whack.sh - Whack the moles your current scanner can't see.

by
Per the FBI's IC3 warning, TDS kits fingerprint IPs to hide payloads, targeting only residential, mobile, or specific ASNs. To catch them, you have to blend in. whack.sh allows you to scan any URL via datacenter, residential, mobile, VPN and BYO egress options at once. Then diffs the captures to expose cloaking, TDS, phishing sites and malware a datacenter-only IP scanner misses. Datacenter egress is free (first 5MB/scan); our curl API drives every tier, free or paid.

Add a comment

Replies

Best

In June, the FBI’s IC3 released a PSA warning that malicious Traffic Distribution Systems (TDS) are bypassing traditional defenses by aggressively filtering visitors based on IP and device data to hide their final payloads.

If your threat intel relies on datacenter-bound scans alone, you're only seeing what the threat actor wants you to see. Modern phishing and TDS kits fingerprint ASNs to serve a clean face to scanners, revealing the real payload only to residential and mobile users, or to a specifically targeted ASN (for phishing, malware, or other attacks).

To catch them, you have to blend in.

That's why I built . Drop in a single URL, and it triggers a simultaneous fan-out across datacenter, residential, mobile, VPN, and BYO egress options. Full request waterfall and redirect/TDS chain is captured for each path—then diffs the results to expose the cloaking instantly to detect the hidden payloads (malware, phishing, viruses, scareware, etc.).

See the full architecture: