26.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-11T19:51:26.000Z",
      "name": "ingdirect-cliente-gestion.com",
      "description": "Suspicious phishing domain impersonating ING Espa\u00f1a, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ingdirect-cliente-gestion.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ingspain/cf141307-2c57-44bb-bdf6-f1cc5639af50/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ingspain"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3ae8277a-44be-51ad-844d-b29d940b9480",
      "created": "2026-07-12T01:02:21.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-12T01:02:21.000Z",
      "name": "app81-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'app81-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/945ed8a4-192c-4c36-a89d-e9591a57ebac/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--949d11cc-308c-5188-a57d-bc2f6ef4e271",
      "created": "2026-07-12T01:02:55.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-12T01:02:55.000Z",
      "name": "pe-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'pe-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/201e4501-6dfd-4eda-baed-200cdc85547b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--71445875-90a3-550d-8f92-844381589dc4",
      "created": "2026-07-12T01:02:59.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-12T01:02:59.000Z",
      "name": "facebook-verification-system3.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-verification-system3.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/1f33ee25-77ee-4a72-b6aa-989fbdd78797/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c60cfa4a-64d7-55a2-9416-e990dbecc330",
      "created": "2026-07-12T01:03:06.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-12T01:03:06.000Z",
      "name": "metamasklskog.gitbook.io",
      "description": "Suspicious phishing domain impersonating MetaMask, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'metamasklskog.gitbook.io']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/metamask/f0c7c137-c905-495b-bba7-25f07c30a2c5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "metamask"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c728e095-9f0b-5a14-b87e-29c1ec73099e",
      "created": "2026-07-12T13:01:31.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-12T13:01:31.000Z",
      "name": "mb-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mb-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3563f3a1-cd54-4deb-bc94-f94482855ef1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9917d971-3974-5ccc-b8dc-5492e24391f7",
      "created": "2026-07-12T13:01:38.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-12T13:01:38.000Z",
      "name": "facebook-new-security.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-new-security.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/7a255b02-374d-4855-b3e9-ddcf7b2d8291/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--54d523b4-ef55-5bc4-9c77-f03106ef7e21",
      "created": "2026-07-12T13:01:41.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-12T13:01:41.000Z",
      "name": "facebook--br.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook--br.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3594fa2f-3031-4b6d-9a44-9f366f8ae90a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--baafccbb-926e-5d08-b604-444cf5153884",
      "created": "2026-07-12T13:01:51.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-12T13:01:51.000Z",
      "name": "click-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'click-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3c227bb5-1e31-400c-bf22-c4205ec2c13c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c11914f-0b51-5190-96cd-ebd274bf23b0",
      "created": "2026-07-12T13:01:52.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-12T13:01:52.000Z",
      "name": "online-facebook-privacy.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'online-facebook-privacy.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/735913fc-d4d3-4ad1-b2d7-33c9bb6555a4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d18fe183-8d73-5daf-8a28-8ae92622ac81",
      "created": "2026-07-12T15:41:21.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-12T15:41:21.000Z",
      "name": "click5.microsoftsupportcenter.digital",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'click5.microsoftsupportcenter.digital']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/1da42bf9-a9be-4b92-b23b-cbe979eee023/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--48580561-6d6c-564f-81e5-6ce419954b78",
      "created": "2026-07-12T15:41:21.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-12T15:41:21.000Z",
      "name": "ingdirect-alerta-clientes.com",
      "description": "Suspicious phishing domain impersonating ING Espa\u00f1a, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ingdirect-alerta-clientes.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ingspain/13b037cb-a3c8-4cca-8053-f481f2720efa/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ingspain"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f8f42792-a506-55e2-9c99-c775f86ab829",
      "created": "2026-07-12T15:41:21.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-12T15:41:21.000Z",
      "name": "ingdirect-gestiones-incidencia.com",
      "description": "Suspicious phishing domain impersonating ING Espa\u00f1a, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ingdirect-gestiones-incidencia.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ingspain/eb5aaa78-6688-4685-939c-7b6debe3995c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ingspain"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--952fc023-a831-5328-9185-31b3dfe32b2f",
      "created": "2026-07-12T15:41:22.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-12T15:41:22.000Z",
      "name": "bb.google77bd.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 21/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bb.google77bd.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 21,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/2cc9f36e-9c2d-42c7-8452-d0e8ee863ca0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fcfba7e4-6842-5c9f-81fb-8eb6825e74da",
      "created": "2026-07-12T15:41:23.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-12T15:41:23.000Z",
      "name": "googlebusiness.xyz",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googlebusiness.xyz']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/23a7c852-6d1f-4bb7-bf1a-58fdf18b6eca/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2aaf73a3-6ebb-5780-b5fb-8cc8833fc805",
      "created": "2026-07-12T15:41:23.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-12T15:41:23.000Z",
      "name": "ingdirect-usuario-soporte.com",
      "description": "Suspicious phishing domain impersonating ING Espa\u00f1a, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ingdirect-usuario-soporte.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ingspain/b75cdb17-191a-41ae-84da-076d97475730/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ingspain"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5d234ea1-178c-5eba-bd54-8eb106082ed2",
      "created": "2026-07-12T15:41:24.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-12T15:41:24.000Z",
      "name": "ingdirect-clientes-alerta.com",
      "description": "Suspicious phishing domain impersonating ING Espa\u00f1a, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ingdirect-clientes-alerta.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ingspain/c4f0a746-1867-489c-be4d-f7c5b6c204ee/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ingspain"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4a84549-34d8-5a16-af09-e8953046657c",
      "created": "2026-07-12T15:41:24.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-12T15:41:24.000Z",
      "name": "ingdirect-web-validado.com",
      "description": "Suspicious phishing domain impersonating ING Espa\u00f1a, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ingdirect-web-validado.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ingspain/c76ab4b3-c1ea-497d-91fe-6ce2027faf4d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ingspain"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d53e3707-2a29-5de4-ae2e-565599577471",
      "created": "2026-07-12T15:41:24.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-12T15:41:24.000Z",
      "name": "openai-online.net",
      "description": "Suspicious phishing domain impersonating ChatGPT, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'openai-online.net']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/chatgpt/4e85d5c8-48e8-4ab1-9195-c1799bf9fc11/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "chatgpt"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4db36a65-a3a8-506b-bad9-7057f78a25ff",
      "created": "2026-07-12T15:41:24.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-12T15:41:24.000Z",
      "name": "usps-pickup.com",
      "description": "Suspicious phishing domain impersonating USPS, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'usps-pickup.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/usps/b3f47861-eacf-42c3-a4f7-1227a5173912/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "usps"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1456d639-123e-5ac4-9ca2-ea4135f4cf93",
      "created": "2026-07-12T15:41:25.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-12T15:41:25.000Z",
      "name": "ingdirect-ingreso-usuarios.com",
      "description": "Suspicious phishing domain impersonating ING Espa\u00f1a, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ingdirect-ingreso-usuarios.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ingspain/9295692d-118f-40f1-9a83-23291e5d97d2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ingspain"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--af23d0e1-7b76-5763-b8e3-7a8134b08e50",
      "created": "2026-07-12T15:41:25.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-12T15:41:25.000Z",
      "name": "ingdirect-soporte-servicios.com",
      "description": "Suspicious phishing domain impersonating ING Espa\u00f1a, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ingdirect-soporte-servicios.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ingspain/4109d73f-c1cf-48fd-977a-b5f97f3ea4f4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ingspain"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--434f0cf1-05db-5fe0-8d6e-2163d0c0fbc4",
      "created": "2026-07-12T15:41:26.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-12T15:41:26.000Z",
      "name": "click6.microsoftsupportcenter.digital",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'click6.microsoftsupportcenter.digital']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/26e74f36-d9b6-418b-b32d-5d2b065b7208/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--272f5c1e-4150-5419-adcc-9e87d4c478a0",
      "created": "2026-07-13T01:01:20.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-13T01:01:20.000Z",
      "name": "accounts-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'accounts-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/ef756b22-f225-491b-a58f-a1bd193cc308/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f07b61a5-dfd8-528c-a942-c22583c26630",
      "created": "2026-07-13T01:01:34.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-13T01:01:34.000Z",
      "name": "facebook-www.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-www.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/167f459a-da90-4a14-942b-e5678e587e26/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd26582c-a3fd-5fa6-b166-a0b7e9a6dc54",
      "created": "2026-07-13T01:01:37.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-13T01:01:37.000Z",
      "name": "home-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'home-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/d25b1b8f-af34-4c5f-8c97-e7328ed3bd07/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--52cf2682-c28d-5e5b-900b-157cc2318db5",
      "created": "2026-07-13T01:01:39.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-13T01:01:39.000Z",
      "name": "facebook-login-login.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-login-login.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/d805b229-2383-43d2-bdc2-7580386b8ca7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c8a1499b-385b-5200-af2c-9fef8af362b8",
      "created": "2026-07-13T01:01:42.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-13T01:01:42.000Z",
      "name": "uk-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'uk-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/6ff1ddcd-4cba-4fe0-a003-3f26a48c58c0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6a84545d-673c-549e-983b-26f18b065141",
      "created": "2026-07-13T05:46:50.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-13T05:46:50.000Z",
      "name": "googleplty.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googleplty.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/244e8248-2926-40b9-b004-cfaf28e719fa/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--13fc4f89-85b4-528b-83a0-c294b1d954e0",
      "created": "2026-07-13T05:47:11.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-13T05:47:11.000Z",
      "name": "mhsdns.com",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mhsdns.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//cec6765a-ac8e-44bb-aedf-179a105110a4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--89dacec2-ef10-559f-8896-587eb6f96634",
      "created": "2026-07-13T05:47:11.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-13T05:47:11.000Z",
      "name": "rberthelette.com",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'rberthelette.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//bfe3b071-b9a6-4d65-b9a5-18119c3acbec/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--acc426d8-4f77-5f7b-9603-662029e9e530",
      "created": "2026-07-13T13:01:48.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-13T13:01:48.000Z",
      "name": "facebook-th.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-th.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/9918b10a-9389-44a6-b217-28463d18010b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5b78d2bb-f845-51cc-b30d-d8194cd0b892",
      "created": "2026-07-13T13:01:53.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-13T13:01:53.000Z",
      "name": "facebook-us.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-us.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/ad9625b9-6e0f-4b0c-80c6-95806c77ce01/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--21fac35b-f0ea-574b-8141-2502d7c28a3d",
      "created": "2026-07-13T13:01:55.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-13T13:01:55.000Z",
      "name": "facebook-ca.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-ca.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/f7f34949-aea8-461e-be34-44b3de17bb35/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--71df1a48-e279-5279-8a9e-816347b4be0b",
      "created": "2026-07-13T13:01:58.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-13T13:01:58.000Z",
      "name": "fake-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'fake-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/5db340d4-c4b1-408a-beed-d310d69bbe10/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4cc237c5-d191-5da2-85a6-b182245bc275",
      "created": "2026-07-13T13:02:00.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-13T13:02:00.000Z",
      "name": "sena-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'sena-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c0473ceb-47ca-4ec0-ae9d-06a1e63609c1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2d36c1fb-5a41-5092-8121-399a63dd139d",
      "created": "2026-07-13T13:02:02.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-13T13:02:02.000Z",
      "name": "facebook-sa.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-sa.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/befabd16-6d45-404c-acd9-a9715b89fe6d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--62729d87-d2a4-5656-bda6-5c5614f3ca55",
      "created": "2026-07-13T13:02:10.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-13T13:02:10.000Z",
      "name": "vn-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'vn-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/b072b8b0-d893-4e45-9a05-21f9754245b2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0c92a39e-4de2-51b9-9d4d-8f20e5559aeb",
      "created": "2026-07-13T13:02:13.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-13T13:02:13.000Z",
      "name": "facebooklogin1234.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin1234.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/a7f28f6c-db2a-46d3-a746-754684b6e49c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--69fcbe7e-3ae9-544a-bc98-3c9a697fc76d",
      "created": "2026-07-13T13:02:16.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-13T13:02:16.000Z",
      "name": "facebook-mx.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-mx.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/ef5a8cb2-7e0c-4ef1-8682-c3d96047b506/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9ee4575c-af42-55e6-835a-aec9b4a9e7a4",
      "created": "2026-07-13T13:02:20.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-13T13:02:20.000Z",
      "name": "facebook-official-page.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-official-page.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/aad9e123-dd97-4e54-84f9-22a8913fcc3e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7f15adee-1b4c-55ba-ab2a-1e7937fdb8d8",
      "created": "2026-07-13T13:02:21.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-13T13:02:21.000Z",
      "name": "facebook-vn.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-vn.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/5c20abff-4d68-4aa7-acfe-21b1f21496f5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f62e8fc-8667-5427-b447-cf0dccc52521",
      "created": "2026-07-14T01:02:06.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-14T01:02:06.000Z",
      "name": "facebooklogin13.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin13.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/480276f6-e7fd-4433-bd74-40ab032d080a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d720b3c4-72e0-5be6-a646-7e17c951ded0",
      "created": "2026-07-14T01:02:16.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-14T01:02:16.000Z",
      "name": "facebook-vn-com.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-vn-com.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/711bbb58-dffc-46c8-9d61-66225c47e3b8/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--61b35bf4-78e6-579c-a8f6-317293b5a0c1",
      "created": "2026-07-14T13:02:24.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-14T13:02:24.000Z",
      "name": "r-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'r-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c8a06548-614a-418d-b7ad-75fdf094b59b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--777026f0-af78-57fc-8df4-a5e95a55c0d4",
      "created": "2026-07-14T13:02:31.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-14T13:02:31.000Z",
      "name": "ww-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ww-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/8e474612-4766-4efd-aa4b-9798b0103a0c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2cece366-8fd8-5ab8-94c8-8ea633c9a8f3",
      "created": "2026-07-14T13:02:32.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-14T13:02:32.000Z",
      "name": "meme-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'meme-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/374604a3-290c-4fb4-a645-6a258424b302/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eeb0b571-3413-5b7e-9208-d4386854fd02",
      "created": "2026-07-14T13:02:35.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-14T13:02:35.000Z",
      "name": "facebook-22.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-22.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/0f30d905-81be-4e3f-8601-d7d74c1737b7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--54d1fc22-9571-545e-af98-6c2f24395902",
      "created": "2026-07-14T13:02:40.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-14T13:02:40.000Z",
      "name": "facebook-5645464.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-5645464.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/7d058dc2-9038-40c7-a448-555ef38b9ab7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e9765c06-0322-5da8-862c-316ab572d941",
      "created": "2026-07-14T13:03:00.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-14T13:03:00.000Z",
      "name": "facebook-seks-45.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-seks-45.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/5cf95b60-46aa-41be-9eb1-5b6e8f447a4c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d3e0e5ed-9216-561d-873f-683d3db939b7",
      "created": "2026-07-14T13:03:03.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-14T13:03:03.000Z",
      "name": "facebook-channel.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-channel.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/603dd38f-3c34-4a3a-b79a-3aaf93caa98e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6bd080c9-42e6-5b65-9ce2-529af5e5b9c2",
      "created": "2026-07-14T13:03:05.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-14T13:03:05.000Z",
      "name": "facebook-ng.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-ng.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/966b534e-ef0a-4555-adaa-fdb7a20914a7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--01fabf06-4987-537f-8963-e7bc4ce5ce6b",
      "created": "2026-07-14T13:03:11.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-14T13:03:11.000Z",
      "name": "instagramaccounthacks.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramaccounthacks.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/760388a4-ecd2-4c0c-9680-aeb95d658fa0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a1be505c-66c1-5789-b916-31165fb96a47",
      "created": "2026-07-14T13:03:13.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-14T13:03:13.000Z",
      "name": "facebookloginapps.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginapps.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/2d1fe52a-3b2b-4a3d-ac25-3c232ee58160/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--12fe52a0-ed58-5818-a917-5db0e638f01b",
      "created": "2026-07-14T21:00:40.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-14T21:00:40.000Z",
      "name": "microsoft.updata.net.cn",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoft.updata.net.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/3e9b9685-7b3c-4c65-b646-842441c00c51/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f86bd026-49e7-514a-aeed-6d9193f2af20",
      "created": "2026-07-15T01:01:03.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-15T01:01:03.000Z",
      "name": "secutury-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'secutury-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/dd8d457d-f8cb-4567-9ba5-fd3c37435447/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--63c6304c-05dd-5bfe-a5bb-d264bdaf3106",
      "created": "2026-07-15T01:01:09.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-15T01:01:09.000Z",
      "name": "jwb-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'jwb-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/6dbacaad-9107-47e2-a7d5-da587fcf63a9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--03f3a5a9-3d52-511e-900a-aee3162aecbb",
      "created": "2026-07-15T01:01:14.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-15T01:01:14.000Z",
      "name": "facebook-account-login-page.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-account-login-page.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/166bea03-7616-43e7-a17f-d2791d020e18/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da5af006-35a9-5e0d-b4f5-c61e3277d6cc",
      "created": "2026-07-15T13:01:08.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-15T13:01:08.000Z",
      "name": "nw-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'nw-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/7ad0b839-f509-4cbf-ad85-52d86d5744a2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b2ea749b-4e8d-5d25-b25d-4640d8d0b629",
      "created": "2026-07-16T00:38:22.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-16T00:38:22.000Z",
      "name": "www-app-google.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'www-app-google.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/bf2b9c5b-9e90-4256-85f1-720f2d238e51/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5992ae52-1cd2-5e56-9574-ec0f2b3036b4",
      "created": "2026-07-16T01:01:13.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-16T01:01:13.000Z",
      "name": "facebook-eu.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-eu.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/bf7d718f-50eb-42fb-ac92-30fb3db9804f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3f6e4ede-0aec-5643-a581-9795b76f52d2",
      "created": "2026-07-16T01:01:15.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-16T01:01:15.000Z",
      "name": "facebook-qa.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-qa.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/2e736496-d79e-45dc-ab12-748aaf3ac60b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9314af17-c68c-5ae8-841a-773ee9523816",
      "created": "2026-07-16T13:01:03.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-16T13:01:03.000Z",
      "name": "facebooklogin17.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin17.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/a3cb513b-4e49-4304-9014-c9f5e073d8cb/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fa9c0b8d-d9f5-5928-befb-82cda3a3b11a",
      "created": "2026-07-17T01:03:03.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-17T01:03:03.000Z",
      "name": "facebookloginuser.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginuser.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/53ea55da-e98f-41cf-aa8c-474548f367ab/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--879d3d94-f171-5411-8825-a84577e8e88a",
      "created": "2026-07-17T01:04:26.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-17T01:04:26.000Z",
      "name": "facebook-help-m.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-help-m.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/5c8ea14e-83ec-4229-a95c-938615e7799d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e7e67fa-8786-585e-a1de-7ac58aeebc7b",
      "created": "2026-07-17T13:01:07.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-17T13:01:07.000Z",
      "name": "facebook-pt.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-pt.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/f648ac2f-7604-4e57-933e-714eefa435cc/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6c625479-19ec-5913-b669-62e21576a7ae",
      "created": "2026-07-17T13:01:10.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-17T13:01:10.000Z",
      "name": "facebook-login-page.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-login-page.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/484862d0-19f2-4cfe-9f54-c3160a2d6a12/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b0c898d-203c-5dc6-b5c6-2eb2a89d2c22",
      "created": "2026-07-17T13:01:12.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-17T13:01:12.000Z",
      "name": "brad-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'brad-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/66108f28-dce0-45c0-8228-9a739fad3f4d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b7cfa5b-cc42-5225-9e8b-2cba54b1fca5",
      "created": "2026-07-17T13:01:13.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-17T13:01:13.000Z",
      "name": "su-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'su-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/40a7120e-fb28-42be-a199-2bf8a301e67a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ab3430f2-5d51-503d-9165-4b00d44237ee",
      "created": "2026-07-18T01:03:09.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-18T01:03:09.000Z",
      "name": "facebook-login0.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-login0.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/01bf3029-d5fc-46d4-a1fb-25f468cafa80/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aeff0036-6a62-54d4-8e1d-66611fa2667a",
