aa_v3.exe

Ammyy Admin

Ammyy LLC

The application aa_v3.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from www.ammyy.com.
Publisher:
Ammyy LLC

Product:
Ammyy Admin

Version:
3.5

MD5:
94fd70d6a78ecbb78766616734c4b84b

SHA-1:
f18eff4013cbf3e7063b448b914a2b2d1d782e57

SHA-256:
34fbfa6b04820ff6df62c35db29f1cc93b5dcdb7034428c652f3a917f6725ceb

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 6:10:14 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic
16.8.9.22

File size:
823.5 KB (843,256 bytes)

Product version:
3.5

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\aa_v3.exe

File PE Metadata
Compilation timestamp:
5/29/2015 4:06:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:BVFUEuNmwvGrw9i0aTGRGicBckyyFRtWY1iOFTsvOVV0gO7gVVDq:dUEUUw9RaTNicBrPFRtJ1i0TsC5FRq

Entry address:
0x7C3CE

Entry point:
33, F2, 24, E5, 69, DA, 45, B7, A9, 03, 45, 20, D6, 35, 6B, A1, 00, 00, 80, EA, 26, 0F, AF, D2, 69, C0, D5, EC, BF, 51, 0F, CB, E8, 10, 00, 00, 00, 3B, D5, 70, 07, 31, D0, BA, 2A, 6F, 7D, 23, 4A, 2A, CC, 3B, D9, 80, F5, 11, F6, C6, 18, F7, C3, 54, 3F, 8A, D0, 35, 80, 55, 00, 00, FF, C3, 5D, 0F, 6E, ED, 74, 04, 0B, F7, FF, C9, 1C, 38, 81, F5, E8, 69, 00, 00, 4A, 0F, 7E, EE, 85, DE, 88, F7, 81, C6, B9, 52, 04, 00, 88, D5, 81, C6, 3A, 0A, 00, 00, B8, BC, 28, EF, 96, EB, 08, 32, CF, C7, C3, D9, 3B, 77, A1, 0F...
 
[+]

Entropy:
6.7984

Code size:
520 KB (532,480 bytes)

The file aa_v3.exe has been seen being distributed by the following URL.

Remove aa_v3.exe - Powered by Reason Core Security