gdiplus.dll

Microsoft GDI+

广兴网络科技(上海)有限公司

Publisher:
Microsoft Corporation  (signed by 广兴网络科技(上海)有限公司)

Product:
Microsoft® Windows® Operating System

Description:
Microsoft GDI+

Version:
5.1.3097.0 (xpclient.010811-1534)

MD5:
375c189223324a26cc8d7d8f8aed0cc2

SHA-1:
8663f3441347f0828fa0e9cd08dc04381ad80677

SHA-256:
1a4032dc948b680f672667fd6192f80384a9dfc2fe2f212cf7b7ced4b592abe9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/28/2024 11:43:00 AM UTC  (today)

File size:
1.6 MB (1,705,728 bytes)

Product version:
5.1.3097.0

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
gdiplus

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\ہض°ةتسئµةçاّ\gdiplus.dll

Digital Signature
Authority:
WoSign CA Limited

Valid from:
3/11/2014 10:38:58 AM

Valid to:
3/10/2017 10:38:58 AM

Subject:
CN=广兴网络科技(上海)有限公司, E=software@leba99.cn, O=广兴网络科技(上海)有限公司, L=上海市, S=上海市, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
2C681EF3094A08F19A8B4C495AC68EDF

File PE Metadata
Compilation timestamp:
9/4/2001 10:25:32 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
7.0

CTPH (ssdeep):
24576:e0CiGmsJ2LC4jJmNwP+6fBUAK8C0m1DQucWM9nul/SuyZfWPP90bTv6i:e0K2L1Pjf2AKWmFcLulMZ9HL

Entry address:
0x472CB

Entry point:
55, 8B, EC, 53, 8B, 5D, 08, 56, 8B, 75, 0C, 85, F6, 57, 8B, 7D, 10, 0F, 84, D5, 73, 00, 00, 83, FE, 01, 0F, 85, D8, 73, 00, 00, A1, E0, A7, 20, 7A, 85, C0, 0F, 85, 1F, BA, 03, 00, 57, 56, 53, E8, CF, FE, FF, FF, 85, C0, 0F, 84, 1C, BA, 03, 00, 57, 56, 53, E8, 1E, 00, 00, 00, 83, FE, 01, 89, 45, 0C, 0F, 85, C0, 73, 00, 00, 85, C0, 0F, 84, 07, BA, 03, 00, 8B, 45, 0C, 5F, 5E, 5B, 5D, C2, 0C, 00, 6A, 08, 68, D8, 68, 0E, 7A, E8, 77, A4, FB, FF, 33, F6, 46, 8B, 45, 0C, 83, E8, 00, 0F, 84, D4, 7E, 00, 00, 48, 75...
 
[+]

Entropy:
6.8268

Developed / compiled with:
Microsoft Visual C++

Code size:
1.5 MB (1,544,192 bytes)

Scan gdiplus.dll - Powered by Reason Core Security