{
  "ml": {
    "v": "4",
    "fs": [
      {
        "id": 0,
        "prob": 0.9989545345306396,
        "class": 1
      },
      {
        "id": 1,
        "prob": 0.9091514945030212,
        "class": 0
      },
      {
        "id": 2,
        "prob": 0.8691674470901489,
        "class": 0
      },
      {
        "id": 3,
        "prob": 0.8320392370223999,
        "class": 0
      },
      {
        "id": 4,
        "prob": 0.2697274088859558,
        "class": 0
      },
      {
        "id": 5,
        "prob": 0.8035574555397034,
        "class": 0
      },
      {
        "id": 6,
        "prob": 0.48227646946907043,
        "class": 0
      }
    ],
    "prob": 0.99895453,
    "class": 1,
    "oprob": 0.99895453,
    "models": [
      {
        "m": "az",
        "prob": 0.9962555,
        "class": 0
      },
      {
        "m": "az/native",
        "prob": 0.99797446,
        "class": 0
      },
      {
        "m": "az/pe",
        "prob": 0.99895453,
        "class": 0
      }
    ],
    "oclass": 0,
    "version": "v16.16",
    "thresholds": [
      0.9961138,
      0.99909174
    ],
    "analyzed_at": "2026-05-06T08:38:46Z"
  },
  "path": "502438",
  "raw": {
    "v": "4",
    "fs": [
      {
        "f": "KO₁₂(As₁₁Er₁₂P₅SC₁₅AlCo₂Dy₂I₇LaPr₂Xe)H₉(Cm₂Db₃F₇HfMgOs₆Po₈CrDs)Md₄(Bi₉BkSiPa)",
        "k": {
          "pe.timestamp": 1268634470,
          "hashes.imphash": "b79ccc89c12a6cfc9c32a2979ad8cc72",
          "build.target_arch": "x86",
          "pe.linker_version": "9.0",
          "pe.resource_types[0]": "RT_BITMAP",
          "pe.resource_types[1]": "RT_ICON",
          "pe.resource_types[2]": "RT_DIALOG",
          "pe.resource_types[3]": "RT_STRING",
          "pe.resource_types[4]": "RT_GROUP_ICON",
          "pe.resource_types[5]": "RT_MANIFEST",
          "pe.manifest.dpi_aware": true,
          "pe.rich_header.xor_key": "0x8defa739",
          "hashes.rich_header_hash": "94967df01c5600a04f08b27eed7fcf3da07fd69706058a35db6bcf16d7e8b4d9",
          "pe.inflated_sections[0]": ".data",
          "pe.manifest.description": "WinRAR SFX module",
          "pe.dll_characteristics.no_seh": true,
          "binary.top_complex_unnamed[0].cc": 141,
          "binary.top_complex_unnamed[1].cc": 111,
          "binary.top_complex_unnamed[2].cc": 105,
          "binary.top_complex_unnamed[3].cc": 64,
          "binary.top_complex_unnamed[4].cc": 57,
          "binary.top_complex_unnamed[5].cc": 55,
          "binary.top_complex_unnamed[6].cc": 53,
          "binary.top_complex_unnamed[7].cc": 41,
          "pe.dll_characteristics.nx_compat": true,
          "pe.manifest.dependencies[0].name": "Microsoft.Windows.Common-Controls",
          "pe.manifest.dependencies[0].type": "win32",
          "pe.manifest.supported_os[0].guid": "{e2011457-1546-43c5-a5fe-008deee3d3f0}",
          "pe.manifest.supported_os[0].name": "vista",
          "pe.manifest.supported_os[1].guid": "{35138b9a-5d96-4fbd-8e2d-a2440225f93a}",
          "pe.manifest.supported_os[1].name": "win7",
          "binary.top_complex_unnamed[0].bbs": 204,
          "binary.top_complex_unnamed[1].bbs": 219,
          "binary.top_complex_unnamed[2].bbs": 158,
          "binary.top_complex_unnamed[3].bbs": 99,
          "binary.top_complex_unnamed[4].bbs": 102,
          "binary.top_complex_unnamed[5].bbs": 95,
          "binary.top_complex_unnamed[6].bbs": 92,
          "binary.top_complex_unnamed[7].bbs": 73,
          "binary.top_complex_unnamed[0].addr": "0x4039f5",
          "binary.top_complex_unnamed[0].size": 3447,
          "binary.top_complex_unnamed[1].addr": "0x4082dd",
          "binary.top_complex_unnamed[1].size": 1484,
          "binary.top_complex_unnamed[2].addr": "0x40bf72",
          "binary.top_complex_unnamed[2].size": 2767,
          "binary.top_complex_unnamed[3].addr": "0x407de7",
          "binary.top_complex_unnamed[3].size": 1270,
          "binary.top_complex_unnamed[4].addr": "0x40cc05",
          "binary.top_complex_unnamed[4].size": 1914,
          "binary.top_complex_unnamed[5].addr": "0x401ca1",
          "binary.top_complex_unnamed[5].size": 2092,
          "binary.top_complex_unnamed[6].addr": "0x410e69",
          "binary.top_complex_unnamed[6].size": 1229,
          "binary.top_complex_unnamed[7].addr": "0x4103c8",
          "binary.top_complex_unnamed[7].size": 1150,
          "pe.manifest.assembly_identity.name": "WinRAR SFX",
          "pe.manifest.assembly_identity.type": "win32",
          "pe.manifest.dependencies[0].version": "6.0.0.0",
          "pe.rich_header.entries[0].use_count": 8,
          "pe.rich_header.entries[1].use_count": 19,
          "pe.rich_header.entries[2].use_count": 171,
          "pe.rich_header.entries[3].use_count": 5,
          "pe.rich_header.entries[4].use_count": 1,
          "pe.rich_header.entries[5].use_count": 44,
          "pe.rich_header.entries[6].use_count": 1,
          "pe.rich_header.entries[7].use_count": 1,
          "pe.rich_header.entries[8].use_count": 1,
          "pe.manifest.dependencies[0].language": "*",
          "pe.rich_header.entries[0].product_id": 109,
          "pe.rich_header.entries[1].product_id": 123,
          "pe.rich_header.entries[2].product_id": 1,
          "pe.rich_header.entries[3].product_id": 149,
          "pe.rich_header.entries[4].product_id": 131,
          "pe.rich_header.entries[5].product_id": 132,
          "pe.rich_header.entries[6].product_id": 146,
          "pe.rich_header.entries[7].product_id": 148,
          "pe.rich_header.entries[8].product_id": 145,
          "pe.manifest.assembly_identity.version": "1.0.0.0",
          "pe.manifest.requested_execution_level": "asInvoker",
          "pe.rich_header.entries[0].build_number": 50727,
          "pe.rich_header.entries[0].product_name": "unknown",
          "pe.rich_header.entries[1].build_number": 50727,
          "pe.rich_header.entries[1].product_name": "unknown",
          "pe.rich_header.entries[2].product_name": "Imp_VS_v6_or_earlier",
          "pe.rich_header.entries[3].build_number": 21022,
          "pe.rich_header.entries[3].product_name": "unknown",
          "pe.rich_header.entries[4].build_number": 30729,
          "pe.rich_header.entries[4].product_name": "C_VS2008_LTCG",
          "pe.rich_header.entries[5].build_number": 30729,
          "pe.rich_header.entries[5].product_name": "Cpp_VS2008_LTCG",
          "pe.rich_header.entries[6].build_number": 30729,
          "pe.rich_header.entries[6].product_name": "Linker_VS2008_LTCG",
          "pe.rich_header.entries[7].build_number": 21022,
          "pe.rich_header.entries[7].product_name": "unknown",
          "pe.rich_header.entries[8].build_number": 30729,
          "pe.rich_header.entries[8].product_name": "Linker_VS2008",
          "pe.dll_characteristics.terminal_server_aware": true,
          "pe.manifest.dependencies[0].public_key_token": "6595b64144ccf1df",
          "pe.manifest.dependencies[0].processor_architecture": "*",
          "pe.manifest.assembly_identity.processor_architecture": "*"
        },
        "x": 175,
        "id": 0,
        "is": [
          "DeleteFileA",
          "DeleteFileW",
          "CreateDirectoryA",
          "CreateDirectoryW",
          "FindClose",
          "FindNextFileA",
          "FindFirstFileA",
          "FindNextFileW",
          "FindFirstFileW",
          "GetTickCount",
          "WideCharToMultiByte",
          "MultiByteToWideChar",
          "GetVersionExA",
          "GlobalAlloc",
          "lstrlenA",
          "GetModuleFileNameA",
          "FindResourceA",
          "GetModuleHandleA",
          "HeapAlloc",
          "GetProcessHeap",
