v0.3.5
FEATURE
- Added API function:
PESieve_scan_ex
- allowing to retrieve scan and dump JSON reports directly into the supplied memory buffer ( Issue #105 ) - Allow to scan own workingset ( Issue #104 )
- Added one more shellcode pattern ( Issue #108 )
- Added version information to resources
BUGFIX
- Fixed getting stuck on scanning for PE artifacts (in some rare cases)
- Fixed checking mapped modules against the image on disk (fixed issue with the remote module not being copied)
- Fixed false positive - MUI files detected as implanted, when using 32bit scanner on 64bit system (FS redirection issue)
- Other small fixes
See also: HollowsHunter v0.3.5 & MalUnpack v0.9.6 with the latest PE-sieve