gdiplus.dll

Microsoft GDI+

Sven Brinkmann

Publisher:
Microsoft Corporation  (signed by Sven Brinkmann)

Product:
Microsoft® Windows® Operating System

Description:
Microsoft GDI+

Version:
5.1.3097.0 (xpclient.010817-1148)

MD5:
746698e0d70fe363208475e0ef5ff3ca

SHA-1:
b2d1a7cb2f7674e0ad3db7c4a142c1005b0f31a7

SHA-256:
12f8d7272fea9e37fbb6f095bf59bbc9f6a4419a1aed6990cda015044a49ddd6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/20/2024 1:50:44 PM UTC  (today)

File size:
1.6 MB (1,706,120 bytes)

Product version:
5.1.3097.0

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
gdiplus

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\gdiplus.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/7/2012 2:00:00 AM

Valid to:
7/1/2013 1:59:59 AM

Subject:
CN=Sven Brinkmann, OU=SECURE APPLICATION DEVELOPMENT, O=Sven Brinkmann, L=Schoeneck, S=Hessen, C=DE

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
08308C0A955B6F47E4FFD7B043E118B6

File PE Metadata
Compilation timestamp:
8/18/2001 7:33:41 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
7.0

CTPH (ssdeep):
24576:NSWwWpX3g7mgl074FUSIgi3g4bMG0x15IMQMLklslaswMeEd5DoQbcnO5c/Kj:NhwltF7C3/ouMvoslp3on

Entry address:
0x1FDF

Entry point:
55, 8B, EC, 53, 8B, 5D, 08, 56, 8B, 75, 0C, 85, F6, 57, 8B, 7D, 10, 0F, 84, 9B, 13, 01, 00, 83, FE, 01, 0F, 85, 9E, 13, 01, 00, A1, 20, A6, E7, 70, 85, C0, 0F, 85, BB, 0D, 08, 00, 57, 56, 53, E8, CF, FE, FF, FF, 85, C0, 0F, 84, B8, 0D, 08, 00, 57, 56, 53, E8, 1E, 00, 00, 00, 83, FE, 01, 89, 45, 0C, 0F, 85, 86, 13, 01, 00, 85, C0, 0F, 84, A3, 0D, 08, 00, 8B, 45, 0C, 5F, 5E, 5B, 5D, C2, 0C, 00, 6A, 08, 68, 60, BC, D5, 70, E8, 63, FC, FF, FF, 33, F6, 46, 8B, 45, 0C, 83, E8, 00, 0F, 84, 9A, 1E, 01, 00, 48, 75...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.5 MB (1,544,192 bytes)

Scan gdiplus.dll - Powered by Reason Core Security