About whack.sh

A cloaked threat shows one face to scanners and another to victims. whack.sh exists to show you both.

The gap we close

Most URL scanners look from a single datacenter vantage point — the exact vantage cloakers fingerprint and feed a clean decoy. The malicious payload only renders for real users on real residential and mobile IPs, so a datacenter-only scan records “benign” and moves on. The mole never surfaces.

whack.sh loads a URL through datacenter, residential and mobile sources at once — or your own IP/ASN with bring-your-own vantage points — and diffs the captures. The page that only misbehaves for real users on real networks can’t hide. We call it the Split-Horizon Diff, and the divergence it surfaces is scored 0–100.

Deeper than scanner-vs-user

Sophisticated kits fingerprint the visitor’s ASN and tailor the payload to the organization behind it: a bank’s corporate range gets a pixel-perfect employee re-validation screen built to harvest that company’s credentials, while a scanner gets a parked page. By logging which payload deploys to which ASN, whack.sh turns one URL into a map of who a campaign is hunting — the orgs in the blast radius, spotted before their VPN logins start leaking.

Built for the people who hunt these threats

Phishing and abuse investigators, SOC and incident-response analysts, brand- and ad-fraud teams, and threat-intel researchers. Datacenter scanning is free for the first 5 MB, no card — and the curl-first API drives every tier, not just the free one. Paid residential and mobile egress unlock the cross-IP diff; bring-your-own vantage points (Team Hunter and up) let a team scan from its own network to expose ASN-targeted lures.

How we handle what we find

  • Captured malware is neutralized, not re-armed. When a target serves a payload, the scan node keeps the very file it delivered to the browser — no separate fetch over the scan path that would tip off the cloaker — then defangs it at rest (inert: can’t execute or trip AV) and hashes it against public malware databases. Raw samples are kept server-side for detection, operator-only and never served for download from whack.sh; confirmed-malicious samples are contributed to public malware-research platforms (VirusTotal, MalwareBazaar, OTX).
  • Faithful loads, not corner-cutting. Every egress runs a full, real-browser load — cutting corners to save bytes is exactly the behavioral fingerprint cloakers watch for.
  • Evidence, not accusations. Verdicts are automated assessments from observed behavior, not statements of fact about any party. Flagged in error? Request a re-review.

The first tool, not the last

whack.sh is the opening tool in a broader security platform — one wallet, one key, more tools to come. Everything is curl-first and built to wire into the pipeline you already run.

whack.sh is live. Create your account for a free key — datacenter scanning is free for the first 5 MB of every scan, no card.