{"type":"bundle","id":"bundle--b7e6d6d4-de84-4314-8bf8-1565f0a22966","objects":[{"type":"identity","spec_version":"2.1","id":"identity--133db99c-0921-469e-b127-6363a0ef0b1e","created":"2026-09-16T12:06:41.272Z","modified":"2026-09-16T12:06:41.272Z","name":"ZeroHour","identity_class":"system","description":"Indicators auto-extracted from public security reporting. Verify before use."},{"type":"indicator","spec_version":"2.1","id":"indicator--cfe15255-5e2e-45fa-93c8-a2a3dfe06b0c","created":"2026-09-12T14:40:00.000Z","modified":"2026-09-16T12:06:41.272Z","created_by_ref":"identity--133db99c-0921-469e-b127-6363a0ef0b1e","name":"email: mail@journalistjagmeet.com","description":"Seen in \"Revolut confirms customer data breach through fake government requests\" (TechCrunch · Security). Context: You can contact or verify outreach from Jagmeet by emailing mail@journalistjagmeet.com . View Bio","pattern":"[email-addr:value = 'mail@journalistjagmeet.com']","pattern_type":"stix","valid_from":"2026-09-12T14:40:00.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"TechCrunch · Security","url":"https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--c8d71472-2d4b-4064-8e24-5a9e48dd8e2b","created":"2026-09-01T21:30:18.000Z","modified":"2026-09-16T12:06:41.272Z","created_by_ref":"identity--133db99c-0921-469e-b127-6363a0ef0b1e","name":"email: contratos_docusing@relatorio01a.colombstracciatella","description":"Seen in \"Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)\" (SANS Internet Storm Center). Context: 2026 22:01:41 +0000 (UTC) Sender: \"Contrato Via Docusing\" <contratos_docusing@relatorio01a.colombstracciatella[.]cfd> Date: Wed, 26 Aug 2026 19:01:16 -0300 Subject: Assin","pattern":"[email-addr:value = 'contratos_docusing@relatorio01a.colombstracciatella']","pattern_type":"stix","valid_from":"2026-09-01T21:30:18.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33300"}]}]}