Skip to content
Suspicious65/100actionalert_only
VerdictIQSecurity Report

Subject

eorthopaedics[.]com

Recommended actionalert_onlyIOC typedomainVerified2026-08-01

Risk level

Suspicious

score 65 / 100

Why this verdict

Evidence and analysis

VerdictIQ AIGenerated from 25 deterministic signals

eorthopaedics[.]com is classified as suspicious with a risk score of 65/100: ambiguous posture; signals suggest concern but lack convergent evidence. The recommended downstream action is alert_only.

The risk model observed 25 signals (including 4 core signals) across 5 taxonomy groups (Threat Intelligence, HTTP Crawling, DNS History, and others). The strongest indicators are Listed in Malware Sources, Flagged by Security Vendors, IP on Blacklist, plus 22 additional supporting signals. Each signal carries its own trigger evidence and direction; signal fusion drives the calibrated tier assignment.

Recommended response. Surface to analyst review or SIEM correlation. Evidence is strong enough to warrant attention but not strong enough to block without context. For active investigation, run POST /verdict with the indicator to confirm the verdict against the current state of the domain. VerdictIQ's scoring recomputes today's signals on every call.

VerdictIQ AI re-states deterministic signal evidence as natural language. The verdict itself comes from the calibrated risk model, not the AI layer. Re-runs are stable and explainable.

Signal evidence

Top 10 of 25Showing all 25
  • Listed in Malware SourcescoreThreat IntelligenceIt means that the domain has appeared in public or open-source malware intelligence feeds.
  • Flagged by Security VendorscoreThreat IntelligenceIt means that one or more commercial security vendors, including antivirus engines, sandboxes, or threat intelligence providers, have classified or reported the domain as malicious.
  • IP on BlacklistcoreThreat IntelligenceIt means the IP address appears in at least one threat intelligence blacklist, indicating it has been associated with suspicious or malicious activity such as spam, scanning or malware hosting.
  • Newly-Issued SSL CertificateHTTP CrawlingIt indicates that the SSL certificate associated with the domain has been newly created or issued.
  • Non-Public DomainHTTP CrawlingIt refers to a domain that operates with restricted accessibility, its HTTP/HTTPS services are either protected, limited to specific users, or intentionally unreachable from the public internet.
  • Domain Ownership Transition in Last MonthWHOISIt indicates that the WHOIS ownership or registrant details of a domain have recently changed.
  • Low Content Density (Homepage)HTTP CrawlingIt means that the domain’s homepage contains a very small amount of textual or visual content.
  • Multi Group Blacklist MatchThreat IntelligenceIt means the IP matches several independent blacklist groups simultaneously, such as spam, malware hosting, scanning, botnet traffic, or brute-force sources.
  • Default Web Page DetectedHTTP CrawlingIt refers to a website that displays the default or placeholder page of a known web technology, such as 'Apache Default Page' or 'Nginx Welcome Page'.
  • Newly-Activated DomainDNS HistoryIt indicates that the domain has recently become active and started responding to DNS queries after a period of inactivity or recent registration.
  • IP Blacklisted Recently (High Freshness)Threat IntelligenceIt means the IP has appeared in one or more threat intelligence blacklist datasets, indicating that it has been associated with abusive or malicious activity such as spam, scanning, botnet traffic…
  • Recently Isolated DomainPopularity & BacklinkA domain whose harmonic centrality places it in the deep tail (very few distinct sources link to it) while PageRank is also in the mid-to-tail range.
  • Weak Popularity DomainPopularity & BacklinkIt represents a domain with limited but detectable user traffic or DNS activity.
  • Limited Web Structure DetectedHTTP CrawlingIt means the domain hosts only a few subpages or internal links.
  • Large-Scale Enterprise IP BlockcoreDNS HistoryIt indicates that the IP address belongs to a large-scale, long-established, and officially allocated enterprise network.
  • Observed and Registered Geolocation ConsistencyDNS HistoryIt indicates that the observed geolocation of the IP matches its registered geolocation, suggesting a stable and expected geographic placement for the infrastructure at the time of observation.
  • Strict-Policy RIR RegionDNS HistoryIt indicates that the ASN is allocated by a regional internet registry known for strict allocation controls and strong abuse-handling processes, providing supportive safe context for the…
  • Current and Historical Geolocation AlignmentDNS HistoryIt indicates that the geolocation of the domain’s currently active IP addresses is consistent with the geolocations observed in its historical IP usage, suggesting continuity in infrastructure…
  • Country-Level IP Geolocation CentralizationDNS HistoryIt indicates that all currently active IP addresses of a domain are geographically concentrated in a single location scope, typically within one country.
  • Paid Public NS Usage Premium ProviderDNS HistoryIt indicates that the domain is backed by a paid, reputable DNS provider rather than free or disposable nameservers.
  • Major Cloud or CDN InfrastructureDNS HistoryIt indicates that the ASN belongs to a clearly identified regulated network category such as major cloud/CDN providers, government infrastructure, or academic and research networks.
  • CDN Infrastructure DetectedDNS HistoryThe domain is hosted on shared infrastructure such as a CDN, cloud provider, or shared hosting platform.
  • Single DC Hub FootprintDNS HistoryIt indicates that the IP address belongs to data center or hosting infrastructure and describes the current geographic footprint of that infrastructure based on observed IP locations.
  • ASN Allocated Long Time AgoDNS HistoryIt means that the ASN was allocated many years ago and has a long operational history.
  • Registry–Geo CIDR Full MatchDNS HistoryIt indicates that the delegated registry CIDR fully matches the geolocation CIDR, meaning the entire IP block consistently maps to a single country or region with no fragmentation.

Read the full scoring methodology at /product/ioc-verdict or the canonical signal taxonomy at /signal-library.

More like this

Similar verdicts

Domains sharing signals with eorthopaedics[.]com. Pattern similarity often indicates campaign reuse or shared infrastructure.

Query any domain, not just this one

POST /verdict returns the same signals, score and recommended action for any indicator you send, computed against today's data.

Part of a curated wave, re-verified periodically; reports older than 90 days are de-indexed until re-verified. Dispute a verdict at reports@verdictiq.io, response within 5 business days. Trust & compliance →