      "created": "2026-07-18T13:01:47.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-18T13:01:47.000Z",
      "name": "facebook-cdn.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-cdn.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/6dc03801-92d2-45d0-b055-01f9f9113a73/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--eafb5ed9-b8b6-573d-943d-e685e18a9983",
      "created": "2026-07-18T13:01:51.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-18T13:01:51.000Z",
      "name": "ly-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ly-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/34c89fda-234d-470c-95e0-f35031da2301/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd5101c5-46e5-5a3b-88b0-65dc48bbc079",
      "created": "2026-07-18T13:02:37.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-18T13:02:37.000Z",
      "name": "services-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'services-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/bcef11a1-3c7d-4c67-81b6-be782fe81a32/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4df6ee2d-74a7-526c-9a60-968f4fc33b2e",
      "created": "2026-07-18T13:02:39.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-18T13:02:39.000Z",
      "name": "facebooklogin18.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin18.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/860ec897-3b26-425a-b304-fa667b564061/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4179a01b-b9cc-5e8a-a625-fe281d76c266",
      "created": "2026-07-18T13:02:41.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-18T13:02:41.000Z",
      "name": "empresas-hsbc.com",
      "description": "Suspicious phishing domain impersonating HSBC, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'empresas-hsbc.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/hsbc/656cdf99-a953-4192-8ab7-8cf0962606bc/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "hsbc"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4ce06b4a-02de-5f8e-a0c7-261a11e16f12",
      "created": "2026-07-19T01:02:16.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-19T01:02:16.000Z",
      "name": "sk-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'sk-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c8e24f42-b925-4619-8520-af00c106e94f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a09cd08e-3373-5c43-be9f-30da829d58eb",
      "created": "2026-07-19T01:02:21.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-19T01:02:21.000Z",
      "name": "facebook-9.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-9.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/a5c06203-6af5-496a-aaa2-87b9279ca826/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--567af8eb-069f-51f4-8039-277f9c68e45e",
      "created": "2026-07-19T08:11:29.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-19T08:11:29.000Z",
      "name": "microsoftai.pl",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoftai.pl']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/7c104beb-6cbd-4c2d-aad5-0fa2603ff03e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a684c6fb-8b64-55c2-9fa9-545058603e57",
      "created": "2026-07-19T13:01:27.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-19T13:01:27.000Z",
      "name": "facebook-find.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-find.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/22856948-8aa0-4fda-a06f-0457168467f6/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0e64ad3b-7c22-59ac-b96a-600ce97c1e2f",
      "created": "2026-07-19T13:01:29.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-19T13:01:29.000Z",
      "name": "ani-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ani-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/a860de31-8dc1-4598-936f-ef911a89318f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b4249cde-4df5-5df2-863a-bf463841cdb8",
      "created": "2026-07-19T13:01:41.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-19T13:01:41.000Z",
      "name": "usacrazyseller.com",
      "description": "Suspicious phishing domain impersonating LinkedIn, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'usacrazyseller.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/linkedin/10a3b0d9-7de8-4a52-97cb-b31b9fc35e08/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "linkedin"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c196acfe-d901-5856-a16c-4bf8684b6002",
      "created": "2026-07-20T01:01:39.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-20T01:01:39.000Z",
      "name": "facebooklogini.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogini.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/52954f4c-5d51-4eaf-a731-7048dbfcc5cf/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3fb456d4-9b4a-5fd5-bbd1-bdc79837a622",
      "created": "2026-07-20T12:34:47.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-20T12:34:47.000Z",
      "name": "uspssmartpackagelockers.com",
      "description": "Suspicious phishing domain impersonating USPS, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'uspssmartpackagelockers.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/usps/6f1e7fe2-188d-4f2c-b76d-680c46e66afe/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "usps"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--86cfff79-fc76-5dfd-bb7b-b8eab2d5dc2a",
      "created": "2026-07-20T13:02:12.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-20T13:02:12.000Z",
      "name": "facebook-login-web.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-login-web.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/97417ee6-49b4-4492-ba03-6caf7839989f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e54e8504-eb6d-53e4-93f7-9a803be878a5",
      "created": "2026-07-20T13:02:21.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-20T13:02:21.000Z",
      "name": "facebooksecurityhelp.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooksecurityhelp.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/fc5bc47b-8b86-4eac-beea-bcd87c789b44/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a8230f1-9134-5e5c-b7fc-c3b09d27799e",
      "created": "2026-07-20T13:02:37.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-20T13:02:37.000Z",
      "name": "info-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'info-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3604834e-7b07-4001-a991-006ffd3d4db5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d682ecb7-ed17-5679-bc46-a719b3c91d54",
      "created": "2026-07-20T13:02:53.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-20T13:02:53.000Z",
      "name": "facebook-groups-new.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-groups-new.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/4eb25870-e3e2-4a9d-9473-b7cc65a5e9da/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc165c6f-5dca-527c-a732-3b108abdf462",
      "created": "2026-07-20T18:15:31.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-20T18:15:31.000Z",
      "name": "netflix520.com",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflix520.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/56f4d4bb-687e-45dd-b08d-402358b197db/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c1d1b78-744e-5136-a5e0-995622d6be3c",
      "created": "2026-07-21T01:01:17.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-21T01:01:17.000Z",
      "name": "bbvalues.uk",
      "description": "Suspicious phishing domain impersonating BBVA, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bbvalues.uk']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bbva/23e87ca8-5181-42e4-8742-0ea639f64232/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bbva"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--befd0fae-b5da-5ab1-9b96-c254d6007f4d",
      "created": "2026-07-21T13:01:12.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-21T13:01:12.000Z",
      "name": "love-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'love-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/17f81f25-a053-4a0f-be44-2f77ac578947/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bb379430-a85b-5131-bc54-86c1892c426c",
      "created": "2026-07-21T13:01:15.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-21T13:01:15.000Z",
      "name": "facebookdatingonfacebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookdatingonfacebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/250a46e9-85b5-46eb-b2f2-6e50d22d37da/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b178e69e-2a96-5634-92d8-995f12803389",
      "created": "2026-07-21T13:01:22.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-21T13:01:22.000Z",
      "name": "bbva-hiring-paperless.appspot.com",
      "description": "Suspicious phishing domain impersonating BBVA, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bbva-hiring-paperless.appspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bbva/483241bc-0edd-4151-bb15-9fe871cb34db/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bbva"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b90fc462-383f-5412-9301-eab9620c2e7f",
      "created": "2026-07-22T01:03:03.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-22T01:03:03.000Z",
      "name": "facebok-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebok-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/d8d1b4a6-9096-413d-9c5e-bbfe01073e94/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87432734-bd72-55a3-8b31-d485878fb409",
      "created": "2026-07-22T01:03:10.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-22T01:03:10.000Z",
      "name": "jo-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'jo-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/4799078c-a0fa-4c29-824f-1622671828df/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e0534b31-5f6f-51bf-8e52-9f2350cc9bf2",
      "created": "2026-07-22T01:03:14.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-22T01:03:14.000Z",
      "name": "facebook-gamehacks.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-gamehacks.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/b3bec619-a1d4-4a86-944d-bfcab851c86b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5146bd40-09c6-5ed9-b5b4-f9b79cb10762",
      "created": "2026-07-22T01:03:18.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-22T01:03:18.000Z",
      "name": "facebook-q.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-q.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/dcda95f4-7761-4639-ba28-c9a29dbca884/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d7253dfa-e0b7-501f-bfef-6a43dd3f54e8",
      "created": "2026-07-22T01:03:26.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-22T01:03:26.000Z",
      "name": "facebook-account-manager.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-account-manager.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/f57bd13d-5a17-471e-9b66-737656906dea/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da7e298d-a997-5356-8b16-dc7c101add4a",
      "created": "2026-07-22T05:48:09.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-22T05:48:09.000Z",
      "name": "play-google.cam",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'play-google.cam']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/8d9dd06a-6225-46c4-9317-2b83312e7807/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b8c69314-0eb9-553f-a5a5-84769e4e9c34",
      "created": "2026-07-22T13:01:54.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-22T13:01:54.000Z",
      "name": "facebook-vu.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-vu.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/ee5b415b-06a8-430c-a7d7-088bcaa0dcbb/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b3ab1bf7-01d2-550c-81ca-ac59fc06eaa2",
      "created": "2026-07-22T13:01:58.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-22T13:01:58.000Z",
      "name": "facebooklogin333.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin333.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/1ca0d6ed-c768-4b41-8676-62afd1057ec2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--357473de-d32f-5178-9ac7-bd8a051016be",
      "created": "2026-07-22T13:02:02.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-22T13:02:02.000Z",
      "name": "instagramcoverrbrasilinstagram.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramcoverrbrasilinstagram.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/46a65d94-9e22-48d4-a602-127e3018433e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--17196182-12b3-58c6-959a-345ff3633063",
      "created": "2026-07-22T13:02:08.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-22T13:02:08.000Z",
      "name": "facebook-int.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-int.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/a02eff5d-c116-405e-9b2f-e555bcf3f933/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--83fe4b8d-8714-5cfd-8a01-0abbc5799892",
      "created": "2026-07-22T13:02:13.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-22T13:02:13.000Z",
      "name": "facebookloginfriends.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginfriends.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/4d5f10ad-bf1a-4a02-9112-b59a31526d55/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--327ecd9a-e47b-5e52-bf2d-485b941fd835",
      "created": "2026-07-22T13:02:15.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-22T13:02:15.000Z",
      "name": "facebook7-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook7-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/ac9c74de-0bf7-4dd4-a9a1-fe0b0eb6b9b5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b2edefcb-a43a-5dfe-975e-00fd886f92b8",
      "created": "2026-07-22T13:02:17.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-22T13:02:17.000Z",
      "name": "facebook-facebook1.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-facebook1.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/56669579-785c-4741-9d50-dbfe53cd0e3d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1c65c930-f28d-508d-9214-5cc5632d4d52",
      "created": "2026-07-22T13:02:20.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-22T13:02:20.000Z",
      "name": "help-instagram.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'help-instagram.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/2ba75fcd-f685-419f-a1fb-5ab94a426600/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8b0202da-9157-5db1-8762-6ea7261cf56f",
      "created": "2026-07-22T13:02:23.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-22T13:02:23.000Z",
      "name": "facebook-fb-com.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-fb-com.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/dda3d97a-abde-47eb-98d4-cc5a03dddfad/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--75af4664-352d-5d5c-9bd6-cc429c16a661",
      "created": "2026-07-22T17:20:19.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-22T17:20:19.000Z",
      "name": "bbvaglobalwealthadvisors.com",
      "description": "Suspicious phishing domain impersonating BBVA, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bbvaglobalwealthadvisors.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bbva/323dfc8c-089e-416f-a4c1-42ab52899060/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bbva"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a800d822-35bd-5090-bc7d-e98f218b2a1a",
      "created": "2026-07-22T23:04:16.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-22T23:04:16.000Z",
      "name": "ebay-app.com",
      "description": "Suspicious phishing domain impersonating eBay, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ebay-app.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ebay/3f7de289-508f-4a07-a152-78467a1f30ae/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ebay"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--78d456ff-19cc-5d89-95d4-aa55dc1f3514",
      "created": "2026-07-23T01:01:20.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-23T01:01:20.000Z",
      "name": "tara-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'tara-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/cc2d2240-ec33-4ee5-93fd-0cad356e5745/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--201072f5-e925-514b-a734-349c0f631958",
      "created": "2026-07-23T01:01:27.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-23T01:01:27.000Z",
      "name": "instagramcheck.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramcheck.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/5e1c7733-3cc6-493c-85a7-8100de840fef/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--696197c5-2c88-5f69-a616-0b96a8e59a2f",
      "created": "2026-07-23T01:01:32.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-23T01:01:32.000Z",
      "name": "lovefive-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'lovefive-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/310840fe-8db1-4c59-8c42-c7e1a6c8f0d2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e4ae3c29-f620-55b4-a3cb-82bb433d0cb2",
      "created": "2026-07-23T01:01:35.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-23T01:01:35.000Z",
      "name": "facebook-supports.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-supports.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/1f6f36f1-e706-41ad-92fe-9e1592d8dd64/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--628bb3ca-daa1-5d17-b3bd-0ee42e550f15",
      "created": "2026-07-23T01:01:41.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-23T01:01:41.000Z",
      "name": "emailnotifications.m365-microsoft.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 21/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'emailnotifications.m365-microsoft.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 21,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/cd267dfc-abf2-428a-8266-fdeb1382bc4f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--01998a41-f2cc-57f2-944c-e676d98182ba",
      "created": "2026-07-23T12:01:00.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-23T12:01:00.000Z",
      "name": "paypal-refund.com",
      "description": "Suspicious phishing domain impersonating PayPal, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'paypal-refund.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/paypal/83c47439-fc31-473d-8855-85e31d1fffd3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "paypal"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e070180d-b41b-5a57-8c35-4e087a9c4967",
      "created": "2026-07-23T13:01:51.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-23T13:01:51.000Z",
      "name": "instagram-change-password.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-change-password.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/a0a36105-eb57-45c7-a820-4df8fb019108/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--724578ca-ee93-5598-b3d5-782e86920b8d",
      "created": "2026-07-23T13:01:54.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-23T13:01:54.000Z",
      "name": "facebook-verify.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-verify.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/eb9a6da1-63e9-45ba-a052-599a5778efde/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ba9e6e13-0131-5e4e-8f48-3c29043b3974",
      "created": "2026-07-23T13:01:57.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-23T13:01:57.000Z",
      "name": "instagram-jennifer.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-jennifer.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/ec26a484-faa3-431d-a5c7-8e92d63b7854/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8899f101-858d-534d-92a0-e1bef928d4d8",
      "created": "2026-07-23T13:02:11.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-23T13:02:11.000Z",
      "name": "dj-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'dj-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/b8baa040-0cc0-4513-ad83-5066bb11c6df/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a7c57d85-bbbb-57bf-86cb-8dd0cd8c0bc8",
      "created": "2026-07-23T13:02:22.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-23T13:02:22.000Z",
      "name": "faceb00klogin.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'faceb00klogin.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/094de6a9-0272-4365-8ee7-8202d3ace25f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c9e3e1ef-5e72-5382-a211-3c78c26a2fa1",
      "created": "2026-07-23T13:02:35.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-23T13:02:35.000Z",
      "name": "app-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'app-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/026c60bf-afb2-43a1-bb07-18a3eebb7cde/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c4788152-1dff-5fef-837c-d95118b6869d",
      "created": "2026-07-23T13:02:40.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-23T13:02:40.000Z",
      "name": "facebooksociallink.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooksociallink.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3773a35b-b319-4282-a02b-97e8742125e9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9d468b87-0d9d-5cbb-ac43-d2b2626412e4",
      "created": "2026-07-23T13:02:44.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-23T13:02:44.000Z",
      "name": "facebookcustomersupportnumber25.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookcustomersupportnumber25.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/efc3cb5c-1cb9-43a6-9b25-0290a38ca71d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--850076da-4b8e-506d-b978-2109c3cd5c85",
      "created": "2026-07-23T13:02:48.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-23T13:02:48.000Z",
      "name": "facebookpageslinkk.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookpageslinkk.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/0a4d4691-3929-4b26-a505-cf447b52515e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e7dee465-cff9-537a-9793-727abd2f1aa4",
      "created": "2026-07-24T01:02:03.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-24T01:02:03.000Z",
      "name": "bet-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bet-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/44ee93b6-e0ca-457a-9055-2e15956fd11a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1899fa31-ab6a-594e-ac59-9fbf6db0974f",
      "created": "2026-07-24T01:02:13.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-24T01:02:13.000Z",
      "name": "tb-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'tb-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/fb0f2ee1-d0a7-49b3-b411-4657252a20b3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--024c4891-9998-547b-ada0-9f75f6ad86c0",
      "created": "2026-07-24T05:49:01.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-24T05:49:01.000Z",
      "name": "google-verify.email",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'google-verify.email']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/6b2cbe41-61e9-4cd5-a362-b4791a896d7f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--66f81287-19c5-547c-86cc-700ae35909eb",
      "created": "2026-07-24T11:00:44.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-24T11:00:44.000Z",
      "name": "googlepodstream.unaux.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googlepodstream.unaux.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/e9c56b3a-f572-42d6-85fe-97559174a969/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--df0fad2b-e59d-5816-8997-dd7e2b1a00d2",
      "created": "2026-07-24T13:01:24.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-24T13:01:24.000Z",
      "name": "123-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '123-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/a4913c12-f71a-4534-b9c7-741421b31858/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--10399bd7-72f9-575b-9530-d6bc775ad622",
      "created": "2026-07-24T13:01:38.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-24T13:01:38.000Z",
      "name": "instagramloginpage111.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramloginpage111.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/e45d0422-f9a5-4781-96a8-18af1563ae60/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ae7334e4-6bec-5db1-82ab-43f7c866ef3c",
      "created": "2026-07-24T13:01:40.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-24T13:01:40.000Z",
      "name": "facebook-do.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-do.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/270da7cd-f622-4e0b-9a08-58351640bcc4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--db1589fc-9c03-59d9-8b1c-8392821c0052",
      "created": "2026-07-24T13:01:43.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-24T13:01:43.000Z",
      "name": "login-page-instagram.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'login-page-instagram.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/c49093d0-2045-4741-a948-711c40a5cdd7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9b1facb8-b6bf-56ab-8f51-2aefcb96cd30",
      "created": "2026-07-25T01:02:05.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-25T01:02:05.000Z",
      "name": "facebook-hack-accounts.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-hack-accounts.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/f89073c6-2491-42a9-b9d7-da14865a61ab/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--baea8658-bd78-5803-9d50-1fdd4c4396ed",
      "created": "2026-07-25T01:02:13.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-25T01:02:13.000Z",
      "name": "facebook-verification-system5.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-verification-system5.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/5633b0ab-4b97-46de-8357-a8d92e21d1b8/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--225cd160-b52e-530a-9b5b-3b429fdea90b",
      "created": "2026-07-25T01:02:16.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-25T01:02:16.000Z",
      "name": "facebooklogin99999.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin99999.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/790c921e-d7cb-4634-aebc-d32c5f2befce/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--734b4cac-6e64-5136-b3b5-0b172107ebd4",
      "created": "2026-07-25T01:02:25.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-25T01:02:25.000Z",
      "name": "facebook-mark.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-mark.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/bbd003f4-9659-4c3c-9e3a-3fec438f331e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e2773b66-954f-5a5d-8b2e-17cf1be815d0",
      "created": "2026-07-25T01:02:36.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-25T01:02:36.000Z",
      "name": "facebook-247-support.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 44/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-247-support.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 44,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3aeedbee-358e-4620-a8cf-3bb682363f4c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7ecdda70-49da-528e-a942-a4103c632f6f",
      "created": "2026-07-25T01:03:29.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-25T01:03:29.000Z",
      "name": "facebook-trk.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-trk.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/afb4462e-8dbe-470d-9500-84f056e7573f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b7854958-9787-5a7b-900b-4cd64ae7dc75",
      "created": "2026-07-25T01:04:05.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-25T01:04:05.000Z",
      "name": "facebookloginss.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginss.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3af8f0b7-efd4-4770-b3ed-6ec8499159d9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e0d4de3e-c908-5cbd-8210-d2ab95363ea5",
      "created": "2026-07-25T01:04:19.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-25T01:04:19.000Z",
      "name": "facebook-di.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-di.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/b41a25e6-96bd-4667-9b8d-179b7483889c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a0a43656-7f11-55bf-8128-a4e6a8b92422",
      "created": "2026-07-25T01:05:48.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-25T01:05:48.000Z",
