beservice.exe

BattlEye Innovations e.K.

This is a setup program which is used to install the application. The file has been seen being downloaded from www.battleye.com and multiple other hosts.
Publisher:
BattlEye Innovations e.K.  (signed and verified)

MD5:
1ae796b9e58b21f902b88b4bb8a549cc

SHA-1:
ae0a5a7c122a4fa558ab2ef98f140317f4afacbf

SHA-256:
f9a5c3c6824b67c903d5b7cc688b08f41c83cb68c9f11757c7b4cde7a37dfaa9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 1:56:29 AM UTC  (today)

File size:
1.5 MB (1,526,792 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\steam\steamapps\common\dayz\battleye\beservice.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
11/9/2015 7:00:00 PM

Valid to:
11/14/2018 7:00:00 AM

Subject:
CN=BattlEye Innovations e.K., O=BattlEye Innovations e.K., L=Tübingen, S=Baden-Württemberg, C=DE

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0F5A57726999506B6F93FD9A150B88FA

File PE Metadata
Compilation timestamp:
4/4/2016 5:00:43 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
14.0

CTPH (ssdeep):
24576:/E88Pb5/imAApvA40K3WLZMrLcMce1HTPtIXRiFmY35ZB1+ZBOMCCXQLnCtb4qO5:vEvbMqrAo1HsiFmQ1DMCsQrKHtk

Entry address:
0xB6544

Entry point:
52, C7, 04, 24, D1, E3, 7B, 4D, 9C, 9C, 9C, C7, 44, 24, 08, 02, E8, 59, E7, C6, 44, 24, 04, B6, 60, 66, 89, 7C, 24, 08, 8D, 64, 24, 28, E9, 43, DB, 0F, 00, 8D, 64, 24, 04, 0F, 85, 89, BB, 0F, 00, F8, 66, D3, EE, 89, F9, 66, FF, C6, 29, D9, 66, 0F, CE, 9C, 66, 0F, CE, F7, D6, 8D, 74, 24, 04, 54, C6, 04, 24, 6C, 60, 8D, 64, 24, 28, E9, 22, 83, 08, 00, 9C, E9, 28, 80, 0F, 00, 60, 69, D2, 0A, 00, 00, 00, E8, 8C, A8, 0F, 00, 63, 92, 5E, 9A, 72, 86, 22, 77, 89, 99, FE, 26, C2, FA, D2, 52, B2, 4E, 7A, 0D, 31, 5E...
 
[+]

Entropy:
7.8427  (probably packed)

Code size:
113 KB (115,712 bytes)

The file beservice.exe has been seen being distributed by the following 2 URLs.

Scan beservice.exe - Powered by Reason Core Security