Whack the moles your scanner can't see.

Load any URL through datacenter, residential and mobile egress at once, then diff the captures to expose the cloaking, TDS and malware a datacenter-only scan never sees. Free from datacenter egress for the first 5 MB per scan; the curl API drives every tier, free or paid.

$ whack <url>

The gap

Datacenter-only scanners have a tell. They run from a handful of cloud ASNs — AWS, GCP, Azure — and cloakers know every one. The moment a request arrives from a known scanner range, the traffic distribution system fingerprints the IP and serves a clean decoy: a parked page, a harmless redirect, a login form that does nothing. Your scanner records “benign” and moves on. The mole never surfaced.

The malicious payload only renders for real users on real residential and mobile IPs — the exact view a datacenter scan can't reach. And it goes deeper: sophisticated kits fingerprint the visitor's ASN and tailor the payload to the organization behind it. A request from a bank's corporate range doesn't get commodity malware — it gets a pixel-perfect employee re-validation screen built to harvest that company's credentials. One URL can serve a parked page to a scanner, generic malware to a home user on residential, a different payload again over mobile, and a targeted corporate-login lure to an employee at the org it's actually hunting.

whack.sh closes the gap by looking from every angle at once and diffing what comes back — and by logging which payload deploys to which ASN. Divergence across egress is the cloak slipping, scored 0–100; the per-ASN map turns “is this URL bad?” into “who is this campaign targeting, and what credentials is it after?” Spot the organizations in the blast radius before the VPN logins start leaking. See how it works →

Why we built it

whack.sh didn't start as a product — it started as field work. Two investigations into live cloaking and traffic-distribution operations publish at the end of July 2026.

The SHA-256 digests below are published now as cryptographic commitments to those findings — a timestamped record that the analysis predates its disclosure and wasn't changed after the fact. When each report drops, run sha256sum on it: the digest must match what's recorded here.

Investigation commitments · SHA-256
C7183F66E1981525FECCB6681F4990463907BFD638E7DD89972885DBC0237BAC 8321941690069E369C268148ADE5A2D10050138A99FF2FEE247BCE7030227BE4

What you get

Split-Horizon Diff

Load one URL through datacenter, residential and mobile egress at once, then diff how the page mutates across IP types. Any divergence is cloaking — caught, scored and shown side by side.

Multi-Egress Capture

A single whack <url> fires through datacenter, residential and mobile IPs in parallel. A cloaker that serves a clean decoy to datacenter scanners can’t hide when three IP classes hit together.

Per-Country Exit

Pin your scan’s exit country. The datacenter leg routes in-country at the US price (free for the first 5 MB, then 1 cr/MB); a paid residential or mobile leg exits your chosen country for a flat +2 credits. The report shows each leg’s true exit IP and country — verified when the sticky exit probe succeeds — so you can test geo-targeted cloaking from where it actually lands.

Per-Hop IP Intelligence

Every hop in the chain is enriched live via worldip.io: reverse DNS (PTR), ASN and organization, country, and the announced BGP prefix. You see exactly whose infrastructure each redirect rides on.

Proxy, VPN & Anonymizer Detection

Each hop’s IP is screened for residential-proxy, VPN, relay and hosting use with 30-day abuse density. Anonymized infrastructure is flagged inline and folded into the cloaking score.

Redirect / TDS Chain

Follow the full hop sequence through traffic-distribution systems to the final payload, with status, host and TLS at every step. The chain that routes a victim is the chain we map.

Who it's for

Phishing & Abuse Investigation

Phishing kits cloak: they fingerprint the visitor and serve a clean decoy to anything that smells like a datacenter scanner. whack <url> loads the target through residential and mobile egress too, so the mole that hides from everyone else gets whacked — full HAR, screenshot timeline, and the live redirect/TDS chain.

Targeted-Campaign & Exposure Mapping

When a cloaker singles out corporate ASNs to harvest employee or VPN credentials, the per-ASN payload log shows which organizations it’s tailoring lures for — turning one malicious URL into a map of who’s in the blast radius, so a SOC knows it’s a target before credentials leak.

Brand & Ad-Fraud Protection

Cloaked landers and fake storefronts show one face to your monitoring and another to real users on a phone. The Split-Horizon Diff catches that gap across datacenter, residential and mobile IPs, with a 0–100 divergence score telling you exactly how hard a page is hiding.

Threat-Intel & IOC Enrichment

Turn a single URL into shareable intel. whack.sh extracts IOCs from every egress path and exports them as CSV, STIX 2.1 or MISP — and since every endpoint is a curl endpoint, you can wire enrichment straight into your pipeline.

Malware & TDS Research

Trace the full traffic distribution system from entry to payload. By default the scan stays invisible — the node flags the payload URL but never fetches the body. Out-of-band sample capture (forced-download files hashed against the feeds and stored only if novel, the raw sample operator-only and never web-distributed) is on the roadmap — study the delivery chain without re-arming it. You always get the verdict, the full chain and IOCs.

SOC Triage & Incident Response

A user reports a suspicious link — verify it across every egress in seconds, confirm or dismiss the threat, and attach the HAR, screenshot timeline and cloaking score straight to the ticket. Turn “is this safe to click?” into a scored answer your analysts can act on.

FAQ

How is whack.sh different from urlscan.io or Browserling?

Those tools scan a URL from one vantage point — typically a datacenter IP. Cloakers know datacenter ranges cold and serve them a clean decoy, so the threat never shows up. whack.sh loads the same URL through datacenter, residential and mobile egress simultaneously and diffs the results — built to catch the page that only misbehaves when it thinks no analyst is watching.

What is the Split-Horizon Diff?

It’s the core of the product. We capture the full HAR, screenshot timeline and redirect chain from each egress type, then diff them against each other. When the datacenter capture shows a parked page but the mobile capture drops a fake login or a forced download, that divergence is the cloak — caught in the act.

Can it detect ASN- or org-targeted cloaking?

Yes — it’s a core reason multi-egress matters. Beyond datacenter-vs-real-user, advanced kits fingerprint the visitor’s ASN and serve org-specific payloads — a fake corporate login to a bank’s range, for instance — to harvest employee or VPN credentials. whack.sh exposes the payload served to the vantage points that matter and logs which payload hits which ASN, so you can map exactly who a campaign is targeting.

How does the cloaking score work?

We measure divergence across your egress captures — differences in DOM, redirect chains, network requests and rendered screenshots — and roll it into a single 0–100 score. Zero means the page looked identical no matter who asked; a high score means it served materially different content to different IP types.

What do “egress types” mean and why does mobile cost more?

Egress is the kind of IP your scan exits from: datacenter (cloud ranges), residential (real home ISP IPs) or mobile (real carrier IPs). Cloakers trust residential and mobile far more than datacenter. Mobile costs more because carrier IPs are the scarcest and most expensive to source — the multiplier reflects that reality.

Get on the list. Bring your own curl.

whack.sh is coming soon. Drop your email and grab a free key at launch — scan from datacenter egress with the full curl-first API, free for the first 5 MB of every scan, then add residential and mobile egress to whack the moles a datacenter-only scan can't see.

Already have a key? Sign in →