Check-Host.cc

Domain

pl.so

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of pl.so

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
A/AAAA targets
Subdomains
CT + scan + body
Record Types
seen in DNS
Observed Certs
in our scans

DNS Records

A
AAAA
MX
NS
TXT
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Every subdomain we know about — harvested from CT-log SANs, scan-observed certs and HTML body references — paired with its current A/AAAA target.

Subdomain Resolves to Last seen
mininglicense.moemw.pl.so 2026-07-20 23:15:53.363
assets.qardho.pl.so
1970-01-01 00:00:00.000
bosaso.pl.so 2026-06-19 23:02:42.612
cid.pl.so 2026-06-03 12:58:10.564
cto.pl.so 2026-06-21 11:03:14.269
demo.garowecity.pl.so
1970-01-01 00:00:00.000
dev.moercc.pl.so
1970-01-01 00:00:00.000
en.parliament.pl.so
1970-01-01 00:00:00.000
examination.moehe.pl.so
1970-01-01 00:00:00.000
fms.garowecity.pl.so 2026-05-31 23:00:49.975
galkacyo.pl.so 2026-06-06 01:54:23.346
garowecity.pl.so 2026-06-17 14:37:00.598
hmis-training.moh.pl.so 2026-06-20 01:32:12.527
hmis.moh.pl.so
1970-01-01 00:00:00.000
hrm.qardho.pl.so
1970-01-01 00:00:00.000
mail.police.pl.so
1970-01-01 00:00:00.000
moehe.pl.so 2026-06-04 03:33:51.489
moemw.pl.so 2026-06-19 23:02:42.612
mof.pl.so
1970-01-01 00:00:00.000
mohadm.pl.so
1970-01-01 00:00:00.000
mohamedsalh.moitt.pl.so 2026-07-18 00:57:28.822
mojcrar.pl.so 2026-07-26 03:31:29.946
molah.pl.so 2026-07-20 11:50:31.570
mowdafa.pl.so
1970-01-01 00:00:00.000
pec.pl.so
1970-01-01 00:00:00.000
phpc.pl.so 2026-06-20 13:55:44.235
pmc.pl.so 2026-07-25 05:55:30.244
pneb.pl.so
1970-01-01 00:00:00.000
police.pl.so
1970-01-01 00:00:00.000
puntlandtcfn.pl.so 2026-06-23 16:57:25.829
registry.pl.so 2026-06-01 06:21:52.879
statistics.pl.so
1970-01-01 00:00:00.000
www.assets.qardho.pl.so
1970-01-01 00:00:00.000
www.demo.garowecity.pl.so
1970-01-01 00:00:00.000
www.dev.moercc.pl.so
1970-01-01 00:00:00.000
www.en.parliament.pl.so
1970-01-01 00:00:00.000
www.examination.moehe.pl.so
1970-01-01 00:00:00.000
www.fms.garowecity.pl.so 2026-05-31 23:00:49.975
www.hmis-training.moh.pl.so
1970-01-01 00:00:00.000
www.hrm.qardho.pl.so
1970-01-01 00:00:00.000
www.land.garowecity.pl.so 2026-06-01 06:19:01.317
www.mof.pl.so
1970-01-01 00:00:00.000
www.mohamedsalh.moitt.pl.so 2026-07-18 00:57:28.822
www.police.pl.so
1970-01-01 00:00:00.000
www.task.garowecity.pl.so 2026-06-01 06:19:01.317

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Subject: pl.soupz.biz
Issuer: YE1
SANs: *.pl.soupz.biz, pl.soupz.biz
Subject: db-wpl.solog.id
Issuer: E7
SANs: db-wpl.solog.id
Subject: hmis-training.moh.pl.so
Issuer: YR1
SANs: hmis-training.moh.gov.so, hmis-training.moh.pl.so
Subject: *.tpl.southernglazers.com
Issuer: DigiCert Global G2 TLS RSA SHA256 2020 CA1
SANs: *.tpl.southernglazers.com, tpl.southernglazers.com
Subject: apl.souholdings.co.jp
Issuer: FujiSSL SHA2 Domain Secure Site CA
SANs: apl.souholdings.co.jp, www.apl.souholdings.co.jp
Subject: sandbox-bnpl.soluix.ai
Issuer: E7
SANs: sandbox-api-bnpl.soluix.ai, sandbox-bnpl.soluix.ai
Subject: *.tpl.southernglazers.com
Issuer: DigiCert Global G2 TLS RSA SHA256 2020 CA1
SANs: *.tpl.southernglazers.com, tpl.southernglazers.com
Subject: admin.adp.raspl.solutions
Issuer: R3
SANs: admin.adp.raspl.solutions
Subject: *.tpl.southernglazers.com
Issuer: DigiCert Global G2 TLS RSA SHA256 2020 CA1
SANs: *.tpl.southernglazers.com, tpl.southernglazers.com

IPs Citing This Domain

No citing IPs found yet

As the world-sweep progresses, hosts referencing this domain in their HTML will surface here.

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Domain timeline pending

Passive-DNS history accumulates as our forward-DNS crawler observes A/AAAA/MX/NS/TXT records over time.