splunk-netmon.exe

  • File Path: C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe
  • Description: Network monitor

Hashes

Type Hash
MD5 F86EAD8C9AF88B4189EB311AE908A3F0
SHA1 CE68C45B1FC2D19397718D518F6D11F022B4CC3E
SHA256 4E4AEF2A402A9CCC36D79C09D1EE87F6C1387325144A271526A9E9979F8C5FC8
SHA384 55BA1A3FDBF9F5E5610932BE9C94EC5787908ADEBA2A8051F9682A9A2D635295500BE2843FE42B9D5246956F7AC11F35
SHA512 AE5E836B69630DF9C94C9145A56C740B010E52BE4D6A5CA6356E2D1BE532EB9317548A7C495831138DB51E1B22A70ED4BFD85C067537F37408D3ED0416A94F49
SSDEEP 196608:jdKj8glzazO4XYUxz86LLswE7t64KvvY336iPR2HvFL:kjVlz5UxYYLUk4WicHt
IMP FD2D4472615B421BAEF1D51F46EF5F52
PESHA1 258B42F819D8A961F67A94E67C2AEFBEDD6173F4
PE256 1AA1CBC48D485A23BE7AE8A1A721ECCC509F194F4A9E27F5B4BB82B4ECFDE875

Runtime Data

Usage (stderr):

wmain: SPLUNK_HOME must be set.  Stopping.
SPLUNK_HOME must be set.  Stopping.

Loaded Modules:

Path
C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\SYSTEM32\ntdll.dll

Signature

  • Status: Signature verified.
  • Serial: 014E132916D610BB301B22ABBD994616
  • Thumbprint: B8B4F0D3FD0571E184DEBB76A1F6DB73F30FA233
  • Issuer: CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US
  • Subject: CN=”Splunk, Inc.”, O=”Splunk, Inc.”, L=San Francisco, S=California, C=US, SERIALNUMBER=4109614, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Delaware, OID.1.3.6.1.4.1.311.60.2.1.3=US

File Metadata

  • Original Filename: splunk-netmon.exe
  • Product Name: Splunk Application
  • Company Name: Splunk Inc.
  • File Version: 8.2.3
  • Product Version: 8.2.3 (Build cd0848707637)
  • Language: English (United States)
  • Legal Copyright: Copyright (C) 2005-2021
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: Unknown

MIT License. Copyright (c) 2020-2021 Strontic.