      "name": "facebookloginguidance.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginguidance.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/86296e06-df28-4a67-83cd-1975258f5cb2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0914c6c5-27b4-5526-98b2-4a0bce451d9d",
      "created": "2026-07-25T13:01:37.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-25T13:01:37.000Z",
      "name": "facebooklogin01.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin01.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/6859fc30-2d6e-4fb2-979c-e179e0ff418a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--402f4405-37ea-590f-a739-96958d58c230",
      "created": "2026-07-25T13:01:40.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-25T13:01:40.000Z",
      "name": "instagramlogin99.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramlogin99.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/f5b9d7e1-45da-45ac-9cb5-1e111b259370/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--95a58394-4bf0-5332-8386-d7fc9fdd4854",
      "created": "2026-07-25T13:01:42.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-25T13:01:42.000Z",
      "name": "facebook-login-be.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-login-be.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/2b61a5dd-394d-4015-b008-92b47a1d55a9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2d1bbda-7754-581c-a366-8d2452b8a373",
      "created": "2026-07-25T13:01:46.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-25T13:01:46.000Z",
      "name": "facebook-benjamin.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-benjamin.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/9f10fe8a-c098-44bd-89ad-396a26cead96/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--794198ae-184b-5e42-9fe2-ed0cb060d7c0",
      "created": "2026-07-25T13:01:49.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-25T13:01:49.000Z",
      "name": "facebookloginapp.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginapp.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/81427d41-7a30-48e3-9ba5-7570c6882273/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--72275b62-2c4b-58b9-9baf-f940c49faa3d",
      "created": "2026-07-25T13:01:52.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-25T13:01:52.000Z",
      "name": "instagramlogin24.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramlogin24.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/1323e5ee-020a-49ba-84bd-5adbb0185079/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e1c686c1-bc41-517b-9eb5-a381107d5183",
      "created": "2026-07-25T13:01:55.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-25T13:01:55.000Z",
      "name": "facebooksecure.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooksecure.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/6d4931be-51a8-4339-856d-2100cdebb27c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--76289843-fec9-5abe-a1d5-759976dce540",
      "created": "2026-07-25T13:01:56.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-25T13:01:56.000Z",
      "name": "facebookverifyyouraccount.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookverifyyouraccount.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/834d1298-453d-4e02-a7a1-f8b93705e5e5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c940df39-730e-5e2a-a9c5-b40a7cb49271",
      "created": "2026-07-25T13:01:58.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-25T13:01:58.000Z",
      "name": "instagramlogin77.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramlogin77.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/e81d4311-0ce9-4855-8b65-e2eb630b60af/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5000706-4aeb-51ea-acad-aeb8ca24a768",
      "created": "2026-07-25T13:02:02.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-25T13:02:02.000Z",
      "name": "instagramlogin124.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramlogin124.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/ed52cac4-4db8-4455-b3d2-ed25f261a853/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--675f6bff-2a4d-5ae0-a58f-54606ba46822",
      "created": "2026-07-25T13:02:09.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-25T13:02:09.000Z",
      "name": "facebook-community.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-community.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c4691c76-4192-4c5a-8906-6ac42fc8b0e6/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dc160ec3-c114-5869-8aa0-fc6753d5a9af",
      "created": "2026-07-25T13:02:12.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-25T13:02:12.000Z",
      "name": "facebooke-login.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooke-login.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/08068293-0500-46b8-9331-6e24be342cbf/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32bb359d-88f9-53fd-a099-9dc8022105b2",
      "created": "2026-07-26T01:03:21.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-26T01:03:21.000Z",
      "name": "facebook-pi.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-pi.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/2fb86d0c-4bee-4989-88ef-6d1fe66d92d1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6a6e554d-28e1-56b7-93b1-36b70fad3a0e",
      "created": "2026-07-26T01:03:24.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-26T01:03:24.000Z",
      "name": "instagram-baittouts-login.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-baittouts-login.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/d3ba1276-9019-477b-a373-d5d134907842/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ca0907ee-2cc3-5eb6-bfee-ecdf500e52ef",
      "created": "2026-07-26T01:03:28.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-26T01:03:28.000Z",
      "name": "neda-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'neda-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/954f7510-6600-44e9-8e1d-7e7564eca341/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e837b735-9bda-58e0-bc95-731fa0afb7b1",
      "created": "2026-07-26T01:03:31.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-26T01:03:31.000Z",
      "name": "instagramlogin68.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramlogin68.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/ef228d45-10dd-4741-a33d-0cdd74c45545/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c9052113-4de4-5402-9309-a5ad94a272fc",
      "created": "2026-07-26T01:03:36.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-26T01:03:36.000Z",
      "name": "z-instagram.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'z-instagram.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/77f717b0-9b2a-40f7-8178-ef422c660496/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6bca90bd-4353-52e1-aab9-c6530fc284c8",
      "created": "2026-07-26T01:03:37.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-26T01:03:37.000Z",
      "name": "facebookbfacebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookbfacebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c80af9b9-3ba5-45c6-8737-d79afc86bf36/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--80408013-45ad-5a06-806f-a6aadde2689f",
      "created": "2026-07-26T01:03:46.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-26T01:03:46.000Z",
      "name": "facebookloginsignub.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginsignub.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/15497459-c0ab-4c98-851b-9d06dc01e2f0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ce20c916-43df-5201-b9db-68636dee5004",
      "created": "2026-07-26T01:03:48.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-26T01:03:48.000Z",
      "name": "facebook-login-it.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-login-it.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/176c7a1e-4e82-4ce0-ade8-991414ff634c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--12aa58a2-6487-5fa3-a638-a9fb7add67b1",
      "created": "2026-07-26T01:04:01.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-26T01:04:01.000Z",
      "name": "instagram-login.hashnode.dev",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-login.hashnode.dev']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/74bd5cbb-85a6-4396-b0ca-f8ef93d9c493/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6cf43233-3b21-5c7f-bb64-59c98d1127b7",
      "created": "2026-07-26T01:04:08.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-26T01:04:08.000Z",
      "name": "instagramfollowers146.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramfollowers146.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/5dd55974-c01b-4537-b417-07a1e7ac7f70/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f7e7bf90-941a-54a0-99ab-d69eed334fd3",
      "created": "2026-07-26T01:04:16.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-26T01:04:16.000Z",
      "name": "facebookloginnew.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginnew.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/48224f19-0ebf-44da-bcf3-918c8e88b069/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ac0deeda-e5dc-59eb-9d66-71f4d4f9305c",
      "created": "2026-07-26T13:01:22.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-26T13:01:22.000Z",
      "name": "facebookuseraccount.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookuseraccount.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/8d07e50b-66d4-4743-9a56-77d0ce58eec0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d746bd0f-6230-5a0f-bb77-eeba7e89f7fb",
      "created": "2026-07-26T13:01:26.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-26T13:01:26.000Z",
      "name": "facebook-0-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-0-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c17e85bb-f2e9-45fb-9f44-4db1f7f3aea1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b9f5101e-bca5-5c25-b3ff-b834a9ce8b3a",
      "created": "2026-07-26T13:01:36.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-26T13:01:36.000Z",
      "name": "facebook-source.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-source.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/9704af42-f5d5-4ce7-a866-ea95cd70cc6e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--17872549-9cc7-5b95-9194-62d3cce10b9c",
      "created": "2026-07-27T00:04:05.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-27T00:04:05.000Z",
      "name": "mi-santander.com",
      "description": "Suspicious phishing domain impersonating Banco Santander, detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mi-santander.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/santander/60341f53-919a-40d3-bd09-2a6e393cbf1c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "santander"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4c3c89eb-1074-5d0b-a73d-606877446aba",
      "created": "2026-07-27T00:04:09.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-27T00:04:09.000Z",
      "name": "steamcommunity.ing",
      "description": "Suspicious phishing domain impersonating Steam, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'steamcommunity.ing']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/steam/313f67ab-4a8f-45bb-9541-895ecd934014/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "steam"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fad3e773-ca9b-564d-ab9c-d1e884f4b5e2",
      "created": "2026-07-27T00:04:16.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-27T00:04:16.000Z",
      "name": "santanderbank.shop",
      "description": "Suspicious phishing domain impersonating Banco Santander, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'santanderbank.shop']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/santander/a41863d8-6c4a-4f9b-8a94-bad456ce923d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "santander"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--31ec3430-51bf-5dc5-be3a-2b74abe49fe5",
      "created": "2026-07-27T01:01:23.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-27T01:01:23.000Z",
      "name": "instagramfollowers7894.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramfollowers7894.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/79a0819e-9425-411f-8c04-d076a48ae2f0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1e720f4f-332c-5c49-afb1-6bf7d14cdd83",
      "created": "2026-07-27T01:01:49.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-27T01:01:49.000Z",
      "name": "facebook-services-login.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-services-login.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/70138f6a-ba13-46da-b7d1-e6d134c60524/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--acaa7d49-45ef-5273-aaa3-d832de3abc87",
      "created": "2026-07-27T01:01:54.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-27T01:01:54.000Z",
      "name": "instagramlikescheap.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramlikescheap.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/5acafb8a-41c8-4d33-85b6-adb84cc56595/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3112503c-0f19-5561-a2d3-fa3678a58043",
      "created": "2026-07-27T01:01:56.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-27T01:01:56.000Z",
      "name": "instagram-verifications.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-verifications.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/334763eb-cbab-4a4e-b88f-9882e77b3b29/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e91840b1-c365-59c8-a0b7-3ed9c3e64cfb",
      "created": "2026-07-27T01:01:58.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-27T01:01:58.000Z",
      "name": "facebooklogincc.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogincc.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/b19c7c76-9286-4574-945d-b592e1f986a9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--42585b56-f9fb-5314-97ca-64f3232f930d",
      "created": "2026-07-27T05:04:31.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-27T05:04:31.000Z",
      "name": "invreceiptslinkedin.com",
      "description": "Suspicious phishing domain impersonating LinkedIn, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'invreceiptslinkedin.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/linkedin/3608123f-e170-4687-83cd-7e6dfde6099c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "linkedin"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0ff13522-7092-5551-aa6c-568dd6dc3cca",
      "created": "2026-07-27T05:04:48.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-27T05:04:48.000Z",
      "name": "receipts-andy-linkedin.com",
      "description": "Suspicious phishing domain impersonating LinkedIn, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'receipts-andy-linkedin.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/linkedin/68a187e0-d129-424a-8353-b9cadb7547a9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "linkedin"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f1f94d73-4822-52d9-890a-40907b5d3c87",
      "created": "2026-07-27T05:04:59.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-27T05:04:59.000Z",
      "name": "receiptslinkedin.com",
      "description": "Suspicious phishing domain impersonating LinkedIn, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'receiptslinkedin.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/linkedin/975bd679-992b-4f7e-a6c8-22c617c83296/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "linkedin"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5e699768-5dd2-5479-b924-e9912b2b8cd9",
      "created": "2026-07-27T05:05:05.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-27T05:05:05.000Z",
      "name": "facebookshops.best",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookshops.best']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/86d42b79-c24a-441d-b210-2b501a36423f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f5d3b07b-4864-5685-bfc8-86e8d65d1bff",
      "created": "2026-07-27T13:02:24.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-27T13:02:24.000Z",
      "name": "zeta-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'zeta-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3563406b-dbe8-4051-bdd4-b78e8bf95f50/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6d3953e0-4f84-5326-ad4d-a70de681b6f5",
      "created": "2026-07-27T13:02:27.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-27T13:02:27.000Z",
      "name": "instagram-open.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-open.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/f6b975d4-5ea6-4117-b7c2-f578f4722bed/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6c5da20d-e800-5340-bafb-c18fd820e10c",
      "created": "2026-07-27T13:02:30.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-27T13:02:30.000Z",
      "name": "facebook-ana.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-ana.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/058fc690-89cc-45b1-90e3-28100c74610a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9f5e55db-5f83-5080-826b-2c1a9fcbcac9",
      "created": "2026-07-27T13:02:39.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-27T13:02:39.000Z",
      "name": "amazon-ae-relay.apps.prov.cx",
      "description": "Suspicious phishing domain impersonating Amazon, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'amazon-ae-relay.apps.prov.cx']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/amazon/52a2d664-efef-4b6c-af31-5001088d0ded/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "amazon"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f42cae60-da8a-5914-bcf2-f689d755f1d9",
      "created": "2026-07-27T13:02:44.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-27T13:02:44.000Z",
      "name": "instagramlogin-k.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramlogin-k.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/bca8a741-9f1a-46b0-b984-038b7e3bfaf1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--602f9ee8-2678-55af-8602-3f3a47172050",
      "created": "2026-07-27T13:02:51.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-27T13:02:51.000Z",
      "name": "instagram-users.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-users.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/eb88cc4f-407d-4a33-860f-076a8de7744f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d9f01c4b-a899-5fc8-88b9-c30b13e08983",
      "created": "2026-07-27T16:03:29.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-27T16:03:29.000Z",
      "name": "helpsecurity-microsoft.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'helpsecurity-microsoft.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/301d9f55-4ccb-496b-9e58-f7b6b134a669/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b321641c-79cd-5b44-ba11-8774d5a32eb2",
      "created": "2026-07-27T16:03:30.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-27T16:03:30.000Z",
      "name": "microsoft365businessbasic.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 21/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoft365businessbasic.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 21,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/c00c8349-6c13-44c8-ab8f-c74716786713/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ba82e2a0-242e-5cdd-b15a-e6cc43900626",
      "created": "2026-07-27T16:03:39.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-27T16:03:39.000Z",
      "name": "instagramaccount.info",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramaccount.info']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/66ae3b8d-c194-45b5-a371-e2ce13827a82/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fcc7f0b5-0311-5e1d-8b5a-a917b4fd0e07",
      "created": "2026-07-27T19:03:59.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-27T19:03:59.000Z",
      "name": "movistarepayco.com",
      "description": "Suspicious phishing domain impersonating Movistar, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'movistarepayco.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/movistar/87bd92ec-f35d-438b-9c76-634b791a5006/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "movistar"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--48c677fd-77ae-5917-8286-69f7c91ebf76",
      "created": "2026-07-28T00:19:03.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-28T00:19:03.000Z",
      "name": "fifa-store.shop",
      "description": "Suspicious phishing domain impersonating FIFA World Cup, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'fifa-store.shop']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/fifa/88fc08ba-c884-40a6-b5ac-b5e1ee97f166/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "fifa"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc23b757-e193-5fe8-a2ec-8e38c0af6e7c",
      "created": "2026-07-28T00:44:30.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-28T00:44:30.000Z",
      "name": "facebookcustomer-service.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookcustomer-service.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/af047a57-435b-4c2c-bc32-726566fc4188/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f96b1f60-adce-540d-b5c6-315eebd5d984",
      "created": "2026-07-28T01:02:28.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-28T01:02:28.000Z",
      "name": "facebook-notification.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-notification.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/530da9c3-56d8-42e6-9e06-eac94370780a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d346a170-e4aa-59e2-8bca-f35fa3e09e80",
      "created": "2026-07-28T01:02:37.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-28T01:02:37.000Z",
      "name": "facebook-in.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-in.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/ad8a1853-941d-4a93-bb84-1441b35327c8/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2c306eb3-4b66-5252-b644-f38b7f034a92",
      "created": "2026-07-28T01:02:39.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-28T01:02:39.000Z",
      "name": "trust-wallet.daservglobal.com",
      "description": "Suspicious phishing domain impersonating Trust Wallet, detected by phishunt.io (score 13/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'trust-wallet.daservglobal.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 13,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/trustwallet/1a853a99-08c0-4585-ab04-68c929ecc554/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "trustwallet"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--71e7d146-ef98-5a81-b918-ed604bffe502",
      "created": "2026-07-28T03:04:56.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-28T03:04:56.000Z",
      "name": "premio-instagram.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'premio-instagram.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/12a4d469-24d2-40e9-b811-441ebbbffc03/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b2c491e1-33c4-585a-bffe-c52b3bdc721c",
      "created": "2026-07-28T03:05:14.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-28T03:05:14.000Z",
      "name": "saque-instagram.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'saque-instagram.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/a3656af7-0774-493e-a776-959f78db627c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--da20f073-8f0b-5be2-bba3-66bc36ccd98a",
      "created": "2026-07-28T03:05:15.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-28T03:05:15.000Z",
      "name": "noreply-icloud.app",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'noreply-icloud.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/3fd21102-4478-4caf-a6a6-d4fdedd25cad/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e239307a-ebea-5911-89e3-7cde54900f89",
      "created": "2026-07-28T05:49:24.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-28T05:49:24.000Z",
      "name": "a1-kraken.com",
      "description": "Suspicious phishing domain impersonating Kraken, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'a1-kraken.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/kraken/2239ae2f-33e8-4d74-8e38-39dbe5eae7b4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "kraken"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a0cbe85c-f3df-5187-baf6-c2fb926c2477",
      "created": "2026-07-28T13:01:29.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-28T13:01:29.000Z",
      "name": "facebooklogin21.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin21.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/9dfc64a0-1743-4127-b0c4-47d02d064858/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0945430-16d8-5206-ae21-03229a56bd47",
      "created": "2026-07-28T13:01:32.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-28T13:01:32.000Z",
      "name": "facebooklogin239.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin239.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/bccef171-ea7f-44d9-9c40-4be8ff1d0fdf/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0a37f890-cc36-58f8-b509-3d3b6990d8b4",
      "created": "2026-07-28T18:05:50.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-28T18:05:50.000Z",
      "name": "office365licensingsupport.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'office365licensingsupport.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/c69639c2-f6a3-4077-8381-01427010e537/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a46e5612-8ff1-599b-b988-20a9502049e4",
      "created": "2026-07-28T18:06:11.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-28T18:06:11.000Z",
      "name": "icloud-network.com",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 21/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'icloud-network.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 21,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/c954789c-9e62-4746-ad39-de61f285aa9a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5b6493e5-377e-5c8c-ba5a-993da405da0c",
      "created": "2026-07-28T18:06:30.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-28T18:06:30.000Z",
      "name": "assign-icloud.com",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 19/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'assign-icloud.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 19,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/30581b1a-6c8a-4908-8caa-578c225c586b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--074e2ced-3867-592d-b7ed-44dcce662bb5",
      "created": "2026-07-28T18:06:38.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-28T18:06:38.000Z",
      "name": "outlookmail.social",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 17/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'outlookmail.social']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 17,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/abcc9681-d61f-47c6-9034-20dd13655fdf/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2c561a76-4649-5ce5-bc69-788f431181a2",
      "created": "2026-07-28T18:06:57.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-28T18:06:57.000Z",
      "name": "steamcommunity.blog",
      "description": "Suspicious phishing domain impersonating Steam, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'steamcommunity.blog']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/steam/828fed5d-1fd1-4474-94f7-2c36de53a517/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "steam"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7498f3ae-6cf9-5267-b8ce-f48195059124",
      "created": "2026-07-28T23:17:01.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-28T23:17:01.000Z",
      "name": "netflixroulette.club",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflixroulette.club']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/84a09bad-8b31-4737-88c6-8c940ae35acc/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--29f0ad8a-cf99-5cd6-972e-88f5c81e4e24",
      "created": "2026-07-29T01:01:34.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-29T01:01:34.000Z",
      "name": "login-my-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'login-my-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/f587fc58-489d-4ccd-afd5-d91bb1dbd467/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--412e5d0d-9779-52a3-b244-d256e3b6d1be",
      "created": "2026-07-29T01:01:42.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-29T01:01:42.000Z",
      "name": "jj-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'jj-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/782bea7b-506d-41cb-ab96-efbfa8507676/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--684a3357-3f2d-51ac-a66e-a402b0e99706",
      "created": "2026-07-29T01:01:46.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-29T01:01:46.000Z",
      "name": "rama-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'rama-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/0adf392d-1c67-408e-9286-fb080024732f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9471e6d8-c519-5839-844d-f6fb09eb5bec",
      "created": "2026-07-29T01:02:30.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-29T01:02:30.000Z",
      "name": "facebookloginpage2025.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginpage2025.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/352af64d-5010-4db0-bd3a-e1675fdb8ab9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2348c75a-8fc8-50ab-a66a-e817b193d72f",
      "created": "2026-07-29T05:48:30.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-29T05:48:30.000Z",
      "name": "microsoft365updates.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoft365updates.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/003cde31-66bf-4247-94a9-3a6fff361e87/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b31f387b-32d9-5040-b336-4d0f2edad306",
      "created": "2026-07-29T13:01:59.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-29T13:01:59.000Z",
      "name": "instagramrecovery.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramrecovery.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/78e16f99-d44c-4366-93f9-99851ed4fb7a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4271bdce-c5c5-5d21-a373-c1ef18418d62",
      "created": "2026-07-29T13:02:05.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-29T13:02:05.000Z",
      "name": "facebook-germany.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-germany.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c3ac9ca1-2311-49eb-bbc9-2cc5f4e12850/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2902886e-7b6e-5546-93ef-ce3b99b3d462",
      "created": "2026-07-29T13:03:24.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-29T13:03:24.000Z",
      "name": "facebookuserlogin.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookuserlogin.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/f19dc248-d203-43c5-a57f-f6b2ebfb4678/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea657705-95cb-5018-b678-a73b8e877469",
      "created": "2026-07-29T20:24:34.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-29T20:24:34.000Z",
      "name": "netflixreviewflix.com",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflixreviewflix.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/8c6ef71b-2f60-4f27-ae69-6fb25a10bebc/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--412b199c-c7a2-5f4a-a781-81cd75cd4d90",
      "created": "2026-07-29T20:33:01.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-29T20:33:01.000Z",
      "name": "googleplaiby.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googleplaiby.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/a7586c12-bb04-46ff-8b30-4789b37d1f34/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6394e82e-d2d3-5dfd-89bc-372ac2a377e9",
      "created": "2026-07-30T01:01:03.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-30T01:01:03.000Z",
      "name": "paypalcorp.blogspot.com",
      "description": "Suspicious phishing domain impersonating PayPal, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'paypalcorp.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/paypal/7ff8be0a-cc0b-4431-a13d-026275bccd63/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "paypal"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e441d90f-b0d1-58d0-8a87-8314df33e6f7",
      "created": "2026-07-30T13:02:00.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-30T13:02:00.000Z",
      "name": "facebookk.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookk.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c625b3e8-a095-420d-b383-41e5e2c2996d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--af2df56a-4d2a-5388-a4e0-9b858fc98c7c",
      "created": "2026-07-30T13:02:05.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-30T13:02:05.000Z",
      "name": "facebookahla.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookahla.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/0414fecd-ccc9-4571-9327-66446d6ab1dd/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--377b7ae3-837f-57f4-bda1-aab7c6ca12f9",
      "created": "2026-07-30T13:02:08.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-30T13:02:08.000Z",
      "name": "facebook1019key.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook1019key.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/1fbf7b6d-7515-4bc3-b6fe-35b36159bff2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fc4270c0-20f9-5a95-98e9-f9b96b690921",
      "created": "2026-07-30T13:02:16.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-30T13:02:16.000Z",
      "name": "instagramsnp.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramsnp.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/a01eb744-16c9-41ed-96ef-e98208378436/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c9a7f110-4b76-5884-beac-a9551b489360",
      "created": "2026-07-30T13:23:59.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-30T13:23:59.000Z",
      "name": "google1107.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'google1107.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/b22515f2-4aa2-4063-be79-83e2fb2d44fd/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bae7c543-66e4-5c21-9c68-1c24679f5230",
      "created": "2026-07-31T01:01:11.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-31T01:01:11.000Z",
      "name": "facebooknenys.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooknenys.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/9e0857d7-8f9b-4c17-8c71-e803cf0ee159/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2a86c4e9-3c5e-5e20-9928-b2683f3cb502",
      "created": "2026-07-31T05:46:06.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-31T05:46:06.000Z",
      "name": "support-inc-apple.com",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'support-inc-apple.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/ee035d88-20b0-41fa-b4b0-10fc71078207/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e40f674-0b8a-5816-b648-2ae108c54945",
      "created": "2026-07-31T05:46:07.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-31T05:46:07.000Z",
      "name": "icloudwebmx-ext04.help",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'icloudwebmx-ext04.help']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/d36953ae-ccd3-4d1f-819c-8c3ce2e6e1e2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6af537f5-d181-5fbc-843a-dc7426c98182",
      "created": "2026-07-31T05:46:08.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-31T05:46:08.000Z",
      "name": "googleepway.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googleepway.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/aac2278b-0aa1-43d1-acdb-88c1073ea391/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--21f94b72-7fb1-58fe-9bf5-efa2d629b17e",
      "created": "2026-07-31T05:46:09.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-31T05:46:09.000Z",
      "name": "app.googleoa.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 45/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'app.googleoa.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 45,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/9e538a2b-ddf7-4f94-8324-7ae9866fbd2f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0124055a-89e6-5f6d-8150-f86b8ec7f180",
      "created": "2026-07-31T05:46:11.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-31T05:46:11.000Z",
      "name": "microsoft-sharepoint.fr",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoft-sharepoint.fr']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/3330b4e8-0014-4140-986a-5f568a20d334/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--03a75c01-be5d-56ef-9329-42b52e3d70e0",
      "created": "2026-07-31T07:09:17.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-31T07:09:17.000Z",
      "name": "googlepeey.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googlepeey.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/887b795e-4e51-4db4-9f35-ecb4673cf05a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--691ef5fc-2131-56a6-8529-33b74307656c",
      "created": "2026-07-31T13:01:47.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-31T13:01:47.000Z",
      "name": "eu-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'eu-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/fb59902c-6086-446c-9172-d7ebaabc59c9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9966f240-c75d-514f-b897-ca17548dc5ef",
      "created": "2026-07-31T17:47:00.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-31T17:47:00.000Z",
      "name": "google-account-login.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'google-account-login.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/45fe8f8a-76fe-4ad8-8c1a-6c2b82302380/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c40891d3-ade5-5f0f-9b11-2ec39dfabfc2",
      "created": "2026-08-01T00:55:43.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-01T00:55:43.000Z",
      "name": "google8upbd.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'google8upbd.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/a04089ae-5c8a-4075-8272-cff6ef6ee5c2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ac1c56fb-466a-5a11-b6af-bf461badcd2f",
      "created": "2026-08-01T01:01:31.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-01T01:01:31.000Z",
      "name": "facebooklogin19.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogin19.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/433c8d9b-55a7-4344-9f08-f5cac5b05c02/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--05f80b19-e901-5f03-83ec-775d1fc93465",
      "created": "2026-08-01T01:01:51.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-01T01:01:51.000Z",
      "name": "bankofamericamailcompte.blogspot.com",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bankofamericamailcompte.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/ad8b0b9d-3408-4974-853a-7e2c75993ead/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--43067483-329b-5f37-be66-63364aa3b93d",
      "created": "2026-08-01T01:01:54.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-01T01:01:54.000Z",
      "name": "instagram-register.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-register.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/ffed60d9-1ad3-4bea-9982-e7e0c6fee77d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d05ef18-8fed-5865-918e-bdc6199d2fac",
      "created": "2026-08-01T06:19:22.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-01T06:19:22.000Z",
      "name": "edge-microsoft-zh.com.cn",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'edge-microsoft-zh.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/4e4284af-88e3-4313-817a-8c2d773ef5a8/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c24754b1-3e01-52e5-a3c9-1e0f7c1baec9",
      "created": "2026-08-01T07:01:27.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-01T07:01:27.000Z",
      "name": "google1208.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'google1208.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/f7c499f2-3d40-40be-83f6-26e3617d3a86/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fcfa118d-887c-5d43-af03-452a1e65b5a1",
      "created": "2026-08-01T08:33:27.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-01T08:33:27.000Z",
      "name": "whm.backend.hsbcbank-london.ws",
      "description": "Suspicious phishing domain impersonating HSBC, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'whm.backend.hsbcbank-london.ws']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/hsbc/43a0049d-23e8-42c1-8d93-2b025183f640/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "hsbc"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9120ed74-a5fc-5692-850b-42f771278535",
      "created": "2026-08-01T10:28:41.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-01T10:28:41.000Z",
      "name": "googlepllry.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googlepllry.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/c23ea5ab-ab49-4f15-84e2-194a90773bc4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ae375cad-4bb8-55a0-a382-590c5218ba91",
      "created": "2026-08-01T13:01:30.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-01T13:01:30.000Z",
      "name": "trackingnumbers.org",
      "description": "Suspicious phishing domain impersonating FedEx, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'trackingnumbers.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/fedex/88975cb3-0c45-486f-9f7d-1348b221ca53/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "fedex"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6989e665-0926-5e8b-ae3f-0d4964a14f5f",
      "created": "2026-08-01T13:02:40.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-01T13:02:40.000Z",
      "name": "z-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'z-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/9ac05aa6-b5e4-4c8d-9d1e-bb3357b271ef/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7045b70d-13e9-5e6a-ac84-41fda9b42ec1",
      "created": "2026-08-01T13:02:44.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-01T13:02:44.000Z",
      "name": "trackingnumbers.org",
      "description": "Suspicious phishing domain impersonating USPS, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'trackingnumbers.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/usps/68555614-a607-4cfa-82e8-5cd3f93d1801/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "usps"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b1ea7436-e87d-5be1-8019-3a1b967cc04c",
      "created": "2026-08-01T13:02:49.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-01T13:02:49.000Z",
      "name": "facebookwebsite9.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookwebsite9.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/4160086c-ae15-4c53-9fd5-92e9e7223087/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2024789-1740-523e-aa43-ad603390dda4",
      "created": "2026-08-02T01:02:35.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-02T01:02:35.000Z",
      "name": "facebook-rus.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-rus.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c165624f-39ce-44b5-a480-41e486e2496b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4509dfc1-801d-5624-835f-c1ef47c03b2a",
      "created": "2026-08-02T01:02:42.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-02T01:02:42.000Z",
      "name": "facebookfakepage.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookfakepage.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/ac005a29-85eb-4bd7-80d5-8a7db2b163de/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--65f3bf6f-40f1-5cc5-8658-a47f198d3073",
      "created": "2026-08-02T01:40:43.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-02T01:40:43.000Z",
      "name": "googlepepy.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googlepepy.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/4aa4bd5c-7c69-4c4f-a287-b89881b0f783/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6b728c9f-735a-5ff2-81d0-6a8db8e353c2",
      "created": "2026-08-02T04:16:59.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-02T04:16:59.000Z",
      "name": "googlepemy.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googlepemy.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/36ad3c2a-c030-4e10-88b6-4fe082768e58/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b18f2fe2-07e9-5820-9d56-ce2e0337cc96",
      "created": "2026-08-02T05:43:20.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-02T05:43:20.000Z",
      "name": "microsoftuk.co",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoftuk.co']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/3690fadf-3111-4434-b66d-d6a1c6ac27bb/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ea9f700a-ab35-5cbe-9032-176e9b9e0831",
      "created": "2026-08-02T09:53:52.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-02T09:53:52.000Z",
      "name": "googleplrzy.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googleplrzy.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/f8ef7760-00de-4c4d-86d7-59c64c2eb067/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--47ec162f-003f-53d3-9328-a0e4e58bfc53",
      "created": "2026-08-02T11:43:48.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-02T11:43:48.000Z",
      "name": "fedexinterviewprep.com",
      "description": "Suspicious phishing domain impersonating FedEx, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'fedexinterviewprep.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/fedex/17671297-3f0a-43a9-8dcb-9e138804d137/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "fedex"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--89870221-d581-5bcb-95ab-c3db8bfa74ff",
      "created": "2026-08-02T13:01:44.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-02T13:01:44.000Z",
      "name": "metamaskextensionnn.gitbook.io",
      "description": "Suspicious phishing domain impersonating MetaMask, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'metamaskextensionnn.gitbook.io']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/metamask/61f6e500-4ea1-4aa5-ae84-6967f2acb023/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "metamask"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53071ed0-8984-52bc-a649-ed307726ddf8",
      "created": "2026-08-02T13:01:56.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-02T13:01:56.000Z",
      "name": "faceb0k-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'faceb0k-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/9193f058-089f-4c69-a550-cd613db05679/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0814fdf-d116-5bb6-8139-e4535a8d1c2f",
      "created": "2026-08-02T13:02:20.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-02T13:02:20.000Z",
      "name": "facebookfakelogin.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookfakelogin.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/a0657687-64f2-42b4-886a-28b154c78554/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b857f98d-e077-5157-84e4-306c8a675cf8",
      "created": "2026-08-02T13:37:57.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-02T13:37:57.000Z",
      "name": "thrift.ww17.jorgazsb.scotiabank-secure.info",
      "description": "Suspicious phishing domain impersonating Scotiabank, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'thrift.ww17.jorgazsb.scotiabank-secure.info']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/scotiabank/79daf6d1-1c6e-41b0-8876-1db057db3a96/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "scotiabank"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1fcd8f2b-e3d2-53cc-989e-dfa5f5db7223",
      "created": "2026-08-02T16:10:23.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-02T16:10:23.000Z",
      "name": "traefik.ww17.jorgazsb.scotiabank-secure.info",
      "description": "Suspicious phishing domain impersonating Scotiabank, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'traefik.ww17.jorgazsb.scotiabank-secure.info']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/scotiabank/436d9c87-38b3-4319-8d05-ea59689eeef5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "scotiabank"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d492f6be-e9f2-5889-a344-4c9a8e1e0153",
      "created": "2026-08-03T19:19:57.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-03T19:19:57.000Z",
      "name": "fifaworldcups26.com",
      "description": "Suspicious phishing domain impersonating FIFA World Cup, detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'fifaworldcups26.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/fifa/533521fa-bac4-4abe-8151-838b6b2f783c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "fifa"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--44ef304f-db05-52bc-b4b2-e5d223f872cc",
      "created": "2026-08-04T01:00:43.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-04T01:00:43.000Z",
      "name": "instagram-tip.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-tip.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/75d0ed8b-9254-48ca-89cd-60fe3fc09170/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d918e32-17e9-56bf-8df5-f04c1852dde1",
      "created": "2026-08-04T05:24:57.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-04T05:24:57.000Z",
      "name": "ebay-wholesale.com",
      "description": "Suspicious phishing domain impersonating eBay, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ebay-wholesale.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ebay/c55dc147-70fc-4413-a070-10ebe58c25b2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ebay"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c7729c6-b007-5f0a-85e8-e81c12ce4721",
      "created": "2026-08-04T12:00:47.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-04T12:00:47.000Z",
      "name": "pago-correos.es",
      "description": "Suspicious phishing domain impersonating Correos, detected by phishunt.io (score 15/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'pago-correos.es']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 15,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/correos/316f385c-73d1-4559-89a6-e665fe469fb4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "correos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cb0155cb-8a2d-5d67-b117-65bbd4ddd9b8",
      "created": "2026-08-04T13:02:02.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-04T13:02:02.000Z",
      "name": "santander2026.dothome.co.kr",
      "description": "Suspicious phishing domain impersonating Banco Santander, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'santander2026.dothome.co.kr']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/santander/03d2d72c-3b3f-4bcd-8399-3294d49c42ff/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "santander"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a5edc627-82f6-5957-bfb7-2d5d71fb1b4c",
      "created": "2026-08-04T17:27:09.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-04T17:27:09.000Z",
      "name": "warehouse.ww17.jorgazsb.scotiabank-secure.info",
      "description": "Suspicious phishing domain impersonating Scotiabank, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'warehouse.ww17.jorgazsb.scotiabank-secure.info']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/scotiabank/710e1213-f3c7-421b-b6c8-79f606b3d418/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "scotiabank"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4b24e4c6-66a0-5f0c-9034-52a992f0e375",
      "created": "2026-08-05T05:27:31.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-05T05:27:31.000Z",
      "name": "ewlpnkrg.login.wccheck-0209014e-ext.santander.bimp-bot.duckdns.org",
      "description": "Suspicious phishing domain impersonating Banco Santander, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ewlpnkrg.login.wccheck-0209014e-ext.santander.bimp-bot.duckdns.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/santander/d371b197-ebdd-467d-8a2b-dcac979b46c2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "santander"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ddaa6fef-7188-5b9d-bad7-3e2525ed8942",
      "created": "2026-08-05T05:27:31.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-05T05:27:31.000Z",
      "name": "ewlpnkrg.www.login.wccheck-0209014e-ext.santander.bimp-bot.duckdns.org",
      "description": "Suspicious phishing domain impersonating Banco Santander, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ewlpnkrg.www.login.wccheck-0209014e-ext.santander.bimp-bot.duckdns.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/santander/9c728943-8728-4102-a4ab-b806081e4bd4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "santander"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4e1aa287-13f8-57e2-8b92-9bbc8a9f717c",
      "created": "2026-08-05T10:34:09.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-05T10:34:09.000Z",
      "name": "netflix-games.click",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflix-games.click']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/9e9b5105-b33a-4ae4-84d8-45f76d274552/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--af524f88-f57a-5389-ada5-d9e11feb9788",
      "created": "2026-08-05T13:01:15.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-05T13:01:15.000Z",
      "name": "amazon.biowikiweb.com",
      "description": "Suspicious phishing domain impersonating Amazon, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'amazon.biowikiweb.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/amazon/be52dde9-23ca-43cc-b75b-e691fa4dd3f4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "amazon"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8c25535a-bcae-54d3-825f-e55f32884ccf",
      "created": "2026-08-05T13:01:17.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-05T13:01:17.000Z",
      "name": "proteccion-outlook2026.iceiy.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'proteccion-outlook2026.iceiy.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/786d71cd-f6e5-47b2-a8b6-13f9a22983bc/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c5cb8078-8dfd-59a6-81d1-84924e4a7fc3",
      "created": "2026-08-05T17:26:58.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-05T17:26:58.000Z",
      "name": "www1-icloud.com",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'www1-icloud.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/aca57edd-bfd4-49af-8ec4-dd3bb93af0eb/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--018a55d2-7a12-55d9-b248-a5a3e2de043e",
      "created": "2026-08-05T17:26:58.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-05T17:26:58.000Z",
      "name": "paypal.com-websppsc-verification.epsilons.co",
      "description": "Suspicious phishing domain impersonating PayPal, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'paypal.com-websppsc-verification.epsilons.co']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/paypal/0c02bd9a-9cad-4ba6-98eb-241c2156a393/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "paypal"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fd821d41-40dd-5366-a294-692381879402",
      "created": "2026-08-06T05:26:44.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-06T05:26:44.000Z",
      "name": "photosharing-icloud.com",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'photosharing-icloud.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/bdddfd4e-a4ac-42f1-a07f-300eec069a3c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1afe0d90-0282-5e4f-adb3-d8ff01d85836",
      "created": "2026-08-06T05:26:45.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-06T05:26:45.000Z",
      "name": "gateareis.vu",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'gateareis.vu']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//81e42650-1d0c-40f8-aaf6-ceea99c1e421/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--52e4c95f-245d-55a9-bf9e-fd397fff88d3",
      "created": "2026-08-06T05:26:45.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-06T05:26:45.000Z",
      "name": "munimventures.com",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'munimventures.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//eb274379-7b2a-49e5-9074-512ee201c371/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--64708955-6f40-5baf-a620-182aeafbe009",
      "created": "2026-08-07T01:01:18.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-07T01:01:18.000Z",
      "name": "trezor-login-us-auth-start.typedream.app",
      "description": "Suspicious phishing domain impersonating Trezor, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'trezor-login-us-auth-start.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/trezor/73ac3f6d-0b65-47ff-9eb9-12215eef4cac/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "trezor"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2135e80b-62df-5123-9a8b-8a486e8d5e18",
      "created": "2026-08-07T01:01:35.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-07T01:01:35.000Z",
      "name": "facebook-developers.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-developers.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/e9768ca8-3fc5-4c12-8c74-420c2c0e89a7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f407e93d-15fc-5017-b65a-f7986389770c",
