Message Log / dfx[rule1]

Threat Surface

info

Sender Risk

4 / 5

HIGH

Sandbox

4 / 5

SUSPICIOUS

Source Validation

SPFPASS
DKIMPASS
DMARCMISSING POLICY

Verdicts

SPAMCLEAN
PhishingDIRTY-CONTINUE
MalwareCLEAN
Anti-SpoofSPOOF HARD FAIL

bug_reportIOC Indicators

IP185.220.101.47TOR EXIT
DOMAINphish-login.ioPHISHING
HASHa3f2c1...d9e8MALWARE
EMAILspoofed@baskent.trSPOOF
mark_email_read

Yazılım Firmalarına Özel Grup Sağlık ve Siber Güvence Çözümleri

From: Eray Ötegen <eray.otegen@baskentsigorta.com.tr>

IN QUEUE

Oct 8, 2025 17:36:19 +0300

rule_settingsOperations Log

ProfileResultModuleOperation
EmailFiltering - emailfilteringClean--
Yara - YARA Profile 1Clean--
Spam - intelroomDirty - ContinuesourcedetectResult for symbol: HAS_LIST_UNSUB: True
Phishing - Intelroom Test2Dirty - ContinueMilterEnvelope sender domain does not match visible From address
Malware - dsxxxClean--

Module Detection Stats (Last 24 Hours)

Malware0
Phishing1
CTI0
Threshold0
Safe Browsing0
Spam1
DLP0
YARA0
Anti Spoof1
Email Filtering0

Threat Category Breakdown

Malware

FINANCE
21 threats
HR
21 threats
IT
21 threats

Malware

67 total
FINANCE
21
Trojan.GenericKDBackdoor.Agent
HR
14
Ransomware.LockyWorm.AutoRun
IT
9
Rootkit.HiddenSpyware.AgentTesla
R&D
17
Exploit.CVE-2023Dropper.Generic
LEGAL
6
Adware.BrowserMod

Phishing

FINANCE
21 threats
HR
21 threats
IT
21 threats

Phishing

101 total
FINANCE
34
DocuSign LureInvoice Scam
HR
28
LinkedIn PhishFake HR Portal
IT
19
VPN Login SpoofMFA Bypass
R&D
12
IP Theft Attempt
LEGAL
8
Contract Lure PDF

BEC

FINANCE
21 threats
HR
21 threats
IT
21 threats

BEC

88 total
FINANCE
45
CEO FraudWire Transfer Request
HR
22
Payroll RedirectW-2 Fraud
IT
11
Vendor Impersonation
R&D
7
IP Request Fraud
LEGAL
3
Legal Counsel Spoof

DLP

FINANCE
21 threats
HR
21 threats
IT
21 threats

DLP

121 total
FINANCE
18
PII Leak - Credit CardIBAN Exposure
HR
31
Employee Data ExportGDPR Violation
IT
24
Source Code ExfilAPI Key Leak
R&D
39
Patent Draft LeakProduct Roadmap
LEGAL
9
Contract Exfiltration

publicGeoIP Threat Origin

RU
CN
TR
US
PK
DE
CountryThreats
🇷🇺Russia
62
🇨🇳China
15
🇰🇵North Korea
8
🇺🇸USA
13
🇹🇷Turkey
25
🇵🇰Pakistan
12
🇺🇦Ukraine
11
🇩🇪Germany
43

bar_chartThreat Detection Timeline (Last 30 Days)

Last 7 days shown

SOC Drilldown Tools

DMX detects and recommends actions

Infrastructure & Enforcement

SPF Fail Rate
4.3% Medium
TLS Delivery Rate
98.1% OK
DMARC Align-Pass
92.7% OK
Sandbox Nodes
6/6 Healthy
CTI Feed (VirusTotal)
2h delay Delayed

attachmentAttachments & Sandbox

image

image.png

8 KBimage/png

1 / 5
description

offer.docx

64 KBapplication/vnd.openxmlformats...

4 / 5
picture_as_pdf

contract.pdf

112 KBapplication/pdf

2 / 5

Top 5 Response Recommendations

block

Auto-Quarantine Executables

domain_verification

Flag Lookalike Domains

warning

Alert on External Auto-Reply

code_off

Disarm Office Macros

campaign

Trigger User Awareness Popup

linkExtracted Links

https://example.com/promoLOW RISK
https://phish-login.io/verifyHIGH RISK
https://secure-login.bizMEDIUM RISK

codeEmail Header Summary

Return-Patheray.otegen@baskentsigorta.com.tr
Received-SPFpass (google.com)
X-Forwarded-Toexternal-relay.io:25warning
MIME-Version1.0
X-MailerPHP/7.4.33warning

shieldQuarantine Actions