{
  "ml": {
    "v": "4",
    "fs": [
      {
        "id": 0,
        "prob": 0.9998549222946167,
        "class": 2
      }
    ],
    "prob": 0.9998549,
    "class": 2,
    "models": [
      {
        "m": "az",
        "prob": 0.9997812,
        "class": 2
      },
      {
        "m": "az/native",
        "prob": 0.99984276,
        "class": 0
      },
      {
        "m": "az/pe",
        "prob": 0.9998549,
        "class": 2
      }
    ],
    "version": "v16.16",
    "thresholds": [
      0.9953178,
      0.9991311
    ],
    "analyzed_at": "2026-05-03T01:55:15Z"
  },
  "path": "36989",
  "raw": {
    "v": "4",
    "fs": [
      {
        "f": "KO₅(ErAs₅C₃I₃P₂)H₄(DsOs₂Po₂Db)Md₂(Bi₆)",
        "x": 198,
        "id": 0,
        "is": [
          "MethCallEngine",
          "rtcRandomNext",
          "rtcRandomize",
          "rtcMsgBox",
          "rtcDoEvents",
          "rtcSpaceBstr",
          "rtcSpaceVar",
          "EVENT_SINK_AddRef",
          "rtcKillFiles",
          "DllFunctionCall",
          "rtcCommandVar",
          "EVENT_SINK_Release",
          "rtcShell",
          "rtcArray",
          "EVENT_SINK_QueryInterface",
          "vbaExceptHandler",
          "rtcStringVar",
          "rtcVarBstrFromAnsi",
          "rtcChangeDir",
          "rtcCreateObject2",
          "ProcCallEngine",
          "rtcBstrFromAnsi",
          "rtcDir",
          "rtcFileLength",
          "rtcErrObj",
          "ThunRTMain",
          "rtcLeftCharBstr",
          "rtcGetPresentDate",
          "rtcGetSecondOfMinute",
          "rtcSetFileAttr"
        ],
        "ms": {
          "binary": {
            "code_size": 45056.0,
            "file_size": 73888.0,
            "import_count": 30.0,
            "string_count": 118.0,
            "section_count": 3.0,
            "avg_complexity": 7.17,
            "function_count": 6.0,
            "import_density": 0.68,
            "max_complexity": 28.0,
            "string_density": 2.68,
            "overall_entropy": 4.17,
            "avg_basic_blocks": 10.0,
            "avg_section_size": 23210.67,
            "function_density": 0.14,
            "avg_function_size": 172.5,
            "avg_string_length": 14.81,
            "complexity_per_kb": 0.16,
            "max_string_length": 63.0,
            "wide_string_count": 45.0,
            "writable_sections": 1.0,
            "avg_string_entropy": 3.04,
            "code_section_ratio": 0.33,
            "code_to_data_ratio": 1.83,
            "rsrc_to_file_ratio": 0.33,
            "text_to_file_ratio": 0.61,
            "total_basic_blocks": 60.0,
            "executable_sections": 1.0,
            "section_name_entropy": 3.01,
            "string_length_stddev": 12.37,
            "largest_section_ratio": 0.61,
            "sentence_string_count": 4.0,
            "sentence_string_ratio": 0.03,
            "function_analysis_depth": 2.0,
            "has_malformed_structure": true,
            "normalized_import_count": 0.11,
            "normalized_section_count": 0.19
          }
        },
        "ss": [
          [
            77,
            "!This program cannot be run in DOS mode."
