File verdict·MT AI Engine assessment
Our call

Is AyazMt2_Global.exe safe?Malicious

Do not run this file
15Safety ratingCritical risk

This unsigned executable performs process injection and direct-IP communication, characteristic of a downloader retrieving unauthorized components from remote servers.

downloader
Evidence snapshot
  • 1 high-confidence signature or behavior rule matched this file.
  • 2 of 74 antivirus engines flagged the file, including AhnLab-V3 and Zillya.
  • One or more independent reference checks were incomplete or unavailable.
AyazMt2_Global.exe
6.5 MB
bdf2f4914525937e67a600205a1c
Antivirus
2 of 74 flagged
Code signing
Unsigned
First seen
First seen 28 days ago
01

Before opening

Do not open or run it. Delete the file from the device.

02

If you already ran it

Disconnect from the internet, run a full antivirus scan, then secure important accounts from a clean device.

Chapter 02

Intelligence

The complete saved assessment, kept intact and grounded in the scan evidence.

MT AI Engine · Verdict analysis

The reasoning behind this verdict

This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.

85%Confidence
Very high
Reasoning

The file is unsigned and lacks any established publisher history, which is atypical for legitimate software. During execution, it triggered high-severity alerts for process injection (T1055) and direct-IP communication, both of which are common techniques used by malware to bypass security monitoring. While the detection rate across our antivirus network is low, the observed behavioral patterns strongly align with malicious downloader activity. The file retrieves multiple compressed components from an external cloud host, which is consistent with the downloader classification provided by our engines.

Analyst conclusion

Our analysis identified high-risk behaviors including process injection and direct-IP command-and-control communication. Given the lack of a valid digital signature and the retrieval of external components, this file is considered a security risk.

Detailed assessment

What We Detected

The file AyazMt2_Global.exe is an unsigned executable that exhibits suspicious behavioral patterns. Our analysis identified the use of process injection (MITRE T1055), a technique used to hide malicious code within legitimate system processes to evade detection.

Threat Behavior

The sample bypasses standard reputation systems by communicating directly with external IP addresses rather than using DNS. It also acts as a downloader, retrieving multiple compressed files (e.g., .lz files) from metin35.turklokasyon.cloud, which are then written to the local system. This behavior is consistent with the delivery of secondary payloads.

What To Do Now

We recommend blocking this file from executing in your environment. If this file was downloaded as part of a game installation, ensure you are using official, verified sources. Perform a full system scan if this file has already been executed.

Where this verdict could be wrong2 caveats
  • The majority of engines (72/74) did not detect the file as malicious, which could suggest a false positive or a highly targeted, novel threat.
  • The file may be a legitimate game patcher for a private server, as indicated by the filename 'AyazMt2' and the download of game-related assets like 'metin2client.bin'.

These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.

Points against
  • Unsigned executable
  • Process injection (T1055)
  • Direct-IP C2 communication
  • Downloader behavior
  • Retrieves external components
Recommended action

Do not execute this file. Remove it from your system and ensure your security software is updated to block similar unauthorized downloaders.

Chapter 03

Behavior

Plain-English impact first, then the observed runtime evidence.

What this file does

Observed actions and their security significance

  • High concern: Injected code into another process, a technique that can conceal execution.

  • Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.

These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.

Threat context

How downloaders work

This file is a delivery vehicle. On its own it can look small and harmless, but its job is to quietly pull down and install the REAL payload — often a stealer, ransomware, or bot — from a server the attacker controls.

Bottom line:Because the dangerous part arrives later, early scans can look cleaner than the threat really is.

Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
2

Adversary techniques mapped to the MITRE ATT&CK framework.

T1055· Process injectionT1071· Application protocol
Spawned processes
1
$(unnamed)
"C:\Users\user\Desktop\AyazMt2_Global.exe"
Network activity
14
IP addresses4
  • 8.8.8.8
  • 169.150.236.106
  • 104.21.14.136
  • 162.159.36.2
URLs10
  • http://patcher.metin35.com/ayaz_metin2torrent.config.xml
  • http://metin35.turklokasyon.cloud/ayazmt2/0.0.0.1/crclist
  • http://metin35.turklokasyon.cloud/ayazmt2/0.0.0.1/metin2client.bin.lz
  • http://metin35.turklokasyon.cloud/ayazmt2/0.0.0.1/pack/locale.edata.lz
  • http://metin35.turklokasyon.cloud/ayazmt2/0.0.0.1/pack/locale.epk.lz
  • http://metin35.turklokasyon.cloud/ayazmt2/0.0.0.1/pack/root.edata.lz
+4 more
Filesystem & mutexes
19
Files written15
  • temp\bdf2f4914525937e6745ebb8e548cadffe6d07b6aeda3f254848a3a600205a1c.stderr.log
  • temp\bdf2f4914525937e6745ebb8e548cadffe6d07b6aeda3f254848a3a600205a1c.stdout.log
  • C:\Users\<USER>\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9C6Q2GAH\ayaz_metin2torrent.config[1].xml
  • C:\Users\<USER>\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9C6Q2GAH\crclist[1]
  • C:/Users/<USER>/Downloads//metin2client.bin
+10 more
Files deleted2
  • C:\Users\<USER>\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9C6Q2GAH\ayaz_metin2torrent.config[1].xml
  • C:\Users\<USER>\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9C6Q2GAH\crclist[1]
Mutexes created2
  • D1A41C06-CECA-45b0-A3C0-347271EED100
  • \Sessions\1\BaseNamedObjects\D1A41C06-CECA-45b0-A3C0-347271EED100
Dropped payload

Files this sample writes at runtime

This file drops 8 children at runtime. None are currently flagged malicious in our cache.

