What is new

Changelog

03 SEP 2026

KittyVex 1.1 CURRENT

  • Static lab for EXE, DLL, JAR, and CLASS: PyInstaller unpack of user modules, PE metadata, packer hints, MITRE tags, shareable reports, markdown, history, and two-sample compare.
  • Catch Discord webhooks (including canary/ptb), Discord bot tokens, Telegram bot tokens, and chat IDs from assignments, JSON, constructors, UTF-16, and URLs. Tokens stay full with real dots; junk prefixes are stripped.
  • Identify-only live checks: webhook GET, Telegram getMe, Discord bot /users/@me. Extracted tokens still show if the check times out.
  • Reports lead with Ratter, What it does, recovered config, families, and score reasons. Filter DigiCert, OID IPs, fake wallets, and library junk.
  • Scoring stacks C2 channels realistically instead of jumping to 100. Packed-only samples stay low.
  • Family fingerprints for Discord.py/js/JDA, Telegram/Pyrogram/Telethon/Aiogram, stealers, loaders, C2 frameworks, and Android RATs.
  • Fast scans: windowed PE harvest, skip Python library folders, prefer small user pycs, 90s overlay wait, cold-boot wake.
  • Leak strip on the far left of Scan: live webhooks and bot tokens, one small blurred line, copy on hover. Header and reports stay centered.
  • Pixel Kitty logo, Discord join tab, nicer two-drop compare with shared / only-A / only-B, builder leaks, host intel, wallets, extra secrets.
28 AUG 2026

KittyVex 1.0

  • Static triage for EXE, DLL, JAR, and CLASS files.
  • PyInstaller unpack and Python bytecode / string extraction without executing the sample.