sznsetup.exe

Seznam.cz, a.s.

The application sznsetup.exe by Seznam.cz, a.s has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
Seznam.cz, a.s.  (signed and verified)

MD5:
8c3d3b40859995b88bb8d1e6839f5d96

SHA-1:
e29b036e00603008331600e5a490f7ac66e78197

SHA-256:
d62c6d007efaa1c5fe4faec07134e84659cea994fce802574a470364b0313bbc

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 4:08:15 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Seznam (M)
16.10.19.12

File size:
2.2 MB (2,330,136 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\seznam.cz\install\sznsetup.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
3/30/2012 2:00:00 AM

Valid to:
4/5/2013 1:59:59 AM

Subject:
CN="Seznam.cz, a.s.", O="Seznam.cz, a.s.", L=Prague, S=Prague, C=CZ

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
21B58554A9C9CF7AFF175ED969E70001

File PE Metadata
Compilation timestamp:
5/4/2012 10:37:26 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
49152:cbMcV25/QuXXHL5ir0xF1F0a3kGtJCF19UxDWjHJ:cbpVC/hHL53xL7KFfB

Entry address:
0x7C506

Entry point:
E8, DD, 59, 00, 00, E9, 95, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 10, 83, 7D, 10, 00, 53, 56, 57, 0F, 84, C6, 00, 00, 00, FF, 75, 14, 8D, 4D, F0, E8, 48, F4, FF, FF, 8B, 5D, 08, 85, DB, 75, 27, E8, BB, 39, 00, 00, C7, 00, 16, 00, 00, 00, E8, 5E, 39, 00, 00, 80, 7D, FC, 00, 74, 07, 8B, 45, F8, 83, 60, 70, FD, B8, FF, FF, FF, 7F, E9, 8F, 00, 00, 00, 8B, 75, 0C, 85, F6, 74, D2, BF, FF, FF, FF, 7F, 39, 7D, 10, 76, 21, E8, 83, 39, 00, 00, C7, 00, 16, 00, 00, 00, E8, 26, 39, 00, 00, 80, 7D, FC, 00, 74, 07, 8B...
 
[+]

Code size:
733 KB (750,592 bytes)

Remove sznsetup.exe - Powered by Reason Core Security