How a whack.sh multi-egress scan works

Ninety-four seconds: one link, three vantages, and the file only two of them were allowed to see.

Transcript

0:00
Every URL scanner checks a link the same way: from a datacenter IP. Cloakers recognise those ranges instantly, so they serve them something harmless. You move on.
0:11
In June the FBI warned about exactly this: these systems avoid detection by displaying safe content to undesired targets, including security researchers.
0:23
whack.sh requests that same link from multiple vantages at once, not just a single datacenter IP. Residential, mobile, VPN, or even your own device. Same link, same second.
0:37
Here's what that looks like. The datacenter vantage gets a 404. Looks clean, while residential and mobile are handed a seventy-three kilobyte executable. Same URL. Same moment. That gap is the cloak: a traffic distribution system deciding who gets the real payload. A datacenter-only scanner would have called this safe, and moved on.
1:01
Two independent vantages. Different countries, different carriers. The same SHA-256 hash payload delivered. And the datacenter still reports clean. Two caught it. One never saw it.
1:15
We score the result on what each vantage saw, and we show you why. Then you get everything we captured: HAR files, screenshots, the full chain, and IOCs.
1:26
Confirmed samples are contributed to the threat hunting community. whack.sh. See what other scanners miss.

Want the mechanics rather than the film? How it works walks the same flow step by step, and the example report shows what a finished scan actually returns.