About whack.sh
A cloaked threat shows one face to scanners and another to victims. whack.sh exists to show you both.
The gap we close
Most URL scanners look from a single datacenter vantage point — the exact vantage cloakers fingerprint and feed a clean decoy. The malicious payload only renders for real users on real residential and mobile IPs, so a datacenter-only scan records “benign” and moves on. The mole never surfaces.
whack.sh loads a URL through datacenter, residential and mobile sources at once — or your own IP/ASN with bring-your-own vantage points — and diffs the captures. The page that only misbehaves for real users on real networks can’t hide. We call it the Split-Horizon Diff, and the divergence it surfaces is scored 0–100.
Deeper than scanner-vs-user
Sophisticated kits fingerprint the visitor’s ASN and tailor the payload to the organization behind it: a bank’s corporate range gets a pixel-perfect employee re-validation screen built to harvest that company’s credentials, while a scanner gets a parked page. By logging which payload deploys to which ASN, whack.sh turns one URL into a map of who a campaign is hunting — the orgs in the blast radius, spotted before their VPN logins start leaking.
Built for the people who hunt these threats
Phishing and abuse investigators, SOC and incident-response analysts, brand- and ad-fraud teams, and threat-intel researchers. Datacenter scanning is free for the first 5 MB, no card — and the curl-first API drives every tier, not just the free one. Paid residential and mobile egress unlock the cross-IP diff; bring-your-own vantage points (Team Hunter and up) let a team scan from its own network to expose ASN-targeted lures.
How we handle what we find
- Captured malware is neutralized, not re-armed. When a target serves a payload, the scan node keeps the very file it delivered to the browser — no separate fetch over the scan path that would tip off the cloaker — then defangs it at rest (inert: can’t execute or trip AV) and hashes it against public malware databases. Raw samples are kept server-side for detection, operator-only and never served for download from whack.sh; confirmed-malicious samples are contributed to public malware-research platforms (VirusTotal, MalwareBazaar, OTX).
- Faithful loads, not corner-cutting. Every egress runs a full, real-browser load — cutting corners to save bytes is exactly the behavioral fingerprint cloakers watch for.
- Evidence, not accusations. Verdicts are automated assessments from observed behavior, not statements of fact about any party. Flagged in error? Request a re-review.
The first tool, not the last
whack.sh is the opening tool in a broader security platform — one wallet, one key, more tools to come. Everything is curl-first and built to wire into the pipeline you already run.
whack.sh is live. Create your account for a free key — datacenter scanning is free for the first 5 MB of every scan, no card.
whack