beservice.exe

BattlEye Innovations e.K.

This is a setup program which is used to install the application. The file has been seen being downloaded from www.battleye.com and multiple other hosts.
Publisher:
BattlEye Innovations e.K.  (signed and verified)

MD5:
9a5960cdb5ad027643e373b8f0b2ad50

SHA-1:
49cac525d57b05044a0c7915c598d3e5b5398e38

SHA-256:
1517fc81cdff21f370b5753de0235d5f7219c1cca4795a60634b8bcad74b6bb1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/16/2024 3:30:57 PM UTC  (today)

File size:
1.5 MB (1,536,008 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\steam\steamapps\common\arma 3\battleye\beservice.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
11/10/2015 1:00:00 AM

Valid to:
11/14/2018 1:00:00 PM

Subject:
CN=BattlEye Innovations e.K., O=BattlEye Innovations e.K., L=Tübingen, S=Baden-Württemberg, C=DE

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0F5A57726999506B6F93FD9A150B88FA

File PE Metadata
Compilation timestamp:
4/7/2016 12:37:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
14.0

CTPH (ssdeep):
24576:gS1MAhod0m++xh9+NA3tauYHvPy2IGFchwkFzh9DNLnCtb4qOsTTLo:gsxh2Yoa+9aJHny2bFcBzhlNrKHtk

Entry address:
0x18FFFD

Entry point:
60, 88, 54, 24, 08, 57, C7, 44, 24, 20, 63, 39, E5, 28, 60, E9, FC, 40, 02, 00, 95, AF, A8, 8E, 91, 90, 02, 6D, 79, 91, 2C, AC, 14, 2A, 83, 9A, 12, BE, 12, 30, 75, 8C, 3C, A0, D4, E9, 3F, 5C, 9C, B6, 1B, 29, 84, 9C, 6E, 44, 07, 6D, C9, C5, 59, D3, 00, 38, CC, 80, 77, F6, BD, FF, 43, C0, CA, FD, A5, 2B, 90, A6, 7A, F2, 43, 9B, AA, 33, 30, 60, 08, 5C, 60, 80, 6D, EC, D5, 2A, 1C, CD, 77, A8, 19, E2, 74, 33, 24, 39, 41, 08, D2, AB, FD, 38, 92, A1, 79, 5C, 17, 88, 4A, 31, A8, C6, 37, B7, 71, A4, 0D, 28, 99, F2...
 
[+]

Entropy:
7.8191  (probably packed)

Code size:
113 KB (115,712 bytes)

The file beservice.exe has been seen being distributed by the following 2 URLs.

Scan beservice.exe - Powered by Reason Core Security