mustang_setup_landpage_5f5757db-ff40-3850-bf14-bb67f8cfa8ca_1.0.exe

Mustang Browser

RAFO TECHNOLOGY INC

The application mustang_setup_landpage_5f5757db-ff40-3850-bf14-bb67f8cfa8ca_1.0.exe by RAFO TECHNOLOGY INC has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from download.rafotech.com and multiple other hosts. While running, it connects to the Internet address c5.3e.559e.ip4.static.sl-reverse.com on port 80 using the HTTP protocol.
Publisher:
Rafotech  (signed by RAFO TECHNOLOGY INC)

Product:
Mustang Browser

Version:
1.44.46.7

MD5:
0188bb97cc3cdd8c50404e59bdd95d81

SHA-1:
a4946cb4a18f6ec8dbac8cb9a186805d1757993f

SHA-256:
d66d151fc51714a975fedd400253839476a1c7f93a6d335b8170982546ea8821

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
10/31/2024 11:06:40 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Fafo.MB (M)
16.11.10.14

File size:
39.3 MB (41,231,448 bytes)

Product version:
1.44.46.7

Copyright:
Copyright 2015 Rafotech. All rights reserved

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\mustang_setup_landpage_5f5757db-ff40-3850-bf14-bb67f8cfa8ca_1.0.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
2/25/2016 5:55:49 AM

Valid to:
4/18/2019 8:50:02 AM

Subject:
CN=RAFO TECHNOLOGY INC, O=RAFO TECHNOLOGY INC, L=Alhambra, S=California, C=US

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11219A0D0B3C92177FBC72BF3432CF8A4CB9

File PE Metadata
Compilation timestamp:
9/19/2016 7:03:39 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
786432:7Gwq03r8wGyF5Y+6U0KQ3ljMJ9eIdz4T7PT3zvh0kWvlbu8Lr/8sUF9DGaz:zL3rlGmV6Tbs9zhgrjUPUDDlz

Entry address:
0x247DF

Entry point:
E8, 2D, 76, 00, 00, E9, 7F, FE, FF, FF, E8, 27, 6B, 00, 00, 85, C0, 75, 06, B8, D4, 61, 44, 00, C3, 83, C0, 0C, C3, 55, 8B, EC, 56, E8, E4, FF, FF, FF, 8B, 4D, 08, 51, 89, 08, E8, 20, 00, 00, 00, 59, 8B, F0, E8, 05, 00, 00, 00, 89, 30, 5E, 5D, C3, E8, F3, 6A, 00, 00, 85, C0, 75, 06, B8, D0, 61, 44, 00, C3, 83, C0, 08, C3, 55, 8B, EC, 8B, 4D, 08, 33, C0, 3B, 0C, C5, 68, 60, 44, 00, 74, 27, 40, 83, F8, 2D, 72, F1, 8D, 41, ED, 83, F8, 11, 77, 05, 6A, 0D, 58, 5D, C3, 8D, 81, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8...
 
[+]

Entropy:
7.9978  (probably packed)

Code size:
207.5 KB (212,480 bytes)

The file mustang_setup_landpage_5f5757db-ff40-3850-bf14-bb67f8cfa8ca_1.0.exe has been seen being distributed by the following 15 URLs.

http://download.rafotech.com/.../download.php?cid=landpage&s2sid=325A3282-57D4-51A6-8033-D6D31409B2A5&guid=624c27a0-a888-239c-c936-c9635f9cf4fa

http://download.rafotech.com/.../download.php?cid=landpage&s2sid=8414D2DB-D316-65CD-999F-3B9621AD20DE&guid=70a5c90d-7927-3236-abe-833712e9551f

http://download.rafotech.com/.../download.php?cid=landpage&s2sid=F122D773-E14E-62B7-F1CE-6D4CD664ECED&guid=60c5ce93-3ad9-ce38-5435-fe4572f69915

http://download.rafotech.com/.../download.php?cid=landpage&s2sid=3461FD4D-D0B9-69BB-6A59-17C03C65DD88&guid=b4f349a4-8d15-5de7-135a-e6a1a61328d2

http://download.rafotech.com/.../download.php?cid=landpage&s2sid=C5953F06-FA4E-D36E-81CE-253D727187AD&guid=17fb49b-2298-a11-87cc-80aea9ae4c8d

http://download.rafotech.com/.../download.php?cid=landpage&s2sid=7B27D261-FAE6-F0DD-C758-D82AC38584F9&guid=79179b8b-30b5-e7c4-6d9e-8cea5b6ba6f5

https://mustangbrowser.it.softonic.com/download-tracker?th=1/.../jh2KoIkwd6MWFdMHTqMWwNzt3irJLFAplkt1kjxpZflby9wvhHQ06xBC75FR3inLZ5B0w TZXdxSFy7RMMkSIU6gp5pRfA==

http://download.rafotech.com/.../download.php?cid=landpage&s2sid=73B3836B-E00C-6F43-42F0-7A2A045556D7&guid=4d0be1dd-a43d-8086-1866-32c1842a9fe

http://download.rafotech.com/.../download.php?cid=landpage&s2sid=4E900E07-8849-6CBF-DF4C-B9F0F3DCF92D&guid=77b0bf4c-4f25-5d2e-43ac-e8cee56fe25b

http://download.rafotech.com/.../download.php?cid=landpage&s2sid=C73E7375-F9FC-23B0-A630-79E9BF96EEFE&guid=df6341a9-d1e7-99a7-8e8c-8b9011a7b8b

http://download.rafotech.com/.../download.php?cid=landpage&s2sid=27CE7A9A-E3DD-3BA3-C8C5-DF3568A328A3&guid=b2ef8c82-695d-e04e-cc5d-ee3ce8827690

http://download.rafotech.com/.../download.php?cid=landpage&s2sid=8AFCC104-D71D-616E-7CE0-AD5B27441EAB&guid=6b4f5234-7d43-e6dd-b935-fd86b75c89

http://download.rafotech.com/.../download.php?cid=bxk

http://download.rafotech.com/.../download.php?cid=dlsite

http://download.rafotech.com/.../download.php?cid=landpage&s2sid=CAA55E4B-76CA-DC5D-32B0-9C33E071B28E&guid=631a625c-253a-da80-fdd3-d68bd6ea2b2

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to c5.3e.559e.ip4.static.sl-reverse.com  (158.85.62.197:80)