      "created": "2026-08-07T01:01:47.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-07T01:01:47.000Z",
      "name": "facebooklogininfo.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklogininfo.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/992cf1ef-6dff-453f-b9a9-ace798ae6294/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e75f71bb-2b2a-5a30-b106-d9a054a7dfaa",
      "created": "2026-08-07T05:29:09.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-07T05:29:09.000Z",
      "name": "skachat-microsoft-visual.ru",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 21/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'skachat-microsoft-visual.ru']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 21,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/a73bb666-4a16-4c6c-93e1-c72cbcdc2632/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--62f78516-7b4d-5497-8d86-279bb0c1abf9",
      "created": "2026-08-07T10:29:04.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-07T10:29:04.000Z",
      "name": "netflixtoto.xyz",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflixtoto.xyz']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/51d1a433-258a-448a-a25e-2edb7e76b3fe/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2079b5b9-9b37-515a-8c85-c0448faa1731",
      "created": "2026-08-07T17:27:20.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-07T17:27:20.000Z",
      "name": "login.rmdbwskx.santander.bimp-bot.duckdns.org",
      "description": "Suspicious phishing domain impersonating Banco Santander, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'login.rmdbwskx.santander.bimp-bot.duckdns.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/santander/4466ee66-95d8-4787-aa29-9987c06d1e34/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "santander"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--374af4f9-dfaa-5591-afbf-ba9ee40961d8",
      "created": "2026-08-07T17:27:25.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-07T17:27:25.000Z",
      "name": "login.wccheck-b18ca936-a.santander.bimp-bot.duckdns.org",
      "description": "Suspicious phishing domain impersonating Banco Santander, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'login.wccheck-b18ca936-a.santander.bimp-bot.duckdns.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/santander/eae29de0-315e-41e6-9cf7-46d7dcf32858/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "santander"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5e3f74a6-c0e7-50b4-b620-b01bfa1ebce1",
      "created": "2026-08-07T17:27:29.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-07T17:27:29.000Z",
      "name": "plugins.sugar-outlook.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 19/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'plugins.sugar-outlook.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 19,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/4f73247b-82f4-487f-9dc2-ee3e7ef99b2e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2ec6c870-20df-5bfa-9d24-bc9298f46cb8",
      "created": "2026-08-07T17:28:13.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-07T17:28:13.000Z",
      "name": "skachat-itunes.ru",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 17/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'skachat-itunes.ru']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 17,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/a88d6386-25c4-4559-ac01-7f9762653d37/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e23b376a-6554-50b9-8b13-133e9445fc46",
      "created": "2026-08-07T23:13:32.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-07T23:13:32.000Z",
      "name": "googleplouy.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googleplouy.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/5f320075-1cbd-48c7-9474-9490b3c58167/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--52706451-0d55-575c-bf59-7afa15732201",
      "created": "2026-08-08T01:02:19.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-08T01:02:19.000Z",
      "name": "outlooksereguri365.hstn.me",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'outlooksereguri365.hstn.me']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/68e9f160-6b3f-4377-b074-1267b4b88d10/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--395c7767-c1bc-5b85-b470-9dd748f6be58",
      "created": "2026-08-08T01:02:24.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-08T01:02:24.000Z",
      "name": "docs-google.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 15/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'docs-google.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 15,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/c66902dc-fa0a-4dd1-b87d-11a9e847bbeb/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e5228dd-b22b-59a0-8da7-bcb8dddd9b2d",
      "created": "2026-08-08T01:02:28.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-08T01:02:28.000Z",
      "name": "login-east3.cashappps.com",
      "description": "Suspicious phishing domain impersonating Cash App, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'login-east3.cashappps.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/cashapp/8e74bf82-2f08-4eb4-b614-a09631847cb3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "cashapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--53ed3931-e534-5845-a2b4-f7c97a14ba9f",
      "created": "2026-08-08T05:27:31.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-08T05:27:31.000Z",
      "name": "erutjhpk.login.dwmnhsqa.wccheck-6b3c4826-a.santandertelephony-yfcowbeta.bimp-bot.duckdns.org",
      "description": "Suspicious phishing domain impersonating Banco Santander, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'erutjhpk.login.dwmnhsqa.wccheck-6b3c4826-a.santandertelephony-yfcowbeta.bimp-bot.duckdns.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/santander/c0e09d5a-8c3d-45bd-985c-dd44008ad503/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "santander"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0da17f3e-48d5-51a1-884e-ded0c7349d89",
      "created": "2026-08-08T05:27:36.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-08T05:27:36.000Z",
      "name": "lkgrazsl.login.5b55bakaizeipheexooz.bckwsbem.santander.bimp-bot.duckdns.org",
      "description": "Suspicious phishing domain impersonating Banco Santander, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'lkgrazsl.login.5b55bakaizeipheexooz.bckwsbem.santander.bimp-bot.duckdns.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/santander/9a303b31-c9bf-4144-bfa6-05113726db44/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "santander"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--881a4b3f-81e6-536f-99a1-3ea117f41041",
      "created": "2026-08-08T05:27:54.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-08T05:27:54.000Z",
      "name": "deluxxe.com.br",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'deluxxe.com.br']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//7d611647-69a0-40c9-8244-63777bc41cf9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3b256ebb-47ea-5e03-8d8e-af5b5f1348a1",
      "created": "2026-08-08T13:01:39.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-08T13:01:39.000Z",
      "name": "instagram-demo.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-demo.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/8162cf24-aa2c-4060-b3b3-58f2d370b5a5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--62cf7a84-7ecd-5254-9be1-7f1b8998c304",
      "created": "2026-08-08T13:01:41.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-08T13:01:41.000Z",
      "name": "facebook-verification-system4.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-verification-system4.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/24730bfa-9f5c-4e65-9834-f06e49aa9cc3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fe2400b1-f070-511a-94fe-c6a61cb4a757",
      "created": "2026-08-08T13:01:59.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-08T13:01:59.000Z",
      "name": "facebookbigeronline.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookbigeronline.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/fba6a261-1c2d-4acd-b0db-0bc6a648443f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--25cc414b-502a-5eae-ad29-8be211396451",
      "created": "2026-08-08T13:03:00.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-08T13:03:00.000Z",
      "name": "instagram-instagram.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-instagram.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/7d2801f2-90d7-45f6-be1a-f52beb7780dc/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3f81be2d-56af-5906-bd77-f11ef12851d5",
      "created": "2026-08-08T13:03:03.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-08T13:03:03.000Z",
      "name": "binance-register.blogspot.com",
      "description": "Suspicious phishing domain impersonating Binance, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'binance-register.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/binance/10383449-d039-4cbf-b53e-4864fdf6049d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "binance"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8bba899d-8cd8-529e-9cc1-5e767f3d0c4c",
      "created": "2026-08-08T17:28:15.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-08T17:28:15.000Z",
      "name": "icloudhelp.com",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'icloudhelp.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/be9df45e-b373-4409-91d1-8c335cbbac35/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d43c4dd3-b596-5bdb-a433-38651cb2b82b",
      "created": "2026-08-08T17:29:35.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-08T17:29:35.000Z",
      "name": "rec-netflix.com",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 17/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'rec-netflix.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 17,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/8d6927f7-5399-4656-bb51-a2c6a1d68c8a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f2b5892b-0144-554d-a500-dc2417a0232d",
      "created": "2026-08-09T01:02:25.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-09T01:02:25.000Z",
      "name": "facebookloginreview.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginreview.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/873ee835-e761-4a8e-a218-244cac34d3b0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--66147837-9ec6-5caf-8f59-fe3b0ff8ad28",
      "created": "2026-08-09T01:03:37.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-09T01:03:37.000Z",
      "name": "www-itausegurancas.rf.gd",
      "description": "Suspicious phishing domain impersonating Ita\u00fa, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'www-itausegurancas.rf.gd']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/itau/44581d7a-fb39-4f7c-a9bc-903e36d847c0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "itau"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5cb92bd9-b3bb-5e0a-bc65-cc148207d272",
      "created": "2026-08-09T05:25:57.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-09T05:25:57.000Z",
      "name": "microsoft.vpn-update.org",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 21/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoft.vpn-update.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 21,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/b502902a-e5e4-4cbf-b958-ca816cb59d87/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bc8858ea-7153-5982-aa2e-8b4a1e290a3f",
      "created": "2026-08-09T07:58:03.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-09T07:58:03.000Z",
      "name": "hotmail143.net",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'hotmail143.net']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/4df56670-68d7-4de7-a5ca-8a0e6e49ce90/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--449483fa-865f-5321-bd37-9fa72f80f05e",
      "created": "2026-08-09T13:01:39.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-09T13:01:39.000Z",
      "name": "facebook-linkedin.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-linkedin.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/098798a2-b137-4ced-9464-782f965d50f9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--33711ef9-e11a-5cd6-8f35-42d1c5a706ca",
      "created": "2026-08-09T13:01:44.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-09T13:01:44.000Z",
      "name": "instagramloginpassword.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramloginpassword.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/ec274c28-c16d-4cbc-8459-c21bef552293/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ac7d6b01-4fb4-5fc1-98b3-18ba9336fe14",
      "created": "2026-08-09T13:01:46.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-09T13:01:46.000Z",
      "name": "facebook-login-redirect.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-login-redirect.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/1a5e591a-b95f-4e9c-9baa-2a761f179322/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a3f4e70c-9310-5b52-bb4c-374ded47b9e3",
      "created": "2026-08-09T14:10:18.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-09T14:10:18.000Z",
      "name": "site.outlookindia.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'site.outlookindia.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/8e1b3f68-ea34-4784-84ec-7e453d0c1806/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7afd968c-bf85-53b0-bfc7-33c94a4ceb11",
      "created": "2026-08-09T17:27:01.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-09T17:27:01.000Z",
      "name": "update-netflix.info",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'update-netflix.info']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/0e54cb89-1430-4209-ba50-23a84486d0d4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--38c354ac-e38b-568f-b1c5-83c6e0b5655a",
      "created": "2026-08-10T01:01:21.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-10T01:01:21.000Z",
      "name": "facebook-fansdanssapage.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-fansdanssapage.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/ab7ead5f-ce4c-47f2-a947-c8c570058620/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--defe0138-8c6d-5a6f-9e48-0f53ae136ec9",
      "created": "2026-08-10T01:01:27.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-10T01:01:27.000Z",
      "name": "facebooksuporteolaine.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooksuporteolaine.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/2919cd6a-3ace-459e-90ca-9a6126d1ac82/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b943e52-8b62-52ab-b053-6e7cee103836",
      "created": "2026-08-10T01:01:33.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-10T01:01:33.000Z",
      "name": "instagramfollowersfake.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 44/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramfollowersfake.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 44,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/d3a8db48-4003-4946-85c7-b96df63f2482/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1494adcf-597d-5e25-8413-f6398037d3a5",
      "created": "2026-08-10T01:01:36.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-10T01:01:36.000Z",
      "name": "instagramsupportverify.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramsupportverify.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/78d25570-614a-4457-97f6-92b30f68bea5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--397cc13c-674f-5d3a-b2fe-adb77e7bcabf",
      "created": "2026-08-10T05:28:05.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-10T05:28:05.000Z",
      "name": "short.googleadsense.com.tr",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'short.googleadsense.com.tr']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/4c99201c-2ad9-4157-a7df-65893fa82ab3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6bb1e0f7-2f8e-5ab0-b048-6c94d4f3905a",
      "created": "2026-08-10T13:01:02.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-10T13:01:02.000Z",
      "name": "facebooklivepage.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebooklivepage.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/0de5a27f-d424-4978-ab6c-5744639ed122/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--55cef9e2-0309-500d-bf08-b17435a1eb91",
      "created": "2026-08-10T15:03:12.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-10T15:03:12.000Z",
      "name": "www-microsoft.com.cn",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'www-microsoft.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/24638ba6-d041-4826-963d-91ddb02fa6c9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c4307dc0-af9b-50be-8672-b2981af540ee",
      "created": "2026-08-11T01:01:30.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-11T01:01:30.000Z",
      "name": "facebook-2022.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-2022.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c8bad0a3-916c-4541-b110-3db533b24ee4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2a02bc60-cae7-5d72-8951-199e8a88db3f",
      "created": "2026-08-11T05:25:56.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-11T05:25:56.000Z",
      "name": "search.g0ogle.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'search.g0ogle.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/426999c3-f019-4b00-a16d-07cb324f3234/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--219937c5-f6fe-5793-b916-9a259b7e8467",
      "created": "2026-08-11T05:25:56.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-11T05:25:56.000Z",
      "name": "fedexsubdelivery.com",
      "description": "Suspicious phishing domain impersonating FedEx, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'fedexsubdelivery.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/fedex/f53df695-fa05-49c0-89d2-562c3a0680d0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "fedex"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9e5ce915-1862-528c-97cd-90655308c268",
      "created": "2026-08-11T09:27:47.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-11T09:27:47.000Z",
      "name": "secure-dropbox.ist",
      "description": "Suspicious phishing domain impersonating Dropbox, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'secure-dropbox.ist']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dropbox/14e1304d-f0c9-4171-9426-3a5dd7859400/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dropbox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--27122d68-0cd2-5f16-a52e-f81d7f02648b",
      "created": "2026-08-11T10:22:58.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-11T10:22:58.000Z",
      "name": "googlepelay.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googlepelay.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/5073adfc-7955-4090-adbb-418c41b28c73/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--81636038-81d0-591c-bc42-dcf41e871c7e",
      "created": "2026-08-11T13:01:29.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-11T13:01:29.000Z",
      "name": "facebookloginid.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookloginid.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3db4e53a-628b-48d1-b789-3a2a1b4494f9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--114f905b-8fa5-5d47-8d46-9fa54038ebfe",
      "created": "2026-08-12T00:09:04.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-12T00:09:04.000Z",
      "name": "google1308.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'google1308.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/bfcd443d-0ad1-42ff-8062-d1e57c8a1fe6/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8b11bc22-06ea-5ae7-ac53-4e2e4b1035e7",
      "created": "2026-08-12T00:14:38.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-12T00:14:38.000Z",
      "name": "google1302.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'google1302.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/0b2f2c33-e609-45c3-b56a-deca25d016e7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ecd72d18-1dbb-5091-982a-3508d372741d",
      "created": "2026-08-12T01:01:43.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-12T01:01:43.000Z",
      "name": "facebook-auto-liker.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-auto-liker.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/5b70c512-af2e-4e61-9131-0dba6e66187b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e81edb7e-5d0b-563f-af27-e74dcf312e12",
      "created": "2026-08-12T05:24:41.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-12T05:24:41.000Z",
      "name": "googleww.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googleww.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/5daf0342-1061-447d-966b-edf3459588ad/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c5b5efb8-6a6b-5023-ab14-85e22561f810",
      "created": "2026-08-12T05:25:55.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-12T05:25:55.000Z",
      "name": "gpcconcrete.co.nz",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'gpcconcrete.co.nz']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//3e8fcb48-0af8-4b7b-ba88-e0cb70f2a48b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b4998db8-1936-5d53-91bb-d893949e97ef",
      "created": "2026-08-12T17:26:22.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-12T17:26:22.000Z",
      "name": "confirm-your-account-informations-paypal.com.ifotografix.co.uk",
      "description": "Suspicious phishing domain impersonating PayPal, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'confirm-your-account-informations-paypal.com.ifotografix.co.uk']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/paypal/fb18b8f7-70b2-4819-b376-6d4e4a115210/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "paypal"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67616d5b-9af1-5a7f-8535-68f4f69b305a",
      "created": "2026-08-12T17:28:12.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-12T17:28:12.000Z",
      "name": "api-41829387-44817741.google-cloud.services",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 16/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'api-41829387-44817741.google-cloud.services']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 16,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/7d1c6e5a-3b02-46de-a168-ce42efa1f0fd/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--50cbcdff-80af-550f-ae49-b051b324996b",
      "created": "2026-08-13T01:02:18.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-13T01:02:18.000Z",
      "name": "pay.paykmc.com",
      "description": "Suspicious phishing domain impersonating PayPal, detected by phishunt.io (score 21/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'pay.paykmc.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 21,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/paypal/2e28b2a2-1e5e-4417-b5a7-eafc9310a3bb/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "paypal"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d4b926e9-ef2b-54e3-8e90-021a669bddaa",
      "created": "2026-08-13T01:02:29.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-13T01:02:29.000Z",
      "name": "2017-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '2017-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/90b06bb9-b94f-4f09-bed1-2b4c362054de/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6a025135-d1bf-5cf2-ad01-6c8c1de2f7c7",
      "created": "2026-08-13T05:26:00.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-13T05:26:00.000Z",
      "name": "rcb.cuj.temporary.site",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'rcb.cuj.temporary.site']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//2a1ab1d2-aef2-424a-8901-979e369d31e3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8790d1d8-a0cd-538d-ac9a-f7c3e7e07b9c",
      "created": "2026-08-13T13:02:39.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-13T13:02:39.000Z",
      "name": "ledgrelivapp--crome.typedream.app",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ledgrelivapp--crome.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/28b026ed-8f92-4ead-878f-fcf5c6b67db7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--31745858-4c78-5275-a2b1-848a58da8db4",
      "created": "2026-08-13T13:02:43.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-13T13:02:43.000Z",
      "name": "ledger-live-download-sso-conect.typedream.app",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ledger-live-download-sso-conect.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/2b2bcc96-b2d2-499a-8f24-08ff22af2a4e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f0581e5d-e566-5a95-98a1-bf3113efb6fd",
      "created": "2026-08-13T13:02:49.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-13T13:02:49.000Z",
      "name": "ledger-live-wallet-start-conect-us-en.typedream.app",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ledger-live-wallet-start-conect-us-en.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/2e7035af-c99a-4654-a399-fdc3ac2d1478/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5cf14737-616f-5463-bb1c-2b35f70b6842",
      "created": "2026-08-13T13:03:27.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-13T13:03:27.000Z",
      "name": "binancewallett.blogspot.com",
      "description": "Suspicious phishing domain impersonating Binance, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'binancewallett.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/binance/3ad31d68-66dc-4066-9ad0-48968422d61f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "binance"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff916300-2cca-55e7-beb5-bc60731a0b8e",
      "created": "2026-08-13T17:52:34.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-13T17:52:34.000Z",
      "name": "xfinitywindowfilms.com",
      "description": "Suspicious phishing domain impersonating Xfinity (Comcast), detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'xfinitywindowfilms.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/xfinity/4846d944-1b67-48ef-bc77-021d08ff8627/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "xfinity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--92bb6ab5-c218-5932-9042-3a01daba6652",
      "created": "2026-08-14T13:01:35.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-14T13:01:35.000Z",
      "name": "uspsglobal.delivery",
      "description": "Suspicious phishing domain impersonating USPS, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'uspsglobal.delivery']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/usps/46496331-3805-4e0a-a7ff-3d420999cbf0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "usps"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6e11e5fa-5330-5770-ac05-d3471b70fa0e",
      "created": "2026-08-14T14:00:49.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-14T14:00:49.000Z",
      "name": "facebookteamhelp.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookteamhelp.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c1a2327b-b0c9-4ecf-aab5-41776a8e5669/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a7d72dcc-924d-5cfb-a197-273853867bc1",
      "created": "2026-07-07T01:45:37.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-07T01:45:37.000Z",
      "name": "securedsupport-coinbase.com",
      "description": "Suspicious phishing domain impersonating Coinbase, detected by phishunt.io (score 22/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'securedsupport-coinbase.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 22,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/coinbase/5ab1b47f-1ff3-4b2f-baba-1b0059fca080/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "coinbase"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f2ea96b4-43dc-5865-9416-88f5a7b8f895",
      "created": "2026-07-28T18:07:05.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-07-28T18:07:05.000Z",
      "name": "coinbasebackoffice.exchange",
      "description": "Suspicious phishing domain impersonating Coinbase, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'coinbasebackoffice.exchange']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/coinbase/75df3c6a-708c-4aff-a85d-f43d3c30a7b2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "coinbase"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3e331a14-f1bb-55c2-8e4d-83321bc95c11",
