| Country | Blocked | Share |
|---|---|---|
| United States (US) | 404 | 84.5% |
| United Kingdom (GB) | 24 | 5.0% |
| The Netherlands (NL) | 21 | 4.4% |
| India (IN) | 20 | 4.2% |
| China (CN) | 9 | 1.9% |
Based on emails that reached the content filter. MTA-level blocks (RBL, GeoIP) are not included.
| Domain | Blocked | Avg Score | Volume |
|---|---|---|---|
| gmail.com | 21 | 57.5 | |
| emails.subway.com | 19 | 33.0 | |
| kbra.com | 11 | 11.9 | |
| justandfreegop.com | 10 | 65.8 | |
| outlook.com | 8 | 60.0 | |
| netflir.com | 7 | 44.5 | |
| onedaystl.com | 7 | 50.3 | |
| thesixfigurecoach.com | 6 | 78.6 |
| Score | Sender | Subject |
|---|---|---|
| 161.836 | "Anthem Blue Cross [redacted] - | [[redacted]: New Sender] You've received an encrypted |
| 156.25 | office ShareDocs Team <belinfo@jetro.go. | [[redacted]: New Sender] Re: Online Statement & Ref A |
| 156.134 | " [redacted]-Cpanel Webmail Us | Your web domain email has expired - adv@sadefensej |
| 156.134 | " [redacted]-Cpanel Webmail Us | Your web domain email has expired - office@sadefen |
| 156.134 | " [redacted]-Cpanel Webmail Us | Your web domain email has expired - office@sadefen |
| CVE | Vendor / Product | Ransomware |
|---|---|---|
| CVE-2021-23758 | Ajax.NET Professional Ajax.NET Professional Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. | Unknown |
| CVE-2015-3246 | Red Hat Libuser Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation. | Unknown |
| CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. | Unknown |
| CVE-2022-0995 | Linux Kernel Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system. | Unknown |
| CVE-2026-8452 | Citrix NetScaler ADC and NetScaler Gateway Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service. | Unknown |
| CVE-2019-1068 | Microsoft SQL Server Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account. | Unknown |
| CVE-2026-60004 | Gitea Gitea Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account. | Unknown |
Top threat types:
unknown: 5020 email-related indicators of compromise in the last 24 hours.
| Malware Family | IOCs | Severity |
|---|---|---|
| AsyncRAT | 6 | High |
| Remvio | 6 | High |
| Vidar | 4 | Medium |
| XWorm | 2 | Medium |
| Stealc | 1 | Low |
| HypeAgent | 1 | Low |