
Fixed a bug when handling the imports of some images. Cache Virustotal scores when Internet connection drops. Added detection of Regular Expressions and Threshold.
Extended detection of files embedded in Resources. Added Blacklist of MD5 dedicated to the Overlay. Resolve OpenSSL ordinals API to User friendly names. Added MD5 Blacklist for a file and its Resources. Added detection of references to Firefox API. Added XML-based detection of PeID Signatures. Added PeID Signature detection of Executable embedded in Overlay. Added PeID Signature detection of Executable embedded in Resources. Extended Languages detection and mapping. Added Virustotal aging and submission date.
Corrected duplicates during collection of functions statistics.Since the executable file being analyzed is never started, you can inspect any unknown or malicious executable with no risk. The goal of PEStudio is to detect these anomalies, provide Indicators and score the Trust for the executable being analyzed. In doing so, it generally presents anomalies and suspicious patterns. Malicious executable often attempts to hide its malicious behavior and to evade detection.
PEStudio is free for private non-commercial use only. PEStudio is a unique tool that performs the static investigation of 32-bit and 64-bit executable.