      "created": "2026-08-13T05:25:51.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-13T05:25:51.000Z",
      "name": "164196-coinbase.com",
      "description": "Suspicious phishing domain impersonating Coinbase, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '164196-coinbase.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/coinbase/cfb42cf8-cbf5-4e85-a0fc-021728463ca1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "coinbase"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--93bd685a-0e32-5b0a-8916-e13cf131b230",
      "created": "2026-08-17T01:03:19.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-17T01:03:19.000Z",
      "name": "coinbaseinvestors.ai",
      "description": "Suspicious phishing domain impersonating Coinbase, detected by phishunt.io (score 51/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'coinbaseinvestors.ai']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 51,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/coinbase/988a2c90-1247-44e0-a5cf-7941984c8d0c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "coinbase"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b615d135-90ab-52fd-8ff5-17aa6d978c57",
      "created": "2026-08-22T01:07:05.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-22T01:07:05.000Z",
      "name": "center.metacreatormonetizationsupportsystem.click",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'center.metacreatormonetizationsupportsystem.click']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/b1265f48-0df4-4d32-ac1d-f1b0b5e916c5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9dccab74-065a-5473-9931-319a1311698f",
      "created": "2026-08-22T09:01:58.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-22T09:01:58.000Z",
      "name": "paypal-invoice.com",
      "description": "Suspicious phishing domain impersonating PayPal, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'paypal-invoice.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/paypal/39df5068-0883-41ba-8d1c-ed8e561131fb/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "paypal"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b56ed1df-310b-5216-a5ba-a3c04ce5f0e3",
      "created": "2026-08-22T09:02:16.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-22T09:02:16.000Z",
      "name": "paypal-details.com",
      "description": "Suspicious phishing domain impersonating PayPal, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'paypal-details.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/paypal/048220e1-b13c-452b-9d94-ff38a3704a1e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "paypal"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5f6a278e-db8e-57a0-9f67-1dd490c93baa",
      "created": "2026-08-22T12:20:51.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-22T12:20:51.000Z",
      "name": "whatsapptools.pro",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 21/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'whatsapptools.pro']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 21,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/61156185-d7fd-4e1b-9f86-60b601c16907/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--16b28b35-d567-5be3-ab82-a94376185cbf",
      "created": "2026-08-22T13:02:00.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-22T13:02:00.000Z",
      "name": "paypal-password.blogspot.com",
      "description": "Suspicious phishing domain impersonating PayPal, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'paypal-password.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/paypal/9f8f855d-d4a4-4566-b96e-6b0f083a7034/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "paypal"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--386180eb-1fc8-5cf2-878b-bc20dffa8cdb",
      "created": "2026-08-22T13:02:07.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-22T13:02:07.000Z",
      "name": "facebook-visitantes.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-visitantes.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/0864bbae-1670-4e17-bd74-e74896527d3e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2076d0a1-6482-50c7-a512-3d2ff9bd00dd",
      "created": "2026-08-22T13:02:11.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-22T13:02:11.000Z",
      "name": "facebookclone.duckdns.org",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebookclone.duckdns.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/be50d977-1de9-4bf0-a8fc-3b258b5cedf3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3a00ba93-ea1d-5fd8-bbd0-18c59e177c89",
      "created": "2026-08-22T17:02:40.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-22T17:02:40.000Z",
      "name": "allegrolokalnie.oferta-lokalna8654968923445.shop",
      "description": "Suspicious phishing domain impersonating Allegro, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'allegrolokalnie.oferta-lokalna8654968923445.shop']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/allegro/fef20679-d9c1-4f7d-8745-a529e187911c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "allegro"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--90daf712-c0f6-558f-a878-ddce61236da0",
      "created": "2026-08-22T17:37:57.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-22T17:37:57.000Z",
      "name": "alibaba66malaysia.app",
      "description": "Suspicious phishing domain impersonating Alibaba, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'alibaba66malaysia.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/alibaba/c6a94f9a-411b-4d75-b38e-ab0e995c7d2f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "alibaba"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cbf76f98-30d8-504d-aa71-ad0232cf778f",
      "created": "2026-08-22T17:38:10.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-22T17:38:10.000Z",
      "name": "alibaba33.pro",
      "description": "Suspicious phishing domain impersonating Alibaba, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'alibaba33.pro']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/alibaba/3abe296b-bfc4-434a-8c05-7dd67088ff6e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "alibaba"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1f612054-9a6d-5665-b67e-08beaef1ef41",
      "created": "2026-08-22T17:41:20.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-22T17:41:20.000Z",
      "name": "alibaba666.bet",
      "description": "Suspicious phishing domain impersonating Alibaba, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'alibaba666.bet']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/alibaba/fb624f42-0def-4e1e-8a12-ce3756dce3d8/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "alibaba"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c4f5f68-1cb5-5122-9954-24018c47c31c",
      "created": "2026-08-23T01:03:17.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-23T01:03:17.000Z",
      "name": "me.h5-whatsapp-zn.hl.cn",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'me.h5-whatsapp-zn.hl.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/c961c2e0-75d5-4458-9b43-cebfe349ce0c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--019b6e70-524d-5920-bacd-fe74f820c3c6",
      "created": "2026-08-23T01:03:56.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-23T01:03:56.000Z",
      "name": "xfinity101.duckdns.org",
      "description": "Suspicious phishing domain impersonating Xfinity (Comcast), detected by phishunt.io (score 45/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'xfinity101.duckdns.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 45,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/xfinity/4af36e08-3106-4535-a6b3-ffb3fc9aa52e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "xfinity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--347d7726-f2f3-5cdc-8fe9-e6157dfd951b",
      "created": "2026-08-23T13:03:37.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-23T13:03:37.000Z",
      "name": "whatsapp-tools.lateinos.com.br",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'whatsapp-tools.lateinos.com.br']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/a3e43a05-7829-4c29-8afe-93a5bcda4a7e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--725b6a12-751e-5fe2-8f8e-17123040e573",
      "created": "2026-08-23T17:24:00.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-23T17:24:00.000Z",
      "name": "authentication.citrix-sharing.com",
      "description": "Suspicious phishing domain impersonating Citrix, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'authentication.citrix-sharing.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/citrix/03db0f18-004b-481c-bd30-496fe517a54d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "citrix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c02a622a-f2a2-584b-aa3b-db563271bf14",
      "created": "2026-08-23T20:40:24.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-23T20:40:24.000Z",
      "name": "alibaba666.pro",
      "description": "Suspicious phishing domain impersonating Alibaba, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'alibaba666.pro']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/alibaba/52034821-31e7-4400-8117-b71586cfd4e1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "alibaba"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7b684126-ea33-5125-a045-054310d175f7",
      "created": "2026-08-24T01:02:21.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-24T01:02:21.000Z",
      "name": "instagram.rents.ac",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram.rents.ac']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/6b9365f2-9012-4692-a96d-1536f08ee6e8/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a5931653-6a22-5b06-8df8-1a81d42f346b",
      "created": "2026-08-24T05:25:28.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-24T05:25:28.000Z",
      "name": "spotify-plus.com",
      "description": "Suspicious phishing domain impersonating Spotify, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'spotify-plus.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/spotify/4826a1db-d82d-4e58-b6ac-f7b5f1dc7d8f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "spotify"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--16e1afac-a198-52d7-a6d9-e24462531eb0",
      "created": "2026-08-24T13:01:53.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-24T13:01:53.000Z",
      "name": "lnk.ink",
      "description": "Suspicious phishing domain impersonating SEUR, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'lnk.ink']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/seur/91b6f4f6-d503-4d38-8274-6096d7ddcd66/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "seur"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b8e62251-c4b8-57f8-8026-8e06e0bd13c4",
      "created": "2026-08-24T13:01:57.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-24T13:01:57.000Z",
      "name": "livepc.h5-whatsapp-zn.hl.cn",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'livepc.h5-whatsapp-zn.hl.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/17c59491-da3c-405e-a74e-22ac945f0a11/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0ddb58f1-f416-5be7-a33a-75aca927b818",
      "created": "2026-08-24T22:02:12.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-24T22:02:12.000Z",
      "name": "roblox.com.et",
      "description": "Suspicious phishing domain impersonating Roblox, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'roblox.com.et']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/roblox/65f52312-625a-4ac7-8cc8-c45e300f7e5c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "roblox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--28a32671-a9f5-581a-ab48-4ad841794daa",
      "created": "2026-08-24T22:02:35.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-24T22:02:35.000Z",
      "name": "roblox.com.gr",
      "description": "Suspicious phishing domain impersonating Roblox, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'roblox.com.gr']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/roblox/4def2b22-8304-4fcf-b815-eba710971e95/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "roblox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--65b2f90a-636f-561b-aa2e-c132ed8b746c",
      "created": "2026-08-24T22:03:08.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-24T22:03:08.000Z",
      "name": "roblox.com.bi",
      "description": "Suspicious phishing domain impersonating Roblox, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'roblox.com.bi']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/roblox/f9dd4b1f-e06b-4f38-b794-ab6c5fead730/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "roblox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--36453e59-ef4e-5c91-b363-d8de60339142",
      "created": "2026-08-24T22:03:41.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-24T22:03:41.000Z",
      "name": "roblox.com.bn",
      "description": "Suspicious phishing domain impersonating Roblox, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'roblox.com.bn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/roblox/f927080c-8f92-4892-814b-473d2d069ce3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "roblox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cdf825e8-6fd4-5141-bf7d-1af242bbd98f",
      "created": "2026-08-24T22:03:57.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-24T22:03:57.000Z",
      "name": "roblox.com.pt",
      "description": "Suspicious phishing domain impersonating Roblox, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'roblox.com.pt']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/roblox/ed9aa1fd-c50a-4958-9f4b-5601d237cb16/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "roblox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ce022415-b884-5bb6-9280-d45dbef749e6",
      "created": "2026-08-24T23:32:00.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-24T23:32:00.000Z",
      "name": "roblox.com.kz",
      "description": "Suspicious phishing domain impersonating Roblox, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'roblox.com.kz']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/roblox/62df1e62-030e-40d6-baee-a1f51a3f3895/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "roblox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d8f7346e-11ce-509f-bb9e-11b3c124211c",
      "created": "2026-08-25T01:02:18.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-25T01:02:18.000Z",
      "name": "facebook-ba.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-ba.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/d4129abc-fe27-458c-b8bc-fa8aaab592b4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--699b0808-a691-5d21-b002-599c585aefe4",
      "created": "2026-08-25T01:02:29.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-25T01:02:29.000Z",
      "name": "facebook-hr.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-hr.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3a6a5d74-0def-4f6f-a281-29c91157f4ba/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e28ce511-6859-53f2-a512-3ddc79cbe65a",
      "created": "2026-08-25T01:44:59.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-25T01:44:59.000Z",
      "name": "movistar-recaudo-epayc.com",
      "description": "Suspicious phishing domain impersonating Movistar, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'movistar-recaudo-epayc.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/movistar/29aa00e3-6aee-4730-8ab7-2b7330e4d629/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "movistar"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0ea23719-f5d7-5d47-a707-54df78084b6e",
      "created": "2026-08-25T04:40:28.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-25T04:40:28.000Z",
      "name": "rekemonedasi-facebook.org",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'rekemonedasi-facebook.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/405f101b-c2c7-4281-8dba-e7ea3a13fe4b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--04c421da-91c9-5b44-82d3-45822e8e8003",
      "created": "2026-08-25T13:03:44.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-25T13:03:44.000Z",
      "name": "htttps-www-roblox.co",
      "description": "Suspicious phishing domain impersonating Roblox, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'htttps-www-roblox.co']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/roblox/19f9ba9a-45f9-4353-aa8b-9cb13416572d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "roblox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f7a008a7-81a8-5786-864b-c693526304b3",
      "created": "2026-08-25T13:04:06.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-25T13:04:06.000Z",
      "name": "hhttps-www-roblox.co",
      "description": "Suspicious phishing domain impersonating Roblox, detected by phishunt.io (score 45/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'hhttps-www-roblox.co']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 45,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/roblox/8abffe19-e380-44f3-a2c9-ad55bc4f0353/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "roblox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0ac475e5-1012-5c95-a338-8f9b1ad95b30",
      "created": "2026-08-25T13:04:25.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-25T13:04:25.000Z",
      "name": "ledger-liveusa.zapier.app",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ledger-liveusa.zapier.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/3e0be6b7-9df2-436b-bfc3-90d2ff13348d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de3a7600-8071-580d-841f-a4ad80d22c73",
      "created": "2026-08-25T13:04:33.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-25T13:04:33.000Z",
      "name": "lovevivah.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 16/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'lovevivah.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 16,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/8a3c181b-636b-4ae3-a9f1-49b3949e48f9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--106afd27-12bb-5b0c-b6e8-cd913b366b61",
      "created": "2026-08-25T17:25:05.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-25T17:25:05.000Z",
      "name": "18493821-coinbase.com",
      "description": "Suspicious phishing domain impersonating Coinbase, detected by phishunt.io (score 18/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '18493821-coinbase.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 18,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/coinbase/e271dd57-dc7f-424a-96f1-ce271e16d7ed/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "coinbase"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--75e30c0e-45f4-5f6e-9551-abded7b85790",
      "created": "2026-08-26T01:02:28.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-26T01:02:28.000Z",
      "name": "11ec78d.netsolhost.com",
      "description": "Suspicious phishing domain impersonating SEUR, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '11ec78d.netsolhost.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/seur/57cfda4c-92da-4c95-9103-1d098e50fb92/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "seur"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--34a4c0d9-38a3-5368-8005-01b1f9835dcb",
      "created": "2026-08-26T01:02:29.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-26T01:02:29.000Z",
      "name": "file-whatsappn.hl.cn",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'file-whatsappn.hl.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/ec764242-29fc-4767-b6eb-3c0686476e68/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0f05d221-fe7d-5e00-84ca-0109d7f53dd1",
      "created": "2026-08-26T05:24:34.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-26T05:24:34.000Z",
      "name": "dpdi.xyz",
      "description": "Suspicious phishing domain impersonating DPD, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'dpdi.xyz']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dpd/44c55560-88cc-4bb6-b4f8-89eca0e32acb/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dpd"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6ba75fde-7a05-5b71-8188-7e6370799112",
      "created": "2026-08-26T05:24:35.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-26T05:24:35.000Z",
      "name": "googleplsey.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 30/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googleplsey.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 30,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/132f9033-e3a9-46ed-8f4e-a19a24fdc384/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--87f35744-c7dd-52c7-9b14-ab3751574c15",
      "created": "2026-08-26T06:11:49.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-26T06:11:49.000Z",
      "name": "seureonline.shop",
      "description": "Suspicious phishing domain impersonating SEUR, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'seureonline.shop']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/seur/c650a1b7-f32b-455d-b7cd-acf26c7bf412/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "seur"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b4db1b2f-bbc4-5133-b1f1-ac5f77e4c49b",
      "created": "2026-08-26T13:02:29.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-26T13:02:29.000Z",
      "name": "docusign.login.adrpowersystem.com",
      "description": "Suspicious phishing domain impersonating DocuSign, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'docusign.login.adrpowersystem.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/docusign/9ffeab1c-7104-448d-8365-c298ac72aa33/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "docusign"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bec21446-701c-534e-a157-b42597a7ff20",
      "created": "2026-08-26T13:02:44.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-26T13:02:44.000Z",
      "name": "njj.standard.us-east-1.oortstorages.com",
      "description": "Suspicious phishing domain impersonating DocuSign, detected by phishunt.io (score 75/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'njj.standard.us-east-1.oortstorages.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 75,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/docusign/74c85fa5-5310-4984-b470-8ed47c8cd50b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "docusign"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dd43a1ae-941b-58f7-aa3c-3b2164d62d57",
      "created": "2026-08-26T13:02:52.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-26T13:02:52.000Z",
      "name": "vodafone-form.mhmr.ro",
      "description": "Suspicious phishing domain impersonating Vodafone, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'vodafone-form.mhmr.ro']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/vodafone/05070343-3dff-4532-9a9a-3d92185a0a78/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "vodafone"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1bf92c1b-8f81-5066-b63c-7e082b0f0505",
      "created": "2026-08-26T13:03:05.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-26T13:03:05.000Z",
      "name": "reentrega-seur-envio.cloudaccess.host",
      "description": "Suspicious phishing domain impersonating SEUR, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'reentrega-seur-envio.cloudaccess.host']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/seur/ee4b5ef0-0aa1-42e5-8485-bd05e812d229/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "seur"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fca5a285-fba9-5fb2-b3b2-5eab4ba5f611",
      "created": "2026-08-27T01:04:05.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-27T01:04:05.000Z",
      "name": "facebook-7.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-7.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/1eb71ffa-96b7-4f84-b5bd-01c7a3fec1f0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c9b6633-0f22-595c-91e7-f6963a6a4906",
      "created": "2026-08-27T01:04:29.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-27T01:04:29.000Z",
      "name": "secure-trezor-en-io.typedream.app",
      "description": "Suspicious phishing domain impersonating Trezor, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'secure-trezor-en-io.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/trezor/bed946e5-8788-462e-b4f5-aa4cc279cae4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "trezor"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9cf3ae77-ecaa-5173-9734-8f9d4d630e9c",
      "created": "2026-08-27T01:05:25.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-27T01:05:25.000Z",
      "name": "instagramlogin08.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramlogin08.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/7465a3bd-17b2-4428-834e-501f3a56c6cb/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5ca25b3-35d3-5248-ba78-33c5df70366f",
      "created": "2026-08-27T01:05:48.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-27T01:05:48.000Z",
      "name": "whatsappfreewhatsapp.blogspot.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'whatsappfreewhatsapp.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/eaed4216-b59e-4506-87d4-d4af051cc1c7/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5bb8d017-f824-5693-be9a-b28fcdcfa802",
      "created": "2026-08-27T01:07:10.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-27T01:07:10.000Z",
      "name": "facebook-seks-30.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-seks-30.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/18fed14e-e5eb-4c76-87ae-be95eeb96619/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0c29dbdb-f059-55a2-8981-eea7e6237f4a",
      "created": "2026-08-27T01:07:48.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-27T01:07:48.000Z",
      "name": "dhl-express-test.lobster-cloud.com",
      "description": "Suspicious phishing domain impersonating DHL, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'dhl-express-test.lobster-cloud.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dhl/31ea6339-1b1f-427a-a302-9e9182f72bfd/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dhl"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--557c3095-85c2-5f9f-95d7-6031b3d0ce3b",
      "created": "2026-08-27T01:08:01.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-27T01:08:01.000Z",
      "name": "id-kraken-controle.com",
      "description": "Suspicious phishing domain impersonating Kraken, detected by phishunt.io (score 45/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'id-kraken-controle.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 45,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/kraken/0103be07-698f-4056-99aa-319254882909/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "kraken"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9c2b9290-8abe-514b-a2c3-2600dc7d0c2e",
      "created": "2026-08-27T01:09:31.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-27T01:09:31.000Z",
      "name": "cvmac.id",
      "description": "Suspicious phishing domain impersonating DocuSign, detected by phishunt.io (score 19/100, verdict noise). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'cvmac.id']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 19,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/docusign/89f7d3aa-3534-48ac-afa0-d7d130bef32a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "docusign"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cd9601a0-18fa-5d1e-8cf0-cb2c60af222c",
      "created": "2026-08-27T05:24:43.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-27T05:24:43.000Z",
      "name": "expert-xfinity.best",
      "description": "Suspicious phishing domain impersonating Xfinity (Comcast), detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'expert-xfinity.best']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/xfinity/dbcc6ade-7574-481f-999c-cdb7d75f7689/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "xfinity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a56f520d-1968-5bef-ad9c-a7575a02bb53",
      "created": "2026-08-27T05:24:45.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-27T05:24:45.000Z",
      "name": "icloud-i-cl.com",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'icloud-i-cl.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/54be60c3-aeea-4463-886a-1615b69c2beb/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--7d3b9fb8-5512-5951-9d48-160af5209ed4",
      "created": "2026-08-27T05:26:48.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-27T05:26:48.000Z",
