AA_v3.exe
Classification: Malicious
AA_v3.exe is a malicious file sample. Linked to Flawedammyy malware. Reported by 3 threat sources, last seen 2026-09-02.
Detection summary
- 0 antivirus detections (54% detection ratio)
- 0 IDS alerts
- 2 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: FLAWEDAMMYY (S0381)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Cyber Threat Alliance | 2026-08-08 10:16:25 | 2026-09-02 10:23:58 | malicious-activity | |
| Ammyyadmin | Triage | 2026-04-14 09:13:20 | 2026-08-28 12:28:01 | malicious-activity | |
| Flawedammyy | Triage | 2026-03-16 00:09:53 | 2026-03-16 00:09:53 | malicious-activity | S0381 FlawedAmmyy |
| RemoteAdmin.Ammyy | Hybrid-Analysis | 2020-09-25 13:00:09 | 2020-09-25 13:00:09 |
Tags
ammyyadmin flawedammyy bootkit discovery persistence trojan rat revoked_codesignSample information
- Filenames
- AA_v3.exe, AA_v3.10.exe, AA_v3-3.exe, uzaktan yardım.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 817272 bytes
- MD5
90aadf2247149996ae443e2c82af3730- SHA-1
050b7eba825412b24e3f02d76d7da5ae97e10502- SHA-256
ee573647477339784dcef81024de1be1762833a20e5cc2b89a93e47d05b86b6a- SHA-512
eec32bb82b230dd309c29712e72d4469250e651449e127479d178eddbafd5a46ec8048a753bc2c1a0fdf1dc3ed72a9453ca66fb49cbf0f95a12704e5427182be- First indexed
- 2020-09-25 13:00:09
- Last updated
- 2026-08-28 12:57:32
Process list
| Name | Command line |
|---|---|
| AA_v3.exe | |
| AA_v3.exe | -service -lunch |