Tefor.exe threat report

MD5 23bef57de9c8da5053992b152b7eb7a6
Latest seen 2021-02-21 04:39:19 (5 years ago)
First seen 2021-02-21 04:39:19 (5 years ago)
Size 82 MB
Publisher Alkad Software
Product Tefor

This report summarizes the file identity, detection status, publisher metadata, observed locations, and technical indicators for Tefor.exe. ThreatInfo currently classifies this sample as General Threat.

GridinSoft Anti-Malware detection

GridinSoft already detects this file

The latest ThreatInfo record shows Tefor.exe detected as General Threat. You can download GridinSoft Anti-Malware to scan the system and remove this detection if the file is present on your device.

Detection name
General Threat
Last analysis
2021-02-21 04:39:19 (5 years ago)
File hash
23bef57de9c8da5053992b152b7eb7a6
Download Anti-Malware

Tefor.exe is a Windows file recorded in the ThreatInfo database. It is associated with Tefor. The reported company name is Alkad Software. The current detection status is General Threat, based on the latest analysis from 2021-02-21 04:39:19 (5 years ago).

If Tefor.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as General Threat.

Product Name: Tefor
Company Name: Alkad Software
MD5: 23bef57de9c8da5053992b152b7eb7a6
Size: 82 MB
First Published: 2021-02-21 04:39:19 (5 years ago)
Latest Published: 2021-02-21 04:39:19 (5 years ago)
Status: General Threat (on last analysis)
Analysis Date: 2021-02-21 04:39:19 (5 years ago)
Tefor.exe detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%sysdrive%\games\rust\tefor

ThreatInfo has observed Tefor.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is Spain with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for Tefor.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

Tefor.exe is identified as pe for 32 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x052ab000

PE Sections:

Name Size of data MD5
.text 69394432 f8ad426ad0015efe0e97bddc8eba1de7
.rdata 13948928 8185ae68fa19a0a0d50db15adc4568ed
.data 198656 c3981d6a371db2b9e205d3429de5155b
.00cfg 512 25b153767278fafb806e8928d05d1edb
.rodata 7680 054e7b9dff8f996ef823b227789d447c
.tls 512 93d5257d9f0ae461f5fa4df6c819fd29
.voltbl 1536 1eee25071bb6a8b12ae2e31658aab08d
CPADinfo 512 842689af09e7bf563672a4b43f1a2286
prot 512 bf619eac0cdf3f68d496ea9344137e8b
.rsrc 120320 7ffb82d3ccc75d5b9354316b97318613
.reloc 2427392 52d8260fedba1e21be489a50d35d8ccc
/4 9216 f9633cf797d19e62d1ab5445a02a6508
Í|Ï/£u‡ 16896 3bd0e3059e60fcb7ed301ddea574371e

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: