Skip to content

blaze0089/Vortex-discord-security-

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

5 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

Vortex-discord-security-

Typing SVG
Β  Β  Β 


🎯 What is Vortex?

Vortex is a specialized Discord Malware & token stealer detection platform built from the ground up to identify malicious token stealers with surgical precision. Unlike traditional antivirus solutions that flag everything suspicious, Vortex uses dynamic behavioral analysis to distinguish between legitimate tools (game cheats, mods, trainers) and actual Discord token theft malware.

⚑ THIS IS NOT A TOKEN stealer β€” IT DETECTS THEM ⚑

✨ Why Vortex is Different

πŸ”¬ Traditional Antivirus

- Flags game cheats as malware
- High false positive rate
- Generic threat detection
- No Discord-specific analysis
- Pattern-based only

⚑ Vortex Detection Engine

+ Ignores legitimate game tools
+ ~2% false positive rate
+ Token stealer specialized
+ Discord behavior profiling
+ Multi-layer dynamic analysis

πŸ›‘οΈ Core Features

πŸ” 7-Layer Analysis Engine

Every file goes through 7 independent analysis layers before final verdict. Each layer specializes in different threat indicators.

πŸ’Ž Smart Scanning System

Free Tier

  • βœ… 5 scans per day
  • βœ… Full 7-layer analysis
  • βœ… Badge progression
  • βœ… Leaderboard ranking
  • βœ… Resets midnight IST

Premium Credits

  • βœ… Unlimited scanning
  • βœ… 0 credits for cached files
  • βœ… Priority queue
  • βœ… First-discovery attribution

πŸ† Gamification System

πŸŽ–οΈ Badge System

Analyst Track (Reputation)

Novice Archivist β†’ Data Collector
Digital Hoarder β†’ Archive Guardian
Vault Keeper β†’ Master of Archives

Hunter Track (Detections)

Threat Spotter β†’ Stealer Hunter
Malware Slayer β†’ stealer Exterminator
Discord Purifier

πŸ“Š Leaderboards

Three Rankings

  • πŸ”₯ Reputation Rank
  • 🎯 stealer Detection Rank
  • πŸ… Total Badges Rank

Real-time global standings with automatic badge awards on milestone completion.

πŸ“ˆ Reputation System

Earn Points By:

  • Completing scans
  • Finding new threats
  • First-discovery bonus
  • Premium contributions

Track your impact on the global threat database.


πŸ”¬ Analysis Methods Explained

Method What It Does When Used
Static Analysis Examines file without execution All files
YARA Rules Pattern matching for known stealer signatures Executables
CAPA Capability detection (registry, network, Discord paths) PE files
VirusTotal Cross-reference with 70+ antivirus engines New files
Hybrid Analysis Cloud-based behavioral sandbox Suspicious files
Dynamic Sandbox Controlled execution monitoring High-risk files
AI Verdict Machine learning final decision All scans

πŸ“¦ Special: Archive Handling

RAR/ZIP β†’ Scan archive integrity first
    ↓
 If SAFE β†’ Extract and scan contents individually
    ↓
 If SUSPICIOUS β†’ Flag without extraction (prevents payload detonation)
  • Supported formats: EXE, DLL, RAR, ZIP, 7Z, TAR, GZ, and 40+ more file types
  • Hash tracking: Every file hash saved to global database
  • Duplicate detection: Instant results for previously scanned files

⚠️ CRITICAL SAFETY INFORMATION

🚨 THIS TOOL IS NOT A TOKEN stealer

Vortex DETECTS stealers β€” it is NOT one itself.

However, to perform dynamic behavioral analysis (Sandbox method), Vortex must execute files in a controlled environment. This is why you MUST use a VM.

βœ… Safe Usage Protocol

🟒 Required Setup (MANDATORY)

Environment : Virtual Machine (VMware/VirtualBox)
Discord App : MSI App Player with FAKE account
Token      : Use throwaway/burner Discord account
Network    : Isolated or monitored VM network
Snapshot   : Create VM snapshot before scanning

πŸ”΄ DO NOT

- Run on your main system
- Use real Discord account in VM
- Scan files with real token logged in
- Ignore VM setup instructions
- Share config.json (contains API keys)

⚑ Why VM is MANDATORY

When Vortex runs Sandbox analysis, it executes the file to observe behavior. If the file IS a token stealer and you're running Vortex on your main machine with your real Discord account logged in, the stealer WILL steal your token.

VM Setup Guide: Complete VM Configuration Instructions


πŸ“₯ Download & Installation

🎯 Official Sources ONLY

Β Β 



Full Documentation: vortex-guide-chi.vercel.app

πŸ“‹ Quick Start

# 1. Download Vortex.exe from official sources
# 2. Set up VM with Discord (fake account)
# 3. Run Vortex.exe inside VM
# 4. Create account (no VPN during registration)
# 5. Configure API keys (VirusTotal, Hybrid Analysis, OpenRouter)
# 6. Start scanning files

⚠️ Important: The tool requires Discord to be running during scans for behavioral monitoring. Use a burner account in your VM.


