{
  "ml": {
    "v": "4",
    "fs": [
      {
        "id": 0,
        "prob": 0.008890271186828613,
        "class": 0
      },
      {
        "id": 1,
        "prob": 0.008890271186828613,
        "class": 0
      }
    ],
    "prob": 0.008890271,
    "class": 0,
    "models": [
      {
        "m": "az",
        "prob": 0.0011037971,
        "class": 0
      },
      {
        "m": "az/archive",
        "prob": 0.0005775165,
        "class": 0
      }
    ],
    "version": "v16.16",
    "thresholds": [
      0.9953178,
      0.9991311
    ],
    "analyzed_at": "2026-05-03T06:53:17Z"
  },
  "path": "perl5283delta.1perl.gz",
  "raw": {
    "v": "4",
    "fs": [
      {
        "f": "O₄(As₃CPrS)H(Db)Md₂(Pa)",
        "x": 1,
        "id": 0,
        "sz": 3248,
        "ts": [
          {
            "c": 1.0,
            "d": "Package references CHANGES",
            "e": [
              "Changes"
            ],
            "i": "metadata/package/documentation::references-changelog-changes",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.949999988079071,
            "d": "Generated source marker text",
            "e": [
              "automatically generated"
            ],
            "i": "objectives/anti-static/obfuscation/code-metrics/identifiers::generated-source-marker",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1195.002",
            "c": 1.0,
            "d": "Buffer keyword",
            "e": [
              "\n.    ds C'\n'br\\}\n.\\\"\n.\\\" Escape single quotes in literal strings from groff's Unicode transform.\n.ie \\n(.g .ds Aq \\(aq\n.el     ",
              "10543] Buffer overflow caused by a crafted regular expression\"\n.IX Subsection \"[CVE-2020-10543] Buffer overflow caused by a craf",
              "[CVE\\-2020\\-12723] Buffer overflow caused by a crafted regular expression",
              "12723] Buffer overflow caused by a crafted regular expression",
              "[CVE-2020-12723] Buffer overflow caused by a crafted regular expression",
              "[CVE-2020-12723] Buffer overflow caused by a crafted regular expression"
            ],
            "i": "objectives/supply-chain/hidden-payload/staging::buffer-keyword",
            "l": 1
          },
          {
            "a": "T1068",
            "c": 0.800000011920929,
            "d": "References a CVE identifier",
            "e": [
              "CVE-2020-10543"
            ],
            "i": "objectives/privilege-escalation/exploit/vulnerabilities::cve-mention",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Path-like string pattern",
            "e": [
              "x:\\\\$1\\t\\\\n%\\t\"\\\\$2\""
            ],
            "i": "micro-behaviors/data/text/malware::path-like-pattern",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "File has 30 or more lines",
            "e": [
              "text.total_lines = 189.00"
            ],
            "i": "metadata/package/metrics::file-has-30-plus-lines",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.8999999761581421,
            "d": "Low string density base64 context",
            "e": [
              "text.string_density = 0.54"
            ],
            "i": "objectives/anti-static/obfuscation/code-metrics::js-base64-candidate-low-string-density",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 1.0,
            "d": "HISTORY documentation reference",
            "e": [
              "history"
            ],
            "i": "metadata/package/documentation::references-changelog-history",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "Roff heading prose macros",
            "e": [
              ".PP"
            ],
            "i": "metadata/file/text::roff-heading-macros",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "perl string",
            "e": [
              "\n.    ds C'\n'br\\}\n.\\\"\n.\\\" Escape single quotes in literal strings from groff's Unicode transform.\n.ie \\n(.g .ds Aq \\(aq\n.el     ",
              "\n.IX Title \"PERL5283DELTA 1perl\"\n.TH PERL5283DELTA 1perl 2026-04-11 \"perl v5.42.2\" \"Perl Programmers Reference Guide\"\n.",
              " way too many mistakes in technical documents.\n.if n .ad l\n.nh\n.SH NAME\nperl5283delta ",
              " what is new for perl v5.28.3\n.SH DESCRIPTION\n.IX Header \"DESCRIPTION\"\nThis document describes differences between the 5.28.2 re",
              "perlthanks",
              "    perlthanks\n.Ve\n.PP\nThis will send an email to the Perl 5 Porters list with your show of thanks.\n.SH \"SEE ALSO\"\n.IX Header \"S",
              "R file for how to build Perl.\n.PP\nThe "
            ],
            "i": "objectives/command-and-control/dropper::perl-str",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.949999988079071,
            "d": "Generated file marker text",
            "e": [
              "automatically generated"
            ],
            "i": "objectives/anti-static/obfuscation/code-metrics/structure::generated-file-marker",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.30000001192092896,
            "d": "stderr string reference",
            "e": [
              "\n.    ds C'\n'br\\}\n.\\\"\n.\\\" Escape single quotes in literal strings from groff's Unicode transform.\n.ie \\n(.g .ds Aq \\(aq\n.el     ",
              " If the F register is \u003e0, we'll generate index entries on stderr for\n."
