xdelta64.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from xdelta.software.informer.com and multiple other hosts.
MD5:
39d8ef19f3c377f290f9c9a6b60fdb36

SHA-1:
a9c0ab96f18eef3a93759b30481bc7e68f98b483

SHA-256:
db158cd1587a89fb2c00884f782973ad19a067c4a2bcf453adc4d2a3632ba594

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 2:30:10 AM UTC  (today)

File size:
325 KB (332,800 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\breaking point\xdelta64.exe

File PE Metadata
Compilation timestamp:
1/13/2014 6:53:25 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
6144:4DNdJGXmurHTcVu+DyFTt3vHvL1wGWy/dmcGvNTxHf1QTl5EbHYOTrMno:xrHTSyFt3/JvMcKY50tEno

Entry address:
0x2D6D4

Entry point:
48, 83, EC, 28, E8, A7, 6C, 00, 00, 48, 83, C4, 28, E9, 76, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 4C, 8B, D9, 48, 2B, D1, 0F, 82, 9E, 01, 00, 00, 49, 83, F8, 08, 72, 61, F6, C1, 07, 74, 36, F6, C1, 01, 74, 0B, 8A, 04, 0A, 49, FF, C8, 88, 01, 48, FF, C1, F6, C1, 02, 74, 0F, 66, 8B, 04, 0A, 49, 83, E8, 02, 66, 89, 01, 48, 83, C1, 02, F6, C1, 04, 74, 0D, 8B, 04, 0A, 49, 83, E8, 04, 89, 01, 48, 83, C1, 04, 4D, 8B, C8, 49, C1, E9, 05...
 
[+]

Code size:
237.5 KB (243,200 bytes)

The file xdelta64.exe has been discovered within the following programs.

Arma 3  by Bohemia Interactive
ARMA 3 is an open world tactical shooter video game set in the near-future during the mid-2030s, where NATO forces deployed in the Greek islands of the Aegean Sea are trying to hold off a massive Iranian military offensive from the east.
www.arma3.com
About 4% of users remove it
assassinscreed.ubi.com
8% remove it
Breaking Point  by The Zombie Infection
thezombieinfection.com
About 5% of users remove it
Renegade X  by Totem Arts
About 7% of users remove it
WS Launcher  by Launcher
forums.arma.su
About 1% of users remove it
 
Powered by Should I Remove It?

The file xdelta64.exe has been seen being distributed by the following 2 URLs.

Scan xdelta64.exe - Powered by Reason Core Security