Skip to content
Suspicious61/100actionalert_only
VerdictIQSecurity Report

Subject

clientshostname[.]com

Recommended actionalert_onlyIOC typedomainVerified2026-08-01

Risk level

Suspicious

score 61 / 100

Why this verdict

Evidence and analysis

VerdictIQ AIGenerated from 33 deterministic signals

clientshostname[.]com is classified as suspicious with a risk score of 61/100: ambiguous posture; signals suggest concern but lack convergent evidence. The recommended downstream action is alert_only.

The risk model observed 33 signals (including 9 core signals) across 5 taxonomy groups (WHOIS, HTTP Crawling, DNS History, and others). The strongest indicators are Critical SSL CA Issue, Low-Control General Hosting Network, Flagged by Security Vendors, plus 30 additional supporting signals. Each signal carries its own trigger evidence and direction; signal fusion drives the calibrated tier assignment.

Recommended response. Surface to analyst review or SIEM correlation. Evidence is strong enough to warrant attention but not strong enough to block without context. For active investigation, run POST /verdict with the indicator to confirm the verdict against the current state of the domain. VerdictIQ's scoring recomputes today's signals on every call.

VerdictIQ AI re-states deterministic signal evidence as natural language. The verdict itself comes from the calibrated risk model, not the AI layer. Re-runs are stable and explainable.

Signal evidence

Top 10 of 33Showing all 33
  • Critical SSL CA IssuecoreHTTP CrawlingIt means that the SSL/TLS certificate presented by the domain failed critical validation checks.
  • Low-Control General Hosting NetworkcoreDNS HistoryIt indicates that the ASN belongs to hosting environments statistically associated with higher abuse rates, weak onboarding controls, or historically malicious operations.
  • Flagged by Security VendorscoreThreat IntelligenceIt means that one or more commercial security vendors, including antivirus engines, sandboxes, or threat intelligence providers, have classified or reported the domain as malicious.
  • Listed in Malware SourcescoreThreat IntelligenceIt means that the domain has appeared in public or open-source malware intelligence feeds.
  • SSL Hostname MismatchcoreHTTP CrawlingIt means the SSL/TLS certificate’s Common Name (CN) or Subject Alternative Name (SAN) does not match the accessed domain.
  • Newly-Activated DomainDNS HistoryIt indicates that the domain has recently become active and started responding to DNS queries after a period of inactivity or recent registration.
  • Mostly Abandoned SubdomainsDNS HistoryA significant portion of the domain's subdomains are offline or unreachable.
  • Short-Term SSL Certificate ValidityHTTP CrawlingIt means the SSL/TLS certificate of the domain has an unusually short validity period, often lasting only days or weeks.
  • Weak Popularity DomainPopularity & BacklinkIt represents a domain with limited but detectable user traffic or DNS activity.
  • Free-Issued SSL CertificateHTTP CrawlingIt indicates that the domain uses an SSL certificate issued by a free or automated Certificate Authority, such as Let's Encrypt.
  • Anonymizer/VPN/Proxy IP DetectedThreat IntelligenceThe domain's IP is associated with anonymization services such as VPN providers, Tor exit nodes, or proxy networks.
  • Geolocation Mismatch or High-Risk RegionDNS HistoryIt indicates that the ASN shows geolocation anomalies, such as a mismatch between registry country and observed country or continent, or that it is associated with a country known for elevated abuse…
  • Inactive HTTP Service Detected (Base Domain)HTTP CrawlingIt indicates that the base domain’s web service (HTTP/HTTPS) is no longer responding or has gone offline.
  • Non-Stable DomainDNS HistoryIt refers to domains that frequently fluctuate between being reachable and unreachable at the DNS level.
  • Geo-Registry Country MismatchDNS HistoryThe IP's geolocation doesn't match the RIR allocation country.
  • Newly-Issued SSL CertificateHTTP CrawlingIt indicates that the SSL certificate associated with the domain has been newly created or issued.
  • DNS A Record Resolves to Private IPDNS HistoryIt indicates that a public domain resolves via a DNS A record to a non-routable private or non-public IP address, such as RFC1918, loopback, link-local, or reserved ranges.
  • Long-Registered DomaincoreWHOISIt indicates that the domain’s WHOIS record shows a long registration duration, typically 2, 5, or 10+ years.
  • Many FQDNs Sharing IPcoreDNS HistoryIt means the domain operates with a large number of well-organized and active subdomains.
  • Long-Running IPcoreDNS HistoryThese refer to domains that have consistently resolved through DNS over a long period.
  • Many IPs ResolvedcoreDNS HistoryIt indicates that the domain operates across multiple IP addresses simultaneously.
  • Gradual Popularity Growth DomainPopularity & BacklinkIt reflects a consistent and organic increase in user visits, backlinks, and visibility over time.
  • EU Compliance LocationDNS HistoryIt indicates that the IP address is consistently hosted within EU regions known for strict regulatory, privacy and operational compliance standards, reducing the likelihood of unmanaged or…
  • Observed and Registered Geolocation ConsistencyDNS HistoryIt indicates that the observed geolocation of the IP matches its registered geolocation, suggesting a stable and expected geographic placement for the infrastructure at the time of observation.
  • ASN Allocated Long Time AgoDNS HistoryIt means that the ASN was allocated many years ago and has a long operational history.
  • Paid Mail Service DetectedDNS HistoryIt indicates that the domain uses a paid or premium email service provider.
  • Web Technology Stack DetectedHTTP CrawlingIt means that the domain uses one or more identifiable web technologies, such as CMS platforms (WordPress, Drupal), JavaScript frameworks (React, Angular, Vue), analytics tools, CDNs, or web servers.
  • Strict-Policy RIR RegionDNS HistoryIt indicates that the ASN is allocated by a regional internet registry known for strict allocation controls and strong abuse-handling processes, providing supportive safe context for the…
  • Large-Scale Multi-Country IP DistributionDNS HistoryIt indicates that a domain operates a large number of currently active IP addresses distributed across multiple countries, which is typical for large-scale, globally distributed services.
  • Stable NS Usage Long TermDNS HistoryIt shows that the domain has maintained the same nameserver configuration without fluctuations, suggesting predictable and well-managed DNS infrastructure.
  • Current and Historical Geolocation AlignmentDNS HistoryIt indicates that the geolocation of the domain’s currently active IP addresses is consistent with the geolocations observed in its historical IP usage, suggesting continuity in infrastructure…
  • Newly Broadly ReachablePopularity & BacklinkIt represents a domain that receives links from a large number of distinct sources (high harmonic centrality) but whose linking sources are not authoritative enough to push it into the mainstream…
  • Registry–Geo CIDR Full MatchDNS HistoryIt indicates that the delegated registry CIDR fully matches the geolocation CIDR, meaning the entire IP block consistently maps to a single country or region with no fragmentation.

Read the full scoring methodology at /product/ioc-verdict or the canonical signal taxonomy at /signal-library.

More like this

Similar verdicts

Domains sharing signals with clientshostname[.]com. Pattern similarity often indicates campaign reuse or shared infrastructure.

Query any domain, not just this one

POST /verdict returns the same signals, score and recommended action for any indicator you send, computed against today's data.

Part of a curated wave, re-verified periodically; reports older than 90 days are de-indexed until re-verified. Dispute a verdict at reports@verdictiq.io, response within 5 business days. Trust & compliance →