            ],
            "i": "micro-behaviors/process/fd/stdio::stderr-string",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "CVE reference pattern",
            "e": [
              "CVE-2020-10543"
            ],
            "i": "micro-behaviors/data/text/security::cve-pattern",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.6000000238418579,
            "d": "No comments in code",
            "e": [
              "comments.total = 0.00"
            ],
            "i": "objectives/anti-static/obfuscation/code-metrics/structure::no-comments",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.20000000298023224,
            "d": "output keyword",
            "e": [
              "output"
            ],
            "i": "micro-behaviors/data/text/keywords::output",
            "l": 1
          },
          {
            "d": "overflow keyword",
            "e": [
              "overflow"
            ],
            "i": "micro-behaviors/data/text/keywords::overflow",
            "l": 1
          }
        ],
        "sha": "363542281072b92b592e947857c287cc25c3c5a6f2a463ca2792411bdad831ab",
        "path": "perl5283delta.1perl.gz",
        "type": "gz"
      },
      {
        "f": "O₄(As₃CPrS)H(Db)Md₂(Pa)",
        "x": 1,
        "dp": 1,
        "id": 1,
        "is": [
          "VinCSS",
          "CWS_study_chunk",
          "the"
        ],
        "ms": {
          "text": {
            "digit_ratio": 0.03,
            "space_count": 1042.0,
            "total_lines": 189.0,
            "char_entropy": 5.06,
            "unique_chars": 88.0,
            "import_density": 1.59,
            "string_density": 0.54,
            "ascii_art_lines": 2.0,
            "avg_line_length": 38.34,
            "max_line_length": 114.0,
            "last_line_length": 69.0,
            "most_common_char": "e",
            "whitespace_ratio": 0.17,
            "most_common_ratio": 0.09,
            "identifier_density": 3.12,
            "line_length_stddev": 31.47,
            "encoded_string_ratio": 0.02,
            "normalized_import_count": 0.22,
            "normalized_string_count": 7.42,
            "repeated_char_sequences": 4.0,
            "suspicious_string_ratio": 0.04,
            "max_inline_whitespace_run": 12.0,
            "suspicious_identifier_ratio": 0.04,
            "normalized_unique_identifiers": 43.11
          },
          "imports": {
            "total": 3.0,
            "unique_modules": 3.0,
            "third_party_count": 3.0,
            "third_party_ratio": 1.0
          },
          "strings": {
            "total": 102.0,
            "avg_length": 50.75,
            "max_length": 1688.0,
            "avg_entropy": 3.09,
            "sql_strings": 2.0,
            "total_bytes": 5176.0,
            "entropy_stddev": 1.28,
            "base64_candidates": 2.0,
            "very_long_strings": 1.0,
            "high_entropy_count": 1.0,
            "shell_command_strings": 2.0
          },
          "comments": {},
          "functions": {},
          "identifiers": {
            "total": 589.0,
            "avg_length": 5.92,
            "max_length": 16.0,
            "min_length": 1.0,
            "avg_entropy": 2.17,
            "reuse_ratio": 0.55,
            "unique_count": 326.0,
            "length_stddev": 2.95,
            "hex_like_names": 1.0,
            "has_digit_ratio": 0.01,
            "sequential_names": 12.0,
            "single_char_count": 11.0,
            "single_char_ratio": 0.03,
            "high_entropy_count": 2.0,
            "high_entropy_ratio": 0.01,
            "all_lowercase_ratio": 0.75,
            "all_uppercase_ratio": 0.02,
            "repeated_char_names": 1.0,
            "numeric_suffix_count": 2.0
          }
        },
        "ss": [
          [
            218,
            " Vertical space (when we can't use .PP)"
          ],
          [
            294,
            " Begin verbatim text"
          ],
          [
            347,
            " End verbatim text"
          ],
          [
            387,
            " and \\*(C' are quotes in nroff, nothing in troff, for use with C\u003c\u003e.\n.ie n \\{\\\n.    ds C"
          ],
          [
            388,
            " and "
          ],
          [
            395,
            "(C' are quotes in nroff, nothing in troff, for use with C\u003c\u003e.\n.ie n "
          ],
          [
            466,
            ".    ds C"
          ],
          [
            489,
            " \"\"\n"
          ],
          [
            490,
            " "
          ],
          [
            516,
            "\n.    ds C'\n'br\\}\n.\\\"\n.\\\" Escape single quotes in literal strings from groff's Unicode transform.\n.ie \\n(.g .ds Aq \\(aq\n.el     "
          ],
          [
            517,
            "\n.    ds C'\n'br"
          ],
          [
            534,
            "\n."
