musserver.exe

Mustang Browser

RAFO TECHNOLOGY INC

The application musserver.exe by RAFO TECHNOLOGY INC has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a scheduled task under the Windows Task Scheduler named MustangBrowserUpdateCore triggered daily at a specified time.
Publisher:
Rafotech  (signed by RAFO TECHNOLOGY INC)

Product:
Mustang Browser

Version:
1.44.46.6

MD5:
1833d25fc2171c11d6c05111820fd38c

SHA-1:
becab2b537b4fcb840dec492031fc9d7d07dd14d

SHA-256:
af883ddca2ef0e228e8ee0e971e60b49b92028fd056d77ca55b27c984d4aed28

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/4/2024 5:09:39 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.RafoTech (M)
17.2.10.15

File size:
430.5 KB (440,863 bytes)

Product version:
1.44.46.6

Copyright:
Copyright 2015 Rafotech. All rights reserved

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\mustang browser\mustang\bin\musserver.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
3/17/2015 10:50:02 PM

Valid to:
3/17/2016 10:50:02 PM

Subject:
CN=RAFO TECHNOLOGY INC, O=RAFO TECHNOLOGY INC, L=Alhambra, S=California, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112130B87F4F087E63E0D3D6DC5F093C0729

File PE Metadata
Compilation timestamp:
8/22/2015 3:31:02 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x22A02

Entry point:
E9, 5C, A4, FF, FF, E9, 7F, FE, FF, FF, 3B, 0D, 30, 13, 45, 00, 75, 02, F3, C3, E9, 98, 15, 00, 00, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, 4C, 35, 45, 00, FF, 15, DC, 21, 44, 00, 85, C0, 75, 18, 56, E8, D9, 4A, 00, 00, 8B, F0, FF, 15, 1C, 22, 44, 00, 50, E8, DE, 4A, 00, 00, 59, 89, 06, 5E, 5D, C3, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 77, 6F, 53, 57, A1, 4C, 35, 45, 00, 85, C0, 75, 1D, E8, AF, 40, 00, 00, 6A, 1E, E8, 05, 41, 00, 00, 68, FF, 00, 00, 00, E8, E9, 37, 00, 00, A1, 4C...
 
[+]

Entropy:
6.8859

Packer / compiler:
tElock 0.99 - 1.0 private

Code size:
258 KB (264,192 bytes)

Scheduled Task
Task name:
MustangBrowserUpdateCore

Trigger:
Daily (Runs daily at 1:16 PM)

Description:
Be sure to use the latest version of Mustang Browser. If this task is disabled or stopped, your Mustang Browser will not be updated, which means you c


Remove musserver.exe - Powered by Reason Core Security