πŸŽ“ How It Works

graph TD
    A[Upload File] --> B{File in Database?}
    B -->|Yes| C[Instant Result<br/>Free: 1 credit<br/>Premium: 0 credits]
    B -->|No| D[7-Layer Analysis Begins]
    D --> E[Layer 1: Static Analysis]
    E --> F[Layer 2: YARA Scanning]
    F --> G[Layer 3: CAPA Detection]
    G --> H[Layer 4: VirusTotal Cross-Ref]
    H --> I[Layer 5: Hybrid Analysis]
    I --> J{High Risk?}
    J -->|Yes| K[Layer 6: Sandbox Execution]
    J -->|No| L[Layer 7: AI Verdict]
    K --> L
    L --> M[Final Verdict + Hash Storage]
    M --> N{stealer Detected?}
    N -->|Yes| O[🚨 THREAT - Badge +1 Detection]
    N -->|No| P[βœ… SAFE - Badge +1 Reputation]
Loading

πŸ“Š Accuracy & Performance

🎯 Detection Metrics

True Positive Rate:  ~98%
False Positive Rate: ~2%
Tested on:          10,000+ samples
Specialization:     Discord token stealers

⚑ Performance

Cached Files:    <1 second
New Executables: 3-20 minutes
Large Files:     Up to 30 minutes
Archive Scan:    Varies by size

βœ… What's Considered SAFE

  • Game cheats and trainers (unless they contain token stealers)
  • Modded clients for games
  • Automation tools
  • Cracked software (malware-free)
  • Custom executables without Discord theft behavior

Vortex won't flag your GTA V mod menu or Valorant skin changer β€” unless they're hiding a token stealer.


πŸ” Privacy & Security

πŸ›‘οΈ What Vortex Collects

Account:
  - Username (changeable)
  - Hardware ID (device binding)
  - IP address (registration + anti-VPN)

Scans:
  - File hash (SHA-256)
  - Scan timestamp
  - Verdict result
  - Layer outputs (anonymous)

πŸ”’ What Vortex Protects

Security:
  - API keys encrypted locally
  - Hardware-locked accounts
  - VPN allowed post-registration
  - No file content stored
  - Debugger = instant ban

Files:
  - Only hash stored permanently
  - Metadata for analysis
  - No file re-distribution

🌐 Community & Support

Β Β  Β Β 



πŸ“¬ Get Help

Topic Where to Ask
Setup Issues Discord Server β†’ #support
False Positive Report GitHub Issues
Feature Requests Discord Server β†’ #suggestions
Account Problems Discord DM to @blaze0089

βš–οΈ Legal & Ethics

⚠️ Authorized Use Only

This tool is designed for:
  βœ… Analyzing files you own or have permission to scan
  βœ… Educational and research purposes
  βœ… Personal device security auditing
  βœ… Community threat intelligence sharing

This tool is NOT for:
  ❌ Scanning files without authorization
  ❌ Reverse engineering proprietary software
  ❌ Distributing or sharing malware samples
  ❌ Bypassing anti-cheat or DRM systems

The creator is not responsible for misuse. Use responsibly and legally.


πŸ“œ FAQ

Is Vortex itself a token stealer?

NO. Vortex detects token stealers β€” it is not one. However, it executes files in a Sandbox to analyze behavior, which is why you must use a VM with a fake Discord account.

Why do I need to run Discord with a fake account?

Vortex monitors Discord process behavior during Sandbox analysis. If the scanned file attempts to interact with Discord (token theft, webhook injection, etc.), Vortex catches it. Use a burner/fake account so if a file IS malicious, it steals a worthless token.

Will my game cheats be flagged?

No β€” unless they contain token-stealing functionality. Vortex is trained to ignore legitimate game modifications, trainers, and cheats. Traditional AVs flag these; Vortex doesn't.

Can I get banned for using Vortex?

Discord cannot detect Vortex usage. However, attaching a debugger to Vortex results in an instant permanent account ban (no appeal).

How are duplicates handled?

If a file's hash exists in the database:

  • Free users: Still uses 1 daily scan credit
  • Premium users: Costs 0 credits, instant result
What happens if I scan a RAR/ZIP?
Step 1: Vortex scans the archive container itself
Step 2: If SAFE β†’ Extract and scan each file inside
Step 3: If SUSPICIOUS β†’ Flag immediately without extraction

This prevents accidental execution of packed malware payloads.


πŸ—οΈ Technical Stack

Analysis Engine:  Python 3.11+
Static Analysis:  YARA, CAPA, PEfile
Dynamic Analysis: Custom Sandbox (Windows VM)
AI/ML Engine:     OpenRouter API (Claude/GPT models)
Cross-Reference:  VirusTotal API, Hybrid Analysis API
Database:         PostgreSQL (hash storage)
Frontend:         Custom GUI (Electron-based)
Backend:          FastAPI + WebSockets

πŸ“ˆ Roadmap

Feature Status ETA
Linux Support πŸ”„ Planned Q2 2025
macOS Support πŸ”„ Planned Q3 2025
Browser Extension Scanning πŸ”„ Planned Q2 2025
Mobile App (Android/iOS) πŸ’­ Considering TBD
Custom YARA Rule Upload πŸ’­ Considering TBD
Public API Access πŸ”’ Premium Only Q4 2025

πŸ™ Credits & Attribution

Built by: blaze0089
Powered by: VirusTotal, Hybrid Analysis, OpenRouter, YARA, CAPA
Community: Discord Server Contributors

Special thanks to everyone who reported false positives and helped improve detection accuracy.


πŸ“„ License

Proprietary Software β€” All Rights Reserved

This is closed-source commercial software. The executable is provided for personal use under the terms outlined in the Guide Site.

  • βœ… Personal use allowed
  • βœ… Scanning your own files
  • ❌ Redistribution prohibited
  • ❌ Reverse engineering prohibited (instant ban)
  • ❌ Commercial use without license

πŸ”₯ Stay Protected

Scan smarter. Detect faster. Stay ahead of token stealers.