seznam.cz_30245_2.exe

Seznam.cz, a.s.

The application seznam.cz_30245_2.exe by Seznam.cz, a.s has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from www.slunecnice.cz.
Publisher:
Seznam.cz, a.s.  (signed and verified)

MD5:
c81c2daac9aa913d76bfac5b5e573026

SHA-1:
94e6e4dd281b4cf5bd8df2a352ccc0cebd74c32a

SHA-256:
59f823608b18bf05efefecb69b52ac097b28e1169ff2146f80a3e2576ce889c4

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/25/2024 2:01:23 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Seznam (M)
17.2.7.18

File size:
2.7 MB (2,816,696 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\seznam.cz_30245_2.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
4/6/2016 2:00:00 AM

Valid to:
4/10/2017 1:59:59 AM

Subject:
CN="Seznam.cz, a.s.", O="Seznam.cz, a.s.", L=Praha 5, S=Praha 5, C=CZ

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
6B57C0310010618229A5DBCF37838A9F

File PE Metadata
Compilation timestamp:
12/6/2016 1:32:24 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0x164C9D

Entry point:
E8, 72, 0C, 00, 00, E9, 8E, FE, FF, FF, 3B, 0D, 64, 6F, 65, 00, F2, 75, 02, F2, C3, F2, E9, B0, 08, 00, 00, 53, 56, 57, 6A, 00, 68, A0, 0F, 00, 00, 68, 3C, 39, 66, 00, E8, 19, F6, 02, 00, 83, C4, 0C, 68, 10, C5, 62, 00, FF, 15, C8, D4, 5E, 00, 8B, F0, 85, F6, 0F, 84, 8C, 00, 00, 00, 68, 64, 7F, 61, 00, 56, FF, 15, 78, D4, 5E, 00, 68, 80, 7F, 61, 00, 56, 8B, D8, FF, 15, 78, D4, 5E, 00, 68, 9C, 7F, 61, 00, 56, 8B, F8, FF, 15, 78, D4, 5E, 00, 8B, F0, 85, DB, 74, 37, 85, FF, 74, 33, 85, F6, 74, 2F, 83, 25, 58...
 
[+]

Code size:
1.9 MB (2,011,648 bytes)

The file seznam.cz_30245_2.exe has been seen being distributed by the following URL.

http://www.slunecnice.cz/sw/seznam-cz-prohlizec/stahnout/39921/.../?md5=m4Y_9Wbk-KSVaSM2Oi7FZQ&expires=1484077684

Remove seznam.cz_30245_2.exe - Powered by Reason Core Security