{
  "ml": {
    "v": "4",
    "fs": [
      {
        "id": 0,
        "prob": 0.9411607384681702,
        "class": 0
      }
    ],
    "prob": 0.94116074,
    "class": 0,
    "version": "v16.16",
    "thresholds": [
      0.9815004,
      0.99404883
    ],
    "analyzed_at": "2026-05-01T18:52:29Z"
  },
  "path": "x86__64__lsb__unix-system-v__gcc-5.5.0__O1__no-obf__unstripped__coreutils-8.30__dircolors",
  "raw": {
    "v": "4",
    "fs": [
      {
        "f": "O₂(CI)H₂(FPo)Md₃(HeBi₂)",
        "x": 5,
        "id": 0,
        "is": [
          "",
          "getenv",
          "free",
          "abort",
          "errno_location",
          "strncmp",
          "exit",
          "fpending",
          "puts",
          "textdomain",
          "fclose",
          "bindtextdomain",
          "dcgettext",
          "ctype_get_mb_cur_max",
          "getopt_long",
          "mbrtowc",
          "dup2",
          "strrchr",
          "lseek",
          "fnmatch",
          "memset",
          "freopen",
          "close",
          "libc_start_main",
          "memcmp",
          "fputs_unlocked",
          "calloc",
          "getdelim",
          "strcmp",
          "strndup",
          "gmon_start__",
          "memcpy",
          "fileno",
          "malloc",
          "fflush",
          "nl_langinfo",
          "freading",
          "fwrite_unlocked",
          "realloc",
          "setlocale",
          "printf_chk",
          "error",
          "open",
          "fseeko",
          "cxa_atexit",
          "exit",
          "fwrite",
          "fprintf_chk",
          "mbsinit",
          "iswprint",
          "ctype_b_loc"
        ],
        "ms": {
          "elf": {
            "e_type": 2.0,
            "has_got": true,
            "has_plt": true,
            "has_note": true,
            "e_machine": 62.0,
            "class_bits": 64.0,
            "note_count": 1.0,
            "nx_enabled": true,
            "entry_point": 4200048.0,
            "needed_libs": 1.0,
            "dynsym_count": 66.0,
            "has_eh_frame": true,
            "symtab_count": 250.0,
            "dynrela_count": 7.0,
            "entry_section": ".text",
            "little_endian": true,
            "pltreloc_count": 49.0,
            "has_interpreter": true,
            "fini_array_count": 1.0,
            "init_array_count": 1.0,
            "program_header_count": 8.0,
            "section_header_count": 30.0,
            "load_segment_max_p_memsz": 35124.0,
            "load_segment_max_p_filesz": 35124.0,
            "section_relocation_group_count": 2.0
          },
          "binary": {
            "code_size": 16068.0,
            "file_size": 47888.0,
            "entry_point": 4200048.0,
            "has_overlay": true,
            "code_entropy": 3.95,
            "data_entropy": 3.03,
            "export_count": 141.0,
            "import_count": 51.0,
            "overlay_size": 1924.0,
            "string_count": 480.0,
            "overlay_ratio": 0.04,
            "section_count": 29.0,
            "avg_complexity": 5.22,
            "function_count": 146.0,
            "import_density": 3.25,
            "max_complexity": 335.0,
            "string_density": 30.59,
            "aliased_exports": 58.0,
            "overall_entropy": 2.74,
            "overlay_entropy": 1.56,
            "avg_basic_blocks": 6.14,
            "avg_section_size": 1582.86,
            "dependency_count": 1.0,
            "entropy_variance": 1.6,
            "function_density": 9.3,
            "avg_function_size": 106.1,
            "avg_string_length": 20.35,
            "complexity_per_kb": 0.33,
            "max_string_length": 272.0,
            "avg_string_entropy": 3.22,
            "code_to_data_ratio": 0.54,
            "data_to_file_ratio": 0.0,
            "text_to_file_ratio": 0.32,
            "total_basic_blocks": 896.0,
            "string_length_stddev": 24.06,
            "largest_section_ratio": 0.32,
            "sentence_string_count": 87.0,
            "sentence_string_ratio": 0.18,
            "behavioral_import_ratio": 0.02,
            "function_analysis_depth": 2.0,
            "high_complexity_functions": 1.0
          }
        },
        "ss": [
          [
            0,
            "textdomain"
          ],
          [
            512,
            "/lib64/ld-linux-x86-64.so.2"
          ],
          [
            2595,
            "fflush"
          ],
          [
            2602,
            "__printf_chk"
          ],
          [
            2615,
            "fnmatch"
          ],
          [
            2623,
            "setlocale"
          ],
          [
            2633,
            "mbrtowc"
          ],
          [
            2641,
            "strncmp"
          ],
          [
            2649,
            "optind"
          ],
          [
            2656,
            "strrchr"
          ],
          [
            2664,
            "dcgettext"
          ],
          [
            2674,
            "error"
          ],
          [
            2685,
            "iswprint"
          ],
          [
            2694,
            "realloc"
          ],
          [
            2702,
            "abort"
          ],
          [
            2720,
            "program_invocation_name"
          ],
          [
            2744,
            "__ctype_get_mb_cur_max"
          ],
          [
            2767,
            "calloc"
          ],
          [
            2774,
            "memset"
          ],
          [
            2781,
            "__errno_location"
          ],
          [
            2798,
            "memcmp"
          ],
          [
            2810,
            "__fprintf_chk"
          ],
          [
            2824,
            "stdout"
          ],
          [
            2831,
            "lseek"
          ],
          [
            2837,
            "memcpy"
          ],
          [
            2844,
            "fclose"
          ],
          [
            2851,
            "malloc"
          ],
          [
            2858,
            "__strndup"
          ],
          [
            2868,
            "mbsinit"
          ],
          [
            2876,
            "nl_langinfo"
          ],
          [
            2888,
            "__ctype_b_loc"
          ],
          [
            2902,
            "getenv"
          ],
          [
            2909,
            "_obstack_allocated_p"
          ],
          [
            2930,
            "__freading"
          ],
          [
            2941,
            "stderr"
          ],
          [
            2948,
            "_obstack_begin_1"
          ],
          [
            2965,
            "_obstack_newchunk"
          ],
          [
            2983,
            "getopt_long"
          ],
          [
            2995,
            "freopen"
          ],
          [
            3003,
            "fileno"
          ],
          [
            3010,
            "_obstack_memory_used"
          ],
          [
            3031,
            "__getdelim"
          ],
          [
            3042,
            "fwrite"
          ],
          [
            3049,
            "__fpending"
          ],
          [
            3060,
            "program_invocation_short_name"
          ],
          [
            3090,
            "obstack_alloc_failed_handler"
          ],
          [
            3119,
            "_obstack_begin"
          ],
          [
            3134,
            "bindtextdomain"
          ],
          [
            3149,
            "fwrite_unlocked"
          ],
          [
            3172,
            "__libc_start_main"
          ],
          [
            3190,
            "fseeko"
          ],
          [
            3197,
            "_obstack_free"
          ],
          [
            3211,
            "fputs_unlocked"
          ],
          [
            3226,
            "__progname"
          ],
          [
            3237,
            "__progname_full"
          ],
          [
            3253,
            "__cxa_atexit"
          ],
          [
            3266,
            "__gmon_start__"
          ],
          [
            3303,
            "GLIBC_2.14"
          ],
          [
            6381,
            "AWAVAUATUSH"
          ],
          [
            7907,
            "ATUSH"
          ],
          [
            8849,
            "AUATUSH"
          ],
          [
            10158,
            "8 tw"
          ],
          [
            16068,
            "ATUSL"
          ],
          [
            17575,
            "AWAVM"
          ],
          [
            17669,
            "AWAVAUM"
          ],
          [
            17772,
            "AWAVAUATL"
          ],
          [
            17892,
            "AWAVAUAT"
          ],
          [
            18894,
            "TUUUUUUU"
          ],
          [
            19004,
            "SUUUUUUUH9"
          ],
          [
            19484,
            "AVAUATUSH"
          ],
          [
            20175,
            "W0H9"
          ],
          [
            20800,
            "AWAVA"
          ],
          [
            20807,
            "AUATL"
          ],
          [
            20996,
            "none"
          ],
          [
            21001,
            "NORMAL"
          ],
          [
            21008,
            "TERM"
          ],
          [
            21013,
            "OPTIONS"
          ],
          [
            21021,
            "COLOR"
          ],
          [
            21027,
            "EIGHTBIT"
          ],
          [
            21036,
            "\u003cinternal\u003e"
          ],
          [
            21047,
            "dircolors"
          ],
          [
            21057,
            "Usage: %s [OPTION]... [FILE]"
          ],
          [
            21089,
            "test invocation"
          ],
          [
            21105,
            "Multi-call invocation"
          ],
          [
            21127,
            "sha224sum"
          ],
          [
            21137,
            "sha2 utilities"
          ],
          [
            21152,
            "sha256sum"
          ],
          [
            21162,
            "sha384sum"
          ],
          [
            21172,
            "sha512sum"
          ],
          [
            21182,
            "%s online help: \u003c%s\u003e"
          ],
          [
            21205,
            "GNU coreutils"
          ],
          [
            21229,
            "export LS_COLORS"
          ],
          [
            21247,
            "H. Peter Anvin"
          ],
          [
            21266,
            "extra operand %s"
          ],
          [
            21283,
            "SHELL"
          ],
          [
            21294,
            "setenv LS_COLORS '"
          ],
          [
