aj0453[.]top is classified as suspicious with a risk score of 60/100: ambiguous posture; signals suggest concern but lack convergent evidence. The recommended downstream action is alert_only.
The risk model observed 26 signals (including 6 core signals) across 3 taxonomy groups (HTTP Crawling, DNS History, Threat Intelligence). The strongest indicators are Low-Control General Hosting Network, Flagged by Security Vendors, Critical SSL CA Issue, plus 23 additional supporting signals. Each signal carries its own trigger evidence and direction; signal fusion drives the calibrated tier assignment.
Recommended response. Surface to analyst review or SIEM correlation. Evidence is strong enough to warrant attention but not strong enough to block without context. For active investigation, run POST /verdict with the indicator to confirm the verdict against the current state of the domain. VerdictIQ's scoring recomputes today's signals on every call.