          ],
          [
            538,
            "\n."
          ],
          [
            542,
            " Escape single quotes in literal strings from groff's Unicode transform.\n.ie "
          ],
          [
            621,
            "(.g .ds Aq "
          ],
          [
            634,
            "aq\n.el       .ds Aq '\n."
          ],
          [
            659,
            "\n."
          ],
          [
            663,
            " If the F register is \u003e0, we'll generate index entries on stderr for\n."
          ],
          [
            735,
            " titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index\n."
          ],
          [
            810,
            " entries marked with X\u003c\u003e in POD.  Of course, you'll have to process the\n."
          ],
          [
            885,
            " output yourself in some meaningful fashion.\n."
          ],
          [
            933,
            "\n."
          ],
          [
            937,
            " Avoid warning from groff about undefined register 'F'.\n.de IX\n..\n.nr rF 0\n.if "
          ],
          [
            1018,
            "(.g .if rF .nr rF 1\n.if ("
          ],
          [
            1045,
            "(rF:("
          ],
          [
            1052,
            "(.g==0)) "
          ],
          [
            1065,
            ".    if "
          ],
          [
            1075,
            "F "
          ],
          [
            1081,
            ".        de IX\n.        tm Index:"
          ],
          [
            1116,
            "$1"
          ],
          [
            1122,
            "n%"
          ],
          [
            1129,
            "$2\"\n..\n.        if !"
          ],
          [
            1151,
            "F==2 "
          ],
          [
            1160,
            ".            nr % 0\n.            nr F 2\n.        "
          ],
          [
            1211,
            "\n.    "
          ],
          [
            1219,
            "\n."
          ],
          [
            1223,
            "\n.rr rF\n."
          ],
          [
            1234,
            "\n."
          ],
          [
            1238,
            " Required to disable full justification in groff 1.23.0.\n.if n .ds AD l\n."
          ],
          [
            1313,
            " ========================================================================\n."
          ],
          [
            1390,
            "\n.IX Title \"PERL5283DELTA 1perl\"\n.TH PERL5283DELTA 1perl 2026-04-11 \"perl v5.42.2\" \"Perl Programmers Reference Guide\"\n."
          ],
          [
            1511,
            " For nroff, turn off justification.  Always turn off hyphenation; it makes\n."