            21313,
            "LS_COLORS='"
          ],
          [
            21325,
            "bourne-shell"
          ],
          [
            21338,
            "c-shell"
          ],
          [
            21346,
            "print-database"
          ],
          [
            21366,
            "version"
          ],
          [
            21440,
            "NORM"
          ],
          [
            21445,
            "FILE"
          ],
          [
            21450,
            "RESET"
          ],
          [
            21464,
            "SYMLINK"
          ],
          [
            21472,
            "ORPHAN"
          ],
          [
            21479,
            "MISSING"
          ],
          [
            21487,
            "FIFO"
          ],
          [
            21492,
            "PIPE"
          ],
          [
            21497,
            "SOCK"
          ],
          [
            21506,
            "BLOCK"
          ],
          [
            21516,
            "CHAR"
          ],
          [
            21521,
            "DOOR"
          ],
          [
            21526,
            "EXEC"
          ],
          [
            21531,
            "LEFT"
          ],
          [
            21536,
            "LEFTCODE"
          ],
          [
            21545,
            "RIGHT"
          ],
          [
            21551,
            "RIGHTCODE"
          ],
          [
            21565,
            "ENDCODE"
          ],
          [
            21573,
            "SUID"
          ],
          [
            21578,
            "SETUID"
          ],
          [
            21585,
            "SGID"
          ],
          [
            21590,
            "SETGID"
          ],
          [
            21597,
            "STICKY"
          ],
          [
            21608,
            "STICKY_OTHER_WRITABLE"
          ],
          [
            21634,
            "CAPABILITY"
          ],
          [
            21645,
            "MULTIHARDLINK"
          ],
          [
            21659,
            "CLRTOEOL"
          ],
          [
            21672,
            "%s:%lu: invalid line;  missing second token"
          ],
          [
            21720,
            "%s:%lu: unrecognized keyword %s"
          ],
          [
            21752,
            "Try '%s --help' for more information."
          ],
          [
            21792,
            "Output commands to set the LS_COLORS environment variable.\n\nDetermine format of output:\n  -b, --sh, --bourne-shell    output Bou"
          ],
          [
            21852,
            "Determine format of output:"
          ],
          [
            21880,
            "-b, --sh, --bourne-shell    output Bourne shell code to set LS_COLORS"
          ],
          [
            21952,
            "-c, --csh, --c-shell        output C shell code to set LS_COLORS"
          ],
          [
            22019,
            "-p, --print-database        output defaults"
          ],
          [
            22072,
            "--help     display this help and exit"
          ],
          [
            22120,
            "--version  output version information and exit"
          ],
          [
            22176,
            "If FILE is specified, read it to determine which colors to use for which\nfile types and extensions.  Otherwise, a precompiled da"
          ],
          [
            22177,
            "If FILE is specified, read it to determine which colors to use for which"
          ],
          [
            22250,
            "file types and extensions.  Otherwise, a precompiled database is used."
          ],
          [
            22321,
            "For details on the format of these files, run 'dircolors --print-database'."
          ],
          [
            22400,
            "https://www.gnu.org/software/coreutils/"
          ],
          [
            22440,
            "Report %s translation bugs to \u003chttps://translationproject.org/team/\u003e"
          ],
          [
            22512,
            "Full documentation at: \u003c%s%s\u003e"
          ],
          [
            22544,
            "or available locally via: info '(coreutils) %s%s'"
          ],
          [
            22600,
            "/tmp/coreutils/_out/share/locale"
          ],
          [
            22640,
            "the options to output dircolors' internal database and\nto select a shell syntax are mutually exclusive"
          ],
          [
            22695,
            "to select a shell syntax are mutually exclusive"
          ],
          [
            22744,
            "file operands cannot be combined with --print-database (-p)"
          ],
          [
            22808,
            "no SHELL environment variable, and no shell type option given"
          ],
          [
            23776,
            "# Configuration file for dircolors, a utility to help you set the"
          ],
          [
            23842,
            "# LS_COLORS environment variable used by GNU ls with the --color option."
          ],
          [
            23915,
            "# Copyright (C) 1996-2018 Free Software Foundation, Inc."
          ],
          [
            23972,
            "# Copying and distribution of this file, with or without modification,"
          ],
          [
            24043,
            "# are permitted provided the copyright notice and this notice are preserved."
