d3dcompiler_47.dll

Direct3D HLSL Compiler for Redistribution

Hefei Hejunzhengce Info Tech Co., Ltd.

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The library d3dcompiler_47.dll, “Direct3D HLSL Compiler for Redistribution” has been detected as malware by 1 anti-virus scanner.
Publisher:
Microsoft Corporation  (signed by Hefei Hejunzhengce Info Tech Co., Ltd.)

Product:
Microsoft® Windows® Operating System

Description:
Direct3D HLSL Compiler for Redistribution

Version:
6.3.9600.16384 (winblue_rtm.130821-1623)

MD5:
3fb6ae8cf8d95f6d70ed3f9de23da9a4

SHA-1:
f6a8c358a4843115e02fc2e34d31f88ceda4560f

SHA-256:
4b33abea7aeb21c285f4040606d8cf0229964d40eed127e1c2577c0f21e60a51

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/16/2024 7:46:57 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.9.26.21

File size:
3.3 MB (3,457,520 bytes)

Product version:
6.3.9600.16384

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
d3dcompiler_47.dll

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\local\google\chrome\application\46.10.2479.19\d3dcompiler_47.dll

Digital Signature
Authority:
WoSign CA Limited

Valid from:
3/6/2015 3:35:27 PM

Valid to:
12/30/2016 3:35:27 PM

Subject:
CN="Hefei Hejunzhengce Info Tech Co., Ltd.", O="Hefei Hejunzhengce Info Tech Co., Ltd.", L=Hefei, S=Anhui, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
3312D0B8D4D7941DF85AA59F134E7719

File PE Metadata
Compilation timestamp:
8/22/2013 11:50:06 AM

OS version:
6.3

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

CTPH (ssdeep):
49152:+yZ9lnpmVm/w+EwVOmufvkQS8MH2J9CqS5Sqr88pPWW5KhQYPsXqUiQ6:L9fWAwVBC8MH2JNSF8+YPsXqUT6

Entry address:
0x30E737

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, D1, 08, 00, 00, 5D, E9, 2A, 00, 00, 00, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, B8, 63, 73, 6D, E0, 39, 45, 08, 75, 0D, FF, 75, 0C, 50, E8, 36, 07, 00, 00, 59, 59, 5D, C3, 33, C0, 5D, C3, CC, CC, CC, CC, CC, 6A, 2C, 68, B8, 8F, 31, 10, E8, 49, 09, 00, 00, C7, 45, E4, 01, 00, 00, 00, 33, F6, 89, 75, FC, 8B, 45, 0C, 83, F8, 01, 77, 05, A3, 00, A0, 31, 10, 83, 7D, 0C, 00, 75, 11, 83, 3D, 40, FC, 31, 10, 00, 75, 08, 89, 75, E4, E9, 1E, 02, 00, 00, 8B, 45, 0C, 83...
 
[+]

Entropy:
6.4391

Code size:
3.1 MB (3,245,568 bytes)

Remove d3dcompiler_47.dll - Powered by Reason Core Security