| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2020-Aug-04 23:55:23 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\multi-runner\builds\92d31d76\0\pdi\msi\src\luttest\Release\LutTest.pdb
|
| CompanyName | Portrait Displays |
| FileDescription | LutTest 3D LUT loading tool |
| FileVersion | 4.1.3.0 |
| InternalName | LutTest.exe |
| LegalCopyright | (c) 1993-2020 Portrait Displays, Inc. All rights reserved. |
| OriginalFilename | LutTest.exe |
| ProductName | LutTest |
| ProductVersion | 4.1.3.0 |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Accesses the WMI:
|
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: PORTRAIT DISPLAYS
Issuer: Symantec Class 3 SHA256 Code Signing CA |
| Safe | VirusTotal score: 0/72 (Scanned on 2022-12-25 11:15:43) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 7 |
| TimeDateStamp | 2020-Aug-04 23:55:23 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x31a00 |
| SizeOfInitializedData | 0x1aa00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00011774 (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x33000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x51000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x4c30c |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
WriteConsoleW
ReadConsoleW HeapSize SetEndOfFile GetLastError CreateFileW SetStdHandle SetEnvironmentVariableA FreeEnvironmentStringsW GetEnvironmentStringsW GetOEMCP IsValidCodePage WideCharToMultiByte EnterCriticalSection LeaveCriticalSection DeleteCriticalSection EncodePointer DecodePointer MultiByteToWideChar SetLastError InitializeCriticalSectionAndSpinCount CreateEventW TlsAlloc TlsGetValue TlsSetValue TlsFree GetSystemTimeAsFileTime GetModuleHandleW GetProcAddress CompareStringW LCMapStringW GetLocaleInfoW GetStringTypeW GetCPInfo LocalFree CloseHandle SetEvent ResetEvent WaitForSingleObjectEx UnhandledExceptionFilter SetUnhandledExceptionFilter GetCurrentProcess TerminateProcess IsProcessorFeaturePresent IsDebuggerPresent GetStartupInfoW QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId InitializeSListHead RtlUnwind RaiseException FreeLibrary LoadLibraryExW ExitProcess GetModuleHandleExW HeapAlloc HeapReAlloc HeapFree GetModuleFileNameA GetStdHandle WriteFile GetCommandLineA GetCommandLineW GetACP IsValidLocale GetUserDefaultLCID EnumSystemLocalesW GetFileType FlushFileBuffers GetConsoleCP GetConsoleMode ReadFile SetFilePointerEx GetProcessHeap FindClose FindFirstFileExA FindNextFileA |
|---|---|
| USER32.dll |
wsprintfW
EnumDisplayDevicesA wsprintfA |
| ADVAPI32.dll |
RegCloseKey
RegQueryInfoKeyW RegCreateKeyExA RegEnumKeyExW RegSetValueExW RegSetValueExA RegOpenKeyExA RegEnumValueW RegQueryValueExW RegOpenKeyExW |
| ole32.dll |
CoCreateInstance
CLSIDFromProgID CoSetProxyBlanket CoInitialize CoUninitialize |
| OLEAUT32.dll |
SysFreeString
SysAllocString VariantClear GetErrorInfo |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 4.1.3.0 |
| ProductVersion | 4.1.3.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Portrait Displays |
| FileDescription | LutTest 3D LUT loading tool |
| FileVersion (#2) | 4.1.3.0 |
| InternalName | LutTest.exe |
| LegalCopyright | (c) 1993-2020 Portrait Displays, Inc. All rights reserved. |
| OriginalFilename | LutTest.exe |
| ProductName | LutTest |
| ProductVersion (#2) | 4.1.3.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2020-Aug-04 23:55:23 |
| Version | 0.0 |
| SizeofData | 98 |
| AddressOfRawData | 0x40e20 |
| PointerToRawData | 0x3fc20 |
| Referenced File | C:\multi-runner\builds\92d31d76\0\pdi\msi\src\luttest\Release\LutTest.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2020-Aug-04 23:55:23 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x40e84 |
| PointerToRawData | 0x3fc84 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2020-Aug-04 23:55:23 |
| Version | 0.0 |
| SizeofData | 960 |
| AddressOfRawData | 0x40e98 |
| PointerToRawData | 0x3fc98 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2020-Aug-04 23:55:23 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x44c000 |
|---|---|
| EndAddressOfRawData | 0x44c008 |
| AddressOfIndex | 0x44560c |
| AddressOfCallbacks | 0x4331fc |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_4BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x5c |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x444084 |
| SEHandlerTable | 0x440d20 |
| SEHandlerCount | 64 |
| XOR Key | 0x475450f5 |
|---|---|
| Unmarked objects | 0 |
| 241 (40116) | 14 |
| 243 (40116) | 150 |
| 242 (40116) | 29 |
| ASM objects (VS2015 UPD3 build 24123) | 22 |
| 208 (65501) | 1 |
| C++ objects (VS2015 UPD3 build 24123) | 63 |
| C objects (VS2015 UPD3 build 24123) | 34 |
| Imports (65501) | 13 |
| Total imports | 125 |
| C++ objects (LTCG) (VS2015 UPD3 build 24210) | 4 |
| Resource objects (VS2015 UPD3 build 24210) | 1 |
| 151 | 1 |
| Linker (VS2015 UPD3 build 24210) | 1 |
No comments yet.