Features

Everything you need to expose a cloak and turn one URL into shareable intel.

Feature list

Split-Horizon Diff

Load one URL through datacenter, residential and mobile egress at once, then diff how the page mutates across IP types. Any divergence is cloaking — caught, scored and shown side by side.

Multi-Egress Capture

A single whack <url> fires through datacenter, residential and mobile IPs in parallel. A cloaker that serves a clean decoy to datacenter scanners can’t hide when three IP classes hit together.

Per-Country Exit

Pin your scan’s exit country. The datacenter leg routes in-country at the US price (free for the first 5 MB, then 1 cr/MB); a paid residential or mobile leg exits your chosen country for a flat +2 credits. The report shows each leg’s true exit IP and country — verified when the sticky exit probe succeeds — so you can test geo-targeted cloaking from where it actually lands.

Per-Hop IP Intelligence

Every hop in the chain is enriched live via worldip.io: reverse DNS (PTR), ASN and organization, country, and the announced BGP prefix. You see exactly whose infrastructure each redirect rides on.

Proxy, VPN & Anonymizer Detection

Each hop’s IP is screened for residential-proxy, VPN, relay and hosting use with 30-day abuse density. Anonymized infrastructure is flagged inline and folded into the cloaking score.

Redirect / TDS Chain

Follow the full hop sequence through traffic-distribution systems to the final payload, with status, host and TLS at every step. The chain that routes a victim is the chain we map.

Cloaking Score

Cross-egress divergence and the IP-intel signals collapse into one 0–100 score, so you can triage at a glance and alert on a threshold. A high score is a mole serving two faces.

ASN & Org-Targeted Detection

Advanced kits fingerprint the visitor’s ASN and serve org-specific lures — a fake employee login aimed at a bank’s range. whack.sh logs every payload-to-ASN mapping, revealing who a campaign is hunting.

HAR + Screenshot Timeline

Each egress runs a full, faithful Chromium load — JavaScript executed, every resource fetched — then returns the complete HAR waterfall plus a screenshot. We trim stored response bodies, never the load itself.

IP Trust & Infrastructure Mapping

Every IP carries a worldip.io trust score and band, plus a forward-DNS count of how many domains it hosts. That hosted-domain tell is what exposes parking and cloaker networks running thousands of lookalikes.

Full urlscan-Style Report

One shareable report lays each hop’s IP, PTR, ASN, TLS and headers beside the screenshots and verdict. Open it in its own window or share a gated public link, and export the whole bundle as a zip.

Sample + IOC Pipeline

When the target serves a payload, the scanner keeps the file it delivered to your browser — no give-away second fetch — then neutralizes it at rest and hashes it against public malware databases (you get the sha256 and a VirusTotal link). Confirmed-malicious samples are contributed to the public malware-research community (VirusTotal, abuse.ch MalwareBazaar, AlienVault OTX) so other defenders can block them; raw samples are never served from whack.sh, and neither your identity nor the scanned URL is published with them; capture is bounded by your byte cap and best-effort on fast-rotating hosts. IOC export as CSV, STIX 2.1 or MISP is live today.

AI Plain-English Summary

Optional, and charged only if it runs (3 credits): an AI-written plain-English summary of the scan’s findings and verdict — the automated signals turned into prose a non-analyst can act on. Off unless you ask for it.

Curl-First API

Every endpoint is a curl endpoint and your API key is the login — paste it or click a one-time magic link. httpOnly sessions, no passwords, scriptable from the very first request.

Spend Controls + Anomaly Detection

Set per-account daily and monthly credit caps, then let velocity anomaly detection auto-pause a key on a spike and alert you. A runaway script never burns the budget.