Back to AI app discovery
Whack.sh logo

Whack.sh

Whack the moles your current scanner can't see.

Developer Tools

Screenshots

Homepage screenshot

About Whack.sh

Datacenter-only scanners have a tell. They run from a handful of cloud ASNs — AWS, GCP, Azure — and cloakers know every one. The moment a request arrives from a known scanner range, the traffic distribution system fingerprints the IP and serves a clean decoy: a parked page, a harmless redirect, a login form that does nothing. Your scanner records “benign” and moves on. The mole never surfaced.

The malicious payload only renders for real users on real residential and mobile IPs — the exact view a datacenter scan can't reach. And it goes deeper: sophisticated kits fingerprint the visitor's ASN and tailor the payload to the organization behind it. A request from a bank's corporate range doesn't get commodity malware — it gets a pixel-perfect employee re-validation screen built to harvest that company's credentials. One URL can serve a parked page to a scanner, generic malware to a home user on residential, a different payload again over mobile, and a targeted corporate-login lure to an employee at the org it's actually hunting.

whack.sh closes the gap by looking from every angle at once and diffing what comes back — and by logging which payload deploys to which ASN. Divergence across egress is the cloak slipping, scored 0–100; the per-ASN map turns “is this URL bad?” into “who is this campaign targeting, and what credentials is it after?” Spot the organizations in the blast radius before the VPN logins start leaking.

Ratings & reviews

Announcements

No announcements yet.

Community activity

Recent follows, shares, ratings, and collection saves for Whack.sh.

No community activity yet. Follow or share Whack.sh to get things started.

Comments

Appz prompt

What kind of project would you trust Whack.sh with first?

Sign in to join the discussion.