beservice_x64.exe

Bastian Suter

This is a setup program which is used to install the application. The file has been seen being downloaded from www.battleye.com and multiple other hosts.
Publisher:
Bastian Suter  (signed and verified)

MD5:
973f1ff3da2da1419cd922ad98b9b561

SHA-1:
e72ab784b55856b59143c706a09d74be5b3328f5

SHA-256:
3e62533cdcc8bf8522b7c708c3369a8dc79e41b79436888ab1f23c186283f218

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/16/2024 4:57:38 PM UTC  (today)

File size:
914.9 KB (936,832 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\steam\steamapps\common\arma 2 operation arrowhead\expansion\battleye\beservice_x64.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
3/5/2014 12:00:00 AM

Valid to:
5/13/2015 1:00:00 PM

Subject:
CN=Bastian Suter, O=Bastian Suter, L=Tübingen, S=Baden-Württemberg, C=DE

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0F01D40307832B7F6747D7AB752213DC

File PE Metadata
Compilation timestamp:
3/3/2015 8:16:03 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
8.0

CTPH (ssdeep):
24576:UwKaTvF15GXehX/59CGsKdEq5/bVK3itI0v:ULab1We95wsEq5jVKa7

Entry address:
0x139195

Entry point:
E9, D2, C1, FF, FF, 0A, 3C, AA, 50, FF, 17, 05, 83, BB, 22, F9, 8B, 15, 2E, 56, 1B, 4B, A2, 81, 09, 8C, CA, BB, 8C, 4B, CD, F2, 83, 60, 03, B8, 79, 25, 97, 55, 12, 84, 7C, 0B, 6B, 9A, FC, 11, 3D, A8, E8, A0, 77, 09, EB, BA, DA, 49, 10, 37, D5, FA, 3B, C5, 67, 8A, 5D, 62, 58, 0D, 57, 94, 42, 74, 81, 2F, 43, A3, 52, 06, ED, 6F, E1, EB, 3D, 95, B8, BD, 08, EB, 4B, 8D, 94, B1, 18, 63, BB, 5F, 6C, CA, DE, 06, C0, B6, DF, AA, 03, 36, 82, F8, 35, A3, 2F, 30, 17, 2B, CB, 2B, 12, ED, FB, 97, C7, 13, 9B, 6C, 4F, 74...
 
[+]

Entropy:
7.8765

Packer / compiler:
tElock 0.99 - 1.0 private

Code size:
97 KB (99,328 bytes)

The file beservice_x64.exe has been discovered within the following program.

DayZ  by Bohemia Interactive
www.dayzgame.com
About 9% of users remove it
 
Powered by Should I Remove It?

The file beservice_x64.exe has been seen being distributed by the following 2 URLs.

Scan beservice_x64.exe - Powered by Reason Core Security