libplds4.dll file report

MD5 a669bd65bb57908c35ed4058dea2f9a7
Latest seen 2021-07-07 20:29:45 (4 years ago)
First seen 2017-07-25 16:36:08 (8 years ago)
Size 42 KB
Publisher Mozilla Foundation

Why it matters

Evidence available for this file

Detection

No final classification is available yet.

Timeline

First seen 2017-07-25 16:36:08 (8 years ago); latest analysis 2021-07-07 20:29:45 (4 years ago).

Publisher context

Company metadata: Mozilla Foundation. Product metadata: Netscape Portable Runtime.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Use the hash and metadata below to verify the exact file identity.
  2. Review publisher, signature, paths, and PE details for inconsistencies.
  3. Run a local scan if the file appears unexpectedly or starts with Windows.

libplds4.dll is a Windows file recorded in the ThreatInfo database. It is associated with Netscape Portable Runtime. The reported company name is Mozilla Foundation. The current detection status is Undefined, based on the latest analysis from 2021-07-07 20:29:45 (4 years ago).

ThreatInfo does not have a final classification for this file yet. Use the technical details below to compare the hash, size, signature, and observed locations with the copy found on your device.

Product Name: Netscape Portable Runtime
Company Name: Mozilla Foundation
MD5: a669bd65bb57908c35ed4058dea2f9a7
Size: 42 KB
First Published: 2017-07-25 16:36:08 (8 years ago)
Latest Published: 2021-07-07 20:29:45 (4 years ago)
Status: Undefined (on last analysis)
Analysis Date: 2021-07-07 20:29:45 (4 years ago)
%programfiles%\gimpshop\bin
%programfiles%\gimpshop\lib\gimp\2.0\plug-ins
%programfiles%\gimpshop
%programfiles%\gimpshop\lib\gimp\2.0
%programfiles%\gimpshop
%programfiles%\gimpshop\lib\gimp\2.0
%programfiles%\gimpshop
%programfiles%\gimpshop\lib\gimp\2.0
%programfiles%\gimpshop
%programfiles%\gimpshop

ThreatInfo has observed libplds4.dll in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

32.1%
21.4%
14.3%
7.1%
7.1%
7.1%
7.1%
3.6%

The strongest geographic signal for this file is United States with 32.1% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 75.0%
Windows 7 25.0%

The most common operating system signal for libplds4.dll is Windows 10 with 75.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

libplds4.dll is identified as pe for 32 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x68d40000
Entry Address: 0x00001420

PE Sections:

Name Size of data MD5
.text 30208 b72210a0e52b3f4132b3d2124754efc6
.data 512 175ddb402a1e7b2974b6a4809be1ed12
.rdata 2048 91bd3b2a94bebb2b590b2dafd742b2ed
.bss 0 00000000000000000000000000000000
.edata 1024 4a2ac90c2d0e470df689eae026e1c658
.idata 2048 7d3ab34174cafa23ab7fe883ea684cf5
.CRT 512 50bcb72faba2d27e81da5777ee944c5f
.tls 512 61789e1e7bb2c75a063d5604b487f4d0
.rsrc 1024 bf11428f1d177d2d166e16f86f653e73
.reloc 1536 26f7dec6d743b193943f27012199b846
/4 512 a27ad67875ed4155ae1b71efb8edaffc

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: