I have been working on this project for well over a month and have run over 150,000 scans of known threat URLs. The site began from an investigation into malware distribution on a corporation's lapsed domain. I have a few articles I'll be posting in the coming weeks on tuxxin.com with my findings, but enough of that for now.
During my investigation, I noticed the existence of the TDS (Traffic Direction System) and kept digging further to find out as much information as I could. Doing this manually was a big hassle as every URL scanner out there uses datacenter-based egress IPs, which were being blocked, while the sites were still serving malware to my home connection. I reported my findings within hours to the FBI IC3 on Monday, June 15th; three days later, a TDS PSA was sent out by IC3.
Per the FBI's IC3 warning, TDS kits fingerprint IPs to hide payloads, targeting only residential, mobile, or specific ASNs.
To catch them, you have to blend in. whack.sh allows you to scan any URL via datacenter, residential, mobile, VPN and BYO egress options at once. Then diffs the captures to expose cloaking, TDS, phishing sites and malware a datacenter-only IP scanner misses.
Datacenter egress is free (first 5MB/scan); our curl API drives every tier, free or paid.