          ],
          [
            1589,
            " way too many mistakes in technical documents.\n.if n .ad l\n.nh\n.SH NAME\nperl5283delta "
          ],
          [
            1677,
            " what is new for perl v5.28.3\n.SH DESCRIPTION\n.IX Header \"DESCRIPTION\"\nThis document describes differences between the 5.28.2 re"
          ],
          [
            2027,
            "2020"
          ],
          [
            2033,
            "10543] Buffer overflow caused by a crafted regular expression\"\n.IX Subsection \"[CVE-2020-10543] Buffer overflow caused by a craf"
          ],
          [
            2196,
            "(CW"
          ],
          [
            2201,
            "(C"
          ],
          [
            2217,
            "R integer overflow in the storage space calculations for"
          ],
          [
            2786,
            "[CVE\\-2020\\-10878] Integer overflow via malformed bytecode produced by a crafted regular expression"
          ],
          [
            2787,
            "[CVE"
          ],
          [
            2793,
            "2020"
          ],
          [
            2799,
            "10878] Integer overflow via malformed bytecode produced by a crafted regular expression"
          ],
          [
            2903,
            "[CVE-2020-10878] Integer overflow via malformed bytecode produced by a crafted regular expression"
          ],
          [
            2904,
            "[CVE-2020-10878] Integer overflow via malformed bytecode produced by a crafted regular expression"
          ],
          [
            3375,
            "[CVE\\-2020\\-12723] Buffer overflow caused by a crafted regular expression"
          ],
          [
            3376,
            "[CVE"
          ],
          [
            3382,
            "2020"
          ],
          [
            3388,
            "12723] Buffer overflow caused by a crafted regular expression"
          ],
          [
            3466,
            "[CVE-2020-12723] Buffer overflow caused by a crafted regular expression"
          ],
          [
            3467,
            "[CVE-2020-12723] Buffer overflow caused by a crafted regular expression"
          ],
          [
            4218,
            "Incompatible Changes"
          ],
          [
            4219,
            "Incompatible Changes"
          ],
          [
            4252,
            "Incompatible Changes"
          ],
          [
            4253,
            "Incompatible Changes"
          ],
          [
            4417,
            "Reporting Bugs"
          ],
          [
            4418,
            "Reporting Bugs"
          ],
          [
            4445,
            "Modules and Pragmata"
          ],
          [
            4446,
            "Modules and Pragmata"
          ],
          [
            4479,
            "Modules and Pragmata"
          ],
          [
            4480,
            "Modules and Pragmata"
          ],
          [
            4506,
            "Updated Modules and Pragmata"
          ],
          [
            4507,
            "Updated Modules and Pragmata"
          ],
          [
            4552,
            "Updated Modules and Pragmata"
          ],
          [
            4553,
            "Updated Modules and Pragmata"
          ],
          [
            4694,
            "Testing"
          ],
          [
            4695,
            "Testing"
          ],
          [
            4825,
            "Acknowledgements"
          ],
          [
            4826,
            "Acknowledgements"
          ],
          [
            6191,
            "Reporting Bugs"
          ],
          [
            6192,
            "Reporting Bugs"
          ],
          [
            6219,
            "Reporting Bugs"
          ],
          [
            6220,
            "Reporting Bugs"
          ],
          [
            6742,
            "SECURITY VULNERABILITY CONTACT INFORMATION"
          ],
          [
            6743,
            "SECURITY VULNERABILITY CONTACT INFORMATION"
          ],
          [
            6842,
            "Give Thanks"
          ],
          [
            6843,
            "Give Thanks"
          ],
          [
            6867,
            "Give Thanks"
          ],
          [
            6868,
            "Give Thanks"
          ],
          [
            6996,
            "perlthanks"
          ],
          [
            7008,
            "(C"
          ],
          [
            7013,
            "R program:\n.PP\n.Vb 1\n"
          ],
          [
            7036,
            "    perlthanks\n.Ve\n.PP\nThis will send an email to the Perl 5 Porters list with your show of thanks.\n.SH \"SEE ALSO\"\n.IX Header \"S"
          ],
          [
            7179,
            "IChanges"
          ],
          [
            7189,
            "R file for an explanation of how to view exhaustive details on\nwhat changed.\n.PP\nThe "
          ],
          [
            7276,
            "IINSTALL"
          ],
          [
            7286,
            "R file for how to build Perl.\n.PP\nThe "
          ],
          [
            7326,
            "IREADME"
          ],
          [
            7335,
            "R file for general stuff.\n.PP\nThe "
          ],
          [
            7371,
            "IArtistic"
          ],
          [
            7382,
            "R and "
          ],
          [
            7390,
            "ICopying"
          ]
        ],
        "sz": 7435,
        "ts": [
          {
            "a": "T1027",
            "c": 0.8999999761581421,
            "d": "Low string density base64 context",
            "e": [
              "text.string_density = 0.54"
            ],
