Check-Host.cc

Domain

com.ni

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of com.ni

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
A/AAAA targets
Subdomains
CT + scan + body
Record Types
seen in DNS
Observed Certs
in our scans

DNS Records

A
AAAA
MX
NS
TXT
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Subdomain enumeration pending

Every subdomain ever issued a TLS cert under this apex — extracted from Certificate Transparency logs, our own scan observations and body references.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Subject: mail.aginsa.com.ni
Issuer: Sectigo Public Server Authentication CA DV R36
SANs: aa-ca.com, mail.agencia-alemana.com.ni, mail.aginsa.com.ni
Subject: *.credifin.com.ni
Issuer: YE1
SANs: *.credifin.com.ni
Subject: *.bin.com.ni
Issuer: Sectigo Public Server Authentication CA DV R36
SANs: *.bin.com.ni, bin.com.ni
Subject: monitoring.yota.com.ni
Issuer: YE1
SANs: monitoring.yota.com.ni
Subject: mail.tallerjordan.com.ni
Issuer: mail.tallerjordan.com.ni
SANs: mail.tallerjordan.com.ni
Subject: *.banpro.com.ni
Issuer: Go Daddy Secure Certificate Authority - G2
SANs: *.banpro.com.ni, banpro.com.ni
Subject: appserver.madinisa.com.ni
Issuer: YR1
SANs: appserver.madinisa.com.ni
Subject: *.hackathonicaragua.com.ni
Issuer: Sectigo Public Server Authentication CA DV R36
SANs: *.hackathonicaragua.com.ni, hackathonicaragua.com.ni
Subject: crpv2.ficohsa.com.ni
Issuer: DigiCert EV RSA CA G2
SANs: crpv2.ficohsa.com.ni
Subject: mail.aconic.com.ni
Issuer: Sectigo Public Server Authentication CA DV R36
SANs: mail.aconic.com.ni, www.mail.aconic.com.ni
Subject: *.tecomunica.com.ni
Issuer: Go Daddy Secure Certificate Authority - G2
SANs: *.tecomunica.com.ni, tecomunica.com.ni
Subject: mail.aconisa.com.ni
Issuer: YR2
SANs: mail.aconisa.com.ni
Subject: *.enacal.com.ni
Issuer: Sectigo Public Server Authentication CA DV R36
SANs: *.enacal.com.ni, enacal.com.ni
Subject: *.bin.com.ni
Issuer: Sectigo Public Server Authentication CA DV R36
SANs: *.bin.com.ni, bin.com.ni
Subject: demo.yota.com.ni
Issuer: R12
SANs: demo.yota.com.ni
Subject: www.rocedes.com.ni
Issuer: SSL.com RSA SSL subCA
SANs: www.rocedes.com.ni
Subject: *.bin.com.ni
Issuer: Sectigo Public Server Authentication CA DV R36
SANs: *.bin.com.ni, bin.com.ni
Subject: webmail.plazaintermall.com.ni
Issuer: Sectigo Public Server Authentication CA DV R36
SANs: webmail.plazaintermall.com.ni, www.webmail.plazaintermall.com.ni
Subject: www.sparkwaveagency.com.nikaphotoco.com
Issuer: R3
SANs: *.sparkwaveagency.com, sparkwaveagency.com, sparkwaveagency.com.nikaphotoco.com, www.sparkwaveagency.com.nikaphotoco.com
Subject: *.sinriesgos.com.ni
Issuer: GlobalSign RSA OV SSL CA 2018
SANs: *.sinriesgos.com.ni, sinriesgos.com.ni
Subject: backups.yota.com.ni
Issuer: YR2
SANs: backups.yota.com.ni
Subject: *.ibw.com.ni
Issuer: Starfield Secure Certificate Authority - G2
SANs: *.ibw.com.ni, ibw.com.ni
Subject: mail.aconisa.com.ni
Issuer: YR2
SANs: mail.aconisa.com.ni
Subject: *.bin.com.ni
Issuer: Sectigo Public Server Authentication CA DV R36
SANs: *.bin.com.ni, bin.com.ni
Subject: mlcorp.com.ni
Issuer: YR1
SANs: mlcorp.com.ni
Subject: *.sinriesgos.com.ni
Issuer: GlobalSign RSA OV SSL CA 2018
SANs: *.sinriesgos.com.ni, sinriesgos.com.ni
Subject: *.bin.com.ni
Issuer: Sectigo Public Server Authentication CA DV R36
SANs: *.bin.com.ni, bin.com.ni
Subject: *.bin.com.ni
Issuer: Sectigo Public Server Authentication CA DV R36
SANs: *.bin.com.ni, bin.com.ni
Subject: api.hospitalsaludintegral.com.ni
Issuer: YE2
SANs: api.hospitalsaludintegral.com.ni
Subject: *.credex.com.ni
Issuer: Sectigo Public Server Authentication CA OV R36
SANs: *.credex.com.ni, credex.com.ni

IPs Citing This Domain

No citing IPs found yet

As the world-sweep progresses, hosts referencing this domain in their HTML will surface here.

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

Origin IP Origin ASN CDN ASN Confidence Reasoning
23.8.147.241 AS17639 AS16625 95% cert 0417d1a9… served by 23.8.147.241 (AS17639) carries SAN www.nexcare.3m.com.ni which currently resolves through Akamai (AS16625) at 23.13.165.224, 2a02:26f0:1700:392::34fe, 2a02:26f0:1700:382::34fe
159.203.105.124 AS14061 AS13335 95% cert 35b14b12… served by 159.203.105.124 (AS14061) carries SAN vostv.com.ni which currently resolves through Cloudflare (AS13335) at 188.114.97.3, 188.114.96.3, 2a06:98c1:3120::3, 2a06:98c1:3121::3
168.110.111.111 AS31898 AS16509 95% cert 9833b131… served by 168.110.111.111 (AS31898) carries SAN ws.airbnb.com.ni which currently resolves through Amazon (AS16509) at 52.72.34.61, 54.90.191.231
165.98.68.245 AS28036 AS16509 95% cert c4a64064… served by 165.98.68.245 (AS28036) carries SAN tigo.com.ni which currently resolves through Amazon (AS16509) at 52.0.229.131
138.185.106.35 AS263760 AS8075 95% cert 9a0f22ce… served by 138.185.106.35 (AS263760) carries SAN www.condor.com.ni which currently resolves through Microsoft (AS8075) at 20.49.104.33
192.196.156.75 AS63410 AS16509 95% cert 57e66128… served by 192.196.156.75 (AS63410) carries SAN sinsa.com.ni which currently resolves through Amazon (AS16509) at 52.8.174.221
165.98.122.11 AS18840 AS13335 95% cert f63b4524… served by 165.98.122.11 (AS18840) carries SAN iniser.com.ni which currently resolves through Cloudflare (AS13335) at 104.20.35.103, 172.66.147.169, 2606:4700:10::ac42:93a9, 2606:4700:10::6814:2367
191.98.255.228 AS19447 AS16509 95% cert e089b08e… served by 191.98.255.228 (AS19447) carries SAN alfa.com.ni which currently resolves through Amazon (AS16509) at 3.81.154.101, 54.80.106.147

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Domain timeline pending

Passive-DNS history accumulates as our forward-DNS crawler observes A/AAAA/MX/NS/TXT records over time.