          ],
          [
            152,
            "Rich"
          ],
          [
            432,
            ".text"
          ],
          [
            512,
            ".rsrc"
          ],
          [
            568,
            "MSVBVM60.DLL"
          ],
          [
            4584,
            "frm_main"
          ],
          [
            4597,
            "Main"
          ],
          [
            7287,
            "bcdddddddddef"
          ],
          [
            7301,
            "/Ygggggggggggggg"
          ],
          [
            7446,
            "NEFGH"
          ],
          [
            10064,
            "UUUUUUUUUUUUUUUC"
          ],
          [
            10162,
            "w@gylz///////"
          ],
          [
            10192,
            "cDefE!gYjjiiijj2mnop"
          ],
          [
            10224,
            "UUCCCDVWX"
          ],
          [
            10261,
            "CDEF"
          ],
          [
            11811,
            "bcdefghi"
          ],
          [
            11843,
            "LMNOPQRSTUV"
          ],
          [
            11859,
            "CDEFGGGHIJK"
          ],
          [
            11891,
            "/012"
          ],
          [
            11896,
            "345678"
          ],
          [
            28048,
            "music"
          ],
          [
            28054,
            "Microsoft Windows"
          ],
          [
            29404,
            "wide",
            "*\\AC:\\Documents and Settings\\DucDung\\Desktop\\Pro 3\\Pro3.vbp"
          ],
          [
            31280,
            "class_main"
          ],
          [
            31292,
            "module_main"
          ],
          [
            31308,
            "module_bind"
          ],
          [
            31324,
            "module_rnd"
          ],
          [
            31336,
            "module_registry"
          ],
          [
            31352,
            "module_until"
          ],
          [
            31368,
            "module_path"
          ],
          [
            31380,
            "module_check"
          ],
          [
            31412,
            "wide",
            "SeRestorePrivilege"
          ],
          [
            31456,
            "wide",
            "SeBackupPrivilege"
          ],
          [
            31580,
            "Form"
          ],
          [
            31604,
            "C:\\Program Files\\Microsoft Visual Studio\\VB98\\VB6.OLB"
          ],
          [
            31756,
            "kernel32"
          ],
          [
            31772,
            "CreateMutexA"
          ],
          [
            31844,
            "ReleaseMutex"
          ],
          [
            31916,
            "CloseHandle"
          ],
          [
            32064,
            "Sleep"
          ],
          [
            32140,
            "wide",
            ".exe"
          ],
          [
            32180,
            "wide",
            "Access is denied"
          ],
          [
            32220,
            "wide",
            "System"
          ],
          [
            32276,
            "VBA6.DLL"
          ],
          [
            32368,
            "Class"
          ],
          [
            32392,
            "C:\\WINDOWS\\system32\\msvbvm60.dll\\3"
          ],
          [
            32428,
            "VBRUN"
          ],
          [
            32492,
            "wide",
            ".dat"
          ],
          [
            32508,
            "wide",
            ".zip"
          ],
          [
            32576,
            "advapi32.dll"
          ],
          [
            32596,
            "RegSetValueExA"
          ],
          [
            32668,
            "RegQueryValueExA"
          ],
          [
            32744,
            "RegOpenKeyExA"
          ],
          [
            32816,
            "RegDeleteValueA"
          ],
          [
            32888,
            "RegDeleteKeyA"
          ],
          [
            32960,
            "RegCreateKeyExA"
          ],
          [
            33032,
            "RegCloseKey"
          ],
          [
            33168,
            "RegRestoreKeyA"
          ],
          [
            33240,
            "RegEnumKeyExA"
          ],
          [
            33312,
            "RegEnumValueA"
          ],
          [
            33332,
            "wide",
            "NoFolderOptions"
          ],
          [
            33420,
            "RegCreateKeyA"
          ],
          [
            33492,
            "AdjustTokenPrivileges"
          ],
          [
            33572,
            "LookupPrivilegeValueA"
          ],
          [
            33652,
            "OpenProcessToken"
          ],
          [
            33728,
            "GetCurrentProcess"
          ],
          [
            33804,
            "wide",
            "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CabinetState"
          ],
          [
            33936,
            "wide",
            "FullPath"
          ],
          [
            33968,
            "wide",
            "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced"
          ],
          [
            34092,
            "wide",
            "HideFileExt"
          ],
          [
            34120,
            "wide",
            "Hidden"
          ],
          [
            34148,
            "wide",
            "Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer"
          ],
          [
            34272,
            "wide",
            "Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System"
          ],
          [
            34392,
            "wide",
            "DisableRegistryTools"
          ],
          [
            34440,
            "wide",
            "Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Streams"
          ],
          [
            34564,
            "wide",
            "Settings"
          ],
          [
            34588,
            "wide",
            "Scripting.FileSystemObject"
          ],
          [
            34644,
            "wide",
            "CreateTextFile"
          ],
          [
            34676,
            "wide",
            "Write"
          ],
          [
            34688,
            "wide",
            "Close"
          ],
          [
            34704,
            "wide",
            "temp.zip"
          ],
          [
            34728,
            "wide",
            "Shell.Application"
          ],
          [
            34764,
            "wide",
            "Namespace"
          ],
          [
            34784,
            "wide",
            "CopyHere"
          ],
          [
            34808,
            "user32"
          ],
          [
            34820,
            "FindWindowA"
          ],
          [
            34888,
            "FindWindowExA"
          ],
          [
            34960,
            "SendMessageA"
          ],
          [
            35032,
            "PostMessageA"
          ],
          [
            35104,
            "GetFileAttributesA"
          ],
          [
            35180,
            "ExitWindowsEx"
          ],
          [
            35264,
            "GetWindowTextA"
          ],
          [
            35336,
            "GetWindowTextLengthA"
          ],
          [
            35416,
            "wide",
            "backup"
          ],
          [
            35436,
            "wide",
            "data"
          ],
          [
            35452,
            "wide",
            "System Restore"
          ],
          [
            35488,
            "wide",
            "update"
          ],
          [
            35544,
            "wide",
            "CabinetWClass"
          ],
          [
            35576,
            "wide",
            "ExploreWClass"
          ],
          [
            45208,
            "MethCallEngine"
          ],
          [
            45226,
            "EVENT_SINK_AddRef"
          ],
          [
            45246,
            "DllFunctionCall"
          ],
          [
            45264,
            "EVENT_SINK_Release"
          ],
          [
            45286,
            "EVENT_SINK_QueryInterface"
          ],
          [
            45314,
            "__vbaExceptHandler"
          ],
          [
            45336,
            "ProcCallEngine"
          ],
          [
            49638,
            "wide",
            "VS_VERSION_INFO"
          ],
          [
            49730,
            "wide",
            "VarFileInfo"
          ],
          [
            49762,
            "wide",
            "Translation"
          ],
          [
            49798,
            "wide",
            "StringFileInfo"
          ],
          [
            49858,
            "wide",
            "ProductName"
          ],
          [
            49884,
            "wide",
            "Microsoft Windows"
          ],
          [
            49926,
            "wide",
            "FileVersion"
          ],
          [
            49978,
            "wide",
            "ProductVersion"
          ],
          [
            50034,
            "wide",
            "InternalName"
          ],
          [
            50060,
            "wide",
            "music"
          ],
          [
            50078,
            "wide",
            "OriginalFilename"
          ],
          [
            50112,
            "wide",
            "music.exe"
          ]
        ],
        "sz": 73888,
        "ts": [
          {
            "a": "T1027",
            "c": 0.30000001192092896,
            "d": "PE header too corrupted to parse: Malformed entity: ResourceString value_len (105) exceeds available bytes (20)",
            "e": [
              "Malformed entity: ResourceString value_len (105) exceeds available bytes (20)"
            ],
            "i": "objectives/anti-analysis/pe-tampering/corrupted-header",
            "l": 2,
            "m": "B0001"
