beservice.exe

Bastian Suter

This is a setup program which is used to install the application. It runs as a separate (within the context of its own process) windows Service named “BattlEye Service”. The file has been seen being downloaded from www.battleye.com.
Publisher:
Bastian Suter  (signed and verified)

MD5:
c88b130365524ec69f6b8e0d31d7561d

SHA-1:
2f120fb466a8c9816b3809465e2e4d69c5abcaeb

SHA-256:
5d3797c93420477f4509c037511d497448efda7d567e15cb623fb5eee9209146

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/14/2025 11:42:31 AM UTC  (today)

File size:
1 MB (1,060,352 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\common files\battleye\beservice.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
4/20/2015 3:00:00 AM

Valid to:
6/13/2018 3:00:00 PM

Subject:
CN=Bastian Suter, O=Bastian Suter, L=Tübingen, S=Baden-Württemberg, C=DE

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0CEC25760619513A72214FB3C86C376D

File PE Metadata
Compilation timestamp:
6/9/2015 5:43:27 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
8.0

CTPH (ssdeep):
24576:18WHHXzjxsu6H15yLNjld6DNrwSaSOg56zy87mHN:18oDjxUH15yNzarwQozZmt

Entry address:
0x1B7CA2

Entry point:
E9, B1, 09, 00, 00, 86, 18, 09, D6, 67, 90, 73, 6D, E5, 42, 9D, 78, 69, FD, A4, E7, 8A, 6D, F0, 0F, DE, F1, 74, 7F, 0A, 81, A8, DF, B6, 5D, E4, 0F, DA, E2, AA, 1E, DD, 2E, 84, E8, BD, BB, EC, 40, FF, 46, 23, 21, 02, B6, 77, A0, 85, 74, 5F, 64, EF, 6C, 7F, C6, A3, 86, 24, C0, 7D, DE, D6, 8C, 95, 9E, 7C, 46, 65, A1, E2, 31, 42, 0F, 2A, FD, 70, 57, EE, D9, 74, 2F, 2A, A1, 88, F7, A6, 15, 44, 7B, D2, 15, F8, D7, 0D, 3B, DC, 54, AB, 54, 66, C8, BD, 1E, C8, 10, 9B, AC, 17, 14, 26, E5, 34, 1F, 78, 9D, 1A, 19, 2B...
 
[+]

Packer / compiler:
Xtreme-Protector v1.05

Code size:
104.5 KB (107,008 bytes)

Service
Display name:
BattlEye Service

Service name:
BEService

Type:
Win32OwnProcess


The file beservice.exe has been seen being distributed by the following URL.

Scan beservice.exe - Powered by Reason Core Security