Is CAD Exchanger safe?
No engine detected a threat, and the completed runtime observation, host check, file structure, and independent intelligence produced no corroborating malware indicators.
All 77 antivirus engines returned without a malicious or suspicious detection, including 18 high-trust engines. One completed sandbox run found no malicious verdict or malware-specific technique, while the only contacted domain had no cached threat association; the principal limitation is that the DLL is unsigned.
66e38c13a685ab5f86…e681303804e3dfRecommended next actions
Before opening
Open it only when its sender or download source is one you independently trust.
If you already opened it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 77 antivirus engines returned without a malicious or suspicious detection, including 18 high-trust engines. One completed sandbox run found no malicious verdict or malware-specific technique, while the only contacted domain had no cached threat association; the principal limitation is that the DLL is unsigned.
The antivirus result is consistently benign: 0 of 77 engines flagged the DLL, and all 18 high-trust engines reported it without a detection. One completed sandbox observation produced no malicious verdict and recorded no offensive techniques, dropped payload, or persistence indicator. The sandbox contacted login.live.com, and the host-reputation check covered that sole contact without finding a malicious or suspicious association. Static inspection found neither packing nor high-entropy code, and independent intelligence produced no known-malware or YARA match. The missing digital signature reduces publisher assurance, but it is not supported by any detection, runtime, network, or structural threat evidence.
What We Detected
No antivirus engine flagged this DLL: 0 of 77 reported it as malicious or suspicious, including 18 high-trust engines. Independent checks also returned no MalwareBazaar, CIRCL, or YARAify match.
Threat Behavior
One completed sandbox run produced no malicious verdict and no offensive technique. It recorded several common environmental and system-discovery techniques, plus a connection to login.live.com; the host-reputation check inspected that sole contact and found no malicious or suspicious association. No dropped payload or persistence indicator was reported, and static inspection found no packing or high-entropy code.
What To Do Now
The main uncertainty is the absent digital signature, which prevents verification of the publisher. Obtain the DLL from the software vendor or another trusted distribution channel, keep endpoint protection enabled, and investigate again if its hash changes or unexpected behavior appears.
Where this verdict could be wrong2 caveats
- signing.signed=false for a Win32 DLL, so no verified publisher identity is available.
- The sandbox recorded T1497 environment-evasion awareness and a login.live.com contact, although neither was accompanied by offensive behavior or adverse host reputation.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/77 antivirus engines detected a threat
- 18 high-trust engines reported no detection
- Completed sandbox run had no malicious verdict and no offensive techniques
- The only contacted host had no cached malicious or suspicious association
- No packing, high-entropy code, malicious child, or external-intelligence match
- Unsigned Win32 DLL with no verifiable publisher identity
- Sandbox recorded environment-awareness technique T1497
- Sandbox observed a connection to login.live.com
Use the DLL only if it came from the expected vendor or another trusted source, since it lacks a digital signature. Keep endpoint protection enabled and rescan any updated copy.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 77 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Complete1 contacted host was cross-checked.
YARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 8MITRE ATT&CK techniques
- 0spawned processes
- 1network contacts
- 1filesystem & mutex artifacts
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- login.live.com
- \Device\ConDrv\\Connect
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 0 / 77engines flagged
- 14sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 77 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 15 times from 14 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 03
Scanned file: CAD Exchanger — 66e38c13a685ab5f862ed25bf1f1a878e40b8e3496a4da678fe681303804e3df
ProvenanceObservedSourceUploaded fileObserved at - 04
File written: Connect — \Device\ConDrv\\Connect
ProvenanceObservedSourceIsolated runtime analysisObserved at - 05
Contacted host: login.live.com — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
0 of 77 engines flagged this file
View all 77 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- CAD Exchanger
- Format
- Win32 DLL
- Code signing
- No verified publisher
- Size
- 239.5 KB
- Last analyzed
- Sep 30, 2026, 6:31 PM UTC
66e38c13a685ab5f862ed25bf1f1a878e40b8e3496a4da678fe681303804e3dfSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Open it only when its sender or download source is one you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is CAD Exchanger safe?
What is CAD Exchanger?
How many antivirus engines detected CAD Exchanger?
What is the SHA-256 hash of CAD Exchanger?
Is it safe to open CAD Exchanger?
How up to date is this analysis of CAD Exchanger?
Community
Member reviews and reports for this exact file hash.