Check-Host.cc

Domain

3k.com

Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.

Run a live full scan of 3k.com

On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.

Deep-scan now
Hosting IPs
15
A/AAAA targets
Subdomains
6
CT + scan + body
Record Types
4
seen in DNS
Observed Certs
2
in our scans

DNS Records

A
101.72.248.60, 116.131.226.149, 122.188.44.139, 122.188.45.51, 122.188.57.54, 122.193.250.66, 123.6.42.122, 124.95.136.140
AAAA
MX
10 mxbiz2.qq.com, 5 mxbiz1.qq.com
NS
ns3.dnsv3.com, ns4.dnsv3.com
TXT
v=spf1 include:spf.mail.qq.com ~all
CNAME
CAA

WHOIS / Registration

Registration data planned

Registrar, creation/expiry dates and domain status via RDAP. Rolling out gradually — bulk WHOIS is rate-limited, so we resolve on a prioritized cadence.

Subdomains

Every subdomain we know about — harvested from CT-log SANs, scan-observed certs and HTML body references — paired with its current A/AAAA target.

Tech Stack

Tech detection pending

Wappalyzer-rules detect CMS, frameworks, analytics, JS libs and server-side languages on this domain.

TLS Certificates

Subject: test999.7803k.com
Issuer: YR1
SANs: test999.7803k.com
Subject: segredo.w3k.com.br
Issuer: YR2
SANs: segredo.w3k.com.br, wiki.w3k.com.br
Subject: *.3k.com
Issuer: RapidSSL TLS RSA CA G1
SANs: *.3k.com, 3k.com
Subject: *.3k.com
Issuer: RapidSSL TLS RSA CA G1
SANs: *.3k.com, 3k.com
Subject: *.k3k.com
Issuer: YR1
SANs: *.k3k.com
Subject: vpn.n3k.com
Issuer: R13
SANs: vpn.n3k.com
Subject: www.pi3k.com
Issuer: YR2
SANs: www.pi3k.com
Subject: qqdtpay.3k.com
Issuer: C=CN, ST=Guangdong, L=Shenzhen, O=Unipay Root CA, OU=Unipat Root CA
SANs: qqdtpay.3k.com
Subject: f3kf3k.com
Issuer: YE2
SANs: *.f3kf3k.com, f3kf3k.com
Subject: *.3k.com
Issuer: RapidSSL TLS RSA CA G1
SANs: *.3k.com, 3k.com
Subject: 3k.com
Issuer: 3k.com
SANs: *.3k.com, 3k.com
Subject: us.troimille3k.com
Issuer: ZeroSSL ECC DV SSL CA 2
SANs: us.troimille3k.com
Subject: main2.download3k.com
Issuer: main2.download3k.com
SANs: main2.download3k.com
Subject: d33ps33k.com
Issuer: E8
SANs: d33ps33k.com, www.d33ps33k.com
Subject: coverplus.t3k.com.ph
Issuer: GeoTrust TLS RSA CA G1
SANs: coverplus.t3k.com.ph
Subject: pic.r33k.com
Issuer: R12
SANs: pic.r33k.com
Subject: *.k3k.com
Issuer: R13
SANs: *.k3k.com
Subject: itst3k.com
Issuer: E8
SANs: itst3k.com
Subject: *.k3k.com
Issuer: R13
SANs: *.k3k.com
Subject: entry.723k.com
Issuer: R13
SANs: entry.723k.com
Subject: xn--6qqx5j72e73k.com
Issuer: MySSL.com
SANs: xn--6qqx5j72e73k.com
Subject: *.3k.com
Issuer: TrustAsia RSA DV TLS CA G2
SANs: *.3k.com, 3k.com
Subject: *.3k.com
Issuer: RapidSSL TLS RSA CA G1
SANs: *.3k.com, 3k.com
Subject: api.r3k.com
Issuer: E8
SANs: api.r3k.com
Subject: *.k3k.com
Issuer: R12
SANs: *.k3k.com
Subject: server1.coonlabdatah3k.com
Issuer: R12
SANs: autoconfig.server1.coonlabdatah3k.com, autodiscover.server1.coonlabdatah3k.com, cpanel.server1.coonlabdatah3k.com, cpcalendars.server1.coonlabdatah3k.com, cpcontacts.server1.coonlabdatah3k.com, ipv6.server1.coonlabdatah3k.com, mail.server1.coonlabdatah3k.com, server1.coonlabdatah3k.com, webdisk.server1.coonlabdatah3k.com, webmail.server1.coonlabdatah3k.com, whm.server1.coonlabdatah3k.com, www.server1.coonlabdatah3k.com
Subject: *.3k.com
Issuer: TrustAsia RSA DV TLS CA G3
SANs: *.3k.com, 3k.com
Subject: dpdalipc.aghuu3k.com
Issuer: Certum DV TLS G2 R39 CA
SANs: dpdalih5.aghuu3k.com, dpdalipc.aghuu3k.com, www.dpdalipc.aghuu3k.com
Subject: buddhag33k.com
Issuer: R12
SANs: buddhag33k.com
Subject: *.3k.com
Issuer: TrustAsia RSA DV TLS CA G2
SANs: *.3k.com, 3k.com

IPs Citing This Domain

No citing IPs found yet

As the world-sweep progresses, hosts referencing this domain in their HTML will surface here.

Origin / IP-Leak

USP

When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.

No origin-IP leaks detected (yet)

Either this domain doesn't sit behind a CDN, or we haven't seen a TLS cert from a non-CDN IP matching this hostname. Run a fullscan to refresh the cert→IP cross-reference.

Threat Intelligence

Domain threat-intel pending

Matches in URLhaus, OpenPhish, PhishTank, malware feeds, and Spamhaus DBL.

History

Passive DNS — every value this name ever resolved to and when we first / last observed it. Updates every cycle of our forward-DNS crawler.

Type Value First seen Last seen
A 122.188.57.54 2026-05-25 21:38:03.363 2026-07-26 14:36:44.369
A 218.61.165.129 2026-05-25 21:38:03.363 2026-07-26 14:36:44.369
A 42.4.56.186 2026-05-25 21:38:03.363 2026-06-23 21:51:06.863
A 36.249.93.227 2026-05-25 21:38:03.363 2026-07-26 14:36:44.369
NS ns4.dnsv3.com 2026-05-26 11:11:25.820 2026-05-27 04:52:50.881
NS ns3.dnsv3.com 2026-05-26 11:11:25.820 2026-05-27 04:52:50.881
MX 5 mxbiz1.qq.com 2026-05-26 11:11:25.820 2026-05-27 04:52:50.881
TXT v=spf1 include:spf.mail.qq.com ~all 2026-05-26 11:11:25.820 2026-05-27 04:52:50.881
MX 10 mxbiz2.qq.com 2026-05-26 11:11:25.820 2026-05-27 04:52:50.881
A 116.131.226.149 2026-07-17 01:03:55.008 2026-07-26 14:36:44.369
A 123.6.42.122 2026-07-17 01:03:55.008 2026-07-26 14:36:44.369
A 124.95.136.140 2026-07-17 01:03:55.008 2026-07-26 14:36:44.369
A 122.193.250.66 2026-07-17 01:03:55.008 2026-07-26 14:36:44.369
A 122.188.45.51 2026-07-17 01:03:55.008 2026-07-26 14:36:44.369
A 101.72.248.60 2026-07-17 01:03:55.008 2026-07-26 14:36:44.369
A 122.188.44.139 2026-07-17 01:03:55.008 2026-07-26 14:36:44.369