Threat intelligence sources
whack.sh does not invent its worklist. Suspicious URLs come from public threat-intelligence feeds run by other people, and we say which ones — so anyone can check where a finding started.
What we ingest
Each of these is an independent, publicly documented source. We use them under the terms their operators publish, and we credit them here because a scanner that will not name its inputs is asking to be trusted on nothing.
| Source | What it provides | Used under |
|---|---|---|
| URLhaus (abuse.ch) | URLs observed distributing malware | Free authenticated API |
| ThreatFox (abuse.ch) | Indicators of compromise, with malware family attribution | Free authenticated API |
| OpenPhish | Phishing URLs | Community feed |
| PhishTank (Cisco Talos) | Community-verified phishing URLs | Free, commercial use permitted |
| urlscan.io | Recently submitted URLs, community-tagged | Free API tier |
| urlquery.net | Analysed reports carrying campaign and kit tags | Public API |
| issued.live (Certificate Transparency) | Newly issued certificates for newly registered domains | Public CT logs and domain information |
| worldip.io | IP intelligence — hosting, proxy, VPN and relay classification for the addresses a scan resolves to | Commercial API |
A third party’s label is not our verdict
This is the part worth understanding. When a feed tells us a URL is malicious, that is a lead, not a conclusion. Several of these sources are community-submitted, and a label anyone can attach is a label anyone can attach to your domain.
So a feed hit only ever earns a URL a place in our scan queue. Every verdict whack.sh publishes comes from our own capture — loading the URL ourselves from multiple vantage points and comparing what each one was served. If we score something malicious, that is our observation and our responsibility, not an echo of someone else’s tag.
Newly registered domains
Freshly registered domains and freshly issued certificates are used as discovery signals only. A domain being new is not evidence of anything — the overwhelming majority are entirely legitimate — and no domain is ever scored on its age. It only means the domain may be worth looking at, and the looking is what produces a verdict.
What we send back
Ingesting from the community without contributing to it is freeloading. What we confirm, we give back — see community contributions.
Flagged in error?
Verdicts come from automated analysis and automated analysis is fallible. If something of yours is flagged and you believe it is wrong, ask for a re-review. A human reads those.
whack