How it works

From whack <url> to a scored verdict in four steps — the same flow whether you use the web app or the curl-first API.

The whole flow in 94 seconds — one link checked from a datacenter, a residential line and a mobile carrier at the same time, and what each vantage was served.
How whack.sh scans a URL from multiple sources and diffs the results whack.sh probes one URL simultaneously through datacenter, residential, mobile and bring-your-own egress across the Americas, Europe and Asia-Pacific, then diffs the responses to expose cloaking. A captured payload is neutralized at rest and sealed one-way in an isolated, off-network store for detection, never served for download here. Only a clean verdict returns to whack.sh, which delivers your report. whack.sh split-horizon diff Multi-source fleet AMERICAS EUROPE ASIA-PACIFIC Datacenter Residential Mobile Your device Threat URL cloaks by vantage point Out-of-band sandbox isolated · off-network Sealed vault one-way · off-network Your report verdict · HAR · IOCs
One URL, scanned from every source at once — datacenter, residential, mobile & your own device, across regions. whack.sh diffs the responses to catch cloaking a single-source scanner can’t. A captured payload is neutralized and sealed one-way in an isolated, off-network store — never served for download here; only a clean verdict comes back to build your report.

The steps

  1. 1

    Submit

    Run whack <url> from the curl-first API or paste it in the web app. Your API key is your login — no passwords, and datacenter scanning needs no card. The same key drives every egress and every endpoint.

  2. 2

    Fan out across egress

    The same URL loads simultaneously through datacenter, residential and mobile IPs — or, with BYO vantage points, your own IP/ASN. Datacenter is free for the first 5 MB (then 1 cr/MB); residential (5 credits, incl. 5 MB, then 1 cr/MB) and mobile (10 credits, incl. 5 MB, then 2 cr/MB) are the paid tier. Real residential and mobile IPs are scarce and expensive — exactly why cloakers trust them, and why advanced kits fingerprint the visitor’s ASN to choose which face to serve.

  3. 3

    Capture everything, per egress

    Each path records the full request waterfall (HAR), a screenshot timeline, and the complete redirect/TDS chain — and logs which payload deployed to which egress and ASN. When a target serves a payload — a forced download or a dropper — the scanner keeps the very file it served your browser, with no separate fetch that would tip off the cloaker, bounded by the byte cap you set. Each sample is neutralized at rest and hashed against public malware databases; Confirmed-malicious samples are contributed to the public malware-research community (VirusTotal, abuse.ch MalwareBazaar, AlienVault OTX) so other defenders can block them; raw samples are never served from whack.sh, and neither your identity nor the scanned URL is published with them. On fast-rotating hosts we may prove a payload deployed yet miss the sample itself.

  4. 4

    Diff and score — the Split-Horizon Diff

    We diff the captures across egress to expose what a datacenter-only scan can’t see: divergence means cloaking, scored 0–100. The per-ASN payload map turns one URL into a picture of who a campaign is hunting — the orgs in the blast radius before their VPN logins leak. You get the verdict, the captures, and IOCs ready to export as CSV, STIX 2.1 or MISP. Mole whacked.