openvpn-gui.exe

This is a setup program which is used to install the application. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘openvpn-gui’. The file has been seen being downloaded from openvpn.se.
MD5:
d5de3333ea2bb10015f484134565db92

SHA-1:
f8aa6652e95a532af6a243acb6b72fc4cbc29272

SHA-256:
80dc9692cadaf201903b877b13408d21b0492e7d608b37a2c7736689028a8f6f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 12:15:10 PM UTC  (today)

File size:
97 KB (99,328 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\openvpn\bin\openvpn-gui.exe

File PE Metadata
Compilation timestamp:
8/18/2005 11:57:20 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
1536:tNVInuocjineZI0W/9umMEvrl0t5pCcMIU5BezJXbhS08yY1Wf4C:9i+HwBZzyNTBUretuyYa4C

Entry address:
0x1260

Entry point:
55, 89, E5, 83, EC, 08, C7, 04, 24, 02, 00, 00, 00, FF, 15, 5C, E4, 42, 00, E8, 68, FF, FF, FF, 89, EC, 31, C0, 5D, C3, 89, F6, 55, 89, E5, 83, EC, 08, 8B, 45, 08, 89, 04, 24, FF, 15, 80, E4, 42, 00, 89, EC, 5D, C3, 8D, 76, 00, 8D, BC, 27, 00, 00, 00, 00, 55, 89, E5, 83, EC, 08, 8B, 45, 08, 89, 04, 24, FF, 15, 6C, E4, 42, 00, 89, EC, 5D, C3, 90, 90, 90, 90, 90, 90, 90, 90, 90, 90, 55, 89, E5, 5D, E9, B7, DB, 00, 00, 90, 90, 90, 90, 90, 90, 90, 55, 89, E5, 81, EC, 08, 08, 00, 00, 89, 75, FC, 8B, 55, 0C, 8B...
 
[+]

Packer / compiler:
FreeBasic 0.14

Code size:
58.5 KB (59,904 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
openvpn-gui

Command:
C:\Program Files\openvpn\bin\openvpn-gui.exe


The file openvpn-gui.exe has been seen being distributed by the following URL.

Scan openvpn-gui.exe - Powered by Reason Core Security