95cf4340857883f2b205bf7fdc2a22cfb7c2ead6

Seznam.cz, a.s.

The file 95cf4340857883f2b205bf7fdc2a22cfb7c2ead6 by Seznam.cz, a.s has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is installed within the Mozilla Firefox web browser as part of an addin/plugin.
Publisher:
Seznam.cz, a.s.  (signed and verified)

MD5:
94082434da9f9408d5f9c0398bc3c13c

SHA-1:
666c9e0638a2d7233b239371be2cf3384abc36e4

SHA-256:
e94502454ccf011b1fd0a9b079807075615b08f8d6235b68d52c9144467b8801

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/25/2024 2:10:32 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Seznam (M)
17.2.28.2

File size:
2.7 MB (2,819,790 bytes)

Common path:
C:\users\{user}\appdata\local\mozilla\firefox\profiles\{user}.default\cache2\entries\95cf4340857883f2b205bf7fdc2a22cfb7c2ead6

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
4/6/2016 2:00:00 AM

Valid to:
4/10/2017 1:59:59 AM

Subject:
CN="Seznam.cz, a.s.", O="Seznam.cz, a.s.", L=Praha 5, S=Praha 5, C=CZ

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
6B57C0310010618229A5DBCF37838A9F

File PE Metadata
Compilation timestamp:
12/6/2016 1:32:24 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0x164C9D

Entry point:
E8, 72, 0C, 00, 00, E9, 8E, FE, FF, FF, 3B, 0D, 64, 6F, 65, 00, F2, 75, 02, F2, C3, F2, E9, B0, 08, 00, 00, 53, 56, 57, 6A, 00, 68, A0, 0F, 00, 00, 68, 3C, 39, 66, 00, E8, 19, F6, 02, 00, 83, C4, 0C, 68, 10, C5, 62, 00, FF, 15, C8, D4, 5E, 00, 8B, F0, 85, F6, 0F, 84, 8C, 00, 00, 00, 68, 64, 7F, 61, 00, 56, FF, 15, 78, D4, 5E, 00, 68, 80, 7F, 61, 00, 56, 8B, D8, FF, 15, 78, D4, 5E, 00, 68, 9C, 7F, 61, 00, 56, 8B, F8, FF, 15, 78, D4, 5E, 00, 8B, F0, 85, DB, 74, 37, 85, FF, 74, 33, 85, F6, 74, 2F, 83, 25, 58...
 
[+]

Code size:
1.9 MB (2,011,648 bytes)

Remove 95cf4340857883f2b205bf7fdc2a22cfb7c2ead6 - Powered by Reason Core Security