          "HeapFree",
          "HeapReAlloc",
          "CompareStringA",
          "ExitProcess",
          "GetLocaleInfoA",
          "GetNumberFormatA",
          "lstrcmpiA",
          "GetProcAddress",
          "GetDateFormatA",
          "GetTimeFormatA",
          "FileTimeToSystemTime",
          "FileTimeToLocalFileTime",
          "ExpandEnvironmentStringsA",
          "WaitForSingleObject",
          "SetCurrentDirectoryA",
          "Sleep",
          "GetTempPathA",
          "MoveFileExA",
          "UnmapViewOfFile",
          "GetCommandLineA",
          "MapViewOfFile",
          "CreateFileMappingA",
          "GetModuleFileNameW",
          "SetEnvironmentVariableA",
          "OpenFileMappingA",
          "LocalFileTimeToFileTime",
          "SystemTimeToFileTime",
          "GetSystemTime",
          "IsDBCSLeadByte",
          "GetCPInfo",
          "FreeLibrary",
          "LoadLibraryA",
          "GetCurrentDirectoryA",
          "GetFullPathNameA",
          "SetFileAttributesW",
          "SetFileAttributesA",
          "GetFileAttributesW",
          "GetFileAttributesA",
          "WriteFile",
          "SetLastError",
          "GetStdHandle",
          "ReadFile",
          "CreateFileW",
          "CreateFileA",
          "GetFileType",
          "SetEndOfFile",
          "SetFilePointer",
          "MoveFileA",
          "SetFileTime",
          "GetCurrentProcess",
          "CloseHandle",
          "GetLastError",
          "DosDateTimeToFileTime",
          "LookupPrivilegeValueA",
          "RegOpenKeyExA",
          "RegQueryValueExA",
          "RegCreateKeyExA",
          "RegSetValueExA",
          "RegCloseKey",
          "SetFileSecurityW",
          "SetFileSecurityA",
          "OpenProcessToken",
          "AdjustTokenPrivileges",
          "ORDINAL 17",
          "GetSaveFileNameA",
          "CommDlgExtendedError",
          "GetOpenFileNameA",
          "GetDeviceCaps",
          "GetObjectA",
          "CreateCompatibleBitmap",
          "SelectObject",
          "StretchBlt",
          "CreateCompatibleDC",
          "DeleteObject",
          "DeleteDC",
          "CreateStreamOnHGlobal",
          "OleInitialize",
          "CoCreateInstance",
          "OleUninitialize",
          "CLSIDFromString",
          "ORDINAL 8",
          "ShellExecuteExA",
          "SHFileOperationA",
          "SHGetFileInfoA",
          "SHGetSpecialFolderLocation",
          "SHGetMalloc",
          "SHBrowseForFolderA",
          "SHGetPathFromIDListA",
          "SHChangeNotify",
          "ReleaseDC",
          "GetDC",
          "SendMessageA",
          "wsprintfA",
          "SetDlgItemTextA",
          "EndDialog",
          "DestroyIcon",
          "SendDlgItemMessageA",
          "GetDlgItemTextA",
          "DialogBoxParamA",
          "IsWindowVisible",
          "WaitForInputIdle",
          "GetSysColor",
          "PostMessageA",
          "SetMenu",
          "SetFocus",
          "LoadBitmapA",
          "LoadIconA",
          "CharToOemA",
          "OemToCharA",
          "GetClassNameA",
          "CharUpperA",
          "GetWindowRect",
          "GetParent",
          "MapWindowPoints",
          "CreateWindowExA",
          "UpdateWindow",
          "SetWindowTextA",
          "LoadCursorA",
          "RegisterClassExA",
          "SetWindowLongA",
          "GetWindowLongA",
          "DefWindowProcA",
          "PeekMessageA",
          "GetMessageA",
          "TranslateMessage",
          "DispatchMessageA",
          "GetClientRect",
          "CopyRect",
          "IsWindow",
          "MessageBoxA",
          "ShowWindow",
          "GetDlgItem",
          "EnableWindow",
          "FindWindowExA",
          "wvsprintfA",
          "CharToOemBuffA",
          "LoadStringA",
          "SetWindowPos",
