Skip to content
Critical92/100actionblock_domain
VerdictIQSecurity Report

Subject

cdn-xxx-service[.]net

Recommended actionblock_domainIOC typedomainVerified2026-05-09

Risk level

Critical

score 92 / 100

Why this verdict

VerdictIQ AI commentary

VerdictIQ AIGenerated from 5 deterministic signals

cdn-xxx-service[.]net is classified as critical with a risk score of 92/100: high-confidence malicious posture; multiple core signals reinforce one another. The recommended downstream action is block_domain.

The risk model observed 5 signals (including 3 core signals) across 4 taxonomy groups (Relational Intelligence, Threat Intelligence, DNS History, and others). The strongest indicators are Attacker Group Attribution, IP on Blacklist, Long IP Retention, plus 2 additional supporting signals. Each signal carries its own trigger evidence and direction; signal fusion drives the calibrated tier assignment.

Recommended response. Block at the perimeter (DNS firewall, SWG, EDR network rules). The signal stack supports a deny-by-default posture; blocking is unlikely to disrupt legitimate traffic. For active investigation, run POST /enrichwith the indicator to confirm the verdict against the current state of the domain. VerdictIQ's scoring recomputes today's signals on every call.

VerdictIQ AI re-states deterministic signal evidence as natural language. The verdict itself comes from the calibrated risk model, not the AI layer. Re-runs are stable and explainable.

Signal evidence

Top 3 of 5
Want to score a domain you're investigating with these same signals?Try POST /enrich →
How we got here

Methodology

01
Signal extraction

Telemetry across DNS history, infrastructure (IP/ASN), HTTP crawling, threat intelligence feeds, popularity, and WHOIS taxonomies. Each signal records its trigger evidence and direction.

02
Calibrated scoring

Signals fuse into a deterministic risk model with calibrated thresholds across Critical / High / Medium / Suspicious / Benign tiers. No LLM scoring; no probabilistic black box.

03
Pre-hoc decisioning

Verdicts are available before the indicator fires in your environment. Domains are scored at activation, not after they trigger your detection stack, so you ship the right action without paying the dwell-time cost.

Read the full scoring methodology at /product/enrichment or the canonical signal taxonomy at /signal-library.

More like this

Similar verdicts

Domains sharing signals with cdn-xxx-service[.]net. Pattern similarity often indicates campaign reuse or shared infrastructure.

Curation policy & takedown

Every report passes a strict curation policy: minimum verdict threshold (Critical/High, score ≥ 70), evidence threshold (≥3 signals incl. ≥1 core), brand exclusion, human review. Reports older than 90 days are marked stale and de-indexed until re-verified. Domain owners may dispute a verdict at reports@verdictiq.io ; response within 5 business days. Audit trail in git history. Trust & compliance →