cadstd_lite_v3_install.exe

Apperson & Daughters

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is installed with CadStd. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Apperson & Daughters  (signed and verified)

MD5:
35033d9192cf8f257cf0470fbe8ec8d5

SHA-1:
c43b330f019c10858e250137fbdf998ed7588263

SHA-256:
33ea9ae2f7ae64c353b2e1aaa9bf74e95df0e0295b05e64459b2030acd53f4f1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/8/2024 3:30:49 PM UTC  (today)

File size:
785.3 KB (804,168 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\cadstd_lite_v3_install.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
2/24/2009 8:35:53 PM

Valid to:
2/24/2012 8:35:53 PM

Subject:
CN=Apperson & Daughters, O=Apperson & Daughters, L=Newbury Park, S=CA, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
0AD899C8

File PE Metadata
Compilation timestamp:
2/21/2009 8:46:29 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:x6iXCMsi+TrZzgetSIihEGU/p5/CbrKUv:xpyBi+hzftSXhZq/mT

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, ED, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file cadstd_lite_v3_install.exe has been discovered within the following program.

CadStd  by Apperson & Daughters
www.cadstd.com
About 8% of users remove it
 
Powered by Should I Remove It?

The file cadstd_lite_v3_install.exe has been seen being distributed by the following 13 URLs.

http://gsf-cf.softonic.com/c43/b33/.../file?SD_used=0&channel=WEB&fdh=no&id_file=8782&instance=softonic_es&type=PROGRAM&Expires=1457832594&Signature=QsK0F~Y0WprLtDlOgHBXThzy86-T-l0uA5-nWqwhXy~1dykIEaHk69UrhAEOrbPfAbxv~rZ7dauGwt~oRvDYcshT7JMjB0KtH1XQqjRZRNapHc0fS3EUtCFyV-aZkM7a49PfAdJE-vbWE~bXPiBo7rFXKIBPljxwGVG9bOrRIVM_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=CadStd_Lite_3.7.3_Install.exe

http://gsf-cf.softonic.com/c43/b33/.../file?SD_used=0&channel=WEB&fdh=no&id_file=8782&instance=softonic_es&type=PROGRAM&Expires=1478984528&Signature=dDgHUKLo7Nr25OlVYrTIlpXyXwPIqTOgSDxjnEllvRaL9ZAOtYoYvoE1N6rqU8h41l4X0FRu43-WvDuCUWW5YZSFkkRFm~kL5PdB66QzQz2DesYL9FR5SMBNgbWX~78Kjdg8ITetasKDwUVXysnfI2EapnMWa1u-h8oh9b-nCsE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=CadStd_Lite_3.7.3_Install.exe

http://gsf-cf.softonic.com/c43/b33/.../file?SD_used=0&channel=WEB&fdh=no&id_file=8782&instance=softonic_es&type=PROGRAM&Expires=1478228156&Signature=GnxleXykZ1iN2qEqENck7RM~J11cToe8~SvnHAtkDLwNsStjC37wCV5BYf382HsxSeaKlX1g5-K0r-LGbBaodrV5efq~yEh1ztklKPz5NUi0w4fGsD5wxfscWu1iK9rCv788kHENWNVyGw4UQ4SrNfI2C9mjupgf0P2Fz4KxSJk_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=CadStd_Lite_3.7.3_Install.exe

http://gsf-cf.softonic.com/c43/b33/.../file?SD_used=0&channel=WEB&fdh=no&id_file=8782&instance=softonic_es&type=PROGRAM&Expires=1455063628&Signature=MvUlwGRgSEdNTEFlT2azoOwwcHYDCM1JvKinWtBxjSsfpO0-y4lCn3SSNnULQhq1ty5FPAL9SeU2Ikqh~oP8mCMD65Xppu3rc4ahNfapztr0QGJ~nUP-GMlvLRSYASRrpN-HnQEnNIsbcqfdVLt7InVqSCxPu7vTSIn8YGtNY-I_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=CadStd_Lite_3.7.3_Install.exe

http://gsf-cf.softonic.com/c43/b33/.../file?SD_used=0&channel=WEB&fdh=no&id_file=8782&instance=softonic_es&type=PROGRAM&Expires=1477541213&Signature=hExyWxR6bnYtXvlzv4Fswv6GmihQZMCdzM~hfEQZCUK-D5uc8FMMJq4rn639mexc8F7BymybHH4V7NxHH2P-TX52HtCtM7Cv0H0riWO5LUUq5avRbdlwfSJGvzdfVPi4zDC1KtxRJfo3Ng5~ZhcWvSGfy09EC6vDAzb5cDdJgMw_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=CadStd_Lite_3.7.3_Install.exe

http://gsf-cf.softonic.com/c43/b33/.../file?SD_used=0&channel=WEB&fdh=no&id_file=8782&instance=softonic_es&type=PROGRAM&Expires=1474365228&Signature=N4YFkkhVp4lwT2FNTdGXdcByfpGX0OlftwdWjXbjQytW3imaaw9Yp86DrZCVdtiWoRnx0R5ZqELoOP0QPzh~h6Q1MHxL0e3O-2SFQ~-h~0WT05F7IpV0HUmMXd4E62MeOFqajvkKoH~L8n6k3fdtuYoV6f3y84h9Y539xprHahE_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=CadStd_Lite_3.7.3_Install.exe

http://www.cadstd.com/.../CadStd_Lite_V3_Install.exe

Scan cadstd_lite_v3_install.exe - Powered by Reason Core Security