| Country | Blocked | Share |
|---|---|---|
| United States (US) | 242 | 78.1% |
| The Netherlands (NL) | 33 | 10.6% |
| United Kingdom (GB) | 23 | 7.4% |
| India (IN) | 8 | 2.6% |
| Singapore (SG) | 4 | 1.3% |
Based on emails that reached the content filter. MTA-level blocks (RBL, GeoIP) are not included.
| Domain | Blocked | Avg Score | Volume |
|---|---|---|---|
| gmail.com | 14 | 40.9 | |
| kbra.com | 12 | -0.3 | |
| jjgsxc.com | 8 | 91.0 | |
| dmarc.yahoo.com | 5 | -0.3 | |
| outlook.com | 5 | 33.6 | |
| cloudcontactai.org | 4 | 28.2 | |
| llc1.hkinvests.com | 3 | 48.4 | |
| snap5.snaptobook.com | 3 | 39.8 |
| Score | Sender | Subject |
|---|---|---|
| 241.915 | Voicemail Service <tdupuis@[redacted].c | mew voicemail received |
| 230.85 | Voicemail Service <accounting@troycapita | mew voicemail received |
| 148.486 | Netflix Bonus Gift <support@airportcharl | Claim Your LEGO Racing Car Bonus |
| 138.066 | Netflix Member Reward <support@betting-c | [[redacted]: New Sender] Your Racing Gift Is Ready |
| 137.736 | United Airlines Loyalty Team <support@ve | [[redacted]: New Sender] United Airlines Wants to Hea |
| CVE | Vendor / Product | Ransomware |
|---|---|---|
| CVE-2015-5477 | ISC BIND ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries. | Unknown |
| CVE-2016-3081 | Apache Struts Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled. | Unknown |
| CVE-2023-22894 | Strapi Strapi Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution. | Unknown |
| CVE-2021-3199 | ONLYOFFICE Docs ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution. | Unknown |
| CVE-2015-3306 | ProFTPD ProFTPD ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. | Unknown |
Top threat types:
unknown: 5020 email-related indicators of compromise in the last 24 hours.
| Malware Family | IOCs | Severity |
|---|---|---|
| Vidar | 16 | High |
| XWorm | 2 | Medium |
| AsyncRAT | 2 | Medium |