8 unseen
  • e3b0c44298fc1c149afb52b855Never scanned
    never seen before
  • 35606d78cc61fbdcff0660e13aNever scanned
    never seen before
  • 305b287502650f806f0ac33617Never scanned
    never seen before
  • 3fca4b6edf40289876597554f6Never scanned
    never seen before
  • 70fb3915c7fad3a33892f75d4bNever scanned
    never seen before
  • e89d3838febef3c4c709efb9a6Never scanned
    never seen before
  • 441b290e7dc6334eb502ae912dNever scanned
    never seen before
  • 0b28546be22c71834501d64f5fNever scanned
    never seen before
Chapter 04

Detection & Forensics

Consensus, attribution, signatures, code structure, prevalence, and identity.

Evidence map

Detection sources at a glance

1 completed · 3 unavailable
Antivirus
Threat match
2/74 flagged
Malware samples
Unavailable
unavailable
Researcher rules
Unavailable
unavailable
Reference software
Unavailable
unavailable
Threat attribution
downloader

Category: downloader

External intelligence
No confirmed researcher-database hit

Available reference checks returned no match, but at least one source was unavailable. This is not a clean result.

Rule-based evidence

Signatures and behavior heuristics

A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.

2 heuristics
MITRE ATT&CK profile
Defense evasion× 1C2× 1
Behavior heuristics
Deterministic patterns derived from scan data and observed runtime behavior
  • ProcessInjectionhigh

    MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.

    Evidence
    "C:\Users\user\Desktop\AyazMt2_Global.exe"
  • DirectIpC2medium

    Sample contacted 4 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    8.8.8.8 · 169.150.236.106 · 104.21.14.136
Antivirus consensus

2 of 74 engines flagged this file

2 malicious0 suspicious72 not flagged
Tier-117 engines
0flagged
Tier-240 engines
1flagged
Low-trust17 engines
1flagged
AhnLab-V3malicious
Trojan/Win32.HDC.C793568
Zillyamalicious
Downloader.Delf.Win32.43238
View all 74 engine results
AhnLab-V3DET
ZillyaDET
AcronisOK
AlibabaOK
alibabacloudOK
ALYacOK
Antiy-AVLOK
APEXOK
ArcabitOK
AvastOK
Avast-Mobiletyp
AVGOK
AviraOK
BitDefenderOK
BitDefenderFalxtyp
BkavOK
CAT-QuickHealOK
ClamAVOK
CMCOK
CrowdStrikeOK
CTXOK
CylanceOK
CynetOK
DrWebOK
ElasticOK
EmsisoftOK
ESET-NOD32OK
F-SecureOK
FortinetOK
GDataOK
GoogleOK
GridinsoftOK
huorongOK
Ikarusfai
JiangminOK
K7AntiVirusOK
K7GWOK
KasperskyOK
KingsoftOK
LionicOK
MalwarebytesOK
MaxSecureOK
McAfeeDOK
MicrosoftOK
MicroWorld-eScanOK
NANO-AntivirusOK
PaloaltoOK
PandaOK
RisingOK
SangforOK
SentinelOneOK
SkyhighOK
SophosOK
SUPERAntiSpywareOK
SymantecOK
SymantecMobileInsighttyp
TACHYONOK
tehtrisOK
TencentOK
TrapmineOK
TrellixENSOK
TrendMicroOK
TrendMicro-HouseCallOK
Trustlooktyp
VaristOK
VBA32OK
VIPREOK
VirITOK
ViRobotOK
WebrootOK
XcitiumOK
YandexOK
ZoneAlarmOK
ZonerOK
PE forensics

Section entropy & packers

No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.

ent 8.00Unpacked
Section entropy7 sections
.text
6.60
.rdata
4.91
.data
5.49
.tls
0.00
.SHARED
0.00
.rsrc
4.38
.reloc
5.14
0.0Packed threshold 7.28.0
Prevalence

How widely this file has been seen

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
56
Moderate upload volume.
Total submissions
73
Includes repeat uploads by the same source.
First seen
28d ago
Jun 25, 2026
Prevalence quadrant
Rare · New
Needs evidence-led scrutiny
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Often established software
File identity

Fingerprint and provenance

File name
AyazMt2_Global.exe
Format
Win32 EXE
Code signing
No verified publisher
Size
6.5 MB
Last analyzed
Jul 23, 2026, 4:13 PM UTC
SHA-256
bdf2f4914525937e6745ebb8e548cadffe6d07b6aeda3f254848a3a600205a1c
Chapter 05

Safety & FAQ

Complete recovery guidance and answers for the next decision.

What to do now

This file is dangerous. Treat it as harmful and remove it.

  1. Don't open or run this file. Delete it from your Downloads (or wherever you saved it), then empty the Recycle Bin.

  2. If you already opened it, disconnect from the internet and run a full scan with your antivirus — Windows Security, built into Windows, is sufficient.

  3. If you typed any passwords while it was open, change them from a device you trust.

  4. In future, only download software from the official website or an official app store.

Frequently asked

Safety FAQ

  • Yes — AyazMt2_Global.exe is malicious, so do not run it, and delete it. 2 of 74 antivirus engines flag it (family: downloader). It behaves as a downloader/dropper whose job is to pull additional malware onto the device. If you've already run it, see the removal and recovery steps below.
Unknown files are temporarily processed and submitted to VirusTotal. MalwareTips does not retain the binary after processing. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.