Check-Host.cc

Domain

raw.githubusercontent.com

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of raw.githubusercontent.com

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
A/AAAA targets
Subdomains
CT + scan + body
Record Types
seen in DNS
Observed Certs
in our scans

DNS Records

A
185.199.108.133, 185.199.109.133, 185.199.110.133, 185.199.111.133
AAAA
2606:50c0:8000::154, 2606:50c0:8001::154, 2606:50c0:8002::154, 2606:50c0:8003::154
MX
NS
TXT
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Every subdomain we know about — harvested from CT-log SANs, scan-observed certs and HTML body references — paired with its current A/AAAA target.

Subdomain Resolves to Last seen
raw.githubusercontent.com 2026-07-28 20:39:29.599

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Subject: localhost
Issuer: DarkBot Root CA
SANs: *.github.com, *.githubusercontent.com, 127.0.0.1, api.github.com, gist.github.com, gist.githubusercontent.com, localhost, raw.githubusercontent.com
Subject: raw.githubusercontent.com
Issuer: raw.githubusercontent.com
SANs: raw.githubusercontent.com

IPs Citing This Domain

Hosts whose HTML body references this domain. Strong signal for origin/mirror/embed discovery.

139.227.20.71:8000 href · ×475
117.14.146.100:8000 href · ×474
139.226.133.61:8000 href · ×474
47.117.244.118:8000 href · ×473
104.194.70.187:8000 href · ×473
218.1.210.133:8000 href · ×473
61.184.8.223:8000 href · ×442
47.102.198.132:8000 href · ×438
101.64.139.217:8000 href · ×428
51.195.150.130:443 href · ×304
8.208.71.231:443 href · ×272
35.172.135.17:443 href · ×187
129.226.204.171:443 href · ×149
217.83.194.51:443 href · ×66
152.228.163.14:443 href · ×48
102.38.58.67:443 href · ×42
3.222.46.5:443 href · ×33
1.234.44.32:80 href · ×32
43.134.236.59:443 href · ×31
195.7.7.32:80 href · ×30
13.124.158.252:443 href · ×29
117.157.93.168:80 href · ×28
167.172.36.229:443 href · ×26
103.197.189.114:443 href · ×26
4.156.40.101:80 href · ×26
162.19.221.239:443 href · ×25
43.142.3.123:443 href · ×24
5.75.207.223:80 href · ×24
162.55.210.115:443 href · ×24
44.204.77.93:80 href · ×24
185.103.164.170:443 href · ×23
146.190.11.18:80 href · ×22
192.124.171.147:8443 href · ×22
64.227.130.114:80 href · ×22
141.98.196.79:443 href · ×21
103.179.189.153:443 href · ×20
119.29.68.163:80 href · ×20
45.177.21.134:443 href · ×20
178.105.156.162:8888 href · ×20
68.183.61.91:443 href · ×20
52.7.56.227:80 href · ×18
66.179.248.198:80 href · ×18
89.167.23.62:443 href · ×18
47.116.161.42:80 href · ×18
181.84.217.132:80 href · ×18
92.51.21.149:443 href · ×17
149.248.61.209:443 href · ×17
47.251.42.75:80 href · ×17
149.248.61.209:80 href · ×17
47.238.90.102:80 href · ×17

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Domain timeline pending

Passive-DNS history accumulates as our forward-DNS crawler observes A/AAAA/MX/NS/TXT records over time.