Threat intelligence sources

whack.sh does not invent its worklist. Suspicious URLs come from public threat-intelligence feeds run by other people, and we say which ones — so anyone can check where a finding started.

What we ingest

Each of these is an independent, publicly documented source. We use them under the terms their operators publish, and we credit them here because a scanner that will not name its inputs is asking to be trusted on nothing.

SourceWhat it providesUsed under
URLhaus (abuse.ch)URLs observed distributing malwareFree authenticated API
ThreatFox (abuse.ch)Indicators of compromise, with malware family attributionFree authenticated API
OpenPhishPhishing URLsCommunity feed
PhishTank (Cisco Talos)Community-verified phishing URLsFree, commercial use permitted
urlscan.ioRecently submitted URLs, community-taggedFree API tier
urlquery.netAnalysed reports carrying campaign and kit tagsPublic API
issued.live (Certificate Transparency)Newly issued certificates for newly registered domainsPublic CT logs and domain information
worldip.ioIP intelligence — hosting, proxy, VPN and relay classification for the addresses a scan resolves toCommercial API

A third party’s label is not our verdict

This is the part worth understanding. When a feed tells us a URL is malicious, that is a lead, not a conclusion. Several of these sources are community-submitted, and a label anyone can attach is a label anyone can attach to your domain.

So a feed hit only ever earns a URL a place in our scan queue. Every verdict whack.sh publishes comes from our own capture — loading the URL ourselves from multiple vantage points and comparing what each one was served. If we score something malicious, that is our observation and our responsibility, not an echo of someone else’s tag.

Newly registered domains

Freshly registered domains and freshly issued certificates are used as discovery signals only. A domain being new is not evidence of anything — the overwhelming majority are entirely legitimate — and no domain is ever scored on its age. It only means the domain may be worth looking at, and the looking is what produces a verdict.

What we send back

Ingesting from the community without contributing to it is freeloading. What we confirm, we give back — see community contributions.

Flagged in error?

Verdicts come from automated analysis and automated analysis is fallible. If something of yours is flagged and you believe it is wrong, ask for a re-review. A human reads those.