🌐 document.documentElement
DOMAIN
· host
document.documentelement
· threat 0.50 (HIGH)
· IP Blocklists First seen 2026-08-06 13:11:12 · last seen 2026-08-06 14:48:12
🔄 Pivot:📁 IP Blocklists
Threat score
0.50
MEDIUM
Sightings
4
3 sources
Subdomains (local)
0
from indicators
Related IPs
0
A/AAAA records
DNS records (local)
0
0 types
Reporting sources
3
0 enrichments
📡 Reporting-source breakdown
2
1
3 total source links on this indicator.
🏷 Tag breakdown (domain family)
No data.
📈 DNS record-type counts
No data.
📅 First-seen timeline (family)
1
🏷 WHOIS / Registration (local cache)
No cached WHOIS for document.documentelement. Resolve & cache.
📡 DNS Records
No stored DNS records for document.documentelement, and live DoH is unavailable (offline or non-resolving). Run DNS audit.
🌐 Subdomains — local intel (0)
No subdomains of document.documentelement in local intel. Check crt.sh ↗
📡 Reporting Sources (3)
ELLIO Test | IP Blocklists |
ELLIO Community | IP Blocklists |
ELLIO / Green mixed | IP Reputation |
🌐 Same-ASN domains (0)
No ASN linkage in local intel.
🔍 OSINT pivots — external lookups
🔗 Internal pivots & actions
Every panel resolves local-first: threat, category, first-seen & sightings from
indicators; DNS from dns_records; WHOIS from whois_cache; subdomains via bounded suffix match on indicators; related IPs from A/AAAA records; tags, reporting sources and the link graph from the local relations. Live OTX pulses and DNS-over-HTTPS are optional augmentation and their absence never blanks the dossier.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Audit DNS to build passive history
- Pivot resolved IPs to their dossiers
- Report phishing to registrar/host