seznam.cz.exe

Seznam.cz, a.s.

The application seznam.cz.exe by Seznam.cz, a.s has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from www.slunecnice.cz and multiple other hosts.
Publisher:
Seznam.cz, a.s.  (signed and verified)

MD5:
53bca213f8aeae05ae4690484917a48f

SHA-1:
e6d47c46e046861c36a1847f7c7f848264775d6c

SHA-256:
ece2d733cb6599408eeaa0f36e2279162ae223f2fe84bd7e9d8cd9d521c054f7

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 2:07:05 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Seznam (M)
16.12.12.17

File size:
2.7 MB (2,816,696 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\seznam.cz.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
4/6/2016 2:00:00 AM

Valid to:
4/10/2017 1:59:59 AM

Subject:
CN="Seznam.cz, a.s.", O="Seznam.cz, a.s.", L=Praha 5, S=Praha 5, C=CZ

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
6B57C0310010618229A5DBCF37838A9F

File PE Metadata
Compilation timestamp:
12/6/2016 1:32:24 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0x164C9D

Entry point:
E8, 72, 0C, 00, 00, E9, 8E, FE, FF, FF, 3B, 0D, 64, 6F, 65, 00, F2, 75, 02, F2, C3, F2, E9, B0, 08, 00, 00, 53, 56, 57, 6A, 00, 68, A0, 0F, 00, 00, 68, 3C, 39, 66, 00, E8, 19, F6, 02, 00, 83, C4, 0C, 68, 10, C5, 62, 00, FF, 15, C8, D4, 5E, 00, 8B, F0, 85, F6, 0F, 84, 8C, 00, 00, 00, 68, 64, 7F, 61, 00, 56, FF, 15, 78, D4, 5E, 00, 68, 80, 7F, 61, 00, 56, 8B, D8, FF, 15, 78, D4, 5E, 00, 68, 9C, 7F, 61, 00, 56, 8B, F8, FF, 15, 78, D4, 5E, 00, 8B, F0, 85, DB, 74, 37, 85, FF, 74, 33, 85, F6, 74, 2F, 83, 25, 58...
 
[+]

Code size:
1.9 MB (2,011,648 bytes)

The file seznam.cz.exe has been seen being distributed by the following 9 URLs.

https://www.slunecnice.cz/sw/seznam-cz-prohlizec/stahnout/39921/.../?md5=H7_58WoIar1gscCiYVJfwA&expires=1485456380

https://www.seznam.cz/prohlizec/.../Seznam.cz__120001.exe

http://www.bestmetagrab.com/2QnqIFZa87pcpg0LkIxJ3lPmPszz_wftreCwda_xmdxFGJO 2J0oKyDyWNzuXfZB2qnvTgaP2PZ80XEzpeYsjhKu3icfYOJ5_RGFFLSHYwAexC3NDw3vQ7teR2u2FkoqofuRUPU978n839Iw1Ss2arF4IYJZF2_ u2_dYQDuauhSwdTNFIirwNGcErbddtY7QlDfxxLeh6ZfEySNBH2duXeEBW59eIKUNrgA SvQx7OWzoQZyg_CrUtH56Pbj2UqnBfjvxL LVislI23r0zRg4BCo ZzodKBc99uLHyFz9baHsq VTXPkCUgY9Vr0Ua6YDROX7LM1 w9sKsH2Q3N1uf_pLs8n_Y1_vVQtyfR9bgfWl300A4xLfsdAJUOUyhQ9VoWuDaCKI7GyYaD5_uWXGDHQLZ8QIXIp YzLLlD1axHCOpDNH5d5tuF4NDg6C9bha5Q1ysiHYhw qtBzNe146owrR 0LFCQY1_TqhieDItCY64tVGz QXgWBqdbK Hfn1OgaxlUFEnbRwYq3UokiRRFaRo82A==-G4EAAORte69pxJdoLQmJcqigqZNTvXNfWWtL7wnHKQayQzr aGL6onwa0yyzqOhc0wFOqL3 yGePnV9aXOOZ1 _zV0qv4IMSuwXXClSK6CRfJXbzAb2QBw==-e

https://dl.slunecnice.cz/slunecnice/win/.../Seznam.cz_30245_2.exe

https://www.slunecnice.cz/sw/seznam-cz-prohlizec/stahnout/39921/.../?md5=y28uv-J_8ni0gtgdZxfhMg&expires=1485715131

https://download.seznam.cz/.../Seznam.cz.exe#utm_source=search.seznam.cz&utm_medium=paticka-fulltext-bezpecny-prohlizec-stahnout&utm_term=muže se vyprudokovat vejce k otehotneni bez delohy

https://www.seznam.cz/prohlizec/.../Seznam.cz__120002.exe

https://download.seznam.cz/.../Seznam.cz.exe

https://www.seznam.cz/prohlizec/.../Seznam.cz.exe

Remove seznam.cz.exe - Powered by Reason Core Security