lhmon.sys

Local Network Monitor

International Business Machines Corp.

Publisher:
IBM  (signed by International Business Machines Corp.)

Product:
Local Network Monitor

Description:
Local Network Monitor Helper Driver

Version:
89629

MD5:
ea980a1375baad5870ea91d9dac6b94c

SHA-1:
310b92f3885b53782aa7e6d9dc5d19bfbafcadd6

SHA-256:
f84578c4800ff2590931243551f08006cb14f86e45563eae5c4134a0a5aacfe2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/5/2024 11:44:12 PM UTC  (a few moments ago)

File size:
102.3 KB (104,744 bytes)

Product version:
89629

Copyright:
© IBM. All rights reserved.

Original file name:
NTTDIDR.SYS

File type:
Driver (Win32 SYS)

Common path:
C:\users\{user}\downloads\guardium\guardium_9.5_s-tap_windows_r89629\guardium_9.5_s-tap_windows_r89629\windows-v9_next-89629\windows_stap_r89629_installer\Program Files\ibm\guardium_stap\lhmon.sys

Digital Signature
Authority:
DigiCert Inc

Valid from:
1/9/2015 8:00:00 AM

Valid to:
3/14/2018 8:00:00 PM

Subject:
CN=International Business Machines Corp., O=International Business Machines Corp., L=armonk, S=NY, C=US

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
029877B9426BB8648F1AE4C4687F01F9

File PE Metadata
Compilation timestamp:
10/4/2016 3:06:53 AM

OS version:
5.2

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
7.10

Entry address:
0x1E534

Entry point:
8B, FF, 55, 8B, EC, A1, 28, 60, 02, 00, 85, C0, B9, 40, BB, 00, 00, 74, 04, 3B, C1, 75, 23, 8B, 15, 54, 50, 02, 00, B8, 28, 60, 02, 00, C1, E8, 08, 33, 02, 25, FF, FF, 00, 00, A3, 28, 60, 02, 00, 75, 07, 8B, C1, A3, 28, 60, 02, 00, F7, D0, A3, 24, 60, 02, 00, 5D, E9, 95, FC, FF, FF, CC, 0C, E6, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, B6, ED, 01, 00, 2C, 50, 01, 00, E0, E5, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, EE, 01, 00, 00, 50, 01, 00, F0, E5, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 78, EE, 01, 00...
 
[+]

Entropy:
6.6654

Code size:
83.5 KB (85,504 bytes)

Scan lhmon.sys - Powered by Reason Core Security