musserver.exe

Mustang Browser

RAFO TECHNOLOGY INC

The application musserver.exe by RAFO TECHNOLOGY INC has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a scheduled task under the Windows Task Scheduler named MustangBrowserUpdateCore triggered daily at a specified time.
Publisher:
Rafotech  (signed by RAFO TECHNOLOGY INC)

Product:
Mustang Browser

Version:
1.44.46.6

MD5:
4af874bd83de5438708728a036750fe3

SHA-1:
d91f75cf46aaa0d0762e4be5f585e0ee7313c753

SHA-256:
055181c3fb9d0a7366ad218639459233f96167f254d55b3008d95fa4bd7108a6

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/23/2024 2:53:56 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.RafoTech (M)
17.1.25.4

File size:
430.5 KB (440,863 bytes)

Product version:
1.44.46.6

Copyright:
Copyright 2015 Rafotech. All rights reserved

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\mustang browser\mustang\bin\musserver.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
3/17/2015 11:50:02 PM

Valid to:
3/17/2016 11:50:02 PM

Subject:
CN=RAFO TECHNOLOGY INC, O=RAFO TECHNOLOGY INC, L=Alhambra, S=California, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112130B87F4F087E63E0D3D6DC5F093C0729

File PE Metadata
Compilation timestamp:
8/22/2015 4:31:02 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x22A02

Entry point:
E9, 4E, 5E, FF, FF, E9, 7F, FE, FF, FF, 3B, 0D, 30, 13, 45, 00, 75, 02, F3, C3, E9, 98, 15, 00, 00, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, 4C, 35, 45, 00, FF, 15, DC, 21, 44, 00, 85, C0, 75, 18, 56, E8, D9, 4A, 00, 00, 8B, F0, FF, 15, 1C, 22, 44, 00, 50, E8, DE, 4A, 00, 00, 59, 89, 06, 5E, 5D, C3, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 77, 6F, 53, 57, A1, 4C, 35, 45, 00, 85, C0, 75, 1D, E8, AF, 40, 00, 00, 6A, 1E, E8, 05, 41, 00, 00, 68, FF, 00, 00, 00, E8, E9, 37, 00, 00, A1, 4C...
 
[+]

Entropy:
6.8860

Packer / compiler:
tElock 0.99 - 1.0 private

Code size:
258 KB (264,192 bytes)

Scheduled Task
Task name:
MustangBrowserUpdateCore

Trigger:
Daily (Runs daily at 2:55 AM)

Description:
Be sure to use the latest version of Mustang Browser. If this task is disabled or stopped, your Mustang Browser will not be updated, which means you c


Remove musserver.exe - Powered by Reason Core Security