About whack.sh

A cloaked threat shows one face to scanners and another to victims. whack.sh exists to show you both.

The gap we close

Most URL scanners look from a single datacenter vantage point: the exact vantage cloakers fingerprint and feed a clean decoy. The malicious payload only renders for real users on real residential and mobile IPs, so a datacenter-only scan records "benign" and moves on. The mole never surfaces.

whack.sh loads a URL through datacenter, residential and mobile sources at once (or your own IP/ASN with bring-your-own vantage points) and diffs the captures. The page that only misbehaves for real users on real networks can't hide. We call it the Split-Horizon Diff, and the divergence it surfaces is scored 0-100.

Deeper than scanner-vs-user

Sophisticated kits fingerprint the visitor's ASN and tailor the payload to the organization behind it: a bank's corporate range gets a pixel-perfect employee re-validation screen built to harvest that company's credentials, while a scanner gets a parked page. By logging which payload deploys to which ASN, whack.sh turns one URL into a map of who a campaign is hunting: the orgs in the blast radius, spotted before their VPN logins start leaking.

Built for the people who hunt these threats

Phishing and abuse investigators, SOC and incident-response analysts, brand- and ad-fraud teams, and threat-intel researchers. Datacenter scanning is free and unmetered, no card, and the curl-first API drives every tier, the free one included. Paid residential and mobile egress unlock the cross-IP diff; bring-your-own vantage points (Team Hunter and up) let a team scan from its own network to expose ASN-targeted lures.

How we handle what we find

  • Captured malware is neutralized, not re-armed. When a target serves a payload, the scan node keeps the very file it delivered to the browser (no separate fetch over the scan path that would tip off the cloaker), then defangs it at rest (inert: can't execute or trip AV) and hashes it against public malware databases. Raw samples are kept server-side for detection, operator-only and never served for download from whack.sh; confirmed-malicious samples are contributed to public malware-research platforms (VirusTotal, MalwareBazaar, OTX).
  • Faithful loads, not corner-cutting. Every egress runs a full, real-browser load: cutting corners to save bytes is exactly the behavioral fingerprint cloakers watch for.
  • Evidence, not accusations. Verdicts are automated assessments from observed behavior, not statements of fact about any party. Flagged in error? Request a re-review.

The first tool, not the last

whack.sh is the opening tool in a broader security platform: one wallet, one key, more tools to come. Everything is curl-first and built to wire into the pipeline you already run.

whack.sh is live. Create your account for a free key: datacenter scanning is free and unmetered, no card.