      "name": "sylam.vip",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'sylam.vip']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//c6c7dd3b-9210-4497-b8d7-d11fa83520a8/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--aaaec739-984d-5a1a-9137-bcdf54222d3e",
      "created": "2026-08-27T13:02:08.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-27T13:02:08.000Z",
      "name": "sso-ledger-live-strt-ledger-support-cdn.typedream.app",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'sso-ledger-live-strt-ledger-support-cdn.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/fa1617d5-29f3-4b4c-9262-d423310c8246/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b6cd5175-e1f0-52b7-90b0-9b16f69b889d",
      "created": "2026-08-28T01:02:15.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-28T01:02:15.000Z",
      "name": "login-yahoo-verify.blogspot.com",
      "description": "Suspicious phishing domain impersonating Yahoo, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'login-yahoo-verify.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/yahoo/6429bd71-98d1-4699-8aa8-acf2dc892290/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "yahoo"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--92438f33-c97c-5cfe-9bea-b11ae766ed2a",
      "created": "2026-08-28T01:02:53.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-28T01:02:53.000Z",
      "name": "facebook-links.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-links.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/3dd7002e-fdda-410e-bec2-a636a3605630/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fffbfae5-78ca-5fd0-810d-0d6b84d0449e",
      "created": "2026-08-28T01:02:55.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-28T01:02:55.000Z",
      "name": "icloud.trienkhaiweb.com",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'icloud.trienkhaiweb.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/bf597b67-2acc-4efe-802b-4057b005eeb5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--590f58e9-42f0-592f-a51d-2e6780d8a26c",
      "created": "2026-08-28T01:03:00.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-28T01:03:00.000Z",
      "name": "metamasklogniox.gitbook.io",
      "description": "Suspicious phishing domain impersonating MetaMask, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'metamasklogniox.gitbook.io']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/metamask/9c6b6cb8-1522-4a99-8099-0134f05f9ab8/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "metamask"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a46237e4-fd87-5dd0-8d06-0d03ef82d199",
      "created": "2026-08-28T04:17:22.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-28T04:17:22.000Z",
      "name": "ebay-c.com",
      "description": "Suspicious phishing domain impersonating eBay, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ebay-c.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ebay/fd5640f9-21ad-46b4-b760-d7368aaf83b0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ebay"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--458d7f58-baeb-52c4-ac4b-2878103ddede",
      "created": "2026-08-28T05:24:56.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-28T05:24:56.000Z",
      "name": "ebayfoll.store",
      "description": "Suspicious phishing domain impersonating eBay, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ebayfoll.store']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ebay/40cff67c-d784-4ad1-914f-dada27388d0a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ebay"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c524bcb9-1631-5ccc-98b3-d73a23355137",
      "created": "2026-08-28T05:24:58.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-28T05:24:58.000Z",
      "name": "asif.me",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'asif.me']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//a935dfce-772f-4488-abc9-2e9dbda718bd/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cc9d42b3-740c-5448-8eb2-289262fc6531",
      "created": "2026-08-28T05:26:55.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-28T05:26:55.000Z",
      "name": "prizebond.net.pk",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'prizebond.net.pk']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//d6cb7d4f-5755-4f9d-9793-7c66ed3a58d9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--9fcee453-d798-5d11-a8c3-2e0976f866ad",
      "created": "2026-08-28T10:52:03.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-28T10:52:03.000Z",
      "name": "alibaba66.co",
      "description": "Suspicious phishing domain impersonating Alibaba, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'alibaba66.co']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/alibaba/7a79df0d-c668-4011-a6a4-63fad0585375/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "alibaba"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2225b230-91f5-5dd3-9365-ec1d2ca197fe",
      "created": "2026-08-28T13:15:35.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-28T13:15:35.000Z",
      "name": "web-conect-us-ledger-live-wallet.typedream.app",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'web-conect-us-ledger-live-wallet.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/2711ec30-a33d-4ad0-9ed6-3f3653110f91/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--be0770eb-ff7b-5a61-8eae-abc90841cc24",
      "created": "2026-08-28T13:15:46.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-28T13:15:46.000Z",
      "name": "trezor-io-start-us-help-access.typedream.app",
      "description": "Suspicious phishing domain impersonating Trezor, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'trezor-io-start-us-help-access.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/trezor/5f530f42-a7ba-43d4-806d-9518b1d7fec0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "trezor"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2ffff4f6-c2f0-5f45-b7d3-c039665a99c9",
      "created": "2026-08-28T13:16:39.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-28T13:16:39.000Z",
      "name": "support-ledgrcom-start-web.typedream.app",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'support-ledgrcom-start-web.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/74c1c412-8196-4331-ba59-28bc79518616/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--56ba3bd8-213e-5ca7-9078-01e9d338d542",
      "created": "2026-08-28T15:04:02.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-28T15:04:02.000Z",
      "name": "loja.amazon-promos.shop",
      "description": "Suspicious phishing domain impersonating Amazon, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'loja.amazon-promos.shop']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/amazon/b8aaa8f4-d578-42ee-9569-7dd6319508ea/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "amazon"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6459caef-3e2f-554e-ba8b-90d84ec5375a",
      "created": "2026-08-28T17:24:53.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-28T17:24:53.000Z",
      "name": "shoppingonamazon.net",
      "description": "Suspicious phishing domain impersonating Amazon, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'shoppingonamazon.net']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/amazon/1f3fc203-f91e-4aa0-a893-f725683970d2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "amazon"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--32385953-f2bd-53ea-85bb-09df2d7cd45f",
      "created": "2026-08-28T17:43:26.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-28T17:43:26.000Z",
      "name": "alibaba66slot.app",
      "description": "Suspicious phishing domain impersonating Alibaba, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'alibaba66slot.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/alibaba/efb91061-f898-469d-bd05-7a7e631c9bd9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "alibaba"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5dbe882e-9ec6-5a79-84af-a0e0f66a6411",
      "created": "2026-08-28T22:01:37.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-28T22:01:37.000Z",
      "name": "roblox.com.mu",
      "description": "Suspicious phishing domain impersonating Roblox, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'roblox.com.mu']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/roblox/4cbb35ce-4ad6-4a9f-935c-011c86df94b2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "roblox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4270f0c3-a5ff-5412-848d-e29a78a0c085",
      "created": "2026-08-29T01:02:26.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T01:02:26.000Z",
      "name": "trezor-io-start-conect-auth.typedream.app",
      "description": "Suspicious phishing domain impersonating Trezor, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'trezor-io-start-conect-auth.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/trezor/9f1a698d-511b-4b23-baf7-ebd259ebbec5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "trezor"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fdd894d3-3202-5e08-8087-87a61afdf494",
      "created": "2026-08-29T01:02:32.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T01:02:32.000Z",
      "name": "trezrstartpublic-com-en-auths.typedream.app",
      "description": "Suspicious phishing domain impersonating Trezor, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'trezrstartpublic-com-en-auths.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/trezor/bfc6b96e-0d62-4c56-b360-cb7152107f9f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "trezor"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--edc34c04-9342-5e87-b1eb-9d310c9f77fa",
      "created": "2026-08-29T01:02:43.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T01:02:43.000Z",
      "name": "windows-ledger-live.typedream.app",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'windows-ledger-live.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/7241dbbd-1eba-4a72-a95b-a1b6d7c2d09c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--44aff663-2696-59d3-bd67-cf8c5d870a27",
      "created": "2026-08-29T01:03:10.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T01:03:10.000Z",
      "name": "start-web-en-ledger-live-login.typedream.app",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'start-web-en-ledger-live-login.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/22b0df35-b50a-4419-9f8c-dcef0fd1b8ce/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--df51463c-2fd5-5213-b864-84c5e0bdc39d",
      "created": "2026-08-29T01:03:26.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T01:03:26.000Z",
      "name": "xfinityrefunds.com",
      "description": "Suspicious phishing domain impersonating Xfinity (Comcast), detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'xfinityrefunds.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/xfinity/32c877e9-5663-42b1-91d3-d4c5c5fce56f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "xfinity"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f700012d-d3c2-5805-b15e-08538dd1a3f4",
      "created": "2026-08-29T01:03:32.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T01:03:32.000Z",
      "name": "exodus-wallet.global.ssl.fastly.net",
      "description": "Suspicious phishing domain impersonating Exodus, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'exodus-wallet.global.ssl.fastly.net']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/exodus/d65694ce-deb5-4d2a-92cb-19348f2bcee5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "exodus"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f4eed084-b56a-588d-ac4c-6d41960f9f2b",
      "created": "2026-08-29T01:03:40.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T01:03:40.000Z",
      "name": "pub-d68525cbc6144dcaaac2fc0354aa17dd.r2.dev",
      "description": "Suspicious phishing domain impersonating DocuSign, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'pub-d68525cbc6144dcaaac2fc0354aa17dd.r2.dev']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/docusign/23a5b426-9cc1-4b63-894f-2ec1b860699c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "docusign"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--bdbf1b08-aacf-5ba5-9d6a-57487b71ac05",
      "created": "2026-08-29T05:24:56.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T05:24:56.000Z",
      "name": "fmi-icloud.pro",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'fmi-icloud.pro']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/4d7e18d1-a72a-439d-85df-0a59fc66d14f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--899dcf48-f73d-5fe1-8c1a-0972de8ccca2",
      "created": "2026-08-29T05:24:56.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T05:24:56.000Z",
      "name": "steuerquimica.cl",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'steuerquimica.cl']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//6a59ee2b-f142-4c1d-aad0-33386036ac7f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--487425a8-50f4-5b63-ad9e-be4834c85fca",
      "created": "2026-08-29T05:25:20.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T05:25:20.000Z",
      "name": "icloud-sharedalbum.com",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'icloud-sharedalbum.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/171888d5-fea9-4adb-b324-842a14b22398/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8ec86b0b-f447-555c-8deb-3e849245a7d6",
      "created": "2026-08-29T13:05:12.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T13:05:12.000Z",
      "name": "netflix-login.blogspot.com",
      "description": "Suspicious phishing domain impersonating Netflix, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'netflix-login.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/netflix/536bcb6c-b61d-4c92-b984-e1c863b83b94/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "netflix"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d3279c9a-0d10-5c7c-a765-de0493da7335",
      "created": "2026-08-29T13:06:25.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T13:06:25.000Z",
      "name": "ledger-lives-desktop.square.site",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ledger-lives-desktop.square.site']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/6cc47c8a-77c1-475e-ada7-9783f02f030f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d7dfc1c1-8ed4-53d5-8565-a4b3bbd7aa36",
      "created": "2026-08-29T13:08:44.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T13:08:44.000Z",
      "name": "facebook-login-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-login-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/f3c63666-478e-49fa-b48e-f4d487a3d7f3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--de2935f6-3ccf-5aee-991b-ffd694b09f28",
      "created": "2026-08-29T13:09:29.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T13:09:29.000Z",
      "name": "loginfacebook-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'loginfacebook-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c1a271b3-38e4-4c68-bee2-225ca642ed80/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6287f130-a901-51b8-8b47-2d51d3c0a74c",
      "created": "2026-08-29T13:11:22.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T13:11:22.000Z",
      "name": "vi-facebook.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'vi-facebook.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/c11f5e12-4353-4bd8-82ec-c62082620ae2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b2959481-f465-563f-b8b7-e2abf4a0b618",
      "created": "2026-08-29T13:12:00.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T13:12:00.000Z",
      "name": "whatsapp.dir.com.my",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'whatsapp.dir.com.my']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/d019f376-a20b-4d51-b330-b6dff020df39/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5dff034d-429a-5993-969d-8fe4e9264ce7",
      "created": "2026-08-29T13:12:51.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T13:12:51.000Z",
      "name": "trustwallet-login.blogspot.com",
      "description": "Suspicious phishing domain impersonating Trust Wallet, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'trustwallet-login.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/trustwallet/765b1f40-8289-4413-b52b-cef7206e11ad/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "trustwallet"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fa186554-4eee-55e2-b7f7-669c313b4e05",
      "created": "2026-08-29T13:14:33.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T13:14:33.000Z",
      "name": "facebook-astuces-news.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-astuces-news.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/e5beef27-73de-403b-84df-09dc65aaaa4a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a15d986d-d205-526e-b10f-e178adb079df",
      "created": "2026-08-29T13:16:25.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T13:16:25.000Z",
      "name": "ledger-live-login-web.square.site",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ledger-live-login-web.square.site']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/ff2fd97b-1277-4309-bbf6-020af76f6973/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c9f1ffaa-066f-5215-a60d-f033ba8b309e",
      "created": "2026-08-29T13:17:04.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T13:17:04.000Z",
      "name": "instagram-clone-app-cyi5.bolt.host",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 26/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-clone-app-cyi5.bolt.host']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 26,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/1ac68d54-e43f-40bd-84da-13c5985687c8/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--fcff8394-557e-5af5-ada4-0b6c2880587e",
      "created": "2026-08-29T13:17:45.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T13:17:45.000Z",
      "name": "whatsapp-verify.blogspot.com",
      "description": "Suspicious phishing domain impersonating WhatsApp, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'whatsapp-verify.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/whatsapp/15595635-1b7f-44fd-adbd-d9f5c1f3c958/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "whatsapp"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f88ab2d1-5b02-5c71-a4ff-869badd67ec5",
      "created": "2026-08-29T13:18:44.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T13:18:44.000Z",
      "name": "home-ledgrreliveapp.typedream.app",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'home-ledgrreliveapp.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/af0f53fc-14ac-45cd-84c2-d68a7d7fef32/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b94ddca9-f352-580d-b1e8-b79122937a58",
      "created": "2026-08-29T17:24:49.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T17:24:49.000Z",
      "name": "bankofamerica-com-update-new-secure-loading-sitkey-onilne-pass.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bankofamerica-com-update-new-secure-loading-sitkey-onilne-pass.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/8e2748e9-adbb-495f-9407-7de122befc6a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c2033cc7-f28e-5e8f-9d6c-d46d5820bd42",
      "created": "2026-08-29T17:24:54.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T17:24:54.000Z",
      "name": "bankofamericamortagage.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bankofamericamortagage.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/353ecbed-a09f-487c-b451-a3b4cc83fd08/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--755df61b-dc1a-554c-800f-aabbe579674a",
      "created": "2026-08-29T17:25:01.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T17:25:01.000Z",
      "name": "googleuserlogin.cam",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googleuserlogin.cam']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/f0c3a0b8-b351-4553-bfc0-40be5777decd/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2abd361b-1586-5510-8d3e-f565b93ef0dc",
      "created": "2026-08-29T17:25:18.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T17:25:18.000Z",
      "name": "bankofamerica-verificatie.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bankofamerica-verificatie.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/07f33dae-7af0-4a35-87f2-4c3c3595dccd/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--40ef0815-9d85-5650-8fe2-e35a578aa6c5",
      "created": "2026-08-29T18:01:06.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-29T18:01:06.000Z",
      "name": "dpd.sirjooni.com",
      "description": "Suspicious phishing domain impersonating DPD, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'dpd.sirjooni.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dpd/652ae808-bb8d-4f98-8883-28f7f6fcbdda/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dpd"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5a5ab3e2-5105-5206-be28-6f08ee3bfdfe",
      "created": "2026-08-30T00:01:32.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T00:01:32.000Z",
      "name": "usps.us-nqzqo.life",
      "description": "Suspicious phishing domain impersonating USPS, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'usps.us-nqzqo.life']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/usps/edee3660-19e6-4705-b574-d5c37bfd8bec/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "usps"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--2e327d53-17df-5d91-92f5-8ce7912df22d",
      "created": "2026-08-30T00:33:04.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T00:33:04.000Z",
      "name": "alibaba66a.net",
      "description": "Suspicious phishing domain impersonating Alibaba, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'alibaba66a.net']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/alibaba/df8483e8-a334-4dc4-8bfb-e44d1f7a1366/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "alibaba"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a88c2ebb-d240-5ce2-8ae7-153ce81a2346",
      "created": "2026-08-30T01:02:11.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T01:02:11.000Z",
      "name": "facebook-loging.blogspot.com",
      "description": "Suspicious phishing domain impersonating Facebook, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'facebook-loging.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/facebook/37eb177a-e453-4480-8f48-307ccbdaca88/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "facebook"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--08d420a3-6809-545b-8bbf-bf724075b1de",
      "created": "2026-08-30T01:02:19.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T01:02:19.000Z",
      "name": "trezor-io-lernnu.typedream.app",
      "description": "Suspicious phishing domain impersonating Trezor, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'trezor-io-lernnu.typedream.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/trezor/6dbc4b4e-83cf-4b5a-acff-0124e552d68b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "trezor"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--18677dbc-b3aa-5a8f-8896-9c675130c686",
      "created": "2026-08-30T05:24:51.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T05:24:51.000Z",
      "name": "bankofamerica-com-login-update-unauthorized.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bankofamerica-com-login-update-unauthorized.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/8faa9a7c-c6f0-44d7-9b7f-9d5df440a5d1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0830b20d-1299-52d4-b2bd-b52d985dfae0",
      "created": "2026-08-30T05:24:53.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T05:24:53.000Z",
      "name": "bankofamericablockchain.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bankofamericablockchain.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/85d95ec5-6f19-4c14-9312-3b4c2f18692e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--83ac0a82-900f-5a32-8c92-8fb5415ea52f",
      "created": "2026-08-30T11:01:12.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T11:01:12.000Z",
      "name": "allegrolokalnie.lokalna-47294.sbs",
      "description": "Suspicious phishing domain impersonating Allegro, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'allegrolokalnie.lokalna-47294.sbs']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/allegro/9320552a-7c09-4cfa-bc3e-f31db9304c24/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "allegro"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5166a791-d4cf-5297-b419-9269540a36fb",
      "created": "2026-08-30T13:03:49.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T13:03:49.000Z",
      "name": "start-ledgren.zapier.app",
      "description": "Suspicious phishing domain impersonating Ledger, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'start-ledgren.zapier.app']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ledger/894da4c8-359b-43ba-a290-1db9cba5722f/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ledger"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--62998a49-67e5-5b84-8f23-3c3813541746",
      "created": "2026-08-30T13:04:31.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T13:04:31.000Z",
      "name": "roblox.com.bz",
      "description": "Suspicious phishing domain impersonating Roblox, detected by phishunt.io (score 21/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'roblox.com.bz']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 21,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/roblox/44f846dc-f536-4bcb-bce8-1e7f863906f9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "roblox"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--40a5b9c7-e1c4-57ed-a23f-f331dee0ea70",
      "created": "2026-08-30T13:05:23.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T13:05:23.000Z",
      "name": "on.instagram-g.com.cn",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'on.instagram-g.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/ce96ec60-1c1f-46f5-bb96-858b6bcb0f67/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1dc5ab7a-3d96-5e31-aa88-2190a723c7aa",
      "created": "2026-08-30T13:05:39.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T13:05:39.000Z",
      "name": "cm.instagram-g.com.cn",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 33/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'cm.instagram-g.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 33,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/4e3424d7-2b4e-4f9b-ac50-e5d74be4c228/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--22446f3c-3eab-535c-aa30-1458ce7f60c1",
      "created": "2026-08-30T13:06:02.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T13:06:02.000Z",
      "name": "login.authorised-support.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 45/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'login.authorised-support.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 45,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/15cc6a85-bcbd-4d85-b02c-97aa8ac16f75/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5cba6e4a-7e4a-54bc-8362-6cbb20900a76",
      "created": "2026-08-30T13:06:13.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T13:06:13.000Z",
      "name": "ebay-phone-number.blogspot.com",
      "description": "Suspicious phishing domain impersonating eBay, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'ebay-phone-number.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/ebay/820fa749-5366-4d37-9e6f-b64c8b4fdcb1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "ebay"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0083b153-2c3f-577c-af49-c07e77b2a0f9",
      "created": "2026-08-30T13:07:31.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T13:07:31.000Z",
      "name": "dpd.hhvka.club",
      "description": "Suspicious phishing domain impersonating DPD, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'dpd.hhvka.club']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dpd/40e549e7-12a8-4ed2-a6e2-eee281058684/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dpd"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--316b3824-b4a5-54c5-8dd3-43743fb09c48",
      "created": "2026-08-30T13:07:47.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T13:07:47.000Z",
      "name": "dpd.oovra.club",
      "description": "Suspicious phishing domain impersonating DPD, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'dpd.oovra.club']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dpd/8f0c24e9-933a-4c2c-a426-c73e211ade0c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dpd"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--687934f6-d86c-53d2-af9d-6e0c12294338",
