47ff536f1f5d305eb8e8292262ea0e2165e3f3b7

Seznam.cz, a.s.

The file 47ff536f1f5d305eb8e8292262ea0e2165e3f3b7 by Seznam.cz, a.s has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is installed within the Mozilla Firefox web browser as part of an addin/plugin.
Publisher:
Seznam.cz, a.s.  (signed and verified)

MD5:
c31cbae0a1b28dff4d346d2fb0116fd3

SHA-1:
a548180f82acb693ec0e9f9ecea100a0b66a96bc

SHA-256:
10a9c8c199e1796a77ab0e74284aab37b6d1da49028235e68e0f64930b95a642

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/25/2024 2:29:35 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Seznam (M)
17.2.28.2

File size:
2.7 MB (2,819,790 bytes)

Common path:
C:\users\{user}\appdata\local\mozilla\firefox\profiles\{user}.default\cache2\entries\47ff536f1f5d305eb8e8292262ea0e2165e3f3b7

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
4/6/2016 2:00:00 AM

Valid to:
4/10/2017 1:59:59 AM

Subject:
CN="Seznam.cz, a.s.", O="Seznam.cz, a.s.", L=Praha 5, S=Praha 5, C=CZ

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
6B57C0310010618229A5DBCF37838A9F

File PE Metadata
Compilation timestamp:
12/6/2016 1:32:24 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0x164C9D

Entry point:
E8, 72, 0C, 00, 00, E9, 8E, FE, FF, FF, 3B, 0D, 64, 6F, 65, 00, F2, 75, 02, F2, C3, F2, E9, B0, 08, 00, 00, 53, 56, 57, 6A, 00, 68, A0, 0F, 00, 00, 68, 3C, 39, 66, 00, E8, 19, F6, 02, 00, 83, C4, 0C, 68, 10, C5, 62, 00, FF, 15, C8, D4, 5E, 00, 8B, F0, 85, F6, 0F, 84, 8C, 00, 00, 00, 68, 64, 7F, 61, 00, 56, FF, 15, 78, D4, 5E, 00, 68, 80, 7F, 61, 00, 56, 8B, D8, FF, 15, 78, D4, 5E, 00, 68, 9C, 7F, 61, 00, 56, 8B, F8, FF, 15, 78, D4, 5E, 00, 8B, F0, 85, DB, 74, 37, 85, FF, 74, 33, 85, F6, 74, 2F, 83, 25, 58...
 
[+]

Code size:
1.9 MB (2,011,648 bytes)

Remove 47ff536f1f5d305eb8e8292262ea0e2165e3f3b7 - Powered by Reason Core Security