fofa.info
Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.
Run a live full scan of fofa.info
On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.
DNS Records
WHOIS / Registration
Registration data planned
Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.
Subdomains
Every subdomain we know about — harvested from CT-log SANs, scan-observed certs and HTML body references — paired with its current A/AAAA target.
| Subdomain | Resolves to | Last seen |
|---|---|---|
| www.fofa.info | 2026-05-27 01:49:21.268 | |
| fofa.info | 2026-07-27 03:49:39.738 | |
| en.fofa.info | 2026-06-22 11:40:35.757 | |
| static.fofa.info | 2026-07-22 02:53:41.281 | |
| api.gamma.fofa.info | 2026-07-26 22:47:09.700 |
Tech Stack
Tech detection pending
Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.
TLS Certificates
IPs Citing This Domain
Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.
Origin / IP-Leak
When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.
| Origin IP | Origin ASN | CDN ASN | Confidence | Reasoning |
|---|---|---|---|---|
| 106.75.4.237 | AS23724 | AS13335 | 95% | cert b0aba965… served by 106.75.4.237 (AS23724) carries SAN fofa.info which currently resolves through Cloudflare (AS13335) at 104.20.18.45, 172.66.161.110, 2606:4700:10::6814:122d, 2606:4700:10::ac42:a16e |
| 106.75.17.81 | AS23724 | AS13335 | 95% | cert b0aba965… served by 106.75.17.81 (AS23724) carries SAN fofa.info which currently resolves through Cloudflare (AS13335) at 104.20.18.45, 172.66.161.110, 2606:4700:10::6814:122d, 2606:4700:10::ac42:a16e |
| 106.75.21.61 | AS23724 | AS13335 | 95% | cert b0aba965… served by 106.75.21.61 (AS23724) carries SAN fofa.info which currently resolves through Cloudflare (AS13335) at 104.20.18.45, 172.66.161.110, 2606:4700:10::6814:122d, 2606:4700:10::ac42:a16e |
| 106.75.10.35 | AS23724 | AS13335 | 95% | cert b0aba965… served by 106.75.10.35 (AS23724) carries SAN fofa.info which currently resolves through Cloudflare (AS13335) at 104.20.18.45, 172.66.161.110, 2606:4700:10::6814:122d, 2606:4700:10::ac42:a16e |
| 106.75.5.25 | AS23724 | AS13335 | 95% | cert b0aba965… served by 106.75.5.25 (AS23724) carries SAN fofa.info which currently resolves through Cloudflare (AS13335) at 104.20.18.45, 172.66.161.110, 2606:4700:10::6814:122d, 2606:4700:10::ac42:a16e |
| 106.75.30.132 | AS23724 | AS13335 | 95% | cert b0aba965… served by 106.75.30.132 (AS23724) carries SAN fofa.info which currently resolves through Cloudflare (AS13335) at 104.20.18.45, 172.66.161.110, 2606:4700:10::6814:122d, 2606:4700:10::ac42:a16e |
| 106.75.48.104 | AS23724 | AS13335 | 95% | cert b0aba965… served by 106.75.48.104 (AS23724) carries SAN fofa.info which currently resolves through Cloudflare (AS13335) at 104.20.18.45, 172.66.161.110, 2606:4700:10::6814:122d, 2606:4700:10::ac42:a16e |
| 106.75.22.118 | AS23724 | AS13335 | 95% | cert b0aba965… served by 106.75.22.118 (AS23724) carries SAN fofa.info which currently resolves through Cloudflare (AS13335) at 104.20.18.45, 172.66.161.110, 2606:4700:10::6814:122d, 2606:4700:10::ac42:a16e |
| 106.75.28.30 | AS23724 | AS13335 | 95% | cert b0aba965… served by 106.75.28.30 (AS23724) carries SAN fofa.info which currently resolves through Cloudflare (AS13335) at 104.20.18.45, 172.66.161.110, 2606:4700:10::6814:122d, 2606:4700:10::ac42:a16e |
| 106.75.17.34 | AS23724 | AS13335 | 95% | cert b0aba965… served by 106.75.17.34 (AS23724) carries SAN fofa.info which currently resolves through Cloudflare (AS13335) at 104.20.18.45, 172.66.161.110, 2606:4700:10::6814:122d, 2606:4700:10::ac42:a16e |
Threat Intelligence
Domain threat-intel pending
Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.
History
Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.
| Type | Value | First seen | Last seen |
|---|---|---|---|
| A | 104.20.18.45 | 2026-05-26 03:50:49.068 | 2026-06-22 18:32:56.734 |
| TXT | google-site-verification=np5VWNbYxC8yg3MkP5N1xBhLV35_-MLlJkmYYDUMkoI | 2026-05-26 03:50:49.068 | 2026-06-22 18:32:56.734 |
| NS | ns3.dnsv4.com | 2026-05-26 03:50:49.068 | 2026-07-27 03:49:39.738 |
| AAAA | 2606:4700:10::ac42:a16e | 2026-05-26 03:50:49.068 | 2026-06-22 18:32:56.734 |
| AAAA | 2606:4700:10::6814:122d | 2026-05-26 03:50:49.068 | 2026-06-22 18:32:56.734 |
| A | 172.66.161.110 | 2026-05-26 03:50:49.068 | 2026-06-22 18:32:56.734 |
| NS | ns4.dnsv4.com | 2026-05-26 03:50:49.068 | 2026-07-27 03:49:39.738 |
| A | 106.75.5.150 | 2026-06-25 10:23:09.677 | 2026-07-27 03:49:39.738 |