03 SEP 2026
KittyVex 1.1 CURRENT
- Static lab for EXE, DLL, JAR, and CLASS: PyInstaller unpack of user modules, PE metadata, packer hints, MITRE tags, shareable reports, markdown, history, and two-sample compare.
- Catch Discord webhooks (including canary/ptb), Discord bot tokens, Telegram bot tokens, and chat IDs from assignments, JSON, constructors, UTF-16, and URLs. Tokens stay full with real dots; junk prefixes are stripped.
- Identify-only live checks: webhook GET, Telegram getMe, Discord bot /users/@me. Extracted tokens still show if the check times out.
- Reports lead with Ratter, What it does, recovered config, families, and score reasons. Filter DigiCert, OID IPs, fake wallets, and library junk.
- Scoring stacks C2 channels realistically instead of jumping to 100. Packed-only samples stay low.
- Family fingerprints for Discord.py/js/JDA, Telegram/Pyrogram/Telethon/Aiogram, stealers, loaders, C2 frameworks, and Android RATs.
- Fast scans: windowed PE harvest, skip Python library folders, prefer small user pycs, 90s overlay wait, cold-boot wake.
- Leak strip on the far left of Scan: live webhooks and bot tokens, one small blurred line, copy on hover. Header and reports stay centered.
- Pixel Kitty logo, Discord join tab, nicer two-drop compare with shared / only-A / only-B, builder leaks, host intel, wallets, extra secrets.