      "created": "2026-08-30T13:08:46.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T13:08:46.000Z",
      "name": "dpd.ffmka.club",
      "description": "Suspicious phishing domain impersonating DPD, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'dpd.ffmka.club']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/dpd/aae6b094-d51e-47c8-8fdb-2965fb67e05a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "dpd"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ff5c01c2-9422-5b73-bc34-cf475f6feca3",
      "created": "2026-08-30T17:25:14.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T17:25:14.000Z",
      "name": "support.zoom.us.pro.kaisarstore.dpdns.org",
      "description": "Suspicious phishing domain impersonating Zoom, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'support.zoom.us.pro.kaisarstore.dpdns.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/zoom/12a84c24-2590-4722-98f8-79ae0c5f2949/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "zoom"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5b488b59-53ca-5af6-915d-08af325b7f06",
      "created": "2026-08-30T17:25:15.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T17:25:15.000Z",
      "name": "bankofamericana.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bankofamericana.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/10965b0a-3eae-4847-9dd3-febb5048be24/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c914b255-d8fb-5351-950f-ab2a414a3436",
      "created": "2026-08-30T17:25:15.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T17:25:15.000Z",
      "name": "debt-bankofamerica.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'debt-bankofamerica.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/418a9125-9b8c-47a1-94a6-0d3dcad7c113/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c3560ecd-1403-50ca-94b3-b201880e0aab",
      "created": "2026-08-30T17:25:26.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T17:25:26.000Z",
      "name": "mail.bankofamerica-secure-changelog.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mail.bankofamerica-secure-changelog.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/c3b25cf2-e33c-48b8-849a-2eab63743941/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b0b2e21c-914f-5a4b-af38-5d425306fbc3",
      "created": "2026-08-30T17:25:26.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T17:25:26.000Z",
      "name": "support.zoom.us.vip.kaisarstore.dpdns.org",
      "description": "Suspicious phishing domain impersonating Zoom, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'support.zoom.us.vip.kaisarstore.dpdns.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/zoom/2c1f937d-dbec-4ca1-87ad-eac111516f25/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "zoom"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--790ef169-1f21-512f-9b10-50772e2ac516",
      "created": "2026-08-30T17:25:28.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T17:25:28.000Z",
      "name": "case185366-coinbase.com",
      "description": "Suspicious phishing domain impersonating Coinbase, detected by phishunt.io (score 23/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'case185366-coinbase.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 23,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/coinbase/ab1b63d6-d119-4718-9162-995a28a43c99/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "coinbase"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d8b1caf3-6e28-5f51-92cc-9c74e2df7cd5",
      "created": "2026-08-30T17:25:29.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T17:25:29.000Z",
      "name": "icloudweb-ext1476.click",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 25/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'icloudweb-ext1476.click']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 25,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/df00e8db-48f4-4af0-bffe-3eeb10ad35e9/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6452c173-1de5-53bd-a95d-7e78c0ec7d7a",
      "created": "2026-08-30T17:25:33.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-30T17:25:33.000Z",
      "name": "bankofamericamerchantservices.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'bankofamericamerchantservices.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/d3459d81-10d6-43e5-8861-6d6767111675/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5b4de733-c168-50dd-b86c-89f5172f288e",
      "created": "2026-08-31T01:01:42.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-31T01:01:42.000Z",
      "name": "instagram-accounts-login.duckdns.org",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 70/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-accounts-login.duckdns.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 70,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/e3a4a127-7297-4d13-9b63-1cb247cceb3a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e3c8f387-9b9c-5d03-8583-579567b58cf7",
      "created": "2026-08-31T04:43:21.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-31T04:43:21.000Z",
      "name": "alibaba188.org",
      "description": "Suspicious phishing domain impersonating Alibaba, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'alibaba188.org']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/alibaba/ecdbc638-e3bb-4a4d-8729-f08beaf7c844/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "alibaba"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--39ea4c7a-96ca-5e70-8af6-317f1112f9fb",
      "created": "2026-08-31T05:24:38.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-31T05:24:38.000Z",
      "name": "googleplsmy.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'googleplsmy.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/b2992209-4f37-4f5b-b116-a5ae29f508c5/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--3d15acba-b09c-5a78-a4b9-c520a62b926c",
      "created": "2026-08-31T05:24:44.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-31T05:24:44.000Z",
      "name": "mail.icloud-i-cl.com",
      "description": "Suspicious phishing domain impersonating Apple, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'mail.icloud-i-cl.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/apple/72e0db4a-ce08-45b0-8d96-f53463511c6e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "apple"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ad73c034-e578-596e-af07-46bfb9ea21e2",
      "created": "2026-08-31T05:24:44.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-31T05:24:44.000Z",
      "name": "care-bankofamerica.ph",
      "description": "Suspicious phishing domain impersonating Bank of America, detected by phishunt.io (score 28/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'care-bankofamerica.ph']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 28,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/bankofamerica/815771e9-78d7-4e0b-8fa7-65dfc4b17465/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "bankofamerica"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ddf7adfa-26eb-5068-a3b1-de215f3f68b1",
      "created": "2026-08-31T05:26:28.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-31T05:26:28.000Z",
      "name": "misilabario.cl",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'misilabario.cl']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//864430ec-a961-45b9-bc3a-0e8c6e80c986/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--27c0e531-d8ed-5554-9bb3-d59e2e847198",
      "created": "2026-08-31T05:26:29.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-31T05:26:29.000Z",
      "name": "kenhoward.com",
      "description": "Suspicious phishing domain impersonating an unknown brand, detected by phishunt.io (score 95/100, verdict critical). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'kenhoward.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 95,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious//dfd0a0fb-8a26-49a0-b074-83ef29887b40/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--68b4e712-3fec-5701-8c24-f3991f71f9b4",
      "created": "2026-08-31T09:01:13.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-31T09:01:13.000Z",
      "name": "allegrolokalnie.lokalna-958204.sbs",
      "description": "Suspicious phishing domain impersonating Allegro, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'allegrolokalnie.lokalna-958204.sbs']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/allegro/eb708f04-4a0b-4a8c-9983-6566e04c9ebe/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "allegro"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5705be8e-dbba-5b66-8653-77306b733e84",
      "created": "2026-08-31T09:01:30.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-31T09:01:30.000Z",
      "name": "allegro.lokalna-958204.sbs",
      "description": "Suspicious phishing domain impersonating Allegro, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'allegro.lokalna-958204.sbs']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/allegro/1f5c7ac8-3b8e-4abd-8277-a6d3a5efab65/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "allegro"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--4bf30dde-961f-504e-bd79-7bf2800efa3f",
      "created": "2026-08-31T13:01:46.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-31T13:01:46.000Z",
      "name": "instagram-e.com.cn",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 31/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-e.com.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 31,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/67ac04a3-9c31-41ff-863a-268ac8043659/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e8ea25f5-4e15-590e-9260-d049a1f7faff",
      "created": "2026-08-31T17:24:15.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-31T17:24:15.000Z",
      "name": "54893-coinbase.com",
      "description": "Suspicious phishing domain impersonating Coinbase, detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '54893-coinbase.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/coinbase/86b4a42a-daa7-4dcf-9368-f52ca218a478/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "coinbase"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ca512fee-5398-56c9-8e09-626978f74061",
      "created": "2026-08-31T17:24:16.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-31T17:24:16.000Z",
      "name": "978489-coinbase.com",
      "description": "Suspicious phishing domain impersonating Coinbase, detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '978489-coinbase.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/coinbase/94317a86-0c28-4487-8bf8-08e39ea2a9a2/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "coinbase"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--67834b75-0d16-5a96-a56b-3352b31dcc0e",
      "created": "2026-08-31T17:24:18.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-31T17:24:18.000Z",
      "name": "online.accounts-google-com-id29902wavx-ssl-k-emailrenew55.codes566ghhhbvnnjui.srpska-banka.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'online.accounts-google-com-id29902wavx-ssl-k-emailrenew55.codes566ghhhbvnnjui.srpska-banka.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/f32035b5-08b8-4ccf-86cf-c6548abcf6ac/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--dca7700a-b3b3-5287-ade7-5d3f4b998ed0",
      "created": "2026-08-31T17:24:18.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-31T17:24:18.000Z",
      "name": "accounts-google-com-id29902wavx-ssl-k-emailrenew55.srpska-banka.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'accounts-google-com-id29902wavx-ssl-k-emailrenew55.srpska-banka.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/242b12c6-c117-4f10-bbbc-aa8bd187d9c1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c125f96-e9ca-583d-ad1b-a33f7f7f7277",
      "created": "2026-08-31T17:24:18.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-31T17:24:18.000Z",
      "name": "accounts-google-com.srpska-banka.com",
      "description": "Suspicious phishing domain impersonating Google, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'accounts-google-com.srpska-banka.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/google/8e6f0cef-f412-4cd4-b7e9-ff2812f7d689/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "google"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d6cf811b-20c9-5823-a4e7-6e482079e2a4",
      "created": "2026-08-31T17:24:19.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-31T17:24:19.000Z",
      "name": "metamask88.com",
      "description": "Suspicious phishing domain impersonating MetaMask, detected by phishunt.io (score 29/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'metamask88.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 29,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/metamask/0f83aa77-b3ce-4e5e-8d15-8f404f2bc6a0/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "metamask"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6bc84cf2-ce2b-5c15-988d-021d65b4da54",
      "created": "2026-08-31T17:26:56.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-31T17:26:56.000Z",
      "name": "11.alibaba-taobaol.cn",
      "description": "Suspicious phishing domain impersonating Alibaba, detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '11.alibaba-taobaol.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/alibaba/517c4434-5618-4f43-8ee8-c4cf4494a53b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "alibaba"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f9cd05ad-8860-55b8-89ae-4713ce3c8963",
      "created": "2026-08-31T17:26:56.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-31T17:26:56.000Z",
      "name": "22.alibaba-taobaol.cn",
      "description": "Suspicious phishing domain impersonating Alibaba, detected by phishunt.io (score 20/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = '22.alibaba-taobaol.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 20,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/alibaba/c4b3802f-a0e7-49e3-9ab5-2c669829e1fa/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "alibaba"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0d7b7ebd-fb89-529d-be01-a7f525e8aa15",
      "created": "2026-08-31T20:01:14.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-08-31T20:01:14.000Z",
      "name": "allegrolokalnie.lokalna-ofera930133.lol",
      "description": "Suspicious phishing domain impersonating Allegro, detected by phishunt.io (score 35/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'allegrolokalnie.lokalna-ofera930133.lol']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 35,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/allegro/910ea076-9b2d-4258-a895-8a5c7873d7d8/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "allegro"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ec1dea71-fb7e-5c4a-a62f-1f2a8771ba8a",
      "created": "2026-09-01T01:02:11.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-09-01T01:02:11.000Z",
      "name": "microsoftwordob.blogspot.com",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 41/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'microsoftwordob.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 41,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/4a2c971a-7668-4b8d-adf3-fe2c8306099d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8f5d9fcf-c509-5ba1-ba23-0ac7bfd7a82d",
      "created": "2026-09-01T01:03:21.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-09-01T01:03:21.000Z",
      "name": "swanhui.com",
      "description": "Suspicious phishing domain impersonating USPS, detected by phishunt.io (score 45/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'swanhui.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 45,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/usps/e956dc36-cfc7-4584-a657-38dd43ba8aad/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "usps"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a3c2899a-5ae4-5ca1-a6a9-4ac61b337ae4",
      "created": "2026-09-01T01:03:24.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-09-01T01:03:24.000Z",
      "name": "fls-a29a8cd9-0161-4493-bf5c-9f682b16d0c8.laravel.cloud",
      "description": "Suspicious phishing domain impersonating Microsoft, detected by phishunt.io (score 24/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'fls-a29a8cd9-0161-4493-bf5c-9f682b16d0c8.laravel.cloud']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 24,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/microsoft/19919ae9-db08-4057-8161-09c8a098f403/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "microsoft"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f60d15f5-d0a5-57a8-8d1c-759b28297fc2",
      "created": "2026-09-01T01:03:32.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-09-01T01:03:32.000Z",
      "name": "instagram-app.cn",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 34/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagram-app.cn']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 34,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/51fc1576-1ab3-4934-8ebd-6dc0c6b40fdb/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a5d868ff-eefa-5b96-a561-26a704522b83",
      "created": "2026-09-01T02:00:59.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-09-01T02:00:59.000Z",
      "name": "allegro.plkuptera732183278681.bond",
      "description": "Suspicious phishing domain impersonating Allegro, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'allegro.plkuptera732183278681.bond']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/allegro/fe45a9fe-1921-4a5b-93e7-be2aac595f3c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "allegro"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--c7ed39d8-62ba-5561-840f-9afec7b364ec",
      "created": "2026-09-01T03:01:45.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-09-01T03:01:45.000Z",
      "name": "allegrolokalnie.lokalna-ofera812712.sbs",
      "description": "Suspicious phishing domain impersonating Allegro, detected by phishunt.io (score 36/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'allegrolokalnie.lokalna-ofera812712.sbs']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 36,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/allegro/d4d142b8-1109-470c-a16a-f6801713d73c/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "allegro"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cc4d842e-8734-5e84-a043-2b24142d51cd",
      "created": "2026-09-01T05:01:32.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-09-01T05:01:32.000Z",
      "name": "allegrolokalnie.lokalna-ofeta287689147.sbs",
      "description": "Suspicious phishing domain impersonating Allegro, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'allegrolokalnie.lokalna-ofeta287689147.sbs']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/allegro/dcfc654c-15e7-4fd0-a77f-6a8d247520a6/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "allegro"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8758886f-1a98-5077-8264-836e248b6ace",
      "created": "2026-09-01T05:02:15.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-09-01T05:02:15.000Z",
      "name": "allegro.lokalna-ofeta287689147.sbs",
      "description": "Suspicious phishing domain impersonating Allegro, detected by phishunt.io (score 43/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'allegro.lokalna-ofeta287689147.sbs']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 43,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/allegro/5bbac8c8-3d36-4d44-8d31-428bbc686b4a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "allegro"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--cefe4b4e-b5d7-550b-9b97-8b609d2a9271",
      "created": "2026-09-01T05:02:34.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-09-01T05:02:34.000Z",
      "name": "allegrolokalnie.pl-893057502435.icu",
      "description": "Suspicious phishing domain impersonating Allegro, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'allegrolokalnie.pl-893057502435.icu']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/allegro/6157a43c-88bb-4612-bf83-454fe0048cd4/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "allegro"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--1b06b3fb-52c8-57b4-a7a5-bb3100d68d85",
      "created": "2026-09-01T05:03:17.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-09-01T05:03:17.000Z",
      "name": "allegro.lokalna-0904921.sbs",
      "description": "Suspicious phishing domain impersonating Allegro, detected by phishunt.io (score 38/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'allegro.lokalna-0904921.sbs']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 38,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/allegro/7ecd8512-0da7-4486-904d-74630d72b6ec/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "allegro"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--afb8f7e1-760a-52d4-a751-f8a91778b681",
      "created": "2026-09-01T05:03:39.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-09-01T05:03:39.000Z",
      "name": "allegro.pl-893057502435.icu",
      "description": "Suspicious phishing domain impersonating Allegro, detected by phishunt.io (score 40/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'allegro.pl-893057502435.icu']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 40,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/allegro/1b950e16-3e6e-47ad-a443-bd44104ae54a/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "allegro"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--e4c81055-5303-5262-bf56-ff149ff7c43e",
      "created": "2026-09-01T05:24:22.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-09-01T05:24:22.000Z",
      "name": "fedexonl.com",
      "description": "Suspicious phishing domain impersonating FedEx, detected by phishunt.io (score 27/100, verdict low). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'fedexonl.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 27,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/fedex/5c21b6bd-7522-444a-9e94-51e38a769b5e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "fedex"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6361c275-a5fa-5792-a6a9-ab6061f3f44a",
      "created": "2026-09-01T05:24:22.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-09-01T05:24:22.000Z",
      "name": "correosiicr.cc",
      "description": "Suspicious phishing domain impersonating Correos, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'correosiicr.cc']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/correos/2c775544-dc9a-47cb-9e08-9c196ee9dc17/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "correos"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--898ce250-92af-568e-b2cb-27bcc4071070",
      "created": "2026-09-01T06:01:14.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-09-01T06:01:14.000Z",
      "name": "allegro.oferta-lokalana684538913895.shop",
      "description": "Suspicious phishing domain impersonating Allegro, detected by phishunt.io (score 32/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'allegro.oferta-lokalana684538913895.shop']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 32,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/allegro/cdd4b2f9-1508-4cbd-b98d-9bd044a1841b/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "allegro"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--822cc089-815b-54a0-9152-4befb0bd1c91",
      "created": "2026-09-01T09:01:40.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-09-01T09:01:40.000Z",
      "name": "allegrolokalnie.lokalna-ofeta9914122115.sbs",
      "description": "Suspicious phishing domain impersonating Allegro, detected by phishunt.io (score 37/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'allegrolokalnie.lokalna-ofeta9914122115.sbs']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 37,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/allegro/1e8d84bd-6217-4f69-bf2b-128b736826fa/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "allegro"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--8fc53f27-7432-5a51-bacd-877d2127504c",
      "created": "2026-09-01T09:02:09.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-09-01T09:02:09.000Z",
      "name": "allegro.lokalna-ofeta9914122115.sbs",
      "description": "Suspicious phishing domain impersonating Allegro, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'allegro.lokalna-ofeta9914122115.sbs']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/allegro/055d4881-7117-445a-b38f-32fb2e71eab3/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "allegro"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5c8c7023-4772-5ded-a527-04cad4c446cb",
      "created": "2026-09-01T11:02:13.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-09-01T11:02:13.000Z",
      "name": "allegro.lokalna-8487391.sbs",
      "description": "Suspicious phishing domain impersonating Allegro, detected by phishunt.io (score 47/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'allegro.lokalna-8487391.sbs']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 47,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/allegro/5993cb08-27a8-4a85-b6bc-4ca0bf01078e/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "allegro"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--41af4b2b-5b7b-5a70-858d-d2d0609dcba6",
      "created": "2026-09-01T11:03:10.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-09-01T11:03:10.000Z",
      "name": "allegrolokalnie.lokalna-8487391.sbs",
      "description": "Suspicious phishing domain impersonating Allegro, detected by phishunt.io (score 45/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'allegrolokalnie.lokalna-8487391.sbs']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 45,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/allegro/c21719c0-1577-4ff9-9dab-8749147df14d/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "allegro"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--5b58a2e1-30c7-5d9b-b2da-cebae134748a",
      "created": "2026-09-01T13:04:27.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-09-01T13:04:27.000Z",
      "name": "instagramloginpage2021.blogspot.com",
      "description": "Suspicious phishing domain impersonating Instagram, detected by phishunt.io (score 52/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'instagramloginpage2021.blogspot.com']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 52,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/instagram/5f159c7a-b966-467b-9378-b8c6b79ddca1/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "instagram"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d5b12bbd-8593-5b13-b70a-c7f91018fcf2",
      "created": "2026-09-01T14:01:26.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-09-01T14:01:26.000Z",
      "name": "allegro.lokalna-0493729.sbs",
      "description": "Suspicious phishing domain impersonating Allegro, detected by phishunt.io (score 39/100, verdict medium). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'allegro.lokalna-0493729.sbs']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 39,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/allegro/f977ee3b-2ce1-40b6-8ae9-60bc2f4f5613/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "allegro"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--31a6463f-30bd-555c-9133-75608d279e1d",
      "created": "2026-09-01T15:01:25.000Z",
      "modified": "2026-09-01T15:30:05.000Z",
      "valid_from": "2026-09-01T15:01:25.000Z",
      "name": "allegro.kupteraz429199421.xyz",
      "description": "Suspicious phishing domain impersonating Allegro, detected by phishunt.io (score 42/100, verdict high). Score is a heuristic risk score, not a calibrated probability.",
      "indicator_types": [
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'allegro.kupteraz429199421.xyz']",
      "pattern_type": "stix",
      "pattern_version": "2.1",
      "confidence": 42,
      "created_by_ref": "identity--3a6d556b-bd12-52ee-940a-5f959556769f",
      "object_marking_refs": [
        "marking-definition--94868c89-83c2-464b-929b-a1a8aa3c8487"
      ],
      "external_references": [
        {
          "source_name": "phishunt",
          "url": "https://phishunt.io/suspicious/allegro/026443d2-874d-4329-ba57-f1d7f254de00/",
          "description": "phishunt detection detail page (score breakdown, evidence, related infrastructure)."
        }
      ],
      "labels": [
        "allegro"
      ]
    }
  ]
}