beservice.exe

Bastian Suter

This is a setup program which is used to install the application. The file has been seen being downloaded from www.battleye.com and multiple other hosts.
Publisher:
Bastian Suter  (signed and verified)

MD5:
1605f1d1dcd5ea387cd02f4a8aaaf7de

SHA-1:
a0a04d94914dd5bdc6a3672b5d7610b3e0c2f170

SHA-256:
4d897c3d560bbc0adca49fc9b8fa07d6daad7955cf715f683fcb8892b1fff180

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 12:58:26 AM UTC  (today)

File size:
751.9 KB (769,920 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\steam\steamapps\common\arma 2 operation arrowhead\expansion\battleye\beservice.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
3/5/2014 12:00:00 AM

Valid to:
5/13/2015 1:00:00 PM

Subject:
CN=Bastian Suter, O=Bastian Suter, L=Tübingen, S=Baden-Württemberg, C=DE

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0F01D40307832B7F6747D7AB752213DC

File PE Metadata
Compilation timestamp:
3/3/2015 8:16:04 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

CTPH (ssdeep):
12288:gbuEMWWuDV6J2ePAXryAh5lGABMkdaWJ9mwaIvg8vBc+Sb1fHsnmly9zb/pI/tpZ:IpMWWuDs8ePAXZq69iIVa+kHNlsKet6b

Entry address:
0x8DC3F

Entry point:
E8, 99, 13, 00, 00, 1A, E6, 36, AA, 52, 0D, 6E, 96, AC, 6C, A3, 25, B4, 94, 7B, 65, F4, B4, 1B, BD, 10, C8, 67, 55, E4, FC, 6F, 51, 65, A7, BF, 41, EC, FC, E4, 41, 21, EC, 68, 47, 89, 66, A5, 3B, F2, 0E, B4, 28, 64, 90, F5, 34, D9, 1A, F2, 3D, BB, 20, 29, F0, 26, B5, 1D, ED, 72, BC, 35, C4, 64, 2E, 72, 9F, 03, 09, D7, 95, 37, F3, C2, 6C, 6B, 5D, C2, C5, 44, 95, 83, 6E, 69, 7B, AD, F6, 93, 30, F7, 46, CE, B1, F2, DE, C9, 5A, 16, D9, FF, 76, 86, 11, A3, C9, E7, BE, 6E, 39, AB, DA, F2, 77, 66, 6B, 54, ED, 15...
 
[+]

Entropy:
7.8623  (probably packed)

Code size:
80 KB (81,920 bytes)

The file beservice.exe has been discovered within the following program.

DayZ  by Bohemia Interactive
www.dayzgame.com
About 9% of users remove it
 
Powered by Should I Remove It?

The file beservice.exe has been seen being distributed by the following 2 URLs.

Scan beservice.exe - Powered by Reason Core Security