Skip to content
Suspicious61/100actionalert_only
VerdictIQSecurity Report

Subject

adik4dx5[.]website

Recommended actionalert_onlyIOC typedomainVerified2026-08-01

Risk level

Suspicious

score 61 / 100

Why this verdict

Evidence and analysis

VerdictIQ AIGenerated from 29 deterministic signals

adik4dx5[.]website is classified as suspicious with a risk score of 61/100: ambiguous posture; signals suggest concern but lack convergent evidence. The recommended downstream action is alert_only.

The risk model observed 29 signals (including 8 core signals) across 4 taxonomy groups (Threat Intelligence, DNS History, HTTP Crawling, and others). The strongest indicators are Flagged by Security Vendors, IP on Blacklist, Critical SSL CA Issue, plus 26 additional supporting signals. Each signal carries its own trigger evidence and direction; signal fusion drives the calibrated tier assignment.

Recommended response. Surface to analyst review or SIEM correlation. Evidence is strong enough to warrant attention but not strong enough to block without context. For active investigation, run POST /verdict with the indicator to confirm the verdict against the current state of the domain. VerdictIQ's scoring recomputes today's signals on every call.

VerdictIQ AI re-states deterministic signal evidence as natural language. The verdict itself comes from the calibrated risk model, not the AI layer. Re-runs are stable and explainable.

Signal evidence

Top 10 of 29Showing all 29
  • Flagged by Security VendorscoreThreat IntelligenceIt means that one or more commercial security vendors, including antivirus engines, sandboxes, or threat intelligence providers, have classified or reported the domain as malicious.
  • IP on BlacklistcoreThreat IntelligenceIt means the IP address appears in at least one threat intelligence blacklist, indicating it has been associated with suspicious or malicious activity such as spam, scanning or malware hosting.
  • Critical SSL CA IssuecoreHTTP CrawlingIt means that the SSL/TLS certificate presented by the domain failed critical validation checks.
  • DGA-Generated LabelcoreThreat IntelligenceIt indicates that the domain name exhibits statistical patterns typical of algorithmically generated domains (DGA).
  • Multi Group Blacklist MatchThreat IntelligenceIt means the IP matches several independent blacklist groups simultaneously, such as spam, malware hosting, scanning, botnet traffic, or brute-force sources.
  • NS Unchanged Since Domain CreationDNS HistoryThe domain's nameserver records have never been changed since registration.
  • Malicious Activity Observed During Browser InteractionHTTP CrawlingIt indicates that malicious behavior was detected only during dynamic browser interaction, such as JavaScript execution, redirects, or AJAX calls, rather than in static content.
  • IP Blacklisted Recently (High Freshness)Threat IntelligenceIt means the IP has appeared in one or more threat intelligence blacklist datasets, indicating that it has been associated with abusive or malicious activity such as spam, scanning, botnet traffic…
  • Newly Active HTTP Service DetectedHTTP CrawlingIt indicates that the domain has recently started serving web content over HTTP or HTTPS after a long period of inactivity or being newly registered.
  • Weak Popularity DomainPopularity & BacklinkIt represents a domain with limited but detectable user traffic or DNS activity.
  • Newly-Issued SSL CertificateHTTP CrawlingIt indicates that the SSL certificate associated with the domain has been newly created or issued.
  • Recently Isolated DomainPopularity & BacklinkA domain whose harmonic centrality places it in the deep tail (very few distinct sources link to it) while PageRank is also in the mid-to-tail range.
  • Short-Term SSL Certificate ValidityHTTP CrawlingIt means the SSL/TLS certificate of the domain has an unusually short validity period, often lasting only days or weeks.
  • Limited Web Structure DetectedHTTP CrawlingIt means the domain hosts only a few subpages or internal links.
  • Long-Running IPcoreDNS HistoryThese refer to domains that have consistently resolved through DNS over a long period.
  • Long-lived HTTP Service DetectedcoreHTTP CrawlingThis term refers to a web service (HTTP/HTTPS) that has been continuously active and reachable for a long duration without significant downtime.
  • SSL DV ValidationcoreHTTP CrawlingIt indicates that the SSL/TLS certificate’s Common Name (CN) or Subject Alternative Name (SAN) correctly matches the accessed hostname.
  • Large-Scale Enterprise IP BlockcoreDNS HistoryIt indicates that the IP address belongs to a large-scale, long-established, and officially allocated enterprise network.
  • Paid Public NS Usage Premium ProviderDNS HistoryIt indicates that the domain is backed by a paid, reputable DNS provider rather than free or disposable nameservers.
  • Not Listed in Open-Source Threat FeedsThreat IntelligenceIt indicates that the domain does not appear in any public or open-source threat intelligence feeds, malware repositories, or IOC databases.
  • Content-Rich HomepageHTTP CrawlingIt means that the domain’s homepage contains a sufficient amount of structured, relevant, and well-presented web content.
  • Strict-Policy RIR RegionDNS HistoryIt indicates that the ASN is allocated by a regional internet registry known for strict allocation controls and strong abuse-handling processes, providing supportive safe context for the…
  • ASN Allocated Long Time AgoDNS HistoryIt means that the ASN was allocated many years ago and has a long operational history.
  • Commercial Tech Stack DetectedHTTP CrawlingIt indicates that the domain is using one or more commercial (paid or licensed) technologies or services, such as premium CDN providers, enterprise analytics, managed security platforms, or…
  • Private Certificate Authority (CA) Signed SSL DetectedHTTP CrawlingIt means that the SSL/TLS certificate in use was issued by a private or internal Certificate Authority rather than a globally recognized CA.
  • CDN Infrastructure DetectedDNS HistoryThe domain is hosted on shared infrastructure such as a CDN, cloud provider, or shared hosting platform.
  • Web Technology Stack DetectedHTTP CrawlingIt means that the domain uses one or more identifiable web technologies, such as CMS platforms (WordPress, Drupal), JavaScript frameworks (React, Angular, Vue), analytics tools, CDNs, or web servers.
  • OCSP-Stapled SSL Certificate DetectedHTTP CrawlingIt indicates that the domain’s SSL/TLS certificate supports OCSP stapling, a mechanism that allows the server to provide proof of its certificate’s validity directly during the TLS handshake.
  • Major Cloud or CDN InfrastructureDNS HistoryIt indicates that the ASN belongs to a clearly identified regulated network category such as major cloud/CDN providers, government infrastructure, or academic and research networks.

Read the full scoring methodology at /product/ioc-verdict or the canonical signal taxonomy at /signal-library.

More like this

Similar verdicts

Domains sharing signals with adik4dx5[.]website. Pattern similarity often indicates campaign reuse or shared infrastructure.

Query any domain, not just this one

POST /verdict returns the same signals, score and recommended action for any indicator you send, computed against today's data.

Part of a curated wave, re-verified periodically; reports older than 90 days are de-indexed until re-verified. Dispute a verdict at reports@verdictiq.io, response within 5 business days. Trust & compliance →