Is PrintDisp safe?
No engine detected this longstanding signed executable, while one completed sandbox run found no offensive behavior, malicious verdict, dropped payload, or domain-reputation warning.
All 74 engines returned no malicious or suspicious detection, including 17 tier-1 products. The executable is validly signed, has circulated since 2018, and its completed sandbox run showed no malware-only techniques or malicious conclusion; however, signer history and complete IP-reputation coverage are unavailable.
5aa7e11735f1c61ba5…604f686b66cf2eRecommended next actions
Before opening
Open it only when its sender or download source is one you independently trust.
If you already opened it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 74 engines returned no malicious or suspicious detection, including 17 tier-1 products. The executable is validly signed, has circulated since 2018, and its completed sandbox run showed no malware-only techniques or malicious conclusion; however, signer history and complete IP-reputation coverage are unavailable.
The strongest signal is unanimous antivirus silence: 0 of 74 engines flagged the file, including all 17 reporting tier-1 products. Its signature verifies as belonging to ActMask Group Co., and no brand conflict or packing indicator was identified. One completed sandbox run recorded no offensive techniques, malicious conclusion, persistence indicator, written file, or dropped hash. Reputation checks found no warning among all six contacted domains, though the separate IP list was not fully covered. Longstanding prevalence across 155 sources and 254 submissions since 2018 further supports ordinary software rather than a newly distributed threat. The missing signer history and unavailable YARAify result modestly limit certainty but do not outweigh the consistent evidence.
What We Detected
None of the 74 antivirus engines flagged the executable, including 17 tier-1 products such as Avast, BitDefender, ESET-NOD32, and Kaspersky. The file is validly signed by ActMask Group Co., no conflicting brand claim was detected, and static PE analysis found neither high-entropy code nor likely packing.
Threat Behavior
One completed sandbox run produced no malicious conclusion and no malware-only offensive technique. It recorded no persistence indicator, written file, or dropped hash. All six contacted domains were checked without a malicious or suspicious reputation result; however, not every separately listed IP address received equivalent coverage. The sample has also circulated since 2018 across 155 sources and 254 submissions.
What To Do Now
Normal use is reasonable when the file came from the expected vendor or a trusted distribution channel. Keep endpoint protection enabled and verify the signature still names ActMask Group Co. before execution if the download source is uncertain.
Where this verdict could be wrong3 caveats
- signing.signerStats.found=false and signing.trustedPublisher.matched=false, so the valid 'ActMask Group Co.' signature lacks corroborating publisher history in this dataset.
- The contacted-host cross-check covered all six domains but not every contacted IP, so complete reputation coverage for all network contacts is unavailable.
- externalIntel.availability.yaraify='error', leaving that researcher-rule source unavailable rather than negative.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/74 engines reported a malicious or suspicious result.
- All 17 reporting tier-1 engines returned no detection.
- The signature for 'ActMask Group Co.' verifies successfully.
- One sandbox run had behaviour.offensiveCount=0 and no malicious conclusion.
- The sample has 254 submissions from 155 sources dating to 2018.
- No historical signer statistics are available for 'ActMask Group Co.'
- The signer is not matched to the curated trusted-publisher list.
- Not every contacted IP received a saved reputation cross-check.
- YARAify analysis timed out, leaving a researcher-rule coverage gap.
Use it only from an expected source and confirm the verified signer remains ActMask Group Co. Keep antivirus and endpoint protection enabled.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial6 of 26 contacted hosts were cross-checked; coverage is incomplete.
YARA
CompleteRule evaluation completed with no recorded matches.
External intel
PartialIndependent reference checks were attempted but are incomplete.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 16MITRE ATT&CK techniques
- 7spawned processes
- 26network contacts
- 21filesystem & mutex artifacts
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- crl.comodoca.com
- crl.comodoca.com.cdn.cloudflare.net
- www.microsoft.com
- res.public.onecdn.static.microsoft
- fp2e7a.wpc.phicdn.net
- fp2E7A.wpc.2BE4.phicdn.net
- 204.79.197.203
- a83f:8110:0:a092:2300:d0:9223:0
- 52.251.79.25
- 13.107.39.203
- 23.216.147.64
- 20.99.184.37
- 20.99.133.109
- 23.216.147.76
- 192.229.211.108
- a83f:8110:0:0:0:0:2002:0
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Notepad\lfFaceName
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\GoogleUpdaterInternalService126.0.6441.0\Start
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\GoogleUpdaterInternalService126.0.6441.0\ImagePath
- HKU/S-1-5-21-470376811-3006406624-3672060426-1000/Software/Microsoft/Notepad/lfFaceName
- HKU/S-1-5-21-470376811-3006406624-3672060426-1000/Software/Microsoft/Notepad/szHeader
- HKU/S-1-5-21-470376811-3006406624-3672060426-1000/Software/Microsoft/Notepad/szTrailer
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER1817.tmp.WERInternalMetadata.xml
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER1886.tmp.csv
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER1952.tmp.txt
- C:\Windows\System32\spp\store\2.0\cache\cache.dat
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER1567.tmp.WERInternalMetadata.xml
- CTF.LBES.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
- CTF.Compart.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
- CTF.Asm.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
- CTF.Layouts.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
- CTF.TMD.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 0 / 74engines flagged
- 155sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 74 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has a long, established submission history across 155 sources.
Verdict inputView chapterProvenanceDerivedSourceSubmission historyObserved at - 03
One or more independent reference checks were incomplete or unavailable.
ProvenanceDerivedSourceExternal-intelligence coverageObserved at - 04
Scanned file: PrintDisp — 5aa7e11735f1c61ba5bcc976ff9c0642ca140b34e57b5effde604f686b66cf2e
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\AppData\Local\Temp\executable.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — %SAMPLEPATH%\5aa7e11735f1c61ba5bcc976ff9c0642ca140b34e57b5effde604f686b66cf2e.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
Contacted host: crl.comodoca.com — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
Contacted host: crl.comodoca.com.cdn.cloudflare.net — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
Available reference checks returned no match, but at least one source was unavailable. This is not a clean result.
YARA rules
No matchesThe rule pass completed without a saved public match.
0 of 74 engines flagged this file
View all 74 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- PrintDisp
- Format
- Win32 EXE
- Code signing
- Signature valid: ActMask Group Co.
- Size
- 573.1 KB
- Last analyzed
- Sep 28, 2026, 3:41 PM UTC
5aa7e11735f1c61ba5bcc976ff9c0642ca140b34e57b5effde604f686b66cf2eSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Open it only when its sender or download source is one you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is PrintDisp safe?
What is PrintDisp?
How many antivirus engines detected PrintDisp?
Is PrintDisp digitally signed?
What is the SHA-256 hash of PrintDisp?
Is it safe to open PrintDisp?
How up to date is this analysis of PrintDisp?
Community
Member reviews and reports for this exact file hash.