Skip to content
High75/100actionalert_only
VerdictIQSecurity Report

Subject

mediacdn-fast[.]io

Recommended actionalert_onlyIOC typedomainVerified2026-05-10

Risk level

High

score 75 / 100

Why this verdict

VerdictIQ AI commentary

VerdictIQ AIGenerated from 6 deterministic signals

mediacdn-fast[.]io is classified as high with a risk score of 75/100: elevated-risk posture; converging signals indicate intent. The recommended downstream action is alert_only.

The risk model observed 6 signals (including 6 core signals) across 3 taxonomy groups (DNS History, Threat Intelligence, Relational Intelligence). The strongest indicators are Many IPs Resolved, Many FQDNs Sharing IP, IP on Blacklist, plus 3 additional supporting signals. Each signal carries its own trigger evidence and direction; signal fusion drives the calibrated tier assignment.

Recommended response. Surface to analyst review or SIEM correlation. Evidence is strong enough to warrant attention but not strong enough to block without context. For active investigation, run POST /enrichwith the indicator to confirm the verdict against the current state of the domain. VerdictIQ's scoring recomputes today's signals on every call.

VerdictIQ AI re-states deterministic signal evidence as natural language. The verdict itself comes from the calibrated risk model, not the AI layer. Re-runs are stable and explainable.

Signal evidence

Top 3 of 6
Want to score a domain you're investigating with these same signals?Try POST /enrich →
How we got here

Methodology

01
Signal extraction

Telemetry across DNS history, infrastructure (IP/ASN), HTTP crawling, threat intelligence feeds, popularity, and WHOIS taxonomies. Each signal records its trigger evidence and direction.

02
Calibrated scoring

Signals fuse into a deterministic risk model with calibrated thresholds across Critical / High / Medium / Suspicious / Benign tiers. No LLM scoring; no probabilistic black box.

03
Pre-hoc decisioning

Verdicts are available before the indicator fires in your environment. Domains are scored at activation, not after they trigger your detection stack, so you ship the right action without paying the dwell-time cost.

Read the full scoring methodology at /product/enrichment or the canonical signal taxonomy at /signal-library.

More like this

Similar verdicts

Domains sharing signals with mediacdn-fast[.]io. Pattern similarity often indicates campaign reuse or shared infrastructure.

Curation policy & takedown

Every report passes a strict curation policy: minimum verdict threshold (Critical/High, score ≥ 70), evidence threshold (≥3 signals incl. ≥1 core), brand exclusion, human review. Reports older than 90 days are marked stale and de-indexed until re-verified. Domain owners may dispute a verdict at reports@verdictiq.io ; response within 5 business days. Audit trail in git history. Trust & compliance →