          "GetWindowTextA",
          "GetWindow",
          "GetSystemMetrics",
          "OemToCharBuffA",
          "DestroyWindow"
        ],
        "ms": {
          "pe": {
            "machine": 332.0,
            "checksum": 0.0,
            "rsrc_size": 12288.0,
            "subsystem": 2.0,
            "timestamp": 1268634470.0,
            "icon_count": 2.0,
            "image_base": 4194304.0,
            "rsrc_entropy": 4.52,
            "entry_section": ".text",
            "size_of_image": 147456.0,
            "timestamp_day": 15.0,
            "file_alignment": 512.0,
            "resource_count": 6.0,
            "resource_types": [
              "RT_BITMAP",
              "RT_ICON",
              "RT_DIALOG",
              "RT_STRING",
              "RT_GROUP_ICON",
              "RT_MANIFEST"
            ],
            "timestamp_year": 2010.0,
            "characteristics": 259.0,
            "entry_point_rva": 42929.0,
            "size_of_headers": 4096.0,
            "timestamp_month": 3.0,
            "checksum_missing": true,
            "checksum_present": false,
            "export_timestamp": 1268634470.0,
            "import_dll_count": 9.0,
            "manifest_present": true,
            "computed_checksum": 158796.0,
            "section_alignment": 4096.0,
            "number_of_sections": 5.0,
            "resource_timestamp": 0.0,
            "dll_characteristics": 34048.0,
            "rich_header_present": true,
            "export_timestamp_day": 15.0,
            "linker_major_version": 9.0,
            "export_timestamp_year": 2010.0,
            "api_hashing_indicators": 1.0,
            "export_timestamp_month": 3.0,
            "export_timestamp_present": true,
            "resource_timestamp_present": false,
            "max_section_inflation_ratio": 95.98
          },
          "file": {
            "size": 121794.0
          },
          "binary": {
            "code_size": 67584.0,
            "func_count": 217.0,
            "entry_point": 42929.0,
            "has_overlay": true,
            "code_entropy": 6.58,
            "data_entropy": 4.05,
            "func_density": 3.29,
            "import_count": 163.0,
            "overlay_size": 33218.0,
            "string_count": 364.0,
            "avg_func_size": 628.21,
            "overlay_ratio": 0.27,
            "section_count": 5.0,
            "avg_complexity": 9.26,
            "import_density": 2.47,
            "max_complexity": 141.0,
            "string_density": 5.52,
            "overall_entropy": 3.88,
            "overlay_entropy": 7.99,
            "avg_basic_blocks": 15.66,
            "avg_section_size": 17510.4,
            "dependency_count": 9.0,
            "entropy_variance": 2.08,
            "avg_string_length": 21.51,
            "complexity_per_kb": 0.14,
            "max_string_length": 1462.0,
            "wide_string_count": 52.0,
            "writable_sections": 1.0,
            "avg_string_entropy": 3.13,
            "code_to_data_ratio": 3.38,
            "data_to_file_ratio": 0.0,
            "entry_point_is_rva": true,
            "rsrc_to_file_ratio": 0.1,
            "text_to_file_ratio": 0.55,
            "total_basic_blocks": 3399.0,
            "embedded_file_count": 1.0,
            "executable_sections": 1.0,
            "func_analysis_depth": 2.0,
            "string_length_stddev": 78.58,
            "high_complexity_funcs": 7.0,
            "largest_section_ratio": 0.55,
            "sentence_string_count": 40.0,
            "sentence_string_ratio": 0.11,
            "embedded_archive_count": 1.0,
            "behavioral_import_ratio": 0.02,
            "unnamed_complex_func_count": 7.0
          }
        },
        "ss": [
          [
            77,
            "!This program cannot be run in DOS mode."
