splunk-winprintmon.exe
- File Path:
C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe
- Description: Windows Print Monitor
Hashes
Type |
Hash |
MD5 |
FE6F89B1824B53C288F1C16B65B59A0C |
SHA1 |
BB0015D97A3A79AD63E8609C90036C3903048CBA |
SHA256 |
B9498BE104A9462C2474FC4140B7EDFDE06A0C85183C47D876847C91139F3DA6 |
SHA384 |
941D63027D17125D72ECA85B3029442D3C8DCB8D64F37B9DDF19F1396F7031C8A1110D5266CA25420D4F6F7426EA52D1 |
SHA512 |
2B4E80CF5034366EC53CD9B323B6B3B8D5FE0ED1280ABA51DB7DF71C7F6E1948DDA7EF086532C9031756FBA31941EC681E91296434A9604D1B5DF99CB7C5D3E0 |
SSDEEP |
196608:Fq70Y+8vcuevO1L1FOD1c5jftRd8Rskqw7R0n:TNCcuQOxOD1c/7wCn |
IMP |
35240A25EDE7EC5A65BF627E57E772B9 |
PESHA1 |
B5C4E7E2F652CA1111F7655F91541464898B1E2C |
PE256 |
EB5A3AA335CBECF766DC14D470A5E4551CAC643801095DB60E23C9FD71C2AFC8 |
Runtime Data
Usage (stderr):
runWinPrintMon: SPLUNK_HOME must be set. Stopping.
SPLUNK_HOME must be set. Stopping.
Loaded Modules:
Path |
C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe |
C:\Windows\System32\KERNEL32.DLL |
C:\Windows\System32\KERNELBASE.dll |
C:\Windows\SYSTEM32\ntdll.dll |
Signature
- Status: Signature verified.
- Serial:
014E132916D610BB301B22ABBD994616
- Thumbprint:
B8B4F0D3FD0571E184DEBB76A1F6DB73F30FA233
- Issuer: CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US
- Subject: CN=”Splunk, Inc.”, O=”Splunk, Inc.”, L=San Francisco, S=California, C=US, SERIALNUMBER=4109614, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=Delaware, OID.1.3.6.1.4.1.311.60.2.1.3=US
- Original Filename: splunk-winprintmon.exe
- Product Name: splunk Application
- Company Name: Splunk Inc.
- File Version: 8.2.3
- Product Version: 8.2.3 (Build cd0848707637)
- Language: English (United States)
- Legal Copyright: Copyright (C) 2005-2021
- Machine Type: 64-bit
File Scan
- VirusTotal Detections: Unknown
MIT License. Copyright (c) 2020-2021 Strontic.