Is libssl safe?
No antivirus engine detected this signed, widely submitted CD PROJEKT DLL, and the completed sandbox produced no malicious verdict or offensive behavior.
All 74 antivirus engines were free of detections, including 15 tier-1 engines that reported no threat. The verified CD PROJEKT signature, established prevalence, uneventful sandbox result, and matching publisher history strongly support this being a legitimate library.
aa884b4a6cc60debef…d3949a7a938d87Recommended next actions
Before opening
Open it only when its sender or download source is one you independently trust.
If you already opened it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 74 antivirus engines were free of detections, including 15 tier-1 engines that reported no threat. The verified CD PROJEKT signature, established prevalence, uneventful sandbox result, and matching publisher history strongly support this being a legitimate library.
The DLL received no malicious or suspicious detections from 74 antivirus engines, with 15 tier-1 products reporting no detection. Its digital signature verifies to CD PROJEKT S.A., and no publisher-brand conflict was identified. The sample has been submitted 407 times by 363 sources, indicating established distribution rather than an isolated new artifact. One completed sandbox recorded no offensive techniques, malicious verdict, persistence, or dropped payloads. A prior same-signer library also received a clean assessment, while packing analysis and external research feeds supplied no contrary malware evidence.
What We Detected
No malicious or suspicious detections appeared across 74 antivirus engines. The DLL has a verified digital signature from CD PROJEKT S.A., and no mismatch was found between its claimed identity and signer. It is also well established, with 407 submissions from 363 distinct sources.
Threat Behavior
One completed sandbox run produced no malicious verdict and identified no offensive techniques, persistence indicators, or dropped payloads. The observed techniques were common environmental and DLL-loading activity. No network contacts were recorded during that run; a separate host-reputation cross-check was not available, so no broader network-reputation conclusion is drawn. Static PE analysis found neither high-entropy code nor likely packing.
What To Do Now
The evidence is consistent with a legitimate CD PROJEKT library. Keep endpoint protection enabled and obtain the DLL through the official game installation or update channel; investigate only if its signature becomes invalid or it appears outside the expected application directory.
Where this verdict could be wrong3 caveats
- signing.signerStats.totalSamples=1, so the publisher-history sample is too small to establish automatic trust.
- contactedHosts=null, meaning no completed host-reputation cross-check is available; however, behaviour.contactactedDomains, contactedIps, and contactedUrls are all empty.
- The file carries detect-debug-environment and overlay tags, but behaviour.offensiveCount=0 and no engine or research-intelligence source corroborates malicious use.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/74 antivirus engines detected a threat.
- Verified signature from CD PROJEKT S.A.
- 363 sources and 407 submissions indicate established prevalence.
- No malicious sandbox verdict or offensive techniques.
- No packing, high-entropy code, or external-intelligence match.
- Signer history contains only 1 previously assessed sample.
- The file has detect-debug-environment and overlay tags.
- No separate contacted-host reputation cross-check was available.
Use the DLL from the official CD PROJEKT installation or update channel and keep endpoint protection enabled. Recheck it if the signature fails verification or the file appears in an unexpected location.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 9MITRE ATT&CK techniques
- 8spawned processes
- 0network contacts
- 2filesystem & mutex artifacts
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
libssl
aa884b4a6cc60debefaad24ae6bf211628a2d9cbddfbae3f65d3949a7a938d87
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Windows\sysnative\rundll32.exe" "C:\Users\<USER>\Desktop\libssl-1_1-x64.dll",#1
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\System32\loaddll64.exe loaddll64.exe "C:\Users\user\Desktop\libssl-1_1-x64.dll"
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
Connect
\Device\ConDrv\\Connect
04Isolated runtime analysis
4 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- \Device\ConDrv\\Connect
- \Sessions\1\BaseNamedObjects\Local\SessionImmersiveColorMutex
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 0 / 74engines flagged
- 363sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 74 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has a long, established submission history across 363 sources.
Verdict inputView chapterProvenanceDerivedSourceSubmission historyObserved at - 03
The file has a valid code signature from CD PROJEKT S.A..
ProvenanceObservedSourceCode-signing metadataObserved at - 04
Scanned file: libssl — aa884b4a6cc60debefaad24ae6bf211628a2d9cbddfbae3f65d3949a7a938d87
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Windows\sysnative\rundll32.exe" "C:\Users\<USER>\Desktop\libssl-1_1-x64.dll",#1
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\System32\loaddll64.exe loaddll64.exe "C:\Users\user\Desktop\libssl-1_1-x64.dll"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Connect — \Device\ConDrv\\Connect
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
0 of 74 engines flagged this file
View all 74 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- libssl
- Format
- Win32 DLL
- Code signing
- Signature valid: CD PROJEKT S.A.
- Size
- 647.6 KB
- Last analyzed
- Sep 23, 2026, 4:34 AM UTC
aa884b4a6cc60debefaad24ae6bf211628a2d9cbddfbae3f65d3949a7a938d87Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Open it only when its sender or download source is one you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is libssl safe?
What is libssl?
How many antivirus engines detected libssl?
Is libssl digitally signed?
What is the SHA-256 hash of libssl?
Is it safe to open libssl?
How up to date is this analysis of libssl?
Community
Member reviews and reports for this exact file hash.