cs-coin[.]link is classified as critical with a risk score of 76/100: high-confidence malicious posture; multiple core signals reinforce one another. The recommended downstream action is block_domain.
The risk model observed 21 signals (including 5 core signals) across 4 taxonomy groups (DNS History, HTTP Crawling, Threat Intelligence, and others). The strongest indicators are current_ips_geo_centralization, private_ssl, asn_historical_allocation, plus 18 additional supporting signals. Each signal carries its own trigger evidence and direction; signal fusion drives the calibrated tier assignment.
Recommended response. Block at the perimeter (DNS firewall, SWG, EDR network rules). The signal stack supports a deny-by-default posture; blocking is unlikely to disrupt legitimate traffic. For active investigation, run POST /verdictwith the indicator to confirm the verdict against the current state of the domain. VerdictIQ's scoring recomputes today's signals on every call.