gdiplus.dll

Microsoft GDI+

Sven Brinkmann

Publisher:
Microsoft Corporation  (signed by Sven Brinkmann)

Product:
Microsoft® Windows® Operating System

Description:
Microsoft GDI+

Version:
5.1.3097.0 (xpclient.010817-1148)

MD5:
2002ae37859a73fc20142cb4841a6fdf

SHA-1:
bd622c752bbd17a516dbfee8c2b814138ba0e68e

SHA-256:
bc757cb07640b78b50d014ea7a818d0e697db425a1d1de45dd94d9782109c14f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 12:58:41 AM UTC  (today)

File size:
1.6 MB (1,706,176 bytes)

Product version:
5.1.3097.0

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
gdiplus

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\gdiplus.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/5/2013 1:00:00 AM

Valid to:
7/2/2014 12:59:59 AM

Subject:
CN=Sven Brinkmann, OU=SECURE APPLICATION DEVELOPMENT, O=Sven Brinkmann, L=Schoeneck, S=Hessen, C=DE

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
02CDBE156E250F4D68BB6125ECAA56E2

File PE Metadata
Compilation timestamp:
8/18/2001 6:33:41 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
7.0

CTPH (ssdeep):
24576:6SWwWpX3g7mgl074FUSIgi3g4bMG0x15IMQMLklslaswMeEd5DoQbcnO5c/K0:6hwltF7C3/ouMvoslp3onR

Entry address:
0x1FDF

Entry point:
55, 8B, EC, 53, 8B, 5D, 08, 56, 8B, 75, 0C, 85, F6, 57, 8B, 7D, 10, 0F, 84, 9B, 13, 01, 00, 83, FE, 01, 0F, 85, 9E, 13, 01, 00, A1, 20, A6, E7, 70, 85, C0, 0F, 85, BB, 0D, 08, 00, 57, 56, 53, E8, CF, FE, FF, FF, 85, C0, 0F, 84, B8, 0D, 08, 00, 57, 56, 53, E8, 1E, 00, 00, 00, 83, FE, 01, 89, 45, 0C, 0F, 85, 86, 13, 01, 00, 85, C0, 0F, 84, A3, 0D, 08, 00, 8B, 45, 0C, 5F, 5E, 5B, 5D, C2, 0C, 00, 6A, 08, 68, 60, BC, D5, 70, E8, 63, FC, FF, FF, 33, F6, 46, 8B, 45, 0C, 83, E8, 00, 0F, 84, 9A, 1E, 01, 00, 48, 75...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.5 MB (1,544,192 bytes)

Scan gdiplus.dll - Powered by Reason Core Security