          ],
          [
            24120,
            "# The keywords COLOR, OPTIONS, and EIGHTBIT (honored by the"
          ],
          [
            24180,
            "# slackware version of dircolors) are recognized but ignored."
          ],
          [
            24242,
            "# Below are TERM entries, which can be a glob patterns, to match"
          ],
          [
            24307,
            "# against the TERM environment variable to determine if it is colorizable."
          ],
          [
            24382,
            "TERM Eterm"
          ],
          [
            24393,
            "TERM ansi"
          ],
          [
            24403,
            "TERM *color*"
          ],
          [
            24438,
            "TERM cons25"
          ],
          [
            24450,
            "TERM console"
          ],
          [
            24463,
            "TERM cygwin"
          ],
          [
            24475,
            "TERM dtterm"
          ],
          [
            24487,
            "TERM gnome"
          ],
          [
            24498,
            "TERM hurd"
          ],
          [
            24508,
            "TERM jfbterm"
          ],
          [
            24521,
            "TERM konsole"
          ],
          [
            24534,
            "TERM kterm"
          ],
          [
            24545,
            "TERM linux"
          ],
          [
            24556,
            "TERM linux-c"
          ],
          [
            24569,
            "TERM mlterm"
          ],
          [
            24581,
            "TERM putty"
          ],
          [
            24603,
            "TERM screen*"
          ],
          [
            24616,
            "TERM st"
          ],
          [
            24624,
            "TERM terminator"
          ],
          [
            24662,
            "TERM xterm*"
          ],
          [
            24674,
            "# Below are the color init strings for the basic file types. A color init"
          ],
          [
            24748,
            "# string consists of one or more of the following numeric codes:"
          ],
          [
            24813,
            "# Attribute codes:"
          ],
          [
            24832,
            "# 00=none 01=bold 04=underscore 05=blink 07=reverse 08=concealed"
          ],
          [
            24897,
            "# Text color codes:"
          ],
          [
            24917,
            "# 30=black 31=red 32=green 33=yellow 34=blue 35=magenta 36=cyan 37=white"
          ],
          [
            24990,
            "# Background color codes:"
          ],
          [
            25016,
            "# 40=black 41=red 42=green 43=yellow 44=blue 45=magenta 46=cyan 47=white"
          ],
          [
            25089,
            "#NORMAL 00 # no color code at all"
          ],
          [
            25123,
            "#FILE 00 # regular file: use no color at all"
          ],
          [
            25168,
            "RESET 0 # reset to \"normal\" color"
          ],
          [
            25202,
            "DIR 01;34 # directory"
          ],
          [
            25224,
            "LINK 01;36 # symbolic link. (If you set this to 'target' instead of a"
          ],
          [
            25294,
            "# numerical value, the color is as for the file pointed to.)"
          ],
          [
            25356,
            "MULTIHARDLINK 00 # regular file with more than one link"
          ],
          [
            25412,
            "FIFO 40;33 # pipe"
          ],
          [
            25430,
            "SOCK 01;35 # socket"
          ],
          [
            25450,
            "DOOR 01;35 # door"
          ],
          [
            25468,
            "BLK 40;33;01 # block device driver"
          ],
          [
            25503,
            "CHR 40;33;01 # character device driver"
          ],
          [
            25542,
            "ORPHAN 40;31;01 # symlink to nonexistent file, or non-stat'able file ..."
          ],
          [
            25615,
            "MISSING 00 # ... and the files they point to"
          ],
          [
            25660,
            "SETUID 37;41 # file that is setuid (u+s)"
          ],
          [
            25701,
            "SETGID 30;43 # file that is setgid (g+s)"
          ],
          [
            25742,
            "CAPABILITY 30;41 # file with capability"
          ],
          [
            25782,
            "STICKY_OTHER_WRITABLE 30;42 # dir that is sticky and other-writable (+t,o+w)"
          ],
          [
            25859,
            "OTHER_WRITABLE 34;42 # dir that is other-writable (o+w) and not sticky"
          ],
          [
            25930,
            "STICKY 37;44 # dir with the sticky bit set (+t) and not other-writable"
          ],
          [
            26001,
            "# This is for files with execute permission:"
          ],
          [
            26057,
            "# List any file extensions like '.gz' or '.tar' that you would like ls"
          ],
          [
            26128,
            "# to colorize below. Put the extension, a space, and the color init string."
          ],
          [
            26204,
            "# (and any comments you want to add after a '#')"
          ],
          [
            26253,
            "# If you use DOS-style suffixes, you may want to uncomment the following:"
          ],
          [
            26327,
            "#.cmd 01;32 # executables (bright green)"
          ],
          [
            26416,
            "# Or if you want to colorize scripts even if they do not have the"
          ],
          [
            26482,
            "# executable bit actually set."
