GridinSoft Threat Intelligence

openssl.exe file report

Under review File reputation report
MD5 bda3e7e4198d5c9f2d5662dc791a3076
Latest seen 2026-01-27 23:00:50 (4 months ago)
First seen 2018-10-30 18:15:17 (7 years ago)
Size 910 KB

Why it matters

Evidence available for this file

Detection

No final classification is available yet.

Timeline

First seen 2018-10-30 18:15:17 (7 years ago); latest analysis 2026-01-27 23:00:50 (4 months ago).

Digital signature

Signed by OpenVPN Technologies, Inc.. The signature is reported as valid, but signed files can still be bundled or abused.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Use the hash and metadata below to verify the exact file identity.
  2. Review publisher, signature, paths, and PE details for inconsistencies.
  3. Run a local scan if the file appears unexpectedly or starts with Windows.

openssl.exe is a Windows file recorded in the ThreatInfo database. The current detection status is Undefined, based on the latest analysis from 2026-01-27 23:00:50 (4 months ago).

ThreatInfo does not have a final classification for this file yet. Use the technical details below to compare the hash, size, signature, and observed locations with the copy found on your device.

MD5: bda3e7e4198d5c9f2d5662dc791a3076
Size: 910 KB
First Published: 2018-10-30 18:15:17 (7 years ago)
Latest Published: 2026-01-27 23:00:50 (4 months ago)
Status: Undefined (on last analysis)
Analysis Date: 2026-01-27 23:00:50 (4 months ago)
Signed By: OpenVPN Technologies, Inc.
Status: Valid

The signature on openssl.exe is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.

%programfiles%\totalav
%programfiles%\scanguard
%programfiles%\pcprotect
%programfiles%\totalav\updates\totalav-4.14.31
%programfiles%\totalav\updates\totalav-5.5.83
%sysdrive%\archivos de programa\totalav
%commonappdata%\totalav\updates\5_5_83\extracted
%commonappdata%\totalav\updates\5_5_83\prev

ThreatInfo has observed openssl.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

Windows 10 81.7%
Windows 7 12.9%
Windows 8.1 3.9%
Windows 8 0.3%
Windows Server 2008 R2 0.3%
Windows Server 2016 0.3%
Windows Server 2012 R2 0.3%
Windows Vista 0.2%
Windows XP 0.1%

The most common operating system signal for openssl.exe is Windows 10 with 81.7% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

openssl.exe is identified as pe for 32-bit systems. The subsystem is Windows CUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Format pe
Architecture 32-bit
Subsystem Windows CUI
Entry point 0x000014e0
Image base 0x00400000

PE Sections:

Sections 17
Raw data 627712

Section layout highlights raw-size concentration, repeated names, packer markers, and hashes that can be compared across related samples.

.text 324096 bytes · 51.6% of section data
MD5 37c0f15ea575dbb5aa2aa19590903743
.data 48128 bytes · 7.7% of section data
MD5 ae25bbbeac781e702e80d16821141824
.rdata 115712 bytes · 18.4% of section data
MD5 387a40573f7a265ddb4ffea6a0c33b59
.bss 0 bytes · 0.0% of section data
MD5 00000000000000000000000000000000
.edata 512 bytes · 0.1% of section data
MD5 5b1c5ff5daef6d06572478d6f0f63bb8
.idata 44032 bytes · 7.0% of section data
MD5 3ceb368d3b3079ca6d45fa5568a6dc45
.CRT 512 bytes · 0.1% of section data
MD5 087d7de2adc8cfa90760c2552eae3560
.tls 512 bytes · 0.1% of section data
MD5 f21cd1fabbfef3739ee90be4574ba33f
.reloc 27648 bytes · 4.4% of section data
MD5 3cd768f01a8a655a148a380773b5f519
/4 1024 bytes · 0.2% of section data
Uncommon name
MD5 5e17cfab3a8b4e813eeb2e569848d5cd
/19 41472 bytes · 6.6% of section data
Uncommon name
MD5 d10f6bf38e24e3e3943992bff8188d6c
/31 7168 bytes · 1.1% of section data
Uncommon name
MD5 8742b51b06559eecb4bb248347ad09bc
/45 7168 bytes · 1.1% of section data
Uncommon name
MD5 63803da882096d88ba28ddcec64985f1
/57 2560 bytes · 0.4% of section data
Uncommon name
MD5 f451ebb828f4d8af4b6701dc521b72d1
/70 1536 bytes · 0.2% of section data
Uncommon name
MD5 8fc2ddab3cfca1646fc538c4bd5322e7
/81 4608 bytes · 0.7% of section data
Uncommon name
MD5 bb3d3ddc68b90f73fa2ad6c083e644fb
/92 1024 bytes · 0.2% of section data
Uncommon name
MD5 3af065e0b4b0f1f0cf1fadb0bd0c57ee

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

Report conclusion

This file is still under review

ThreatInfo has not assigned a final verdict yet. Compare the file hash, location, signature, and publisher before trusting the file on a production system.

Scan with GridinSoft Anti-Malware Use a local scan if the file origin or behavior is unclear. Check this hash on VirusTotal

Recommended next steps

  • Compare the local file MD5 with bda3e7e4198d5c9f2d5662dc791a3076.
  • Check the file path, publisher, and signature against the details in this report.
  • Run a GridinSoft scan if the source, path, or behavior looks unusual.