          },
          {
            "c": 0.8500000238418579,
            "d": "FileSystemObject ProgID string",
            "e": [
              "Scripting.FileSystemObject"
            ],
            "i": "micro-behaviors/os/com/object::filesystemobject-progid",
            "l": 3
          },
          {
            "c": 1.0,
            "d": "Binary has low average string entropy",
            "e": [
              "binary.avg_string_entropy = 3.04"
            ],
            "i": "metadata/binary/metrics::avg-string-entropy-4-max",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Binary has low overall entropy",
            "e": [
              "binary.overall_entropy = 4.17"
            ],
            "i": "metadata/binary/metrics::low-overall-entropy-binary",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "PE has low overall entropy",
            "e": [
              "binary.overall_entropy = 4.17"
            ],
            "i": "metadata/binary/layout::low-overall-entropy",
            "l": 2
          },
          {
            "c": 0.9399999976158142,
            "d": "VB6 runtime DLL reference",
            "e": [
              "MSVBVM60.DLL"
            ],
            "i": "metadata/binary/framework::vb6-runtime-dll",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Shell.Application ProgID string",
            "e": [
              "Shell.Application"
            ],
            "i": "micro-behaviors/os/com/object::shell-application-progid",
            "l": 3
          },
          {
            "c": 0.9800000190734863,
            "d": "user32 dynamic dispatch target",
            "e": [
              "user32"
            ],
            "i": "well-known/malware/trojan/shellobject/hijack::user32-dispatch-target",
            "l": 1
          },
          {
            "c": 0.9399999976158142,
            "d": "Hide file extension value",
            "e": [
              "HideFileExt"
            ],
            "i": "metadata/file/text::hide-file-ext-value",
            "l": 3
          },
          {
            "c": 0.8500000238418579,
            "d": "Large zero-entropy placeholder section",
            "e": [
              ".rsrc (size: 24576, entropy: 0.00, perms: -r--)"
            ],
            "i": "metadata/binary/section/metrics::null-placeholder-section",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE standard code/data section",
            "e": [
              ".text",
              ".data"
            ],
            "i": "metadata/binary/section/names::pe-code-data-standard-section",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "PE has many readable strings",
            "e": [
              "binary.string_count = 118.00"
            ],
            "i": "metadata/binary/layout::many-readable-strings",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "FileVersion field marker",
            "e": [
              "FileVersion"
            ],
            "i": "well-known/malware/worm/ludbaruma::fileversion-field",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "PE ProductVersion metadata field",
            "e": [
              "ProductVersion"
            ],
            "i": "metadata/package/versioning::pe-productversion-field",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "Binary imports ADVAPI32.dll",
            "e": [
              "advapi32.dll"
            ],
            "i": "metadata/binary/symbols::imports-advapi32-dll",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "File is a compiled binary",
            "e": [
              "binary.file_size = 73888.00"
            ],
            "i": "metadata/binary/framework::is-binary",
            "l": 1
          },
          {
            "a": "T1005",
            "c": 0.4000000059604645,
            "d": "Generic data extension",
            "e": [
              ".dat"
            ],
            "i": "objectives/collection/file-targeting/filter::dat-extension",
            "l": 1,
            "m": "B0024"
          },
          {
            "c": 1.0,
            "d": "Binary has low average complexity",
            "e": [
              "binary.avg_complexity = 7.17"
            ],
            "i": "metadata/binary/metrics::avg-complexity-15-max",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary is not position-independent (fixed load address)",
            "e": [
              "binary.is_pie = 0.00"
            ],
            "i": "metadata/hardening::no-pie",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Shell CopyHere method string",
            "e": [
              "CopyHere"
            ],
            "i": "micro-behaviors/os/com/object::copyhere-method",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 30+ imports",
            "e": [
              "binary.import_count = 30.00"
            ],
            "i": "metadata/binary/metrics::many-imports-30",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.699999988079071,
            "d": "Windows Production PCA 2011 string",
            "e": [
              "Microsoft Windows",
              "Microsoft Windows"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics::windows-production-pca-2011-string",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.949999988079071,
            "d": "System policies registry path",
            "e": [
              "Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System"
            ],
            "i": "metadata/file/text::policies-system-path",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "Temporary ZIP filename",
            "e": [
              "temp.zip"
            ],
            "i": "objectives/command-and-control/dropper/staging/archive::temp-zip-name",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "VB6 directory enumeration helper",
            "e": [
              "rtcDir"
            ],
            "i": "micro-behaviors/fs/directory/readdir::vb6-rtcdir",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Restore registry key hive",
            "e": [
              "RegRestoreKeyA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-restore-key",
            "l": 2
          },
          {
            "a": "T1546.015",
            "c": 0.949999988079071,
            "d": "Executable path in TypeLib redirection",
            "e": [
              "C:\\WINDOWS\\system32\\msvbvm60.dll"
            ],
            "i": "objectives/persistence/system/registry/com-hijack::typelib-executable-path",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.8399999737739563,
            "d": "Open registry key ANSI",
            "e": [
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-open-key-ex-a",
            "l": 2
          },
          {
            "c": 0.9200000166893005,
            "d": "VB6 runtime library marker",
            "e": [
              "rtcDoEvents"
            ],
            "i": "metadata/binary/framework::vb6-runtime-library",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Tiny writable data section",
            "e": [
              ".data (size: 0)"
            ],
            "i": "metadata/binary/section/metrics::tiny-data-section",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 3+ functions",
            "e": [
              "binary.function_count = 6.00"
            ],
            "i": "metadata/binary/metrics::few-functions-3",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "PE version resource structure",
            "e": [
              "VS_VERSION_INFO"
            ],
            "i": "metadata/package/versioning::pe-version-resource",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE has few sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "metadata/binary/layout::legacy-few-sections",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "ProductVersion field marker",
            "e": [
              "ProductVersion"
            ],
            "i": "well-known/malware/worm/ludbaruma::productversion-field",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.9200000166893005,
            "d": "VB6 rtcVarBstrFromAnsi string builder",
            "e": [
              "rtcVarBstrFromAnsi"
            ],
            "i": "micro-behaviors/data/string::vb6-string-construction-bstr",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.75,
            "d": "Binary exports no symbols",
            "e": [
              "binary.export_count = 0.00"
            ],
            "i": "metadata/binary/symbols::no-exports",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "VB6 runtime entrypoint marker",
            "e": [
              "ThunRTMain"
            ],
            "i": "metadata/binary/framework::vb6-runtime-entry",
            "l": 2
          },
          {
            "d": ".dll extension reference",
            "e": [
              ".dll",
              ".dll"
            ],
            "i": "micro-behaviors/fs/path/extension::dll-dup",
            "l": 2
          },
          {
            "a": "T1059",
            "c": 0.949999988079071,
            "d": "VB6 rtcShell command execution",
            "e": [
              "rtcShell"
            ],
            "i": "micro-behaviors/process/create/shell::vb6-rtcshell",
            "l": 3,
            "m": "E1059"
          },
          {
            "c": 1.0,
            "d": "Binary has 4 or fewer sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "objectives/command-and-control/infrastructure/config::max-sections-4",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 20+ imports",
            "e": [
              "binary.import_count = 30.00"
            ],
            "i": "metadata/binary/metrics::many-imports-20",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.8399999737739563,
            "d": "VB6 PE with three sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "objectives/anti-static/obfuscation/payload::three-section-vb6-layout",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.8799999952316284,
            "d": "Explorer CabinetState registry path",
            "e": [
              "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CabinetState"
            ],
            "i": "metadata/file/text::explorer-cabinet-state-path",
            "l": 3
          },
          {
            "c": 0.9900000095367432,
            "d": "MSVBVM60 runtime marker",
            "e": [
              "MSVBVM60.DLL"
            ],
            "i": "well-known/malware/worm/ludbaruma::msvbvm60-runtime",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.9599999785423279,
            "d": "NoFolderOptions policy value",
            "e": [
              "NoFolderOptions"
            ],
            "i": "objectives/impact/degrade/system::no-folder-options",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "OriginalFilename field marker",
            "e": [
              "OriginalFilename"
            ],
            "i": "well-known/malware/worm/ludbaruma::originalfilename-field",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Shell namespace method string",
            "e": [
              "Namespace"
            ],
            "i": "micro-behaviors/os/com/object::namespace-method",
            "l": 1
          },
          {
            "c": 0.8799999952316284,
            "d": "VB6 file length helper alias",
            "e": [
              "rtcFileLength"
            ],
            "i": "micro-behaviors/fs/file/read::vb6-rtcfilelength",
            "l": 2
          },
          {
            "c": 0.9399999976158142,
            "d": "Explorer Advanced registry path",
            "e": [
              "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced"
            ],
            "i": "metadata/file/text::explorer-advanced-path",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 25+ imports",
            "e": [
              "binary.import_count = 30.00"
            ],
            "i": "metadata/binary/metrics::many-imports-25",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "VB6 random number helper",
            "e": [
              "rtcRandomNext"
            ],
            "i": "micro-behaviors/os/random/generator::vb6-rtc-random-next",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE FileVersion metadata field",
            "e": [
              "FileVersion"
            ],
            "i": "metadata/package/versioning::pe-fileversion-field",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Low function count metric",
            "e": [
              "binary.function_count = 6.00"
            ],
            "i": "metadata/binary/metrics/markers::low-function-count-marker",
            "l": 1
          },
          {
            "a": "T1053.005",
            "c": 0.8999999761581421,
            "d": "Hidden task property",
            "e": [
              "Hidden"
            ],
            "i": "objectives/persistence/login/scheduled-task::hidden-task-property",
            "l": 1,
            "m": "F0012"
          },
          {
            "c": 0.949999988079071,
            "d": "Explorer policies registry path",
            "e": [
              "Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer"
            ],
            "i": "metadata/file/text::policies-explorer-path",
            "l": 2
          },
          {
            "a": "T1112",
            "c": 0.8500000238418579,
            "d": "Create registry key via WinAPI",
            "e": [
              "RegCreateKeyA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-create-key-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "VB6 randomize helper",
            "e": [
              "rtcRandomize"
            ],
            "i": "micro-behaviors/os/random/generator::vb6-rtc-randomize",
            "l": 2
          },
          {
            "c": 0.7200000286102295,
            "d": "Short uppercase mutex token",
            "e": [
              "UUCCCDVWX",
              "LMNOPQRSTUV",
              "CDEFGGGHIJK"
            ],
            "i": "micro-behaviors/process/sync/mutex::short-uppercase-token",
            "l": 1,
            "m": "C0042"
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Set registry value ANSI",
            "e": [
              "RegSetValueExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-set-value-ex-a",
            "l": 2
          },
          {
            "a": "T1112",
            "c": 0.8799999952316284,
            "d": "Create registry key ANSI",
            "e": [
              "RegCreateKeyExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-create-key-ex-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE resource section",
            "e": [
              ".rsrc"
            ],
            "i": "metadata/binary/section/names::pe-resource-section",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Close handle",
            "e": [
              "CloseHandle"
            ],
            "i": "micro-behaviors/process/create/spawn::close-handle-dup",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "VB6 event sink helper",