          ],
          [
            480,
            ".text"
          ],
          [
            559,
            "@.data"
          ],
          [
            600,
            ".CRT"
          ],
          [
            639,
            "@.rsrc"
          ],
          [
            1136,
            "WVS3"
          ],
          [
            1312,
            "WVU3"
          ],
          [
            3467,
            "SUVW"
          ],
          [
            5212,
            "F0QP"
          ],
          [
            7861,
            "C0WP"
          ],
          [
            10595,
            "f90t"
          ],
          [
            24085,
            "f\u003c\u003ctf"
          ],
          [
            33936,
            "SVW3"
          ],
          [
            34336,
            "N0WS"
          ],
          [
            40904,
            "5X A"
          ],
          [
            40978,
            "5P A"
          ],
          [
            41944,
            "EXPSV"
          ],
          [
            48203,
            "/uGj"
          ],
          [
            54523,
            "QQV3"
          ],
          [
            57607,
            "f98t"
          ],
          [
            61633,
            "QSVW"
          ],
          [
            68218,
            "QQVW"
          ],
          [
            69356,
            "SeRestorePrivilege"
          ],
          [
            69376,
            "SeSecurityPrivilege"
          ],
          [
            69432,
            "rtmp%d"
          ],
          [
            69440,
            "YNANRC"
          ],
          [
            69460,
            "bad allocation"
          ],
          [
            69660,
            "\u003cbr\u003e"
          ],
          [
            69684,
            "\u003cstyle\u003ebody{font-family:\"Arial\";font-size:12;}\u003c/style\u003e"
          ],
          [
            69740,
            "\u003c/html\u003e"
          ],
          [
            69748,
            "utf-8\"\u003e\u003c/head\u003e"
          ],
          [
            69768,
            "\u003chead\u003e\u003cmeta http-equiv=\"content-type\" content=\"text/html; charset="
          ],
          [
            69836,
            "\u003chtml\u003e"
          ],
          [
            69844,
            "wide",
            "about:blank"
          ],
          [
            69868,
            "\u003c/style\u003e"
          ],
          [
            69880,
            "\u003cstyle\u003e"
          ],
          [
            69888,
            "\u003c/p\u003e"
          ],
          [
            69896,
            "wide",
            "Shell.Explorer"
          ],
          [
            69928,
            "RarHtmlClassName"
          ],
          [
            69952,
            "__rar_"
          ],
          [
            69996,
            ".rar"
          ],
          [
            70024,
            "*messages***"
          ],
          [
            70076,
            "EDIT"
          ],
          [
            70084,
            "SHAutoComplete"
          ],
          [
            70100,
            "shlwapi.dll"
          ],
          [
            70124,
            "%s %s %s"
          ],
          [
            70136,
            "REPLACEFILEDLG"
          ],
          [
            70152,
            "RENAMEDLG"
          ],
          [
            70164,
            "GETPASSWORD1"
          ],
          [
            70184,
            "ASKNEXTVOL"
          ],
          [
            70196,
            "Software\\WinRAR SFX"
          ],
          [
            70216,
            "STATIC"
          ],
          [
            70224,
            ".exe"
          ],
          [
            70232,
            "Install"
          ],
          [
            70240,
            ".inf"
          ],
          [
            70248,
            ".lnk"
          ],
          [
            70256,
            "%s%s%d"
          ],
          [
            70264,
            "ProgramFilesDir"
          ],
          [
            70280,
            "Software\\Microsoft\\Windows\\CurrentVersion"
          ],
          [
            70324,
            "%s.%d.tmp"
          ],
          [
            70336,
            "Delete"
          ],
          [
            70344,
            "Text"
          ],
          [
            70352,
            "Title"
          ],
          [
            70360,
            "Path"
          ],
          [
            70368,
            "Silent"
          ],
          [
            70376,
            "Overwrite"
          ],
          [
            70388,
            "Setup"
          ],
          [
            70396,
            "TempMode"
          ],
          [
            70408,
            "License"
          ],
          [
            70416,
            "Presetup"
          ],
          [
            70428,
            "Shortcut"
          ],
          [
            70440,
            "SavePath"
          ],
          [
            70452,
            "Update"
          ],
          [
            70460,
            "LICENSEDLG"
          ],
          [
            70476,
            "RichEdit"
          ],
          [
            70496,
            "runas"
          ],
          [
            70504,
            "winrarsfxmappingfile.tmp"
          ],
          [
            70532,
            "-el -s2 \"-d%s\" \"-p%s\" \"-sp%s\""
          ],
          [
            70564,
