Skip to content
Suspicious65/100actionalert_only
VerdictIQSecurity Report

Subject

0721onani[.]xyz

Recommended actionalert_onlyIOC typedomainVerified2026-08-01

Risk level

Suspicious

score 65 / 100

Why this verdict

Evidence and analysis

VerdictIQ AIGenerated from 23 deterministic signals

0721onani[.]xyz is classified as suspicious with a risk score of 65/100: ambiguous posture; signals suggest concern but lack convergent evidence. The recommended downstream action is alert_only.

The risk model observed 23 signals (including 7 core signals) across 3 taxonomy groups (DNS History, Threat Intelligence, HTTP Crawling). The strongest indicators are Low-Control General Hosting Network, Flagged by Security Vendors, Untrusted or Misconfigured SSL Certificate, plus 20 additional supporting signals. Each signal carries its own trigger evidence and direction; signal fusion drives the calibrated tier assignment.

Recommended response. Surface to analyst review or SIEM correlation. Evidence is strong enough to warrant attention but not strong enough to block without context. For active investigation, run POST /verdict with the indicator to confirm the verdict against the current state of the domain. VerdictIQ's scoring recomputes today's signals on every call.

VerdictIQ AI re-states deterministic signal evidence as natural language. The verdict itself comes from the calibrated risk model, not the AI layer. Re-runs are stable and explainable.

Signal evidence

Top 10 of 23Showing all 23
  • Low-Control General Hosting NetworkcoreDNS HistoryIt indicates that the ASN belongs to hosting environments statistically associated with higher abuse rates, weak onboarding controls, or historically malicious operations.
  • Flagged by Security VendorscoreThreat IntelligenceIt means that one or more commercial security vendors, including antivirus engines, sandboxes, or threat intelligence providers, have classified or reported the domain as malicious.
  • Untrusted or Misconfigured SSL CertificatecoreHTTP CrawlingIt indicates that the domain’s SSL/TLS certificate cannot be fully trusted due to issues such as expiration, incorrect configuration, mismatched hostname, or unrecognized certificate authority.
  • Critical SSL CA IssuecoreHTTP CrawlingIt means that the SSL/TLS certificate presented by the domain failed critical validation checks.
  • Untrusted Certificate AuthoritycoreHTTP CrawlingIt means that the SSL/TLS certificate presented by the domain was issued or signed by a Certificate Authority that is not included in the trusted CA store of major browsers or operating systems.
  • Self-Signed SSL CertificatecoreHTTP CrawlingIt means the domain is using an SSL/TLS certificate that was generated and signed by the same entity, without verification by a trusted Certificate Authority (CA).
  • Limited Web Structure DetectedHTTP CrawlingIt means the domain hosts only a few subpages or internal links.
  • Non-Public DomainHTTP CrawlingIt refers to a domain that operates with restricted accessibility, its HTTP/HTTPS services are either protected, limited to specific users, or intentionally unreachable from the public internet.
  • Newly-Activated DomainDNS HistoryIt indicates that the domain has recently become active and started responding to DNS queries after a period of inactivity or recent registration.
  • High-Risk TLD Zone DetectedThreat IntelligenceIt indicates that the domain belongs to a top-level domain (TLD) frequently associated with malicious or fraudulent activity.
  • Geo-Registry Country MismatchDNS HistoryThe IP's geolocation doesn't match the RIR allocation country.
  • Current and Historical Geolocation DivergenceDNS HistoryIt indicates that the geolocation of the domain’s currently active IP addresses significantly differs from the geolocations observed in its historical IP usage, suggesting a notable shift in…
  • Default Web Page DetectedHTTP CrawlingIt refers to a website that displays the default or placeholder page of a known web technology, such as 'Apache Default Page' or 'Nginx Welcome Page'.
  • Geo-Registered Country MismatchDNS HistoryThe IP's geolocation country doesn't match the domain's WHOIS registered country.
  • Large-Scale Enterprise IP BlockcoreDNS HistoryIt indicates that the IP address belongs to a large-scale, long-established, and officially allocated enterprise network.
  • Not Listed in Open-Source Threat FeedsThreat IntelligenceIt indicates that the domain does not appear in any public or open-source threat intelligence feeds, malware repositories, or IOC databases.
  • Web Technology Stack DetectedHTTP CrawlingIt means that the domain uses one or more identifiable web technologies, such as CMS platforms (WordPress, Drupal), JavaScript frameworks (React, Angular, Vue), analytics tools, CDNs, or web servers.
  • CDN Infrastructure DetectedDNS HistoryThe domain is hosted on shared infrastructure such as a CDN, cloud provider, or shared hosting platform.
  • ASN Allocated Long Time AgoDNS HistoryIt means that the ASN was allocated many years ago and has a long operational history.
  • Registry–Geo CIDR Full MatchDNS HistoryIt indicates that the delegated registry CIDR fully matches the geolocation CIDR, meaning the entire IP block consistently maps to a single country or region with no fragmentation.
  • Paid Public NS Usage Premium ProviderDNS HistoryIt indicates that the domain is backed by a paid, reputable DNS provider rather than free or disposable nameservers.
  • Long-Term SSL Certificate ValidityHTTP CrawlingIt means that the SSL/TLS certificate of the domain has been issued with an unusually long validity period (e.g., multiple years).
  • Country-Level IP Geolocation CentralizationDNS HistoryIt indicates that all currently active IP addresses of a domain are geographically concentrated in a single location scope, typically within one country.

Read the full scoring methodology at /product/ioc-verdict or the canonical signal taxonomy at /signal-library.

More like this

Similar verdicts

Domains sharing signals with 0721onani[.]xyz. Pattern similarity often indicates campaign reuse or shared infrastructure.

Query any domain, not just this one

POST /verdict returns the same signals, score and recommended action for any indicator you send, computed against today's data.

Part of a curated wave, re-verified periodically; reports older than 90 days are de-indexed until re-verified. Dispute a verdict at reports@verdictiq.io, response within 5 business days. Trust & compliance →