AA_v3.exe

Classification: Malicious

AA_v3.exe is a malicious file sample. Linked to Flawedammyy malware. Reported by 3 threat sources, last seen 2026-09-02.

Detection summary

  • 0 antivirus detections (54% detection ratio)
  • 0 IDS alerts
  • 2 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Malware families: FLAWEDAMMYY (S0381)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Cyber Threat Alliance 2026-08-08 10:16:25 2026-09-02 10:23:58 malicious-activity
Ammyyadmin Triage 2026-04-14 09:13:20 2026-08-28 12:28:01 malicious-activity
Flawedammyy Triage 2026-03-16 00:09:53 2026-03-16 00:09:53 malicious-activity S0381 FlawedAmmyy
RemoteAdmin.Ammyy Hybrid-Analysis 2020-09-25 13:00:09 2020-09-25 13:00:09

Tags

ammyyadmin flawedammyy bootkit discovery persistence trojan rat revoked_codesign

Sample information

Filenames
AA_v3.exe, AA_v3.10.exe, AA_v3-3.exe, uzaktan yardım.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
817272 bytes
MD5
90aadf2247149996ae443e2c82af3730
SHA-1
050b7eba825412b24e3f02d76d7da5ae97e10502
SHA-256
ee573647477339784dcef81024de1be1762833a20e5cc2b89a93e47d05b86b6a
SHA-512
eec32bb82b230dd309c29712e72d4469250e651449e127479d178eddbafd5a46ec8048a753bc2c1a0fdf1dc3ed72a9453ca66fb49cbf0f95a12704e5427182be
First indexed
2020-09-25 13:00:09
Last updated
2026-08-28 12:57:32

Process list

NameCommand line
AA_v3.exe
AA_v3.exe-service -lunch