{"type":"bundle","id":"bundle--af57c92d-d311-49ea-b71f-1c27f23f7314","objects":[{"type":"identity","spec_version":"2.1","id":"identity--8f3817a1-23b2-4859-853c-3d2ac417ad6f","created":"2026-09-16T08:05:26.135Z","modified":"2026-09-16T08:05:26.135Z","name":"ZeroHour","identity_class":"system","description":"Indicators auto-extracted from public security reporting. Verify before use."},{"type":"indicator","spec_version":"2.1","id":"indicator--fe6e510c-6f24-4d36-915a-96a5a4c3b972","created":"2026-09-12T14:40:00.000Z","modified":"2026-09-16T08:05:26.135Z","created_by_ref":"identity--8f3817a1-23b2-4859-853c-3d2ac417ad6f","name":"email: mail@journalistjagmeet.com","description":"Seen in \"Revolut confirms customer data breach through fake government requests\" (TechCrunch · Security). Context: You can contact or verify outreach from Jagmeet by emailing mail@journalistjagmeet.com . View Bio","pattern":"[email-addr:value = 'mail@journalistjagmeet.com']","pattern_type":"stix","valid_from":"2026-09-12T14:40:00.000Z","labels":["auto-extracted","breach"],"confidence":30,"external_references":[{"source_name":"TechCrunch · Security","url":"https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/"}]},{"type":"indicator","spec_version":"2.1","id":"indicator--a79d6030-a66e-4597-946a-39e49d1e6c28","created":"2026-09-01T21:30:18.000Z","modified":"2026-09-16T08:05:26.135Z","created_by_ref":"identity--8f3817a1-23b2-4859-853c-3d2ac417ad6f","name":"email: contratos_docusing@relatorio01a.colombstracciatella","description":"Seen in \"Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)\" (SANS Internet Storm Center). Context: 2026 22:01:41 +0000 (UTC) Sender: \"Contrato Via Docusing\" <contratos_docusing@relatorio01a.colombstracciatella[.]cfd> Date: Wed, 26 Aug 2026 19:01:16 -0300 Subject: Assin","pattern":"[email-addr:value = 'contratos_docusing@relatorio01a.colombstracciatella']","pattern_type":"stix","valid_from":"2026-09-01T21:30:18.000Z","labels":["auto-extracted","malware"],"confidence":30,"external_references":[{"source_name":"SANS Internet Storm Center","url":"https://isc.sans.edu/diary/rss/33300"}]}]}