Skip to content
Suspicious60/100actionalert_only
VerdictIQSecurity Report

Subject

071781[.]com

Recommended actionalert_onlyIOC typedomainVerified2026-08-01

Risk level

Suspicious

score 60 / 100

Why this verdict

Evidence and analysis

VerdictIQ AIGenerated from 25 deterministic signals

071781[.]com is classified as suspicious with a risk score of 60/100: ambiguous posture; signals suggest concern but lack convergent evidence. The recommended downstream action is alert_only.

The risk model observed 25 signals (including 5 core signals) across 5 taxonomy groups (Threat Intelligence, DNS History, WHOIS, and others). The strongest indicators are Low-Control General Hosting Network, Critical SSL CA Issue, IP on Blacklist, plus 22 additional supporting signals. Each signal carries its own trigger evidence and direction; signal fusion drives the calibrated tier assignment.

Recommended response. Surface to analyst review or SIEM correlation. Evidence is strong enough to warrant attention but not strong enough to block without context. For active investigation, run POST /verdict with the indicator to confirm the verdict against the current state of the domain. VerdictIQ's scoring recomputes today's signals on every call.

VerdictIQ AI re-states deterministic signal evidence as natural language. The verdict itself comes from the calibrated risk model, not the AI layer. Re-runs are stable and explainable.

Signal evidence

Top 10 of 25Showing all 25
  • Low-Control General Hosting NetworkcoreDNS HistoryIt indicates that the ASN belongs to hosting environments statistically associated with higher abuse rates, weak onboarding controls, or historically malicious operations.
  • Critical SSL CA IssuecoreHTTP CrawlingIt means that the SSL/TLS certificate presented by the domain failed critical validation checks.
  • IP on BlacklistcoreThreat IntelligenceIt means the IP address appears in at least one threat intelligence blacklist, indicating it has been associated with suspicious or malicious activity such as spam, scanning or malware hosting.
  • Multi Group Blacklist MatchThreat IntelligenceIt means the IP matches several independent blacklist groups simultaneously, such as spam, malware hosting, scanning, botnet traffic, or brute-force sources.
  • WHOIS Record Updated in Last WeekWHOISIt indicates that the domain's WHOIS data, such as ownership, registrar, or contact details, has been updated within a recent time frame.
  • Malicious Activity Observed During Browser InteractionHTTP CrawlingIt indicates that malicious behavior was detected only during dynamic browser interaction, such as JavaScript execution, redirects, or AJAX calls, rather than in static content.
  • Newly-Activated DomainDNS HistoryIt indicates that the domain has recently become active and started responding to DNS queries after a period of inactivity or recent registration.
  • Weak Popularity DomainPopularity & BacklinkIt represents a domain with limited but detectable user traffic or DNS activity.
  • Assigned IP BlockDNS HistoryIt indicates that the IP block has the RIR status 'assigned', which is commonly associated with end-user or reseller address space that frequently changes hands and exhibits higher abuse rates than…
  • Short-Term SSL Certificate ValidityHTTP CrawlingIt means the SSL/TLS certificate of the domain has an unusually short validity period, often lasting only days or weeks.
  • IP Blacklisted Recently (High Freshness)Threat IntelligenceIt means the IP has appeared in one or more threat intelligence blacklist datasets, indicating that it has been associated with abusive or malicious activity such as spam, scanning, botnet traffic…
  • Inactive HTTP Service Detected (Base Domain)HTTP CrawlingIt indicates that the base domain’s web service (HTTP/HTTPS) is no longer responding or has gone offline.
  • Geo-ASN Country MismatchDNS HistoryThe IP's geolocation country doesn't match the ASN's registered country.
  • Geolocation Mismatch or High-Risk RegionDNS HistoryIt indicates that the ASN shows geolocation anomalies, such as a mismatch between registry country and observed country or continent, or that it is associated with a country known for elevated abuse…
  • Large-Scale Enterprise IP BlockcoreDNS HistoryIt indicates that the IP address belongs to a large-scale, long-established, and officially allocated enterprise network.
  • Cleared by Security VendorscoreThreat IntelligenceIt means that none of the commercial or open-source security vendors, such as antivirus engines, sandbox platforms, or threat intelligence providers, have classified or reported this domain as…
  • Strict-Policy RIR RegionDNS HistoryIt indicates that the ASN is allocated by a regional internet registry known for strict allocation controls and strong abuse-handling processes, providing supportive safe context for the…
  • Registry–Geo CIDR Full MatchDNS HistoryIt indicates that the delegated registry CIDR fully matches the geolocation CIDR, meaning the entire IP block consistently maps to a single country or region with no fragmentation.
  • Observed and Registered Geolocation ConsistencyDNS HistoryIt indicates that the observed geolocation of the IP matches its registered geolocation, suggesting a stable and expected geographic placement for the infrastructure at the time of observation.
  • Not Listed in Open-Source Threat FeedsThreat IntelligenceIt indicates that the domain does not appear in any public or open-source threat intelligence feeds, malware repositories, or IOC databases.
  • Current and Historical Geolocation AlignmentDNS HistoryIt indicates that the geolocation of the domain’s currently active IP addresses is consistent with the geolocations observed in its historical IP usage, suggesting continuity in infrastructure…
  • ASN Allocated Long Time AgoDNS HistoryIt means that the ASN was allocated many years ago and has a long operational history.
  • Web Technology Stack DetectedHTTP CrawlingIt means that the domain uses one or more identifiable web technologies, such as CMS platforms (WordPress, Drupal), JavaScript frameworks (React, Angular, Vue), analytics tools, CDNs, or web servers.
  • Stable NS Usage Long TermDNS HistoryIt shows that the domain has maintained the same nameserver configuration without fluctuations, suggesting predictable and well-managed DNS infrastructure.
  • Paid Public NS Usage Premium ProviderDNS HistoryIt indicates that the domain is backed by a paid, reputable DNS provider rather than free or disposable nameservers.

Read the full scoring methodology at /product/ioc-verdict or the canonical signal taxonomy at /signal-library.

More like this

Similar verdicts

Domains sharing signals with 071781[.]com. Pattern similarity often indicates campaign reuse or shared infrastructure.

Query any domain, not just this one

POST /verdict returns the same signals, score and recommended action for any indicator you send, computed against today's data.

Part of a curated wave, re-verified periodically; reports older than 90 days are de-indexed until re-verified. Dispute a verdict at reports@verdictiq.io, response within 5 business days. Trust & compliance →