Check-Host.cc

Domain

admin.bitninja.io

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of admin.bitninja.io

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
8
A/AAAA targets
Subdomains
CT + scan + body
Record Types
1
seen in DNS
Observed Certs
in our scans

DNS Records

A
136.243.56.38, 136.243.72.177, 136.243.80.118, 144.76.56.45, 46.4.97.232, 5.9.108.156, 5.9.124.238, 5.9.124.26
AAAA
MX
NS
TXT
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Subdomain enumeration pending

Every subdomain ever issued a TLS cert under this apex — extracted from Certificate Transparency logs, our own scan observations and body references.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Certificate observations pending

TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

51.81.183.196:80 href · ×2
173.243.120.200:443 href · ×2
195.252.110.146:80 href · ×2
193.0.253.25:80 href · ×2
152.232.9.174:80 href · ×2
193.203.243.197:80 href · ×2
43.245.53.31:80 href · ×2
203.24.117.133:80 href · ×2
152.232.9.181:80 href · ×2
158.220.119.120:80 href · ×2
66.45.233.198:80 href · ×2
193.203.243.73:80 href · ×2
67.23.250.4:80 href · ×2
194.28.116.89:80 href · ×2
149.62.170.104:80 href · ×2
185.92.196.141:80 href · ×2
194.55.235.186:80 href · ×2
165.227.182.69:80 href · ×2
167.114.135.125:80 href · ×2
146.19.102.96:80 href · ×2
80.71.151.35:80 href · ×2
185.161.17.225:80 href · ×2
88.198.5.151:443 href · ×2
116.202.115.112:80 href · ×2
85.215.179.7:80 href · ×2
195.252.110.234:80 href · ×2
43.245.53.36:80 href · ×2
203.24.117.34:80 href · ×2
185.63.253.77:80 href · ×2
142.132.157.7:443 href · ×2
41.185.6.71:80 href · ×2
41.185.65.208:80 href · ×2
136.243.197.117:80 href · ×2
185.161.18.69:80 href · ×2
139.177.195.177:80 href · ×2
193.203.243.37:80 href · ×2
93.183.81.49:80 href · ×2
46.38.255.190:80 href · ×2
80.77.113.57:80 href · ×2
185.29.24.251:80 href · ×2
45.63.28.240:80 href · ×2
64.34.49.244:80 href · ×2
185.29.27.108:80 href · ×2
203.24.117.208:80 href · ×2
198.244.167.183:80 href · ×2
103.198.69.120:443 href · ×2
185.98.5.168:443 href · ×2
79.110.224.15:80 href · ×2
84.246.245.112:80 href · ×2
46.4.97.122:80 href · ×2

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
A 5.9.108.156 2026-05-25 21:56:50.553 2026-07-23 12:51:02.453
A 136.243.72.177 2026-05-25 21:56:50.553 2026-06-23 14:47:55.053
A 136.243.80.118 2026-05-25 22:00:50.546 2026-06-22 16:49:07.810
A 46.4.97.232 2026-05-25 22:00:50.546 2026-06-23 12:00:01.157
A 5.9.124.238 2026-05-25 22:05:29.416 2026-07-19 06:01:34.840
A 136.243.56.38 2026-05-26 00:07:44.959 2026-07-23 12:51:02.453
A 5.9.124.26 2026-05-26 00:21:04.925 2026-06-23 12:00:01.157
A 144.76.56.45 2026-05-26 00:21:04.925 2026-06-23 14:03:15.723