Teams.exe file report

MD5 8ec44e5d5323e6cb6eb0fc1aba5a7c11
Latest seen 2022-01-06 21:36:55 (4 years ago)
First seen 2021-12-14 21:50:20 (4 years ago)
Size 118 MB
Product Microsoft Teams

Why it matters

Evidence available for this file

Detection

Latest status is clean for this hash.

Timeline

First seen 2021-12-14 21:50:20 (4 years ago); latest analysis 2022-01-06 21:36:55 (4 years ago).

Publisher context

Company metadata: Microsoft Corporation. Product metadata: Microsoft Teams.

Digital signature

Signed by Microsoft Corporation. ThreatInfo marks this publisher as trusted for this record.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Confirm the hash and publisher match the expected software.
  2. Review the observed locations and signature information below.
  3. Rescan if the file was downloaded from an unknown source or appears in an unusual path.

Teams.exe is a Windows file recorded in the ThreatInfo database. It is associated with Microsoft Teams. The reported company name is Microsoft Corporation. The current detection status is Clean, based on the latest analysis from 2022-01-06 21:36:55 (4 years ago).

This record is currently marked as clean, but file reputation can depend on the exact path, hash, and source. Compare the MD5 and publisher data below with the file on your system.

Product Name: Microsoft Teams
Company Name: Microsoft Corporation
MD5: 8ec44e5d5323e6cb6eb0fc1aba5a7c11
Size: 118 MB
First Published: 2021-12-14 21:50:20 (4 years ago)
Latest Published: 2022-01-06 21:36:55 (4 years ago)
Status: Clean (on last analysis)
Analysis Date: 2022-01-06 21:36:55 (4 years ago)
Signed By: Microsoft Corporation
Status: Trusted Publisher

ThreatInfo marks this publisher as trusted for this record, but the file hash and source should still match the expected software distribution.

%localappdata%\microsoft\teams
%localappdata%\microsoft\teams

ThreatInfo has observed Teams.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

50.0%
50.0%

The strongest geographic signal for this file is Australia with 50.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for Teams.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

Teams.exe is identified as pe for 64 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x060e5a70

PE Sections:

Name Size of data MD5
.text 101913088 cbfd6c8d5afde47e13e563fef94a5d74
.rdata 17691648 924ea0e89f623ad8ee6059c36aa692ee
.data 372224 908d05199e43996785bb842180715854
.pdata 2876416 08baf84f1346a8aa4c9812cedb972223
.00cfg 512 e2b618182fd8c941c38ab1e4ceaf33ac
.gehcont 512 6026d0ec8c24bb7cf4fe138d4a215c39
.retplne 512 83377a6277ad66f75d5e3864a90da4e1
.rodata 4608 5103ab26d7d806bfe65557abb8889d40
.tls 512 cf5ca7f097f40d339035f4bc3a623b50
.voltbl 512 49f76ef71f4c9d68fb6c5f0a6ae211bf
CPADinfo 512 60d3ea61d541c9be2e845d2787fb9574
_RDATA 512 3d32c68b0ec9f7140e5bb49735368a2a
.rsrc 237056 cc5a2ecabad409bd2fbe7087b0df8cfe
.reloc 842752 32d24ef9f2d470e8f2851af46854ef98

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: