Whack.sh Tool Scans URLs Across Multiple Network Types to Expose Cloaked Threats
A security researcher has built Whack.sh, a URL threat scanner that simultaneously checks links through datacenter, residential, mobile, VPN, and custom IP egress points to detect threats that evade traditional scanners. The tool was created after the researcher found that standard datacenter-based scanners returned clean results for a malware-serving domain, while a home connection was still being served malicious content. Whack.sh compares captured network traffic across all egress types to uncover cloaking, phishing, and Traffic Direction System (TDS) routing used by attackers to hide payloads from security tools. The researcher reported related findings to the FBI IC3 on June 15, and three days later the agency issued a public service announcement about TDS threats. The tool is set to officially launch on or before August 4, with discovered threats automatically submitted to the Abuse.ch malware database.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in