            "i": "objectives/anti-static/obfuscation/code-metrics::js-base64-candidate-low-string-density",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.8999999761581421,
            "d": "File has 30 or more lines",
            "e": [
              "text.total_lines = 189.00"
            ],
            "i": "metadata/package/metrics::file-has-30-plus-lines",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "Roff heading prose macros",
            "e": [
              ".PP"
            ],
            "i": "metadata/file/text::roff-heading-macros",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Path-like string pattern",
            "e": [
              "x:\\\\$1\\t\\\\n%\\t\"\\\\$2\""
            ],
            "i": "micro-behaviors/data/text/malware::path-like-pattern",
            "l": 2
          },
          {
            "d": "overflow keyword",
            "e": [
              "overflow"
            ],
            "i": "micro-behaviors/data/text/keywords::overflow",
            "l": 1
          },
          {
            "a": "T1195.002",
            "c": 1.0,
            "d": "Buffer keyword",
            "e": [
              "\n.    ds C'\n'br\\}\n.\\\"\n.\\\" Escape single quotes in literal strings from groff's Unicode transform.\n.ie \\n(.g .ds Aq \\(aq\n.el     ",
              "10543] Buffer overflow caused by a crafted regular expression\"\n.IX Subsection \"[CVE-2020-10543] Buffer overflow caused by a craf",
              "[CVE\\-2020\\-12723] Buffer overflow caused by a crafted regular expression",
              "12723] Buffer overflow caused by a crafted regular expression",
              "[CVE-2020-12723] Buffer overflow caused by a crafted regular expression",
              "[CVE-2020-12723] Buffer overflow caused by a crafted regular expression"
            ],
            "i": "objectives/supply-chain/hidden-payload/staging::buffer-keyword",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.949999988079071,
            "d": "Generated source marker text",
            "e": [
              "automatically generated"
            ],
            "i": "objectives/anti-static/obfuscation/code-metrics/identifiers::generated-source-marker",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 1.0,
            "d": "Package references CHANGES",
            "e": [
              "Changes"
            ],
            "i": "metadata/package/documentation::references-changelog-changes",
            "l": 2
          },
          {
            "c": 0.20000000298023224,
            "d": "output keyword",
            "e": [
              "output"
            ],
            "i": "micro-behaviors/data/text/keywords::output",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "HISTORY documentation reference",
            "e": [
              "history"
            ],
            "i": "metadata/package/documentation::references-changelog-history",
            "l": 2
          },
          {
            "c": 0.30000001192092896,
            "d": "stderr string reference",
            "e": [
              "\n.    ds C'\n'br\\}\n.\\\"\n.\\\" Escape single quotes in literal strings from groff's Unicode transform.\n.ie \\n(.g .ds Aq \\(aq\n.el     ",
              " If the F register is \u003e0, we'll generate index entries on stderr for\n."
            ],
            "i": "micro-behaviors/process/fd/stdio::stderr-string",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "perl string",
            "e": [
              "\n.    ds C'\n'br\\}\n.\\\"\n.\\\" Escape single quotes in literal strings from groff's Unicode transform.\n.ie \\n(.g .ds Aq \\(aq\n.el     ",
              "\n.IX Title \"PERL5283DELTA 1perl\"\n.TH PERL5283DELTA 1perl 2026-04-11 \"perl v5.42.2\" \"Perl Programmers Reference Guide\"\n.",
              " way too many mistakes in technical documents.\n.if n .ad l\n.nh\n.SH NAME\nperl5283delta ",
              " what is new for perl v5.28.3\n.SH DESCRIPTION\n.IX Header \"DESCRIPTION\"\nThis document describes differences between the 5.28.2 re",
              "perlthanks",
              "    perlthanks\n.Ve\n.PP\nThis will send an email to the Perl 5 Porters list with your show of thanks.\n.SH \"SEE ALSO\"\n.IX Header \"S",
              "R file for how to build Perl.\n.PP\nThe "
            ],
            "i": "objectives/command-and-control/dropper::perl-str",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.949999988079071,
            "d": "Generated file marker text",
            "e": [
              "automatically generated"
            ],
            "i": "objectives/anti-static/obfuscation/code-metrics/structure::generated-file-marker",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.800000011920929,
            "d": "CVE reference pattern",
            "e": [
              "CVE-2020-10543"
            ],
            "i": "micro-behaviors/data/text/security::cve-pattern",
            "l": 2
          },
          {
            "a": "T1068",
            "c": 0.800000011920929,
            "d": "References a CVE identifier",
            "e": [
              "CVE-2020-10543"
            ],
            "i": "objectives/privilege-escalation/exploit/vulnerabilities::cve-mention",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.6000000238418579,
            "d": "No comments in code",
            "e": [
              "comments.total = 0.00"
            ],
            "i": "objectives/anti-static/obfuscation/code-metrics/structure::no-comments",
            "l": 1,
            "m": "B0032"
          }
        ],
        "sha": "fd00260de6055df7354ea06e9f61a36c5205513275f26b23b62783113fa60df3",
        "path": "perl5283delta.1perl.gz!!perl5283delta.1perl",
        "type": "javascript"
      }
    ],
    "tv": "b2c18"
  }
}