News
Research notes, threat write-ups, and product updates from the whack.sh team.
Nine files, two payloads: a Silver Fox sideloader in an open directory
An open HFS server was serving a Silver Fox DLL-sideloading kit: a Microsoft-signed SPDDUMP.EXE loads a malicious mspdb140.dll, which starts a downloader and a keylogging, clipboard-stealing implant. Nine payload files reduce to two, and one 2 KB loader stub marks both stages.
DeviceCensus.exe DLL sideloading: a dcntel.dll backdoor staged from a WebDAV directory
Nine one-line cmd stagers on an open WebDAV share copy the Microsoft-signed DeviceCensus.exe out of System32 and use it to sideload dcntel.dll, a remote shell that reads its server from a hex-encoded edgeupdate.dat and polls viewpipesync[.]online:9090 every 10 seconds.
Referer-gated cloaking: why our scanner arrives with a source
Referer-gated cloaking branches on where a visitor says they came from, so a scanner that opens a URL cold lands in the clean branch by the operator's own rule. Our scanner can set that source and carry it through the redirect chain, so the page answers as it answers the intended visitor.
Brevo delivered KongTuke ClickFix to 51 customer sites
Brevo served malicious JavaScript from its own delivery infrastructure on September 14, reaching 51 customer domains. Kirk of ADAMnetworks published the analysis; Whack.sh took part in the shared investigation.
PasteSwitch: 108 crypto-theft ads on a hijacked HBO Max Reddit account
Attackers hijacked the official verified u/hbomax Reddit account and ran 108 ClickFix ads in 48 hours, delivering fake Ledger, Trezor and Exodus wallet apps on macOS and clipboard hijackers driven by Binance Smart Chain dead drops. Hudson Rock led the research with ADAMnetworks.
The malware that shows scanners a clean page
A cloaked link serves a clean page to scanners and malware to real visitors. Every reputation engine that checked one recent Carnival Cruise Line case rated it safe for months, because each engine looked from a single datacenter IP. Why a scan verdict describes one observation rather than a URL, why the hop domains are disposable by design, and what multi-vantage checking still cannot catch.
The FBI QTFY Advisory: When Attackers Rent the Same Proxies You Do
The FBI, NSA and CNMF have published a joint advisory on QTFY, a China-linked group the agencies attribute to a Nanjing contractor operating three branded internal platforms. One detail matters for anyone doing URL scanning: its obfuscation network rents the same commercial residential proxy pools legitimate scanners use. We also checked all 435 indicators against our own records and found nothing — and that null result is worth publishing.
#4 on MalwareBazaar — what that proves, and what it does not
whack.sh launched on August 6th. Nearly three weeks in, it is the fourth-largest contributor to abuse.ch MalwareBazaar, alongside GovCERT.ch. That proves the detection pipeline finds real, live malware — verified by three independent platforms. It does not prove we are finding what nobody else can, and we would rather say so.
whack.sh is live
Multi-egress URL scanning is out of build and open to everyone. Check a link from a datacenter, a residential line and a mobile carrier at the same moment — and see what each one was actually served.
Malicious Traffic Distribution Systems: Our Take on the FBI's New Advisory
The FBI's IC3 just warned about malicious Traffic Distribution Systems — links that quietly route real victims to fraud while showing automated checks a clean page. Here's our take on why this threat is so durable, why a single "clean" scan can't be trusted, and why seeing it requires looking the way real visitors do.
whack