mustang_setup_landpage_1f988542-2b54-5d68-846c-cb31aae2572d_1.0.exe

Mustang Browser

RAFO TECHNOLOGY INC

The application mustang_setup_landpage_1f988542-2b54-5d68-846c-cb31aae2572d_1.0.exe by RAFO TECHNOLOGY INC has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from download.rafotech.com.
Publisher:
Rafotech  (signed by RAFO TECHNOLOGY INC)

Product:
Mustang Browser

Version:
1.44.46.7

MD5:
70f1c98b716053af3bec57953293c050

SHA-1:
156fbe91f0ee3149e7d085c996946b8dbbc06b30

SHA-256:
7520fa367ba37d43ad80e4cd0de14340e0737a0ad5554931a345192fae38bbc1

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
10/31/2024 10:49:25 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Fafo.MB (M)
16.11.10.14

File size:
39.3 MB (41,231,960 bytes)

Product version:
1.44.46.7

Copyright:
Copyright 2015 Rafotech. All rights reserved

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\mustang_setup_landpage_1f988542-2b54-5d68-846c-cb31aae2572d_1.0.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
2/25/2016 6:55:49 AM

Valid to:
4/18/2019 8:50:02 AM

Subject:
CN=RAFO TECHNOLOGY INC, O=RAFO TECHNOLOGY INC, L=Alhambra, S=California, C=US

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11219A0D0B3C92177FBC72BF3432CF8A4CB9

File PE Metadata
Compilation timestamp:
9/14/2016 6:36:01 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
786432:dGw203r8wGyF5Y+6U0KQ3X2N2/TQkqMkQYlCMk0BTz7bFZsIbm4sJCyfNvjj:V33rlGmV6Tbn2GqMkQvZuz7bFZtbcJfF

Entry address:
0x247DF

Entry point:
E8, 2D, 76, 00, 00, E9, 7F, FE, FF, FF, E8, 27, 6B, 00, 00, 85, C0, 75, 06, B8, D4, 61, 44, 00, C3, 83, C0, 0C, C3, 55, 8B, EC, 56, E8, E4, FF, FF, FF, 8B, 4D, 08, 51, 89, 08, E8, 20, 00, 00, 00, 59, 8B, F0, E8, 05, 00, 00, 00, 89, 30, 5E, 5D, C3, E8, F3, 6A, 00, 00, 85, C0, 75, 06, B8, D0, 61, 44, 00, C3, 83, C0, 08, C3, 55, 8B, EC, 8B, 4D, 08, 33, C0, 3B, 0C, C5, 68, 60, 44, 00, 74, 27, 40, 83, F8, 2D, 72, F1, 8D, 41, ED, 83, F8, 11, 77, 05, 6A, 0D, 58, 5D, C3, 8D, 81, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8...
 
[+]

Entropy:
7.9978  (probably packed)

Code size:
207.5 KB (212,480 bytes)

The file mustang_setup_landpage_1f988542-2b54-5d68-846c-cb31aae2572d_1.0.exe has been seen being distributed by the following URL.

http://download.rafotech.com/.../download.php?cid=landpage&s2sid=B051DC5D-3811-7BB4-7B15-56B1AADC12D2&guid=f65bcfa6-5968-efb9-555b-c7d7bba88eaf