Use cases

One whack <url>, many jobs done, wherever a page hides its real face from scanners.

Every use case below runs on the same primitive: load the URL from datacenter, residential and mobile sources at once, then diff what each one gets back. When the page changes between sources, that difference is the threat a single-vantage scan is built to miss: caught, scored 0-100, and handed back with the full evidence.

Where whack helps

Phishing & Abuse Investigation

Phishing kits cloak: they fingerprint the visitor and serve a clean decoy to anything that smells like a datacenter scanner. whack <url> loads the target through residential and mobile egress too, so the mole that hides from everyone else gets whacked: full HAR, screenshot timeline, and the live redirect/TDS chain.

Targeted-Campaign & Exposure Mapping

When a cloaker singles out corporate ASNs to harvest employee or VPN credentials, the per-ASN payload log shows which organizations it's tailoring lures for, turning one malicious URL into a map of who's in the blast radius, so a SOC knows it's a target before credentials leak.

Brand & Ad-Fraud Protection

Cloaked landers and fake storefronts show one face to your monitoring and another to real users on a phone. The Split-Horizon Diff catches that gap across datacenter, residential and mobile IPs, with a 0-100 divergence score telling you exactly how hard a page is hiding.

Expired-Domain & Brand-Lifecycle Risk

Your marketing still links to domains you let lapse. When one is re-registered and wired into a cloaking TDS, your own authenticated email (SPF, DKIM and DMARC all passing) becomes the delivery path for malware, and a datacenter scan of the link comes back clean. Feed whack.sh the domains your live campaigns reference and it loads each from residential and mobile too, surfacing the branch a scanner never sees. This is exactly the vector we documented end-to-end against a Fortune 500 brand (read the whitepaper).

Threat-Intel & IOC Enrichment

Turn a single URL into shareable intel. whack.sh extracts IOCs from every egress path and exports them as CSV, STIX 2.1 or MISP, and since every endpoint is a curl endpoint, you can wire enrichment straight into your pipeline.

Malware & TDS Research

Trace the full traffic distribution system from entry to payload. When the chain drops a forced download, the scanner keeps the file the site served your browser (no separate fetch that would re-arm the distributor's cloak), then defangs it, hashes it against public malware databases, and stores it defanged. Confirmed-malicious samples are contributed to the public malware-research community (VirusTotal, abuse.ch MalwareBazaar, AlienVault OTX) so other defenders can block them; raw samples are never served from whack.sh, and neither your identity nor the scanned URL is published with them. Capture is bounded by your byte cap; on a fast-rotating host you still get the verdict and full chain even when the sample itself has rotated away.

SOC Triage & Incident Response

A user reports a suspicious link: verify it across every egress in seconds, confirm or dismiss the threat, and attach the HAR, screenshot timeline and cloaking score straight to the ticket. Turn "is this safe to click?" into a scored answer your analysts can act on.

What every scan hands back

  • A 0-100 cloaking score from the divergence across sources, with each capture shown side by side.
  • The full redirect / TDS chain per source: every hop enriched with IP, PTR, ASN/org and proxy/VPN intelligence.
  • HAR waterfall, screenshot timeline, response headers, cookies and TLS for every source.
  • IOCs ready to export as CSV, STIX 2.1 or MISP, plus a shareable report and the full bundle over the curl-first API.

Seen in the wild

The expired-domain vector above isn't hypothetical. We caught a genuine, authenticated marketing email from a Fortune 500 company routing its customers through a lapsed promotional domain into a cloaking TDS serving browser-hijacker malware (invisible to every datacenter scanner that checked it), and drove it to remediation. Read the full whitepaper →