musserver.exe

Mustang Browser

RAFO TECHNOLOGY INC

The application musserver.exe by RAFO TECHNOLOGY INC has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a scheduled task under the Windows Task Scheduler named MustangBrowserUpdateCore triggered daily at a specified time.
Publisher:
Rafotech  (signed by RAFO TECHNOLOGY INC)

Product:
Mustang Browser

Version:
1.44.46.6

MD5:
eb7c73582d899434529942beb40d4b3b

SHA-1:
505b68cee17bdff0e1bf7250b092c9844f008fac

SHA-256:
2cde41bc895de9238b4a4a05b5798079bf16cdd27ca87d184d0b9dffdf2db011

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 2:50:45 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.RafoTech (M)
17.2.28.2

File size:
430.5 KB (440,863 bytes)

Product version:
1.44.46.6

Copyright:
Copyright 2015 Rafotech. All rights reserved

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\mustang browser\mustang\bin\musserver.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
3/17/2015 10:50:02 PM

Valid to:
3/17/2016 10:50:02 PM

Subject:
CN=RAFO TECHNOLOGY INC, O=RAFO TECHNOLOGY INC, L=Alhambra, S=California, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112130B87F4F087E63E0D3D6DC5F093C0729

File PE Metadata
Compilation timestamp:
8/22/2015 3:31:02 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x22A02

Entry point:
E9, CB, 8A, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, 30, 13, 45, 00, 75, 02, F3, C3, E9, 98, 15, 00, 00, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, 4C, 35, 45, 00, FF, 15, DC, 21, 44, 00, 85, C0, 75, 18, 56, E8, D9, 4A, 00, 00, 8B, F0, FF, 15, 1C, 22, 44, 00, 50, E8, DE, 4A, 00, 00, 59, 89, 06, 5E, 5D, C3, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 77, 6F, 53, 57, A1, 4C, 35, 45, 00, 85, C0, 75, 1D, E8, AF, 40, 00, 00, 6A, 1E, E8, 05, 41, 00, 00, 68, FF, 00, 00, 00, E8, E9, 37, 00, 00, A1, 4C...
 
[+]

Entropy:
6.8813

Packer / compiler:
Xtreme-Protector v1.05

Code size:
258 KB (264,192 bytes)

Scheduled Task
Task name:
MustangBrowserUpdateCore

Trigger:
Daily (Runs daily at 6:43 PM)

Description:
Be sure to use the latest version of Mustang Browser. If this task is disabled or stopped, your Mustang Browser will not be updated, which means you c


Remove musserver.exe - Powered by Reason Core Security