LhmonProxy.sys

Network Filter

International Business Machines Corp.

Publisher:
IBM  (signed by International Business Machines Corp.)

Product:
Network Filter

Description:
TDI Filter Loader Module for NTTDIDR

Version:
89182

MD5:
011bf0665b7eaa73d8ed30be2d41e250

SHA-1:
e8b3863498a90a49da5c1d0aead6a79ca0196fab

SHA-256:
8fc164ad34b9c31bce3b4b80ae5a0889c2962b0fcc79ba3aa900c7c7964f76f6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/6/2024 7:44:38 AM UTC  (today)

File size:
51.8 KB (53,032 bytes)

Product version:
89182

Copyright:
© IBM. All rights reserved.

Original file name:
LhmonProxy.sys

File type:
Driver (Win64 SYS)

Common path:
C:\users\{user}\downloads\guardium\guardium_9.5_s-tap_windows_r89182\guardium_9.5_s-tap_windows_r89182\windows_stap_v9.5_r89182\windows_stap_r89182_installer\Program Files\ibm\guardium_stap\x64\lhmonproxy.sys

Digital Signature
Authority:
DigiCert Inc

Valid from:
1/9/2015 8:00:00 AM

Valid to:
3/14/2018 8:00:00 PM

Subject:
CN=International Business Machines Corp., O=International Business Machines Corp., L=armonk, S=NY, C=US

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
029877B9426BB8648F1AE4C4687F01F9

File PE Metadata
Compilation timestamp:
7/8/2016 10:50:11 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
8.0

Entry address:
0x16010

Entry point:
48, 8B, 05, 09, 41, FF, FF, 49, B9, 32, A2, DF, 2D, 99, 2B, 00, 00, 48, 85, C0, 74, 05, 49, 3B, C1, 75, 2F, 4C, 8D, 05, EE, 40, FF, FF, 48, B8, 20, 03, 00, 00, 80, F7, FF, FF, 48, 8B, 00, 49, 33, C0, 49, B8, FF, FF, FF, FF, FF, FF, 00, 00, 49, 23, C0, 49, 0F, 44, C1, 48, 89, 05, C6, 40, FF, FF, 48, F7, D0, 48, 89, 05, B4, 40, FF, FF, E9, 37, B2, FE, FF, CC, CC, CC, B8, 60, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 8C, 64, 01, 00, 10, 90, 00, 00, A8, 60, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, AE, 64, 01, 00...
 
[+]

Entropy:
6.2961

Code size:
33.5 KB (34,304 bytes)

Scan LhmonProxy.sys - Powered by Reason Core Security