Use cases

One whack <url>, many jobs done — wherever a page hides its real face from scanners.

Every use case below runs on the same primitive: load the URL from datacenter, residential and mobile sources at once, then diff what each one gets back. When the page changes between sources, that difference is the threat a single-vantage scan is built to miss — caught, scored 0–100, and handed back with the full evidence.

Where whack helps

Phishing & Abuse Investigation

Phishing kits cloak: they fingerprint the visitor and serve a clean decoy to anything that smells like a datacenter scanner. whack <url> loads the target through residential and mobile egress too, so the mole that hides from everyone else gets whacked — full HAR, screenshot timeline, and the live redirect/TDS chain.

Targeted-Campaign & Exposure Mapping

When a cloaker singles out corporate ASNs to harvest employee or VPN credentials, the per-ASN payload log shows which organizations it’s tailoring lures for — turning one malicious URL into a map of who’s in the blast radius, so a SOC knows it’s a target before credentials leak.

Brand & Ad-Fraud Protection

Cloaked landers and fake storefronts show one face to your monitoring and another to real users on a phone. The Split-Horizon Diff catches that gap across datacenter, residential and mobile IPs, with a 0–100 divergence score telling you exactly how hard a page is hiding.

Threat-Intel & IOC Enrichment

Turn a single URL into shareable intel. whack.sh extracts IOCs from every egress path and exports them as CSV, STIX 2.1 or MISP — and since every endpoint is a curl endpoint, you can wire enrichment straight into your pipeline.

Malware & TDS Research

Trace the full traffic distribution system from entry to payload. When the chain drops a forced download, the scanner keeps the file the site served your browser — no separate fetch that would re-arm the distributor’s cloak — then defangs it, hashes it against public malware databases, and stores it defanged. Confirmed-malicious samples are contributed to the public malware-research community (VirusTotal, abuse.ch MalwareBazaar, AlienVault OTX) so other defenders can block them; raw samples are never served from whack.sh, and neither your identity nor the scanned URL is published with them. Capture is bounded by your byte cap; on a fast-rotating host you still get the verdict and full chain even when the sample itself has rotated away.

SOC Triage & Incident Response

A user reports a suspicious link — verify it across every egress in seconds, confirm or dismiss the threat, and attach the HAR, screenshot timeline and cloaking score straight to the ticket. Turn “is this safe to click?” into a scored answer your analysts can act on.

What every scan hands back

  • A 0–100 cloaking score from the divergence across sources, with each capture shown side by side.
  • The full redirect / TDS chain per source — every hop enriched with IP, PTR, ASN/org and proxy/VPN intelligence.
  • HAR waterfall, screenshot timeline, response headers, cookies and TLS for every source.
  • IOCs ready to export as CSV, STIX 2.1 or MISP — plus a shareable report and the full bundle over the curl-first API.