Check-Host.cc

Domain

monstergulf.com

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of monstergulf.com

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
32
A/AAAA targets
Subdomains
108
CT + scan + body
Record Types
6
seen in DNS
Observed Certs
4
in our scans

DNS Records

A
4.213.37.235, 4.240.79.173
AAAA
MX
0 monstergulf-com.mail.protection.outlook.com
NS
ns-1061.awsdns-04.org, ns-1611.awsdns-09.co.uk, ns-499.awsdns-62.com, ns-606.awsdns-11.net
TXT
734D-FDF8-B533-0FC6-D825-1238-7504-0D47, MS=ms17054473, MS=ms87638153, atlassian-domain-verification=4WIcK99xcz6I3VhRK6MDk9JG2Dhil1UumtH79JX//XdSlFhWR37vMpmukOE5ReK6, tcj5jtc4mllktfrxvslk2j7x4vphjhmz, v=spf1 ip4:20.204.50.0/24 ip4:40.80.0.0/16 ip4:20.198.97.0/24 ip4:20.244.66.224/28 include:spf.protection.outlook.com -all, xYlS6rhf5hQA80mgSgA3I5H4i4yEMX0/qgIv65xPS3nMOrz2HNhG15qqPDxi3QxtuKjEhNbs9EZ4euKRPGXpbA==
CNAME
CAA
0 issue "digicert.com", 0 issue "letsencrypt.org", 0 issuewild "digicert.com", 0 issuewild "letsencrypt.org"

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Every subdomain we know about — harvested from CT-log SANs, scan-observed certs and HTML body references — paired with its current A/AAAA target.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Certificate observations pending

TLS certs naming this domain in subject or SANs will appear here as our scan-layer catches them.

IPs Citing This Domain

No citing IPs found yet

As the world-sweep progresses, hosts referencing this domain in their HTML will surface here.

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

Origin IP Origin ASN CDN ASN Confidence Reasoning
104.93.116.66 AS7713 AS16625 95% cert e55f8d5e… served by 104.93.116.66 (AS7713) carries SAN media.monstergulf.com which currently resolves through Akamai (AS16625) at 23.220.112.52, 23.56.162.64, 104.85.0.51, 184.30.156.63
104.93.116.66 AS7713 AS20940 95% cert e55f8d5e… served by 104.93.116.66 (AS7713) carries SAN expressresume.monstergulf.com which currently resolves through Akamai (AS20940) at 104.85.0.51, 23.48.8.57, 23.220.112.52, 104.99.232.60
23.208.136.52 AS45758 AS20940 95% cert e55f8d5e… served by 23.208.136.52 (AS45758) carries SAN expressresume.monstergulf.com which currently resolves through Akamai (AS20940) at 104.85.0.51, 184.30.156.63, 23.56.162.64, 23.220.112.52
171.102.240.67 AS7470 AS20940 95% cert e55f8d5e… served by 171.102.240.67 (AS7470) carries SAN media.monstergulf.com which currently resolves through Akamai (AS20940) at 104.85.0.51, 184.30.156.63, 104.99.232.60, 23.220.112.52
171.102.240.67 AS7470 AS16625 95% cert e55f8d5e… served by 171.102.240.67 (AS7470) carries SAN expressresume.monstergulf.com which currently resolves through Akamai (AS16625) at 184.30.156.63, 23.56.162.64, 23.220.112.52, 88.221.168.54
163.28.224.67 AS1659 AS16625 95% cert e55f8d5e… served by 163.28.224.67 (AS1659) carries SAN expressresume.monstergulf.com which currently resolves through Akamai (AS16625) at 184.30.156.63, 23.220.112.52, 88.221.168.54, 104.99.232.60
163.28.224.67 AS1659 AS20940 95% cert e55f8d5e… served by 163.28.224.67 (AS1659) carries SAN help.monstergulf.com which currently resolves through Akamai (AS20940) at 104.85.0.51, 23.220.112.52, 104.99.232.60
23.216.34.243 AS12252 AS16625 95% cert e55f8d5e… served by 23.216.34.243 (AS12252) carries SAN expressresume.monstergulf.com which currently resolves through Akamai (AS16625) at 104.99.232.60, 23.220.112.52

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
NS ns-1061.awsdns-04.org 2026-06-04 23:51:53.290 2026-07-21 05:35:48.278
TXT atlassian-domain-verification=4WIcK99xcz6I3VhRK6MDk9JG2Dhil1UumtH79JX//XdSlFhWR37vMpmukOE5ReK6 2026-06-04 23:51:53.290 2026-07-21 05:35:48.278
NS ns-1611.awsdns-09.co.uk 2026-06-04 23:51:53.290 2026-07-21 05:35:48.278
TXT 734D-FDF8-B533-0FC6-D825-1238-7504-0D47 2026-06-04 23:51:53.290 2026-07-21 05:35:48.278
TXT v=spf1 ip4:20.204.50.0/24 ip4:40.80.0.0/16 ip4:20.198.97.0/24 ip4:20.244.66.224/28 include:spf.protection.outlook.com -all 2026-06-04 23:51:53.290 2026-07-21 05:35:48.278
CAA 0 issuewild "digicert.com" 2026-06-04 23:51:53.290 2026-07-21 05:35:48.278
CAA 0 issue "digicert.com" 2026-06-04 23:51:53.290 2026-07-21 05:35:48.278
A 4.240.79.173 2026-06-04 23:51:53.290 2026-07-21 05:35:48.278
NS ns-499.awsdns-62.com 2026-06-04 23:51:53.290 2026-07-21 05:35:48.278
TXT MS=ms87638153 2026-06-04 23:51:53.290 2026-07-21 05:35:48.278
TXT tcj5jtc4mllktfrxvslk2j7x4vphjhmz 2026-06-04 23:51:53.290 2026-07-21 05:35:48.278
TXT MS=ms17054473 2026-06-04 23:51:53.290 2026-07-21 05:35:48.278
CAA 0 issuewild "letsencrypt.org" 2026-06-04 23:51:53.290 2026-07-21 05:35:48.278
NS ns-606.awsdns-11.net 2026-06-04 23:51:53.290 2026-07-21 05:35:48.278
SRV _sipfederationtls._tcp 100 1 5061 sipfed.online.lync.com 2026-06-04 23:51:53.290 2026-07-21 05:35:48.278
CAA 0 issue "letsencrypt.org" 2026-06-04 23:51:53.290 2026-07-21 05:35:48.278
TXT xYlS6rhf5hQA80mgSgA3I5H4i4yEMX0/qgIv65xPS3nMOrz2HNhG15qqPDxi3QxtuKjEhNbs9EZ4euKRPGXpbA== 2026-06-04 23:51:53.290 2026-07-21 05:35:48.278
MX 0 monstergulf-com.mail.protection.outlook.com 2026-06-04 23:51:53.290 2026-07-21 05:35:48.278
A 4.213.37.235 2026-06-04 23:51:53.290 2026-07-21 05:35:48.278