            "__tmp_rar_sfx_access_check_%u"
          ],
          [
            70596,
            "STARTDLG"
          ],
          [
            70608,
            "sfxname"
          ],
          [
            70651,
            "Z2fQ`InitCommonControlsEx"
          ],
          [
            70680,
            "COMCTL32.DLL"
          ],
          [
            70696,
            "riched20.dll"
          ],
          [
            70712,
            "riched32.dll"
          ],
          [
            71808,
            "KERNEL32.DLL"
          ],
          [
            71821,
            "ADVAPI32.dll"
          ],
          [
            71834,
            "COMCTL32.dll"
          ],
          [
            71847,
            "COMDLG32.dll"
          ],
          [
            71860,
            "GDI32.dll"
          ],
          [
            71870,
            "ole32.dll"
          ],
          [
            71880,
            "OLEAUT32.dll"
          ],
          [
            71893,
            "SHELL32.dll"
          ],
          [
            71905,
            "USER32.dll"
          ],
          [
            71918,
            "DeleteFileA"
          ],
          [
            71932,
            "DeleteFileW"
          ],
          [
            71946,
            "CreateDirectoryA"
          ],
          [
            71964,
            "CreateDirectoryW"
          ],
          [
            71982,
            "FindClose"
          ],
          [
            71994,
            "FindNextFileA"
          ],
          [
            72010,
            "FindFirstFileA"
          ],
          [
            72026,
            "FindNextFileW"
          ],
          [
            72042,
            "FindFirstFileW"
          ],
          [
            72058,
            "GetTickCount"
          ],
          [
            72072,
            "WideCharToMultiByte"
          ],
          [
            72094,
            "MultiByteToWideChar"
          ],
          [
            72116,
            "GetVersionExA"
          ],
          [
            72132,
            "GlobalAlloc"
          ],
          [
            72146,
            "lstrlenA"
          ],
          [
            72156,
            "GetModuleFileNameA"
          ],
          [
            72176,
            "FindResourceA"
          ],
          [
            72192,
            "GetModuleHandleA"
          ],
          [
            72210,
            "HeapAlloc"
          ],
          [
            72222,
            "GetProcessHeap"
          ],
          [
            72238,
            "HeapFree"
          ],
          [
            72248,
            "HeapReAlloc"
          ],
          [
            72262,
            "CompareStringA"
          ],
          [
            72278,
            "ExitProcess"
          ],
          [
            72292,
            "GetLocaleInfoA"
          ],
          [
            72308,
            "GetNumberFormatA"
          ],
          [
            72326,
            "lstrcmpiA"
          ],
          [
            72338,
            "GetProcAddress"
          ],
          [
            72354,
            "GetDateFormatA"
          ],
          [
            72370,
            "GetTimeFormatA"
          ],
          [
            72386,
            "FileTimeToSystemTime"
          ],
          [
            72408,
            "FileTimeToLocalFileTime"
          ],
          [
            72434,
            "ExpandEnvironmentStringsA"
          ],
          [
            72462,
            "WaitForSingleObject"
          ],
          [
            72484,
            "SetCurrentDirectoryA"
          ],
          [
            72506,
            "Sleep"
          ],
          [
            72514,
            "GetTempPathA"
          ],
          [
            72542,
            "UnmapViewOfFile"
          ],
          [
            72560,
            "GetCommandLineA"
          ],
          [
            72578,
            "MapViewOfFile"
          ],
          [
            72594,
            "CreateFileMappingA"
          ],
          [
            72614,
            "GetModuleFileNameW"
          ],
          [
            72634,
            "SetEnvironmentVariableA"
          ],
          [
            72660,
            "OpenFileMappingA"
          ],
          [
            72678,
            "LocalFileTimeToFileTime"
          ],
          [
            72704,
            "SystemTimeToFileTime"
          ],
          [
            72726,
            "GetSystemTime"
          ],
          [
            72742,
            "IsDBCSLeadByte"
          ],
          [
            72758,
            "GetCPInfo"
          ],
          [
            72770,
            "FreeLibrary"
          ],
          [
            72784,
            "LoadLibraryA"
          ],
          [
            72798,
            "GetCurrentDirectoryA"
          ],
          [
            72820,
            "GetFullPathNameA"
          ],
          [
            72838,
            "SetFileAttributesW"
          ],
          [
            72858,
            "SetFileAttributesA"
          ],
          [
            72878,
            "GetFileAttributesW"
          ],
          [
            72898,
            "GetFileAttributesA"
          ],
          [
            72918,
            "WriteFile"
          ],
          [
            72930,
            "SetLastError"
          ],
          [
            72944,
            "GetStdHandle"
          ],
