openssl.exe file report

MD5 bda3e7e4198d5c9f2d5662dc791a3076
Latest seen 2026-01-27 23:00:50 (4 months ago)
First seen 2018-10-30 18:15:17 (7 years ago)
Size 910 KB

Why it matters

Evidence available for this file

Detection

No final classification is available yet.

Timeline

First seen 2018-10-30 18:15:17 (7 years ago); latest analysis 2026-01-27 23:00:50 (4 months ago).

Digital signature

Signed by OpenVPN Technologies, Inc.. The signature is reported as valid, but signed files can still be bundled or abused.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Use the hash and metadata below to verify the exact file identity.
  2. Review publisher, signature, paths, and PE details for inconsistencies.
  3. Run a local scan if the file appears unexpectedly or starts with Windows.

openssl.exe is a Windows file recorded in the ThreatInfo database. The current detection status is Undefined, based on the latest analysis from 2026-01-27 23:00:50 (4 months ago).

ThreatInfo does not have a final classification for this file yet. Use the technical details below to compare the hash, size, signature, and observed locations with the copy found on your device.

MD5: bda3e7e4198d5c9f2d5662dc791a3076
Size: 910 KB
First Published: 2018-10-30 18:15:17 (7 years ago)
Latest Published: 2026-01-27 23:00:50 (4 months ago)
Status: Undefined (on last analysis)
Analysis Date: 2026-01-27 23:00:50 (4 months ago)
Signed By: OpenVPN Technologies, Inc.
Status: Valid

The signature on openssl.exe is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.

%programfiles%\totalav
%programfiles%\scanguard
%programfiles%\scanguard
%programfiles%\totalav
%programfiles%\totalav
%programfiles%\totalav
%programfiles%\totalav
%programfiles%\totalav
%programfiles%\totalav
%programfiles%\scanguard

ThreatInfo has observed openssl.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

15.8%
5.6%
5.4%
4.4%
4.2%
4.1%
3.9%
3.9%
3.4%
2.6%
2.3%
2.3%
2.2%
2.2%
1.9%
1.8%
1.6%
1.4%
1.4%
1.3%
1.2%
1.1%
1.1%
1.1%
1.1%
1.1%
1.0%
1.0%
1.0%
1.0%
0.9%
0.9%
0.8%
0.8%
0.8%
0.7%
0.6%
0.6%
0.6%
0.5%
0.5%
0.5%
0.4%
0.4%
0.4%
0.4%
0.4%
0.4%
0.4%
0.4%
0.3%
0.3%
0.3%
0.3%
0.3%
0.3%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.2%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%
0.1%

The strongest geographic signal for this file is United States with 15.8% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 81.7%
Windows 7 12.9%
Windows 8.1 3.9%
Windows 8 0.3%
Windows Server 2008 R2 0.3%
Windows Server 2016 0.3%
Windows Server 2012 R2 0.3%
Windows Vista 0.2%
Windows XP 0.1%

The most common operating system signal for openssl.exe is Windows 10 with 81.7% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

openssl.exe is identified as pe for 32 systems. The subsystem is Windows CUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows CUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x000014e0

PE Sections:

Name Size of data MD5
.text 324096 37c0f15ea575dbb5aa2aa19590903743
.data 48128 ae25bbbeac781e702e80d16821141824
.rdata 115712 387a40573f7a265ddb4ffea6a0c33b59
.bss 0 00000000000000000000000000000000
.edata 512 5b1c5ff5daef6d06572478d6f0f63bb8
.idata 44032 3ceb368d3b3079ca6d45fa5568a6dc45
.CRT 512 087d7de2adc8cfa90760c2552eae3560
.tls 512 f21cd1fabbfef3739ee90be4574ba33f
.reloc 27648 3cd768f01a8a655a148a380773b5f519
/4 1024 5e17cfab3a8b4e813eeb2e569848d5cd
/19 41472 d10f6bf38e24e3e3943992bff8188d6c
/31 7168 8742b51b06559eecb4bb248347ad09bc
/45 7168 63803da882096d88ba28ddcec64985f1
/57 2560 f451ebb828f4d8af4b6701dc521b72d1
/70 1536 8fc2ddab3cfca1646fc538c4bd5322e7
/81 4608 bb3d3ddc68b90f73fa2ad6c083e644fb
/92 1024 3af065e0b4b0f1f0cf1fadb0bd0c57ee

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: