Check-Host.cc

Domain

tor.box

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of tor.box

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
7
A/AAAA targets
Subdomains
3
CT + scan + body
Record Types
3
seen in DNS
Observed Certs
15
in our scans

DNS Records

A
104.26.14.126, 104.26.15.126, 172.67.75.110
AAAA
2606:4700:20::681a:e7e, 2606:4700:20::681a:f7e, 2606:4700:20::ac43:4b6e
MX
NS
chip.ns.cloudflare.com, leanna.ns.cloudflare.com
TXT
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Every subdomain we know about — harvested from CT-log SANs, scan-observed certs and HTML body references — paired with its current A/AAAA target.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Subject: nginx-guard.tor.box
Issuer: E7
SANs: nginx-guard.tor.box
Subject: gestor.boxpdv.com.br
Issuer: R13
SANs: gestor.boxpdv.com.br

IPs Citing This Domain

No citing IPs found yet

As the world-sweep progresses, hosts referencing this domain in their HTML will surface here.

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

Origin IP Origin ASN CDN ASN Confidence Reasoning
93.123.85.198 AS58212 AS13335 95% cert 1cae3deb… served by 93.123.85.198 (AS58212) carries SAN nginx-guard.tor.box which currently resolves through Cloudflare (AS13335) at 104.26.14.126, 104.26.15.126, 172.67.75.110, 2606:4700:20::681a:e7e

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
A 172.67.75.110 2026-07-20 06:02:13.289 2026-07-20 06:02:13.289
NS leanna.ns.cloudflare.com 2026-07-20 06:02:13.289 2026-07-20 06:02:13.289
AAAA 2606:4700:20::ac43:4b6e 2026-07-20 06:02:13.289 2026-07-20 06:02:13.289
A 104.26.14.126 2026-07-20 06:02:13.289 2026-07-20 06:02:13.289
A 104.26.15.126 2026-07-20 06:02:13.289 2026-07-20 06:02:13.289
AAAA 2606:4700:20::681a:f7e 2026-07-20 06:02:13.289 2026-07-20 06:02:13.289
NS chip.ns.cloudflare.com 2026-07-20 06:02:13.289 2026-07-20 06:02:13.289
AAAA 2606:4700:20::681a:e7e 2026-07-20 06:02:13.289 2026-07-20 06:02:13.289