          ],
          [
            26536,
            "# archives or compressed (bright red)"
          ],
          [
            27075,
            "# image formats"
          ],
          [
            27126,
            ".mjpeg 01;35"
          ],
          [
            27614,
            "# https://wiki.xiph.org/MIME_Types_and_File_Extensions"
          ],
          [
            27691,
            "# audio formats"
          ],
          [
            27940,
            "8.30"
          ],
          [
            27945,
            "write error"
          ],
          [
            27964,
            "/dev/null"
          ],
          [
            27976,
            "A NULL argv[0] was passed through an exec system call."
          ],
          [
            28032,
            "/.libs/"
          ],
          [
            28061,
            "GB18030"
          ],
          [
            28071,
            "literal"
          ],
          [
            28079,
            "shell-always"
          ],
          [
            28092,
            "shell-escape"
          ],
          [
            28105,
            "shell-escape-always"
          ],
          [
            28125,
            "c-maybe"
          ],
          [
            28133,
            "clocale"
          ],
          [
            29944,
            "%s (%s) %s"
          ],
          [
            29967,
            "Written by %s."
          ],
          [
            29983,
            "Written by %s and %s."
          ],
          [
            30006,
            "Written by %s, %s, and %s."
          ],
          [
            30034,
            "Report bugs to: %s"
          ],
          [
            30055,
            "bug-coreutils@gnu.org"
          ],
          [
            30077,
            "%s home page: \u003c%s\u003e"
          ],
          [
            30104,
            "License GPLv3+: GNU GPL version 3 or later \u003chttps://gnu.org/licenses/gpl.html\u003e.\nThis is free software: you are free to change an"
          ],
          [
            30105,
            "License GPLv3+: GNU GPL version 3 or later \u003chttps://gnu.org/licenses/gpl.html\u003e."
          ],
          [
            30185,
            "This is free software: you are free to change and redistribute it."
          ],
          [
            30252,
            "There is NO WARRANTY, to the extent permitted by law."
          ],
          [
            30312,
            "Written by %s, %s, %s,"
          ],
          [
            30335,
            "and %s."
          ],
          [
            30367,
            "%s, and %s."
          ],
          [
            30407,
            "%s, %s, and %s."
          ],
          [
            30447,
            "%s, %s, %s, and %s."
          ],
          [
            30615,
            "%s, %s, and others."
          ],
          [
            30640,
            "General help using GNU software: \u003chttps://www.gnu.org/gethelp/\u003e"
          ],
          [
            30816,
            "Copyright %s %d Free Software Foundation, Inc."
          ],
          [
            30863,
            "memory exhausted"
          ],
          [
            30880,
            "POSIX"
          ],
          [
            30886,
            "ASCII"
          ],
          [
            36192,
            "GCC: (GNU) 5.5.0"
          ]
        ],
        "sz": 47888,
        "ts": [
          {
            "c": 1.0,
            "d": "ELF program interpreter present",
            "e": [
              "/lib64/ld-linux-x86-64.so.2"
            ],
            "i": "metadata/binary/linking::elf-interpreter",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "ELF needed library",
            "e": [
              "libc.so.6"
            ],
            "i": "metadata/binary/linking::elf-needed-lib",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary is not digitally signed",
            "i": "metadata/unsigned",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Binary has many functions (\u003e30)",
            "e": [
              "binary.function_count = 146.00"
            ],
            "i": "metadata/binary/metrics::many-functions",
            "l": 2
          },
          {
            "a": "T1486",
            "c": 0.75,
            "d": "flock LOCK_EX call bytecode pattern",
            "e": [
              "be e4 ea ff ff",
              "bf e4 ea ff ff",
              "bf f1 fe ff ff",
              "bf 76 ea ff ff"
            ],
            "i": "objectives/impact/ransom/esxi::flock-lockex",
            "l": 1,
            "m": "C0027"
          },
          {
            "c": 0.6600000262260437,
            "d": "Write files",
            "e": [
              "fwrite"
            ],
            "i": "micro-behaviors/fs/file/write::write",
            "l": 2
          },
          {
            "d": "SHELL environment variable",
            "e": [
              "SHELL"
            ],
            "i": "micro-behaviors/os/env/vars/system-info::shell-var",
            "l": 2
          },
          {
            "a": "T1055",
            "c": 0.25,
            "d": "Repeated 0x07 code constant (possible PROT_RWX)",