            "e": [
              "EVENT_SINK_AddRef",
              "EVENT_SINK_Release",
              "EVENT_SINK_QueryInterface"
            ],
            "i": "metadata/binary/framework::vb6-runtime-event-helper",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.9900000095367432,
            "d": "PE version resource text",
            "e": [
              "VS_VERSION_INFO"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::anydesk-version-info",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.9399999976158142,
            "d": "Hidden files visibility value",
            "e": [
              "Hidden"
            ],
            "i": "metadata/file/text::hidden-files-value",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "Very low code entropy, minimal code",
            "e": [
              "binary.code_entropy = 0.00"
            ],
            "i": "metadata/binary/resource::low-code-entropy",
            "l": 2
          },
          {
            "c": 0.9900000095367432,
            "d": "MSVBVM60 runtime marker",
            "e": [
              "MSVBVM60.DLL"
            ],
            "i": "well-known/malware/trojan/shellobject::msvbvm60-runtime",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Skips Windows installation directories",
            "e": [
              "WINDOWS"
            ],
            "i": "objectives/impact/infect/binary::skip-windows-install-dir",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.8999999761581421,
            "d": "VB6 rtcCreateObject2 COM constructor",
            "e": [
              "rtcCreateObject2"
            ],
            "i": "micro-behaviors/data/string::vb6-string-construction-create",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1112",
            "c": 0.699999988079071,
            "d": "HKCU\\Software path string",
            "e": [
              "Software\\M",
              "Software\\M",
              "Software\\M"
            ],
            "i": "objectives/anti-static/obfuscation/payload::hkcu-software-text",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.9399999976158142,
            "d": "VB6 DllFunctionCall thunk",
            "e": [
              "DllFunctionCall"
            ],
            "i": "micro-behaviors/dylib/lookup::vb6-dll-function-call",
            "l": 3
          },
          {
            "c": 0.4000000059604645,
            "d": "Very few functions detected",
            "e": [
              "binary.function_count = 6.00"
            ],
            "i": "metadata/binary/metrics::few-functions",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.9200000166893005,
            "d": "Zero-entropy executable section (carved/packed PE)",
            "e": [
              ".text (size: 45056, entropy: 0.00, perms: -r-x)"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics::zero-entropy-executable-section",
            "l": 4,
            "m": "B0032"
          },
          {
            "a": "T1489",
            "c": 0.699999988079071,
            "d": "Versioned service stop context",
            "e": [
              "VS_VERSION_INFO"
            ],
            "i": "objectives/impact/services/stop::versioned-service-stop-context",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Low function count metric",
            "e": [
              "binary.function_count = 6.00"
            ],
            "i": "metadata/binary/anomaly::low-function-count-marker",
            "l": 1
          },
          {
            "d": ".exe extension reference",
            "e": [
              ".exe"
            ],
            "i": "micro-behaviors/fs/path/extension::exe-dup",
            "l": 1
          },
          {
            "a": "T1027.007",
            "c": 0.800000011920929,
            "d": "DLL name strings without LoadLibrary import",
            "e": [
              "binary.import_count = 30.00"
            ],
            "i": "objectives/anti-static/obfuscation/string/runtime-decrypt::dll-names-no-loadlibrary",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "c": 0.8500000238418579,
            "d": "PE with malformed section layout",
            "e": [
              "binary.has_malformed_structure = 1.00"
            ],
            "i": "metadata/binary/metrics::malformed-pe-structure",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Tiny C string section ratio",
            "e": [
              " = 0.0% of total (0 / 73888 bytes)"
            ],
            "i": "metadata/binary/section/metrics::tiny-cstring-section",
            "l": 1
          },
          {
            "a": "T1105",
            "c": 0.800000011920929,
            "d": "Compact PE import table",
            "e": [
              "binary.import_count = 30.00"
            ],
            "i": "objectives/command-and-control/dropper/delivery/download-execute::compact-import-table",
            "l": 1,
            "m": "E1105"
          },
          {
            "a": "T1027",
            "c": 0.8600000143051147,
