xldeletesetup.exe

XL Delete 2

XL Development

This is a self-extracting archive and installer. The file has been seen being downloaded from xl-delete.en.softonic.com and multiple other hosts.
Publisher:
-XL- Development   (signed by XL Development)

Product:
XL Delete 2

Description:
XL Delete 2 Installation

Version:
2.9.0.0

MD5:
5a2e58b348e05d6989e602a692526420

SHA-1:
15e7d38c598ab7a639359615e39a36e7f0bf5314

SHA-256:
06698fe6a5a2f97728c4318a3a46e4c22c9e8ed5626baea60ab372b7799c4b73

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 7:20:25 PM UTC  (today)

File size:
8.2 MB (8,642,416 bytes)

Product version:
2.9.0.0, 0

Copyright:
Copyright 2005-2015 -XL- Development

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\xldeletesetup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/19/2014 7:00:00 PM

Valid to:
1/20/2016 6:59:59 PM

Subject:
CN=XL Development, O=XL Development, L=Poway, S=CA, PostalCode=92064, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00CA2F532BACD17AFAE28E962AA245CA47

File PE Metadata
Compilation timestamp:
11/28/2014 5:13:54 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
196608:Smy2Se0e4yKn3gk8I9kRRO7Gx/fGyktfMUvPimuw:S9be0e8359kRROi5WtfzvP91

Entry address:
0x1E290

Entry point:
E8, 6F, 31, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 78, 30, 43, 00, 89, 0D, 74, 30, 43, 00, 89, 15, 70, 30, 43, 00, 89, 1D, 6C, 30, 43, 00, 89, 35, 68, 30, 43, 00, 89, 3D, 64, 30, 43, 00, 66, 8C, 15, 90, 30, 43, 00, 66, 8C, 0D, 84, 30, 43, 00, 66, 8C, 1D, 60, 30, 43, 00, 66, 8C, 05, 5C, 30, 43, 00, 66, 8C, 25, 58, 30, 43, 00, 66, 8C, 2D, 54, 30, 43, 00, 9C, 8F, 05, 88, 30, 43, 00, 8B, 45, 00, A3, 7C, 30, 43, 00, 8B, 45, 04, A3, 80, 30, 43, 00, 8D, 45, 08, A3, 8C, 30, 43...
 
[+]

Code size:
154.5 KB (158,208 bytes)

The file xldeletesetup.exe has been seen being distributed by the following 2 URLs.

Scan xldeletesetup.exe - Powered by Reason Core Security