gdiplus.dll

Microsoft GDI+

Microsoft Corporation

Publisher:
Microsoft Corporation

Product:
Microsoft® Windows® Operating System

Description:
Microsoft GDI+

Version:
5.1.3097.0 (xpclient.010817-1148)

MD5:
4d328694bb516e46d2d184950d94433f

SHA-1:
9b31771a8c201b74c846da1f1a254866dc2f912d

SHA-256:
8199452af9e5289c126d0ff9d99f2302c52861ec49008702b7f95d64d316383c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 12:39:02 PM UTC  (today)

File size:
1.6 MB (1,700,352 bytes)

Product version:
5.1.3097.0

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
gdiplus

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\customapp\gdiplus.dll

File PE Metadata
Compilation timestamp:
8/18/2001 12:33:41 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
7.0

CTPH (ssdeep):
24576:GSWwWpX3g7mgl074FUSIgi3g4bMG0x15IMQMLklslaswMeEd5DoQbcnO5c/K:GhwltF7C3/ouMvoslp3on

Entry address:
0x1FDF

Entry point:
55, 8B, EC, 53, 8B, 5D, 08, 56, 8B, 75, 0C, 85, F6, 57, 8B, 7D, 10, 0F, 84, 9B, 13, 01, 00, 83, FE, 01, 0F, 85, 9E, 13, 01, 00, A1, 20, A6, E7, 70, 85, C0, 0F, 85, BB, 0D, 08, 00, 57, 56, 53, E8, CF, FE, FF, FF, 85, C0, 0F, 84, B8, 0D, 08, 00, 57, 56, 53, E8, 1E, 00, 00, 00, 83, FE, 01, 89, 45, 0C, 0F, 85, 86, 13, 01, 00, 85, C0, 0F, 84, A3, 0D, 08, 00, 8B, 45, 0C, 5F, 5E, 5B, 5D, C2, 0C, 00, 6A, 08, 68, 60, BC, D5, 70, E8, 63, FC, FF, FF, 33, F6, 46, 8B, 45, 0C, 83, E8, 00, 0F, 84, 9A, 1E, 01, 00, 48, 75...
 
[+]

Entropy:
6.8233

Developed / compiled with:
Microsoft Visual C++

Code size:
1.5 MB (1,544,192 bytes)

The file gdiplus.dll has been seen being distributed by the following 5 URLs.

about:internet

http://www.dahaobj.com/download/emcad/update/.../gdiplus.dll

Scan gdiplus.dll - Powered by Reason Core Security