beservice.exe

Bastian Suter

This is a setup program which is used to install the application. The file has been seen being downloaded from www.battleye.com.
Publisher:
Bastian Suter  (signed and verified)

MD5:
0f82557498afb44700427ca9078e2efd

SHA-1:
feb46c615c9ed38af2983f00bc324353eb7ebc21

SHA-256:
cbf166ed8207258112c61aa863c6875ee264c746929dbbcac59cb1733a3bf620

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/13/2018 5:26:40 PM UTC  (today)

File size:
903.9 KB (925,568 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\steam\steamapps\common\arma 2 operation arrowhead\expansion\battleye\beservice.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
3/4/2014 5:00:00 PM

Valid to:
5/13/2015 6:00:00 AM

Subject:
CN=Bastian Suter, O=Bastian Suter, L=Tübingen, S=Baden-Württemberg, C=DE

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0F01D40307832B7F6747D7AB752213DC

File PE Metadata
Compilation timestamp:
5/10/2015 3:23:44 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

CTPH (ssdeep):
24576:YZPCLoJOROyJLNK2vh3Gx8XKjJdjl6LG/52miHcqKLzr:YhCLVhLJ3GxoEf5V/ujsv

Entry address:
0x17DAC4

Entry point:
E9, C0, 65, FC, FF, B0, 2E, C6, 04, 24, BF, 0F, A3, F6, 84, DE, 88, 14, 24, F2, AE, 88, 2C, 24, E8, 3F, C8, F3, FF, 8B, 74, 24, 70, E9, 2C, 1D, 00, 00, 66, FF, C9, 0F, B6, 06, 66, B9, 48, 25, 66, 0F, A5, E9, 66, D1, D9, 0F, BE, CA, 00, D8, C0, FD, 06, 0F, B6, CA, 66, 0F, BA, F9, 0F, 04, 73, 66, 0F, BD, CB, 0F, C9, 38, CB, 21, F1, F6, D8, B1, 6B, 66, 0F, BA, E9, 05, 68, C0, 71, 53, 6C, 0F, 97, C1, C0, C0, 05, F9, 10, C5, 00, C3, E8, FE, 26, 00, 00, 87, 74, 24, 44, 66, 0F, BE, F1, 66, F7, D6, F7, D6, 68, BA...
 
[+]

Entropy:
7.8579

Packer / compiler:
Xtreme-Protector v1.05

Code size:
96 KB (98,304 bytes)

The file beservice.exe has been discovered within the following program.

DayZ  by Bohemia Interactive
www.dayzgame.com
About 9% of users remove it
 
Powered by Should I Remove It?

The file beservice.exe has been seen being distributed by the following URL.

Scan beservice.exe - Powered by Reason Core Security