gdiplus.dll

Microsoft GDI+

北京八度互联科技有限公司

Publisher:
Microsoft Corporation  (signed by 北京八度互联科技有限公司)

Product:
Microsoft® Windows® Operating System

Description:
Microsoft GDI+

Version:
5.1.3097.0 (xpclient.010811-1534)

MD5:
c09d400ed6b245f56f68734518792d68

SHA-1:
51e38b785de5a4032c48d147f5b01ab0939b5b4a

SHA-256:
0512bf517b8d6b5d6de7b4cbdeeec426a56387a1f3589fcf82ac11672ebc750c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 5:53:39 PM UTC  (today)

File size:
1.6 MB (1,706,320 bytes)

Product version:
5.1.3097.0

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
gdiplus

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\badu\dance\gdiplus.dll

Digital Signature
Authority:
WoSign, Inc.

Valid from:
3/23/2010 8:00:00 AM

Valid to:
3/23/2012 7:59:59 AM

Subject:
CN=北京八度互联科技有限公司, OU=Class 3 - for Microsoft Authenticode Signing, O=北京八度互联科技有限公司, L=海淀区, S=北京市, C=CN

Issuer:
CN=WoSign Code Signing Authority, O="WoSign, Inc.", C=US

Serial number:
3C6AFEFE237D8137B6ABB1FC5188DB81

File PE Metadata
Compilation timestamp:
9/4/2001 4:25:32 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
7.0

CTPH (ssdeep):
24576:j0CiGmsJ2LC4jJmNwP+6fBUAK8C0m1DQucWM9nul/SuyZfWPP90bTv6J:j0K2L1Pjf2AKWmFcLulMZ9Hg

Entry address:
0x472CB

Entry point:
55, 8B, EC, 53, 8B, 5D, 08, 56, 8B, 75, 0C, 85, F6, 57, 8B, 7D, 10, 0F, 84, D5, 73, 00, 00, 83, FE, 01, 0F, 85, D8, 73, 00, 00, A1, E0, A7, 20, 7A, 85, C0, 0F, 85, 1F, BA, 03, 00, 57, 56, 53, E8, CF, FE, FF, FF, 85, C0, 0F, 84, 1C, BA, 03, 00, 57, 56, 53, E8, 1E, 00, 00, 00, 83, FE, 01, 89, 45, 0C, 0F, 85, C0, 73, 00, 00, 85, C0, 0F, 84, 07, BA, 03, 00, 8B, 45, 0C, 5F, 5E, 5B, 5D, C2, 0C, 00, 6A, 08, 68, D8, 68, 0E, 7A, E8, 77, A4, FB, FF, 33, F6, 46, 8B, 45, 0C, 83, E8, 00, 0F, 84, D4, 7E, 00, 00, 48, 75...
 
[+]

Entropy:
6.8271

Developed / compiled with:
Microsoft Visual C++

Code size:
1.5 MB (1,544,192 bytes)

Scan gdiplus.dll - Powered by Reason Core Security