beservice.exe

Bastian Suter

This is a setup program which is used to install the application. It runs as a separate (within the context of its own process) windows Service named “BattlEye Service”. The file has been seen being downloaded from battleye.com.
Publisher:
Bastian Suter  (signed and verified)

MD5:
29875a9aef3f6cb1bdcd190222aea31c

SHA-1:
9c6fd0ad3e539fa9e91c679a4ce5c34949f1ce1b

SHA-256:
e673c26bacc0f5a2234f82c3aee0ef5e7c969fd633e6dd796d9b278e530aa5ae

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
7/17/2025 12:15:40 AM UTC  (today)

Scan engine
Detection
Engine version

McAfee
Generic Obfuscated.c
5600.6906

File size:
685.4 KB (701,824 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\common files\battleye\beservice.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
3/5/2014 8:00:00 AM

Valid to:
5/13/2015 8:00:00 PM

Subject:
CN=Bastian Suter, O=Bastian Suter, L=Tübingen, S=Baden-Württemberg, C=DE

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0F01D40307832B7F6747D7AB752213DC

File PE Metadata
Compilation timestamp:
12/24/2014 5:02:04 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
8.0

CTPH (ssdeep):
12288:esEXSWgs9vj/FaSfPYar7ziu1QpIVU2s60lXSQ9alulugXDBNFpLbj:i/54S3J7Ct60999al8uiDBNnLn

Entry address:
0x8BAA5

Entry point:
E9, EC, 6E, 00, 00, E9, B3, 7C, 00, 00, E9, D7, 0C, 09, 00, E9, 5C, 4B, 09, 00, 00, 00, 57, 69, 6E, 56, 65, 72, 69, 66, 79, 54, 72, 75, 73, 74, 00, AA, E9, 80, 74, 00, 00, 0F, 8E, C3, 42, FF, FF, 88, C4, E9, 27, 69, 00, 00, 2E, AF, 5D, 54, 48, 12, D1, 56, E8, 2E, 63, 2B, B6, 00, F1, 3D, 0C, D0, 9F, 69, B9, B7, A8, 6B, 12, 13, B1, FA, DC, 24, 1E, D9, 0C, 8C, E3, 26, 55, D3, 4C, 92, C7, 8E, F1, F3, 87, 8C, CD, 50, 54, 20, 15, 73, 93, A7, D9, 97, 21, 95, 0E, 0B, ED, B9, 50, E2, D8, 0F, FE, 8D, 60, A3, 64, 46...
 
[+]

Packer / compiler:
Xtreme-Protector v1.05

Code size:
72.5 KB (74,240 bytes)

Service
Display name:
BattlEye Service

Service name:
BEService

Type:
Win32OwnProcess


The file beservice.exe has been seen being distributed by the following URL.

Scan beservice.exe - Powered by Reason Core Security