Is AyazMt2_Global.exe safe?Malicious
This unsigned executable performs process injection and direct-IP communication, characteristic of a downloader retrieving unauthorized components from remote servers.
- 1 high-confidence signature or behavior rule matched this file.
- 2 of 74 antivirus engines flagged the file, including AhnLab-V3 and Zillya.
- One or more independent reference checks were incomplete or unavailable.
bdf2f4914525937e67…a600205a1cBefore opening
Do not open or run it. Delete the file from the device.
If you already ran it
Disconnect from the internet, run a full antivirus scan, then secure important accounts from a clean device.
Intelligence
The complete saved assessment, kept intact and grounded in the scan evidence.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The file is unsigned and lacks any established publisher history, which is atypical for legitimate software. During execution, it triggered high-severity alerts for process injection (T1055) and direct-IP communication, both of which are common techniques used by malware to bypass security monitoring. While the detection rate across our antivirus network is low, the observed behavioral patterns strongly align with malicious downloader activity. The file retrieves multiple compressed components from an external cloud host, which is consistent with the downloader classification provided by our engines.
Our analysis identified high-risk behaviors including process injection and direct-IP command-and-control communication. Given the lack of a valid digital signature and the retrieval of external components, this file is considered a security risk.
What We Detected
The file AyazMt2_Global.exe is an unsigned executable that exhibits suspicious behavioral patterns. Our analysis identified the use of process injection (MITRE T1055), a technique used to hide malicious code within legitimate system processes to evade detection.
Threat Behavior
The sample bypasses standard reputation systems by communicating directly with external IP addresses rather than using DNS. It also acts as a downloader, retrieving multiple compressed files (e.g., .lz files) from metin35.turklokasyon.cloud, which are then written to the local system. This behavior is consistent with the delivery of secondary payloads.
What To Do Now
We recommend blocking this file from executing in your environment. If this file was downloaded as part of a game installation, ensure you are using official, verified sources. Perform a full system scan if this file has already been executed.
Where this verdict could be wrong2 caveats
- The majority of engines (72/74) did not detect the file as malicious, which could suggest a false positive or a highly targeted, novel threat.
- The file may be a legitimate game patcher for a private server, as indicated by the filename 'AyazMt2' and the download of game-related assets like 'metin2client.bin'.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Unsigned executable
- Process injection (T1055)
- Direct-IP C2 communication
- Downloader behavior
- Retrieves external components
Do not execute this file. Remove it from your system and ensure your security software is updated to block similar unauthorized downloaders.
Behavior
Plain-English impact first, then the observed runtime evidence.
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Threat context
How downloaders work
This file is a delivery vehicle. On its own it can look small and harmless, but its job is to quietly pull down and install the REAL payload — often a stealer, ransomware, or bot — from a server the attacker controls.
Bottom line:Because the dangerous part arrives later, early scans can look cleaner than the threat really is.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 8.8.8.8
- 169.150.236.106
- 104.21.14.136
- 162.159.36.2
- http://patcher.metin35.com/ayaz_metin2torrent.config.xml
- http://metin35.turklokasyon.cloud/ayazmt2/0.0.0.1/crclist
- http://metin35.turklokasyon.cloud/ayazmt2/0.0.0.1/metin2client.bin.lz
- http://metin35.turklokasyon.cloud/ayazmt2/0.0.0.1/pack/locale.edata.lz
- http://metin35.turklokasyon.cloud/ayazmt2/0.0.0.1/pack/locale.epk.lz
- http://metin35.turklokasyon.cloud/ayazmt2/0.0.0.1/pack/root.edata.lz
- temp\bdf2f4914525937e6745ebb8e548cadffe6d07b6aeda3f254848a3a600205a1c.stderr.log
- temp\bdf2f4914525937e6745ebb8e548cadffe6d07b6aeda3f254848a3a600205a1c.stdout.log
- C:\Users\<USER>\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9C6Q2GAH\ayaz_metin2torrent.config[1].xml
- C:\Users\<USER>\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9C6Q2GAH\crclist[1]
- C:/Users/<USER>/Downloads//metin2client.bin
- C:\Users\<USER>\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9C6Q2GAH\ayaz_metin2torrent.config[1].xml
- C:\Users\<USER>\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9C6Q2GAH\crclist[1]
- D1A41C06-CECA-45b0-A3C0-347271EED100
- \Sessions\1\BaseNamedObjects\D1A41C06-CECA-45b0-A3C0-347271EED100
Files this sample writes at runtime
This file drops 8 children at runtime. None are currently flagged malicious in our cache.
