Whack the moles your current scanner can't see.
Load any URL through datacenter, residential and mobile egress at once, then diff the captures to expose the cloaking, TDS and malware a datacenter-only scan never sees. Free from datacenter egress for the first 5 MB per scan; the curl API drives every tier, free or paid.
$ whack <url>
The gap
Datacenter-only scanners have a tell. They run from a handful of cloud ASNs — AWS, GCP, Azure — and cloakers know every one. The moment a request arrives from a known scanner range, the traffic distribution system fingerprints the IP and serves a clean decoy: a parked page, a harmless redirect, a login form that does nothing. Your scanner records “benign” and moves on. The mole never surfaced.
The malicious payload only renders for real users on real residential and mobile IPs — the exact view a datacenter scan can't reach. And it goes deeper: sophisticated kits fingerprint the visitor's ASN and tailor the payload to the organization behind it. A request from a bank's corporate range doesn't get commodity malware — it gets a pixel-perfect employee re-validation screen built to harvest that company's credentials. One URL can serve a parked page to a scanner, generic malware to a home user on residential, a different payload again over mobile, and a targeted corporate-login lure to an employee at the org it's actually hunting.
whack.sh closes the gap by looking from every angle at once and diffing what comes back — and by logging which payload deploys to which ASN. Divergence across egress is the cloak slipping, scored 0–100; the per-ASN map turns “is this URL bad?” into “who is this campaign targeting, and what credentials is it after?” Spot the organizations in the blast radius before the VPN logins start leaking. See how it works →
What you get
Split-Horizon Diff
Load one URL through datacenter, residential and mobile egress at once, then diff how the page mutates across IP types. Any divergence is cloaking — caught, scored and shown side by side.
Multi-Egress Capture
A single whack <url> fires through datacenter, residential and mobile IPs in parallel. A cloaker that serves a clean decoy to datacenter scanners can’t hide when three IP classes hit together.
Per-Country Exit
Pin your scan’s exit country. The datacenter leg routes in-country at the US price (free for the first 5 MB, then 1 cr/MB); a paid residential or mobile leg exits your chosen country for a flat +2 credits. The report shows each leg’s true exit IP and country — verified when the sticky exit probe succeeds — so you can test geo-targeted cloaking from where it actually lands.
Per-Hop IP Intelligence
Every hop in the chain is enriched live via worldip.io: reverse DNS (PTR), ASN and organization, country, and the announced BGP prefix. You see exactly whose infrastructure each redirect rides on.
Proxy, VPN & Anonymizer Detection
Each hop’s IP is screened for residential-proxy, VPN, relay and hosting use with 30-day abuse density. Anonymized infrastructure is flagged inline and folded into the cloaking score.
Redirect / TDS Chain
Follow the full hop sequence through traffic-distribution systems to the final payload, with status, host and TLS at every step. The chain that routes a victim is the chain we map.
Who it's for
Phishing & Abuse Investigation
Phishing kits cloak: they fingerprint the visitor and serve a clean decoy to anything that smells like a datacenter scanner. whack <url> loads the target through residential and mobile egress too, so the mole that hides from everyone else gets whacked — full HAR, screenshot timeline, and the live redirect/TDS chain.
Targeted-Campaign & Exposure Mapping
When a cloaker singles out corporate ASNs to harvest employee or VPN credentials, the per-ASN payload log shows which organizations it’s tailoring lures for — turning one malicious URL into a map of who’s in the blast radius, so a SOC knows it’s a target before credentials leak.
Brand & Ad-Fraud Protection
Cloaked landers and fake storefronts show one face to your monitoring and another to real users on a phone. The Split-Horizon Diff catches that gap across datacenter, residential and mobile IPs, with a 0–100 divergence score telling you exactly how hard a page is hiding.
Threat-Intel & IOC Enrichment
Turn a single URL into shareable intel. whack.sh extracts IOCs from every egress path and exports them as CSV, STIX 2.1 or MISP — and since every endpoint is a curl endpoint, you can wire enrichment straight into your pipeline.
Malware & TDS Research
Trace the full traffic distribution system from entry to payload. When the chain drops a forced download, the scanner keeps the file the site served your browser — no separate fetch that would re-arm the distributor’s cloak — then defangs it, hashes it against public malware databases, and stores it defanged. Confirmed-malicious samples are contributed to the public malware-research community (VirusTotal, abuse.ch MalwareBazaar, AlienVault OTX) so other defenders can block them; raw samples are never served from whack.sh, and neither your identity nor the scanned URL is published with them. Capture is bounded by your byte cap; on a fast-rotating host you still get the verdict and full chain even when the sample itself has rotated away.
SOC Triage & Incident Response
A user reports a suspicious link — verify it across every egress in seconds, confirm or dismiss the threat, and attach the HAR, screenshot timeline and cloaking score straight to the ticket. Turn “is this safe to click?” into a scored answer your analysts can act on.
FAQ
How is whack.sh different from urlscan.io or Browserling?
Those tools scan a URL from one vantage point — typically a datacenter IP. Cloakers know datacenter ranges cold and serve them a clean decoy, so the threat never shows up. whack.sh loads the same URL through datacenter, residential and mobile egress simultaneously and diffs the results — built to catch the page that only misbehaves when it thinks no analyst is watching.
What is the Split-Horizon Diff?
It’s the core of the product. We capture the full HAR, screenshot timeline and redirect chain from each egress type, then diff them against each other. When the datacenter capture shows a parked page but the mobile capture drops a fake login or a forced download, that divergence is the cloak — caught in the act.
Can it detect ASN- or org-targeted cloaking?
Yes — it’s a core reason multi-egress matters. Beyond datacenter-vs-real-user, advanced kits fingerprint the visitor’s ASN and serve org-specific payloads — a fake corporate login to a bank’s range, for instance — to harvest employee or VPN credentials. whack.sh exposes the payload served to the vantage points that matter and logs which payload hits which ASN, so you can map exactly who a campaign is targeting.
How does the cloaking score work?
We measure divergence across your egress captures — differences in DOM, redirect chains, network requests and rendered screenshots — and roll it into a single 0–100 score. Zero means the page looked identical no matter who asked; a high score means it served materially different content to different IP types.
What do “egress types” mean and why does mobile cost more?
Egress is the kind of IP your scan exits from: datacenter (cloud ranges), residential (real home ISP IPs) or mobile (real carrier IPs). Cloakers trust residential and mobile far more than datacenter. Mobile costs more because carrier IPs are the scarcest and most expensive to source — the multiplier reflects that reality.
Start scanning. Bring your own curl.
Create an account and get a free key — scan from datacenter egress with the full curl-first API, free for the first 5 MB of every scan, then add residential and mobile egress to whack the moles a datacenter-only scan can't see. No card until you top up.
Already have a key? Sign in →
whack