Information about libEGL.dll

libEGL.dll

libEGL.dll is a Windows file recorded in the ThreatInfo database. It is associated with ANGLE libEGL Dynamic Link Library. The current detection status is Undefined, based on the latest analysis from 2025-06-30 23:00:35 (11 months ago).

ThreatInfo does not have a final classification for this file yet. Use the technical details below to compare the hash, size, signature, and observed locations with the copy found on your device.

Product Name: ANGLE libEGL Dynamic Link Library
MD5: 0518c5f236f046ce43e2f7ed813aac53
Size: 480 KB
First Published: 2025-06-30 23:00:35 (11 months ago)
Latest Published: 2025-06-30 23:00:35 (11 months ago)
Status: Undefined (on last analysis)
Analysis Date: 2025-06-30 23:00:35 (11 months ago)
Signed By: 上海幻电信息科技有限公司
Status: Valid

The signature on libEGL.dll is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.

%programfiles%

ThreatInfo has observed libEGL.dll in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is China with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for libEGL.dll is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

libEGL.dll is identified as pe for 64 systems. The subsystem is Windows CUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows CUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000180000000
Entry Address: 0x0001d740

PE Sections:

Name Size of data MD5
.text 336896 5963deb6f65a58423d38e03e9a5914eb
.rdata 95744 ef84a65ba7966079ff2e9d3aeae58c8d
.data 8192 c28a8047d9cc55883eb03ed87ba7e723
.pdata 16384 b43ce484aac27678ecad5ac8f668977f
.00cfg 512 9583245f1a3030eded97388bdba76b93
.gxfg 9216 fe20e36feb318910138e2139f7750976
.retplne 512 8ba86516d84cef220ecd4ff8550b6df0
.tls 512 1f354d76203061bfdd5a53dae48d5435
.voltbl 512 79bf60a93daf03179b6f9ae1dcd371e2
_RDATA 512 2d8101a9a08b0c62b64aa7dfd7ce73eb
.rsrc 1536 da265149ace2159ae6b35c6c76f91ab4
.reloc 3584 c28a67bd27b572c5077e2a8f3275382b

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: