Skip to content
Suspicious60/100actionalert_only
VerdictIQSecurity Report

Subject

apple[.]com[.]pa

Recommended actionalert_onlyIOC typedomainVerified2026-08-01

Risk level

Suspicious

score 60 / 100

Why this verdict

Evidence and analysis

VerdictIQ AIGenerated from 29 deterministic signals

apple[.]com[.]pa is classified as suspicious with a risk score of 60/100: ambiguous posture; signals suggest concern but lack convergent evidence. The recommended downstream action is alert_only.

The risk model observed 29 signals (including 9 core signals) across 4 taxonomy groups (DNS History, Threat Intelligence, HTTP Crawling, and others). The strongest indicators are IP on Blacklist, Critical SSL CA Issue, Fraud Indicator, plus 26 additional supporting signals. Each signal carries its own trigger evidence and direction; signal fusion drives the calibrated tier assignment.

Recommended response. Surface to analyst review or SIEM correlation. Evidence is strong enough to warrant attention but not strong enough to block without context. For active investigation, run POST /verdict with the indicator to confirm the verdict against the current state of the domain. VerdictIQ's scoring recomputes today's signals on every call.

VerdictIQ AI re-states deterministic signal evidence as natural language. The verdict itself comes from the calibrated risk model, not the AI layer. Re-runs are stable and explainable.

Signal evidence

Top 10 of 29Showing all 29
  • IP on BlacklistcoreThreat IntelligenceIt means the IP address appears in at least one threat intelligence blacklist, indicating it has been associated with suspicious or malicious activity such as spam, scanning or malware hosting.
  • Critical SSL CA IssuecoreHTTP CrawlingIt means that the SSL/TLS certificate presented by the domain failed critical validation checks.
  • Fraud IndicatorcoreThreat IntelligenceIt refers to a domain that visually or semantically resembles a legitimate brand or organization’s domain.
  • SSL Hostname MismatchcoreHTTP CrawlingIt means the SSL/TLS certificate’s Common Name (CN) or Subject Alternative Name (SAN) does not match the accessed domain.
  • IP Blacklisted Recently (High Freshness)Threat IntelligenceIt means the IP has appeared in one or more threat intelligence blacklist datasets, indicating that it has been associated with abusive or malicious activity such as spam, scanning, botnet traffic…
  • DNS A Record Resolves to Private IPDNS HistoryIt indicates that a public domain resolves via a DNS A record to a non-routable private or non-public IP address, such as RFC1918, loopback, link-local, or reserved ranges.
  • Multi Group Blacklist MatchThreat IntelligenceIt means the IP matches several independent blacklist groups simultaneously, such as spam, malware hosting, scanning, botnet traffic, or brute-force sources.
  • Limited Web Structure DetectedHTTP CrawlingIt means the domain hosts only a few subpages or internal links.
  • Non-Public DomainHTTP CrawlingIt refers to a domain that operates with restricted accessibility, its HTTP/HTTPS services are either protected, limited to specific users, or intentionally unreachable from the public internet.
  • Newly-Issued SSL CertificateHTTP CrawlingIt indicates that the SSL certificate associated with the domain has been newly created or issued.
  • Newly Allocated ASN LifecycleDNS HistoryIt indicates that the ASN has been allocated recently in the RIR system.
  • Reputation Decay DomainPopularity & BacklinkIt indicates that the domain’s reputation, visibility, and traffic are steadily declining over time.
  • Weak Popularity DomainPopularity & BacklinkIt represents a domain with limited but detectable user traffic or DNS activity.
  • Short-Term SSL Certificate ValidityHTTP CrawlingIt means the SSL/TLS certificate of the domain has an unusually short validity period, often lasting only days or weeks.
  • Long-Running IPcoreDNS HistoryThese refer to domains that have consistently resolved through DNS over a long period.
  • Owned MX UsagecoreDNS HistoryIt means the domain operates its own mail exchange (MX) servers instead of relying on trusted third-party providers like Google Workspace, Microsoft 365, or Proofpoint.
  • Cleared by Security VendorscoreThreat IntelligenceIt means that none of the commercial or open-source security vendors, such as antivirus engines, sandbox platforms, or threat intelligence providers, have classified or reported this domain as…
  • Large-Scale Enterprise IP BlockcoreDNS HistoryIt indicates that the IP address belongs to a large-scale, long-established, and officially allocated enterprise network.
  • SSL OV ValidationcoreHTTP CrawlingIt means the SSL/TLS certificate of the domain includes verified organizational details that have been authenticated by a Certificate Authority (CA).
  • CDN Infrastructure DetectedDNS HistoryThe domain is hosted on shared infrastructure such as a CDN, cloud provider, or shared hosting platform.
  • Observed and Registered Geolocation ConsistencyDNS HistoryIt indicates that the observed geolocation of the IP matches its registered geolocation, suggesting a stable and expected geographic placement for the infrastructure at the time of observation.
  • Country-Level IP Geolocation CentralizationDNS HistoryIt indicates that all currently active IP addresses of a domain are geographically concentrated in a single location scope, typically within one country.
  • Valid SSL Certificate from Recognized CAHTTP CrawlingIt means the domain uses an SSL/TLS certificate issued by a trusted and globally recognized Certificate Authority (CA).
  • Not Listed in Open-Source Threat FeedsThreat IntelligenceIt indicates that the domain does not appear in any public or open-source threat intelligence feeds, malware repositories, or IOC databases.
  • Stable MX Usage Long TermDNS HistoryIt shows the domain has been using the same mail exchange servers for an extended period, reflecting stable and predictable email infrastructure.
  • Stable NS Usage Long TermDNS HistoryIt shows that the domain has maintained the same nameserver configuration without fluctuations, suggesting predictable and well-managed DNS infrastructure.
  • OCSP-Stapled SSL Certificate DetectedHTTP CrawlingIt indicates that the domain’s SSL/TLS certificate supports OCSP stapling, a mechanism that allows the server to provide proof of its certificate’s validity directly during the TLS handshake.
  • Current and Historical Geolocation AlignmentDNS HistoryIt indicates that the geolocation of the domain’s currently active IP addresses is consistent with the geolocations observed in its historical IP usage, suggesting continuity in infrastructure…
  • Strict-Policy RIR RegionDNS HistoryIt indicates that the ASN is allocated by a regional internet registry known for strict allocation controls and strong abuse-handling processes, providing supportive safe context for the…

Read the full scoring methodology at /product/ioc-verdict or the canonical signal taxonomy at /signal-library.

More like this

Similar verdicts

Domains sharing signals with apple[.]com[.]pa. Pattern similarity often indicates campaign reuse or shared infrastructure.

Query any domain, not just this one

POST /verdict returns the same signals, score and recommended action for any indicator you send, computed against today's data.

Part of a curated wave, re-verified periodically; reports older than 90 days are de-indexed until re-verified. Dispute a verdict at reports@verdictiq.io, response within 5 business days. Trust & compliance →