Skip to content
Suspicious67/100actionalert_only
VerdictIQSecurity Report

Subject

bigolov[.]com

Recommended actionalert_onlyIOC typedomainVerified2026-08-01

Risk level

Suspicious

score 67 / 100

Why this verdict

Evidence and analysis

VerdictIQ AIGenerated from 19 deterministic signals

bigolov[.]com is classified as suspicious with a risk score of 67/100: ambiguous posture; signals suggest concern but lack convergent evidence. The recommended downstream action is alert_only.

The risk model observed 19 signals (including 1 core signals) across 5 taxonomy groups (Popularity & Backlink, DNS History, WHOIS, and others). The strongest indicators are Flagged by Security Vendors, Recently Isolated Domain, Geo-Registry Country Mismatch, plus 16 additional supporting signals. Each signal carries its own trigger evidence and direction; signal fusion drives the calibrated tier assignment.

Recommended response. Surface to analyst review or SIEM correlation. Evidence is strong enough to warrant attention but not strong enough to block without context. For active investigation, run POST /verdict with the indicator to confirm the verdict against the current state of the domain. VerdictIQ's scoring recomputes today's signals on every call.

VerdictIQ AI re-states deterministic signal evidence as natural language. The verdict itself comes from the calibrated risk model, not the AI layer. Re-runs are stable and explainable.

Signal evidence

Top 10 of 19Showing all 19
  • Flagged by Security VendorscoreThreat IntelligenceIt means that one or more commercial security vendors, including antivirus engines, sandboxes, or threat intelligence providers, have classified or reported the domain as malicious.
  • Recently Isolated DomainPopularity & BacklinkA domain whose harmonic centrality places it in the deep tail (very few distinct sources link to it) while PageRank is also in the mid-to-tail range.
  • Geo-Registry Country MismatchDNS HistoryThe IP's geolocation doesn't match the RIR allocation country.
  • Geo-Registered Country MismatchDNS HistoryThe IP's geolocation country doesn't match the domain's WHOIS registered country.
  • Newly-Activated DomainDNS HistoryIt indicates that the domain has recently become active and started responding to DNS queries after a period of inactivity or recent registration.
  • Assigned IP BlockDNS HistoryIt indicates that the IP block has the RIR status 'assigned', which is commonly associated with end-user or reseller address space that frequently changes hands and exhibits higher abuse rates than…
  • Geolocation Mismatch or High-Risk RegionDNS HistoryIt indicates that the ASN shows geolocation anomalies, such as a mismatch between registry country and observed country or continent, or that it is associated with a country known for elevated abuse…
  • Reputation Decay DomainPopularity & BacklinkIt indicates that the domain’s reputation, visibility, and traffic are steadily declining over time.
  • Registered in Last WeekWHOISIt indicates that the domain was registered very recently, within the last week, month, or few months.
  • Weak Popularity DomainPopularity & BacklinkIt represents a domain with limited but detectable user traffic or DNS activity.
  • Newly-Issued SSL CertificateHTTP CrawlingIt indicates that the SSL certificate associated with the domain has been newly created or issued.
  • Inactive HTTP Service Detected (Base Domain)HTTP CrawlingIt indicates that the base domain’s web service (HTTP/HTTPS) is no longer responding or has gone offline.
  • Small Allocation Abuse PatternDNS HistoryIt indicates that a small-sized IP prefix shows a concentration of malicious activity, such as repeated blacklist hits, high-risk domain density, or rapid domain churn, suggesting abuse within the…
  • Domain Ownership Transition in Last MonthWHOISIt indicates that the WHOIS ownership or registrant details of a domain have recently changed.
  • Country-Level IP Geolocation CentralizationDNS HistoryIt indicates that all currently active IP addresses of a domain are geographically concentrated in a single location scope, typically within one country.
  • Registry–Geo CIDR Full MatchDNS HistoryIt indicates that the delegated registry CIDR fully matches the geolocation CIDR, meaning the entire IP block consistently maps to a single country or region with no fragmentation.
  • ASN Allocated Long Time AgoDNS HistoryIt means that the ASN was allocated many years ago and has a long operational history.
  • Current and Historical Geolocation AlignmentDNS HistoryIt indicates that the geolocation of the domain’s currently active IP addresses is consistent with the geolocations observed in its historical IP usage, suggesting continuity in infrastructure…
  • Not Listed in Open-Source Threat FeedsThreat IntelligenceIt indicates that the domain does not appear in any public or open-source threat intelligence feeds, malware repositories, or IOC databases.

Read the full scoring methodology at /product/ioc-verdict or the canonical signal taxonomy at /signal-library.

More like this

Similar verdicts

Domains sharing signals with bigolov[.]com. Pattern similarity often indicates campaign reuse or shared infrastructure.

Query any domain, not just this one

POST /verdict returns the same signals, score and recommended action for any indicator you send, computed against today's data.

Part of a curated wave, re-verified periodically; reports older than 90 days are de-indexed until re-verified. Dispute a verdict at reports@verdictiq.io, response within 5 business days. Trust & compliance →