blackd.exe

IBM ISS Proventia

International Business Machines Corporation

It runs as a separate (within the context of its own process) windows Service named “BlackICE”.
Publisher:
IBM Internet Security Systems  (signed by International Business Machines Corporation)

Product:
IBM ISS Proventia

Description:
blackd

Version:
240.2845.0.0

MD5:
06e01b9fcc9adb9f08ca9c208688b111

SHA-1:
bf98621e50e8fa4ad4553f1fcfbc751e5abe7cff

SHA-256:
b7d6ef2cfce53501241d832f65dcfcdd2bd08dc13d0d49e981c57f88c4453d92

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 10:17:27 AM UTC  (today)

File size:
2.6 MB (2,727,928 bytes)

Product version:
240.2845.0.0

Copyright:
© Copyright IBM Corporation 1994, 2013. All Rights Reserved.

Trademarks:
IBM and the IBM logo are trademarks of IBM Corporation in the United States, other countries, or both.

Original file name:
blackd.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\ibm\host protection\blackd.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/16/2012 2:00:00 AM

Valid to:
10/16/2013 1:59:59 AM

Subject:
CN=International Business Machines Corporation, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=International Business Machines Corporation, L=Kirkland, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2AC606C32F9A926A117431574E5B4BDC

File PE Metadata
Compilation timestamp:
1/4/2013 7:57:49 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:pyfH2aJ7MPlNH61v6Qw6yobJ9Ua1JS/Q0u/GJ2oWzP46bxot1o9I1FM4vA/ol90s:u2aJ7MNNH6p6Qw6yWUKJS/Bu/GJ2oyPM

Entry address:
0x1124A6

Entry point:
E8, 0E, 05, 01, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 5D, E9, 36, 06, 00, 00, 3B, 0D, 10, 62, 65, 00, 75, 02, F3, C3, E9, 8A, 05, 01, 00, 8B, FF, 55, 8B, EC, 83, EC, 20, 53, 57, 33, DB, 6A, 07, 33, C0, 59, 8D, 7D, E4, 89, 5D, E0, F3, AB, 39, 5D, 0C, 75, 15, E8, 2E, 62, 00, 00, C7, 00, 16, 00, 00, 00, E8, 2F, 15, 01, 00, 83, C8, FF, EB, 4D, 8B, 45, 08, 3B, C3, 74, E4, 56, 89, 45, E8, 89, 45, E0, 8D, 45, 10, 50, 53, FF, 75, 0C, 8D, 45, E0, 50, C7, 45, E4, FF, FF, FF, 7F, C7, 45, EC, 42, 00, 00, 00, E8...
 
[+]

Entropy:
6.6019

Code size:
1.9 MB (1,965,056 bytes)

Service
Display name:
BlackICE

Type:
Win32OwnProcess