- e3b0c44298fc1c149afb…52b855Never scannednever seen before
- 35606d78cc61fbdcff06…60e13aNever scannednever seen before
- 305b287502650f806f0a…c33617Never scannednever seen before
- 3fca4b6edf4028987659…7554f6Never scannednever seen before
- 70fb3915c7fad3a33892…f75d4bNever scannednever seen before
- e89d3838febef3c4c709…efb9a6Never scannednever seen before
- 441b290e7dc6334eb502…ae912dNever scannednever seen before
- 0b28546be22c71834501…d64f5fNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Detection sources at a glance
Category: downloader
Available reference checks returned no match, but at least one source was unavailable. This is not a clean result.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
Evidence"C:\Users\user\Desktop\AyazMt2_Global.exe"Sample contacted 4 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence8.8.8.8 · 169.150.236.106 · 104.21.14.136
2 of 74 engines flagged this file
View all 74 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- AyazMt2_Global.exe
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 6.5 MB
- Last analyzed
- Jul 23, 2026, 4:13 PM UTC
bdf2f4914525937e6745ebb8e548cadffe6d07b6aeda3f254848a3a600205a1cSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
Don't open or run this file. Delete it from your Downloads (or wherever you saved it), then empty the Recycle Bin.
If you already opened it, disconnect from the internet and run a full scan with your antivirus — Windows Security, built into Windows, is sufficient.
If you typed any passwords while it was open, change them from a device you trust.
In future, only download software from the official website or an official app store.
Safety FAQ
- Yes — AyazMt2_Global.exe is malicious, so do not run it, and delete it. 2 of 74 antivirus engines flag it (family: downloader). It behaves as a downloader/dropper whose job is to pull additional malware onto the device. If you've already run it, see the removal and recovery steps below.
- AyazMt2_Global.exe is a Windows executable program, about 6.5 MB. Our analysis identifies it as malicious (family: downloader) — a downloader/dropper whose job is to pull additional malware onto the device. Because a file's name and icon can be faked, the safest way to identify it is by its cryptographic hash (below), not its filename.
- 2 of 74 antivirus engines flagged AyazMt2_Global.exe, 2 of them as outright malicious. A detection rate at this level is a reliable signal that the file is dangerous.
- Act quickly. 1) Disconnect the device from the internet to stop the malware communicating or spreading. 2) Run a full scan with reputable anti-malware software (such as Malwarebytes) and quarantine everything it finds. 3) Change your important passwords from a DIFFERENT, clean device — many threats log keystrokes or steal saved credentials. 4) If you bank or shop on this device, watch closely for fraud and alert your bank. 5) For a confirmed infection, the most reliable fix is to back up your personal files and reinstall the operating system for a clean start.
- To remove AyazMt2_Global.exe: 1) restart into Safe Mode (Safe Mode with Networking if you need to download a tool) so the malware doesn't auto-start. 2) Run a full scan with reputable anti-malware software and let it quarantine or delete the detections. 3) Delete the original AyazMt2_Global.exe file and empty the Recycle Bin/Trash. 4) Check your browser extensions, startup items, and scheduled tasks for anything unfamiliar. 5) Reboot and scan again to confirm it's gone. If detections keep coming back, a clean operating-system reinstall is the most dependable cure.
- AyazMt2_Global.exe is classified as a downloader/dropper whose job is to pull additional malware onto the device. Engines attribute it to the downloader family. Knowing the family matters because it tells you the likely impact — data theft, remote control, file encryption, or unwanted ads — and guides the cleanup.
- The SHA-256 hash of AyazMt2_Global.exe is bdf2f4914525937e6745ebb8e548cadffe6d07b6aeda3f254848a3a600205a1c, and its MD5 is 19d43ad00968b18355ab88b7e90e136b. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
- This report reflects the scan run on July 23, 2026. Because a file's hash never changes, the identity of AyazMt2_Global.exe is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.