Skip to content
Suspicious60/100actionalert_only
VerdictIQSecurity Report

Subject

articles[.]sk

Recommended actionalert_onlyIOC typedomainVerified2026-08-01

Risk level

Suspicious

score 60 / 100

Why this verdict

Evidence and analysis

VerdictIQ AIGenerated from 31 deterministic signals

articles[.]sk is classified as suspicious with a risk score of 60/100: ambiguous posture; signals suggest concern but lack convergent evidence. The recommended downstream action is alert_only.

The risk model observed 31 signals (including 12 core signals) across 4 taxonomy groups (HTTP Crawling, DNS History, Popularity & Backlink, and others). The strongest indicators are Self-Signed SSL Certificate, Flagged by Security Vendors, Untrusted or Misconfigured SSL Certificate, plus 28 additional supporting signals. Each signal carries its own trigger evidence and direction; signal fusion drives the calibrated tier assignment.

Recommended response. Surface to analyst review or SIEM correlation. Evidence is strong enough to warrant attention but not strong enough to block without context. For active investigation, run POST /verdict with the indicator to confirm the verdict against the current state of the domain. VerdictIQ's scoring recomputes today's signals on every call.

VerdictIQ AI re-states deterministic signal evidence as natural language. The verdict itself comes from the calibrated risk model, not the AI layer. Re-runs are stable and explainable.

Signal evidence

Top 10 of 31Showing all 31
  • Self-Signed SSL CertificatecoreHTTP CrawlingIt means the domain is using an SSL/TLS certificate that was generated and signed by the same entity, without verification by a trusted Certificate Authority (CA).
  • Flagged by Security VendorscoreThreat IntelligenceIt means that one or more commercial security vendors, including antivirus engines, sandboxes, or threat intelligence providers, have classified or reported the domain as malicious.
  • Untrusted or Misconfigured SSL CertificatecoreHTTP CrawlingIt indicates that the domain’s SSL/TLS certificate cannot be fully trusted due to issues such as expiration, incorrect configuration, mismatched hostname, or unrecognized certificate authority.
  • Listed in Malware SourcescoreThreat IntelligenceIt means that the domain has appeared in public or open-source malware intelligence feeds.
  • Critical SSL CA IssuecoreHTTP CrawlingIt means that the SSL/TLS certificate presented by the domain failed critical validation checks.
  • Untrusted Certificate AuthoritycoreHTTP CrawlingIt means that the SSL/TLS certificate presented by the domain was issued or signed by a Certificate Authority that is not included in the trusted CA store of major browsers or operating systems.
  • Newly-Issued SSL CertificateHTTP CrawlingIt indicates that the SSL certificate associated with the domain has been newly created or issued.
  • Non-Public DomainHTTP CrawlingIt refers to a domain that operates with restricted accessibility, its HTTP/HTTPS services are either protected, limited to specific users, or intentionally unreachable from the public internet.
  • Newly-Activated DomainDNS HistoryIt indicates that the domain has recently become active and started responding to DNS queries after a period of inactivity or recent registration.
  • Limited Web Structure DetectedHTTP CrawlingIt means the domain hosts only a few subpages or internal links.
  • Current and Historical Geolocation DivergenceDNS HistoryIt indicates that the geolocation of the domain’s currently active IP addresses significantly differs from the geolocations observed in its historical IP usage, suggesting a notable shift in…
  • Geolocation Mismatch or High-Risk RegionDNS HistoryIt indicates that the ASN shows geolocation anomalies, such as a mismatch between registry country and observed country or continent, or that it is associated with a country known for elevated abuse…
  • Geo-ASN Country MismatchDNS HistoryThe IP's geolocation country doesn't match the ASN's registered country.
  • Non-Stable DomainDNS HistoryIt refers to domains that frequently fluctuate between being reachable and unreachable at the DNS level.
  • Small IP Block AllocationDNS HistoryIt indicates that the IP block allocated to the ASN is unusually small.
  • Large-Scale Enterprise IP BlockcoreDNS HistoryIt indicates that the IP address belongs to a large-scale, long-established, and officially allocated enterprise network.
  • Long-Running IPcoreDNS HistoryThese refer to domains that have consistently resolved through DNS over a long period.
  • Many IPs ResolvedcoreDNS HistoryIt indicates that the domain operates across multiple IP addresses simultaneously.
  • Many FQDNs Sharing IPcoreDNS HistoryIt means the domain operates with a large number of well-organized and active subdomains.
  • Global Popularity ScorecorePopularity & BacklinkIt refers to globally recognized, high-traffic domains with verified ownership and a long operational history, such as google.com or microsoft.com.
  • Rich Subpage ContentcoreHTTP CrawlingIt means the domain hosts a large number of subpages and internal links, forming a structured and content-rich website.
  • Long-Term SSL Certificate ValidityHTTP CrawlingIt means that the SSL/TLS certificate of the domain has been issued with an unusually long validity period (e.g., multiple years).
  • Country-Level IP Geolocation CentralizationDNS HistoryIt indicates that all currently active IP addresses of a domain are geographically concentrated in a single location scope, typically within one country.
  • EU Compliance LocationDNS HistoryIt indicates that the IP address is consistently hosted within EU regions known for strict regulatory, privacy and operational compliance standards, reducing the likelihood of unmanaged or…
  • Major Cloud or CDN InfrastructureDNS HistoryIt indicates that the ASN belongs to a clearly identified regulated network category such as major cloud/CDN providers, government infrastructure, or academic and research networks.
  • Observed and Registered Geolocation ConsistencyDNS HistoryIt indicates that the observed geolocation of the IP matches its registered geolocation, suggesting a stable and expected geographic placement for the infrastructure at the time of observation.
  • Newly Broadly ReachablePopularity & BacklinkIt represents a domain that receives links from a large number of distinct sources (high harmonic centrality) but whose linking sources are not authoritative enough to push it into the mainstream…
  • Strict-Policy RIR RegionDNS HistoryIt indicates that the ASN is allocated by a regional internet registry known for strict allocation controls and strong abuse-handling processes, providing supportive safe context for the…
  • Centralized IP-Subdomain Infrastructure DetectedDNS HistoryIt indicates that multiple subdomains of the same domain are actively served through a shared IP address over a long period.
  • Content-Rich HomepageHTTP CrawlingIt means that the domain’s homepage contains a sufficient amount of structured, relevant, and well-presented web content.
  • ASN Allocated Long Time AgoDNS HistoryIt means that the ASN was allocated many years ago and has a long operational history.

Read the full scoring methodology at /product/ioc-verdict or the canonical signal taxonomy at /signal-library.

More like this

Similar verdicts

Domains sharing signals with articles[.]sk. Pattern similarity often indicates campaign reuse or shared infrastructure.

Query any domain, not just this one

POST /verdict returns the same signals, score and recommended action for any indicator you send, computed against today's data.

Part of a curated wave, re-verified periodically; reports older than 90 days are de-indexed until re-verified. Dispute a verdict at reports@verdictiq.io, response within 5 business days. Trust & compliance →