beservice.exe

Bastian Suter

This is a setup program which is used to install the application. The file has been seen being downloaded from www.battleye.com and multiple other hosts.
Publisher:
Bastian Suter  (signed and verified)

MD5:
0664ba5ebdcb67336d71285335b7123d

SHA-1:
375432659f3d5d808a9398dbd16df0cbbfce3e7e

SHA-256:
c47bb89ae5349332bc5a9fcba099c11b8859710665890cd8d3c0787d6acc0a34

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 3:00:32 PM UTC  (today)

File size:
963.5 KB (986,624 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\steam\steamapps\common\arma 2 operation arrowhead\expansion\battleye\beservice.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
4/19/2015 5:00:00 PM

Valid to:
6/13/2018 5:00:00 AM

Subject:
CN=Bastian Suter, O=Bastian Suter, L=Tübingen, S=Baden-Württemberg, C=DE

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
07033DEE5ABAFA092E57E090D3A11DE2

File PE Metadata
Compilation timestamp:
9/18/2015 3:21:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

CTPH (ssdeep):
24576:6AM0CTJjQxQRSnppeoqL06Ezu35XTQoPjv8gR7UAHB:81IQRSppfqL06EzuWoPb8gR7UAHB

Entry address:
0x18205C

Entry point:
60, 66, C7, 04, 24, A4, C3, FF, 34, 24, C7, 44, 24, 04, 54, C6, AD, 8B, C7, 44, 24, 20, FF, A7, EE, 3A, FF, 34, 24, C7, 44, 24, 20, F2, D7, 8E, FE, 68, 33, DC, A6, 69, 60, 8D, 64, 24, 44, E9, CF, C0, 00, 00, AC, 1D, 5E, 53, B4, AB, 6F, A5, 94, F5, 83, B2, 8E, FF, 7D, 1C, 7E, 6F, 65, 54, 20, D1, 1B, 7A, FE, 1F, E1, 40, 98, D9, 52, 53, 3E, 16, D1, A0, 5B, 19, A8, 10, 91, C6, 97, 64, 85, 06, CF, 1D, 46, 91, 83, 45, 3C, 23, 33, EF, 85, 45, 0F, 9E, D9, C2, 38, A3, 8C, 33, F7, D1, 71, BB, 68, FC, 70, 71, 1C, 9F...
 
[+]

Entropy:
7.8615  (probably packed)

Code size:
96 KB (98,304 bytes)

The file beservice.exe has been seen being distributed by the following 3 URLs.

http://www.battleye.com/downloads/.../BEService.exe

Scan beservice.exe - Powered by Reason Core Security