            "e": [
              "07 00 00 00",
              "07 00 00 00"
            ],
            "i": "micro-behaviors/mem/protect/modify::rwx-prot-bytes",
            "l": 1
          },
          {
            "d": ".so extension reference",
            "e": [
              ".so"
            ],
            "i": "micro-behaviors/fs/path/extension::so",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "freopen stream redirection import",
            "e": [
              "freopen"
            ],
            "i": "micro-behaviors/process/fd/stdio::freopen-import",
            "l": 3
          },
          {
            "c": 1.0,
            "d": "Binary format is identified",
            "e": [
              "elf.class_bits = 64.00"
            ],
            "i": "metadata/binary::binary-format-checked",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "/dev/null (legitimate discard device)",
            "e": [
              "/dev/null"
            ],
            "i": "micro-behaviors/fs/path/device::dev-null",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Binary has many exports (\u003e10)",
            "e": [
              "binary.export_count = 141.00"
            ],
            "i": "metadata/binary/metrics::many-exports",
            "l": 2
          },
          {
            "c": 0.6000000238418579,
            "d": "Small ELF binary (\u003c 50KB)",
            "e": [
              "x86__64__lsb__unix-system-v__gcc-5.5.0__O1__no-obf__unstripped__coreutils-8.30__dircolors"
            ],
            "i": "metadata/binary/metrics::small-elf-binary",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 40+ imports",
            "e": [
              "binary.import_count = 51.00"
            ],
            "i": "metadata/binary/metrics::many-imports-40",
            "l": 1
          },
          {
            "c": 0.6600000262260437,
            "d": "Reference to /lib64",
            "e": [
              "/lib64/ld-linux-x86-64.so.2"
            ],
            "i": "micro-behaviors/fs/path/system::system-lib64",
            "l": 2
          },
          {
            "d": "Characteristic system library exports",
            "e": [
              "libc_start_main"
            ],
            "i": "micro-behaviors/dylib/library/libc::libc-characteristic-symbols",
            "l": 2
          },
          {
            "c": 0.30000001192092896,
            "d": "GNU coreutils reference",
            "e": [
              "GNU coreutils"
            ],
            "i": "micro-behaviors/dylib/library::gnu-coreutils-ref",
            "l": 2
          },
          {
            "c": 0.20000000298023224,
            "d": "command keyword",
            "e": [
              "Output commands to set the LS_COLORS e…"
            ],
            "i": "micro-behaviors/data/text/keywords::command-dup",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary is not position-independent (fixed load address)",
            "e": [
              "binary.is_pie = 0.00"
            ],
            "i": "metadata/hardening::no-pie",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has low average complexity",
            "e": [
              "binary.avg_complexity = 5.22"
            ],
            "i": "metadata/binary/metrics::avg-complexity-15-max",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has low average string entropy",
            "e": [
              "binary.avg_string_entropy = 3.22"
            ],
            "i": "metadata/binary/metrics::avg-string-entropy-4-max",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "GPL license reference",
            "e": [
              "GPL",
              "GPL"
            ],
            "i": "metadata/package/license::gpl-word",
            "l": 2
          },
          {
            "c": 1.0,
            "d": ".cmd extension",
            "e": [
              "#.cmd 01;32 # executables (bright green)"
            ],
            "i": "metadata/file/extension::cmd-ext",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "File is a compiled binary",
            "e": [
              "binary.file_size = 47888.00"
            ],
            "i": "metadata/binary/framework::is-binary",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "DOS dispatcher check op",
            "e": [
              "mov "
            ],
            "i": "micro-behaviors/os/msdos/internal::dispatcher-signature-op",
            "l": 2
          },
          {
            "a": "T1005",
            "c": 0.4000000059604645,
            "d": "Seeks to position in file",
            "e": [
              "fseeko",
              "fseeko@@GLIBC_2.2.5",
              "rpl_fseeko",
              "sym.imp.fseeko",
              "sym.rpl_fseeko"
            ],
            "i": "micro-behaviors/fs/file/binary::fseek-func",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Binary has low overall entropy",
            "e": [
              "binary.overall_entropy = 2.74"
            ],
            "i": "metadata/binary/metrics::low-overall-entropy-binary",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "CLI help or usage text",
            "e": [
              "Try '%s --help' for more information."
            ],
            "i": "metadata/binary/metrics::help-usage-string",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "ELF dynsym section name",
            "e": [
              ".dynsym"
            ],
            "i": "metadata/binary/linking::elf-dynsym-section-name",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 100+ exports",
            "e": [
              "binary.export_count = 141.00"
            ],
            "i": "metadata/binary/metrics::many-exports-100",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "/tmp/ path component",
            "e": [
              "/tmp/coreutils/_out/share/locale"
            ],
            "i": "micro-behaviors/fs/path/temp::tmp-path-content",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 25+ imports",
            "e": [
              "binary.import_count = 51.00"
            ],
            "i": "metadata/binary/metrics::many-imports-25",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "libc version string pattern",
            "e": [
              "GLIBC",
              "GLIBC",
              "GLIBC",
              "GLIBC",
              "GLIBC",
              "GLIBC",
              "GLIBC",
              "GLIBC",
              "GLIBC",
              "GLIBC",
              "GLIBC",
              "GLIBC",
              "GLIBC",
              "GLIBC",
              "GLIBC",
              "GLIBC"
            ],
            "i": "micro-behaviors/dylib/library/libc::libc-version-string",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 50+ imports",
            "e": [
              "binary.import_count = 51.00"
            ],
            "i": "metadata/binary/metrics::many-imports-50",
            "l": 1
          },
          {
            "a": "T1059.006",
            "c": 0.6000000238418579,
            "d": "Named /tmp execution path",
            "e": [
              "/tmp/coreutils"
            ],
            "i": "objectives/command-and-control/dropper::tmp-path",
            "l": 1,
            "m": "B0024"
          },
          {
            "c": 0.8999999761581421,
            "d": "Abort program execution",
            "e": [
              "abort"
            ],
            "i": "micro-behaviors/os/signal/handler::abort",
            "l": 2
          },
          {
            "d": "TERM environment variable",
            "e": [
              "TERM"
            ],
            "i": "micro-behaviors/os/env/vars/system-info::term-var",
            "l": 2
          },
          {
            "c": 0.20000000298023224,
            "d": "output keyword",
            "e": [
              "the options to output dircolors' internal dat…",
              "-b, --sh, --bourne-shell    output Bourne shell code to set LS_COLORS",
              "…--sh, --bourne-shell    output Bourne shell code to se…",
              "--version  output version information and exit",
              "-c, --csh, --c-shell        output C shell code to set LS_COLORS",
              "…--csh, --c-shell        output C shell code to set LS_…",
              "…e.\n\nDetermine format of output:\n  -b, --sh, --bourne-s…",
              "…--print-database        output defaults",
              "Determine format of output:",
              "-p, --print-database        output defaults"
            ],
            "i": "micro-behaviors/data/text/keywords::output",
            "l": 1
          },
          {
            "d": "Duplicate file descriptor (I/O redirection)",
            "e": [
              "dup2"
            ],
            "i": "micro-behaviors/process/fd/dup::dup2",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "ELF interpreter section name",
            "e": [
              ".interp"
            ],
            "i": "metadata/binary/linking::elf-interpreter-section-name",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 20+ exports",
            "e": [
              "binary.export_count = 141.00"
            ],
            "i": "metadata/binary/metrics::many-exports-20",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Version information string",
            "e": [
              "--version"
            ],
            "i": "metadata/package/help::version-text",
            "l": 2
          },
          {
            "d": "Characteristic system library export __errno_location",
            "e": [
              "errno_location"
            ],
            "i": "micro-behaviors/dylib/library/libc::libc-characteristic-errno",
            "l": 2
          },
          {
            "d": "Binary exports symbols",
            "e": [
              "binary.export_count = 141.00"
            ],
            "i": "metadata/binary/symbols::has-exports",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 9+ exports",
            "e": [
              "binary.export_count = 141.00"
            ],
            "i": "metadata/binary/metrics::many-exports-9",
            "l": 1
          },
          {
            "c": 0.6600000262260437,
            "d": "Open files",
            "e": [
              "open"
            ],
            "i": "micro-behaviors/fs/file/open::open-base",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 50+ functions",
            "e": [
              "binary.function_count = 146.00"
            ],
            "i": "metadata/binary/metrics::many-functions-50",
            "l": 1
          },
          {
            "c": 0.6000000238418579,
            "d": "Copyright notice",
            "e": [
              "Copyright",
              "Copyright"
            ],
            "i": "metadata/package/license::copyright-word",
            "l": 2
          },
          {
            "d": "Usage: label in binary strings",
            "e": [
              "Usage: %s [OPTION]... [FILE]"
            ],
            "i": "metadata/package/help::usage-title-string",
            "l": 1
          },
          {
            "c": 0.4000000059604645,
            "d": "Terminate process immediately without cleanup",
