splunk-winprintmon.exe

  • File Path: C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe
  • Description: Windows Print Monitor

Hashes

Type Hash
MD5 FE6F89B1824B53C288F1C16B65B59A0C
SHA1 BB0015D97A3A79AD63E8609C90036C3903048CBA
SHA256 B9498BE104A9462C2474FC4140B7EDFDE06A0C85183C47D876847C91139F3DA6
SHA384 941D63027D17125D72ECA85B3029442D3C8DCB8D64F37B9DDF19F1396F7031C8A1110D5266CA25420D4F6F7426EA52D1
SHA512 2B4E80CF5034366EC53CD9B323B6B3B8D5FE0ED1280ABA51DB7DF71C7F6E1948DDA7EF086532C9031756FBA31941EC681E91296434A9604D1B5DF99CB7C5D3E0
SSDEEP 196608:Fq70Y+8vcuevO1L1FOD1c5jftRd8Rskqw7R0n:TNCcuQOxOD1c/7wCn
IMP 35240A25EDE7EC5A65BF627E57E772B9
PESHA1 B5C4E7E2F652CA1111F7655F91541464898B1E2C
PE256 EB5A3AA335CBECF766DC14D470A5E4551CAC643801095DB60E23C9FD71C2AFC8

Runtime Data

Usage (stderr):

runWinPrintMon: SPLUNK_HOME must be set.  Stopping.
SPLUNK_HOME must be set.  Stopping.

Loaded Modules:

Path
C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\SYSTEM32\ntdll.dll

Signature

  • Status: Signature verified.
  • Serial: 014E132916D610BB301B22ABBD994616
  • Thumbprint: B8B4F0D3FD0571E184DEBB76A1F6DB73F30FA233
  • Issuer: CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US
  • Subject: CN=”Splunk, Inc.”, O=”Splunk, Inc.”, L=San Francisco, S=California, C=US, SERIALNUMBER=4109614, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Delaware, OID.1.3.6.1.4.1.311.60.2.1.3=US

File Metadata

  • Original Filename: splunk-winprintmon.exe
  • Product Name: splunk Application
  • Company Name: Splunk Inc.
  • File Version: 8.2.3
  • Product Version: 8.2.3 (Build cd0848707637)
  • Language: English (United States)
  • Legal Copyright: Copyright (C) 2005-2021
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: Unknown

MIT License. Copyright (c) 2020-2021 Strontic.