
whack.sh is an innovative multi-egress URL threat scanning SaaS designed to expose cloaking, traffic distribution systems (TDS), and malware that traditional datacenter-only scanners miss. By simultaneously loading a single URL from diverse vantage points—datacenter, residential, and mobile IPs across various regions—it meticulously diffs the captures to reveal hidden malicious payloads.
This powerful tool is essential for cybersecurity professionals, threat intelligence teams, and organizations focused on brand and ad-fraud protection, providing unparalleled visibility into sophisticated online threats.
Key Features
Split-Horizon Diff: Compares page mutations across datacenter, residential, and mobile egress types, scoring divergence (0-100) to pinpoint cloaking.
Multi-Egress Capture: Scans URLs in parallel from datacenter, residential, and mobile IPs, preventing cloakers from serving clean decoys.
Per-Country Exit: Pinpoint scan exit countries for geo-targeted cloaking tests, with verified true exit IPs and countries.
Per-Hop IP Intelligence: Enriches every redirect hop with live data including reverse DNS, ASN, organization, country, and BGP prefix.
Proxy, VPN & Anonymizer Detection: Flags anonymized infrastructure inline and integrates it into the cloaking score.
Redirect / TDS Chain Mapping: Traces the full hop sequence through traffic distribution systems to the final payload, including status, host, and TLS details.
Use Cases
Phishing & Abuse Investigation: Phishing kits often cloak their true intent from datacenter scanners. whack.sh bypasses these cloaks by scanning from residential and mobile IPs, providing full HAR, screenshot timelines, and the live redirect chain to expose the real threat.
Targeted-Campaign & Exposure Mapping: For advanced cloakers targeting specific corporate ASNs with tailored lures (e.g., fake corporate logins), whack.sh logs which payload deploys to which ASN. This transforms a single malicious URL into a map of organizations in the blast radius, enabling SOC teams to proactively identify targets before credential leaks occur.
Brand & Ad-Fraud Protection: Cloaked landers and fake storefronts present different content to monitoring systems versus real users. The Split-Horizon Diff feature precisely identifies this discrepancy across various IP types, providing a clear divergence score to indicate how effectively a page is hiding its true nature.
Pricing Information
whack.sh operates on a freemium model. Scans from datacenter egress are free for the first 5 MB per scan. Residential and mobile egress options are available at an additional cost, with mobile egress being priced higher due to the scarcity and expense of carrier IPs. The powerful curl API drives all tiers, whether free or paid.
User Experience and Support
Designed with an API-first approach, whack.sh caters to developers and security professionals who prefer programmatic access. The service emphasizes integration into existing pipelines via its comprehensive curl API. While specific UI details are not provided, the focus on an API-driven experience suggests a powerful, flexible tool for technical users. Support information is limited to a "Get on the list" option for launch and a "Contact" link, indicating future support channels.
Conclusion
whack.sh offers a critical advantage in the fight against sophisticated online threats by revealing cloaked content and targeted malware that evades conventional scanners. Its unique multi-egress scanning and diffing capabilities provide unparalleled visibility, empowering security teams to proactively identify and mitigate risks. Get on the list today to leverage its powerful API and whack the moles your current scanner can't see.
Tuxxin LLC
All-in-one AI assistant with the most advanced AI models to help you Chat, Search, Write, Read and more.
The scalable and production-ready Directory starter kit.
Get your brand featured here