            "e": [
              "exit",
              "exit"
            ],
            "i": "micro-behaviors/process/terminate/signal::_exit",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 20+ imports",
            "e": [
              "binary.import_count = 51.00"
            ],
            "i": "metadata/binary/metrics::many-imports-20",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Unix /tmp/ path reference",
            "e": [
              "/tmp/coreutils/_out/share/locale"
            ],
            "i": "micro-behaviors/fs/path/temp::unix-temp",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 3+ functions",
            "e": [
              "binary.function_count = 146.00"
            ],
            "i": "metadata/binary/metrics::few-functions-3",
            "l": 1
          },
          {
            "d": "Characteristic system library export __cxa_atexit",
            "e": [
              "cxa_atexit"
            ],
            "i": "micro-behaviors/dylib/library/libc::libc-characteristic-cxa-atexit",
            "l": 2
          },
          {
            "c": 0.30000001192092896,
            "d": "xterm terminal reference",
            "e": [
              "TERM xterm*"
            ],
            "i": "micro-behaviors/process/tty/terminal::xterm-ref",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "ELF64 class marker",
            "e": [
              "elf.class_bits = 64.00"
            ],
            "i": "metadata/binary/metrics::elf64-class",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "ELF dynamic section name",
            "e": [
              ".dynamic"
            ],
            "i": "metadata/binary/linking::elf-dynamic-section-name",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "ELF dynstr section name",
            "e": [
              ".dynstr"
            ],
            "i": "metadata/binary/linking::elf-dynstr-section-name",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 30+ imports",
            "e": [
              "binary.import_count = 51.00"
            ],
            "i": "metadata/binary/metrics::many-imports-30",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 20+ sections (installer/packer)",
            "e": [
              "binary.section_count = 29.00"
            ],
            "i": "metadata/binary/metrics::many-sections-20",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "No stack canary (stack smashing protection absent)",
            "e": [
              "elf.stack_canary = 0.00"
            ],
            "i": "metadata/hardening::no-stack-canary",
            "l": 2
          },
          {
            "c": 0.6000000238418579,
            "d": "Binary not position-independent (no ASLR)",
            "e": [
              "elf.e_type = 2.00"
            ],
            "i": "metadata/hardening::no-pie-struct",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "ELF dynsym section name",
            "e": [
              ".dynsym"
            ],
            "i": "metadata/hardening::elf-dynsym-section-name",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "ELF needed library metadata",
            "e": [
              "libc.so.6"
            ],
            "i": "metadata/binary/linking/runtime::needed-lib",
            "l": 2
          },
          {
            "c": 0.30000001192092896,
            "d": "getenv function (read environment variable)",
            "e": [
              "getenv",
              "sym.imp.getenv"
            ],
            "i": "micro-behaviors/os/env/vars::getenv",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "ELF dynstr section name",
            "e": [
              ".dynstr"
            ],
            "i": "metadata/hardening::elf-dynstr-section-name",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "ELF interpreter section name",
            "e": [
              ".interp"
            ],
            "i": "metadata/hardening::elf-interpreter-section-name",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "ELF program interpreter metadata",
            "e": [
              "/lib64/ld-linux-x86-64.so.2"
            ],
            "i": "metadata/binary/linking/runtime::interpreter",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "No RELRO (GOT writable after load)",
            "e": [
              "elf.relro = 0.00"
            ],
            "i": "metadata/hardening::no-relro",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "ELF dynamic section name",
            "e": [
              ".dynamic"
            ],
            "i": "metadata/hardening::elf-dynamic-section-name",
            "l": 2
          },
          {
            "c": 0.6600000262260437,
            "d": "Reference to /tmp",
            "e": [
              "/tmp/coreutils/_out/share/locale",
              "/tmp/coreutils/_out/share/locale"
            ],
            "i": "micro-behaviors/fs/path/temp::temp-tmp",
            "l": 2
          },
          {
            "a": "T1005",
            "c": 0.75,
            "d": "File content manipulation (read/write/seek)",
            "e": [
              "fwrite",
              "fseeko@@GLIBC_2.2.5",
              "fseeko",
              "sym.rpl_fseeko",
              "sym.imp.fseeko",
              "rpl_fseeko"
            ],
            "i": "micro-behaviors/fs/file/binary::file-manipulation",
            "l": 3
          },
          {
            "c": 0.8500000238418579,
            "d": "Documented command line program",
            "e": [
              "Usage: %s [OPTION]... [FILE]",
              "binary.import_count = 51.00"
            ],
            "i": "metadata/package/help::documented-cli-binary",
            "l": 1
          }
        ],
        "sha": "0700a662bb48545ad5c43f6a2b799165114c2ee2a303277863089102122d55a7",
        "path": "x86__64__lsb__unix-system-v__gcc-5.5.0__O1__no-obf__unstripped__coreutils-8.30__dircolors",
        "type": "elf"
      }
    ],
    "tv": "feb13"
  }
}