            "d": "Long mixed-case identifiers cluster",
            "e": [
              "AdjustTokenPrivileges",
              "GetWindowTextLengthA"
            ],
            "i": "objectives/anti-static/obfuscation/string::long-mixedcase-identifiers",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.6000000238418579,
            "d": "Very few sections (merged/stripped)",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "metadata/binary/metrics::few-sections",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary is not digitally signed",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed::unsigned",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links MSVBVM60.DLL (MethCallEngine, rtcRandomNext, rtcRandomize, rtcMsgBox, rtcDoEvents, ... +25 more)",
            "e": [
              "MSVBVM60.DLL"
            ],
            "i": "metadata/dylib::msvbvm60/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "VB6 shell execution primitive",
            "e": [
              "rtcShell",
              "ThunRTMain"
            ],
            "i": "micro-behaviors/process/create/shell::vb6-shell-execution",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "PE version resource metadata",
            "e": [
              "ProductVersion",
              "FileVersion",
              "VS_VERSION_INFO"
            ],
            "i": "metadata/package/versioning::version-resource-metadata",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "Visual Basic 6 application framework",
            "e": [
              "MSVBVM60.DLL",
              "EVENT_SINK_QueryInterface",
              "EVENT_SINK_AddRef",
              "EVENT_SINK_Release",
              "rtcDoEvents",
              "ThunRTMain"
            ],
            "i": "metadata/binary/framework::vb6-application-framework",
            "l": 2
          },
          {
            "c": 0.8799999952316284,
            "d": "Shell COM archive copy pattern",
            "e": [
              "Shell.Application",
              "Namespace",
              "CopyHere"
            ],
            "i": "micro-behaviors/os/com/object::shell-namespace-copyhere",
            "l": 3
          },
          {
            "c": 0.9200000166893005,
            "d": "VB6 runtime PRNG helpers",
            "e": [
              "rtcRandomNext",
              "rtcRandomize"
            ],
            "i": "micro-behaviors/os/random/generator::vb6-runtime-prng",
            "l": 2
          },
          {
            "a": "T1105",
            "c": 0.8999999761581421,
            "d": "COM ZIP extraction behavior",
            "e": [
              "CopyHere",
              "temp.zip",
              "Namespace",
              "Shell.Application"
            ],
            "i": "objectives/command-and-control/dropper/staging/archive::com-zip-extraction",
            "l": 4
          },
          {
            "c": 0.949999988079071,
            "d": "VB6 runtime API dispatch",
            "e": [
              "ThunRTMain",
              "EVENT_SINK_AddRef",
              "EVENT_SINK_Release",
              "rtcDoEvents",
              "EVENT_SINK_QueryInterface",
              "MSVBVM60.DLL",
              "DllFunctionCall"
            ],
            "i": "micro-behaviors/dylib/lookup::vb6-runtime-api-dispatch",
            "l": 3
          },
          {
            "a": "T1112",
            "c": 0.9200000166893005,
            "d": "Registry open create and write APIs",
            "e": [
              "RegSetValueExA",
              "RegOpenKeyExA",
              "RegCreateKeyExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::registry-write-api-chain",
            "l": 3
          },
          {
            "a": "T1564.001",
            "c": 0.9700000286102295,
            "d": "Hides file extensions via registry tamper",
            "e": [
              "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced",
              "HideFileExt",
              "RegOpenKeyExA",
              "RegCreateKeyExA",
              "RegSetValueExA"
            ],
            "i": "objectives/evasion/file-hiding/system::hide-file-ext-registry-tamper",
            "l": 5
          },
          {
            "a": "T1564.001",
            "c": 0.9800000190734863,
            "d": "Suppresses Explorer file visibility controls",
            "e": [
              "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced",
              "Hidden",
              "RegSetValueExA",
              "RegOpenKeyExA",
              "HideFileExt",
              "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CabinetState",
              "RegCreateKeyExA"
            ],
            "i": "objectives/evasion/file-hiding/system::explorer-visibility-suppression",
            "l": 5
          }
        ],
        "sha": "118328d7d347d53e5e9f7d86636bc767763b2bd4f20e5118ae76b828db854de5",
        "path": "/data/samples/bad/datasets/pe-machine-learning-dataset/36989",
        "type": "pe"
      }
    ],
    "tv": "b2c18"
  }
}