          [
            72958,
            "ReadFile"
          ],
          [
            72968,
            "CreateFileW"
          ],
          [
            72982,
            "CreateFileA"
          ],
          [
            72996,
            "GetFileType"
          ],
          [
            73010,
            "SetEndOfFile"
          ],
          [
            73024,
            "SetFilePointer"
          ],
          [
            73052,
            "SetFileTime"
          ],
          [
            73066,
            "GetCurrentProcess"
          ],
          [
            73086,
            "CloseHandle"
          ],
          [
            73100,
            "GetLastError"
          ],
          [
            73114,
            "DosDateTimeToFileTime"
          ],
          [
            73138,
            "LookupPrivilegeValueA"
          ],
          [
            73162,
            "RegOpenKeyExA"
          ],
          [
            73178,
            "RegQueryValueExA"
          ],
          [
            73196,
            "RegCreateKeyExA"
          ],
          [
            73214,
            "RegSetValueExA"
          ],
          [
            73230,
            "RegCloseKey"
          ],
          [
            73244,
            "SetFileSecurityW"
          ],
          [
            73262,
            "SetFileSecurityA"
          ],
          [
            73280,
            "OpenProcessToken"
          ],
          [
            73298,
            "AdjustTokenPrivileges"
          ],
          [
            73322,
            "GetSaveFileNameA"
          ],
          [
            73340,
            "CommDlgExtendedError"
          ],
          [
            73362,
            "GetOpenFileNameA"
          ],
          [
            73380,
            "GetDeviceCaps"
          ],
          [
            73396,
            "GetObjectA"
          ],
          [
            73408,
            "CreateCompatibleBitmap"
          ],
          [
            73432,
            "SelectObject"
          ],
          [
            73446,
            "StretchBlt"
          ],
          [
            73458,
            "CreateCompatibleDC"
          ],
          [
            73478,
            "DeleteObject"
          ],
          [
            73492,
            "DeleteDC"
          ],
          [
            73502,
            "CreateStreamOnHGlobal"
          ],
          [
            73526,
            "OleInitialize"
          ],
          [
            73542,
            "CoCreateInstance"
          ],
          [
            73560,
            "OleUninitialize"
          ],
          [
            73578,
            "CLSIDFromString"
          ],
          [
            73596,
            "ShellExecuteExA"
          ],
          [
            73614,
            "SHFileOperationA"
          ],
          [
            73632,
            "SHGetFileInfoA"
          ],
          [
            73648,
            "SHGetSpecialFolderLocation"
          ],
          [
            73676,
            "SHGetMalloc"
          ],
          [
            73690,
            "SHBrowseForFolderA"
          ],
          [
            73710,
            "SHGetPathFromIDListA"
          ],
          [
            73732,
            "SHChangeNotify"
          ],
          [
            73748,
            "ReleaseDC"
          ],
          [
            73768,
            "SendMessageA"
          ],
          [
            73782,
            "wsprintfA"
          ],
          [
            73794,
            "SetDlgItemTextA"
          ],
          [
            73812,
            "EndDialog"
          ],
          [
            73824,
            "DestroyIcon"
          ],
          [
            73838,
            "SendDlgItemMessageA"
          ],
          [
            73860,
            "GetDlgItemTextA"
          ],
          [
            73878,
            "DialogBoxParamA"
          ],
          [
            73896,
            "IsWindowVisible"
          ],
          [
            73914,
            "WaitForInputIdle"
          ],
          [
            73932,
            "GetSysColor"
          ],
          [
            73946,
            "PostMessageA"
          ],
          [
            73960,
            "SetMenu"
          ],
          [
            73970,
            "SetFocus"
          ],
          [
            73980,
            "LoadBitmapA"
          ],
          [
            74030,
            "GetClassNameA"
          ],
          [
            74046,
            "CharUpperA"
          ],
          [
            74058,
            "GetWindowRect"
          ],
          [
            74074,
            "GetParent"
          ],
          [
            74086,
            "MapWindowPoints"
          ],
          [
            74104,
            "CreateWindowExA"
          ],
          [
            74122,
            "UpdateWindow"
          ],
          [
            74136,
            "SetWindowTextA"
          ],
          [
            74152,
            "LoadCursorA"
          ],
          [
            74166,
            "RegisterClassExA"
          ],
          [
            74184,
            "SetWindowLongA"
          ],
          [
            74200,
            "GetWindowLongA"
          ],
          [
            74216,
            "DefWindowProcA"
          ],
          [
            74232,
            "PeekMessageA"
          ],
          [
            74246,
            "GetMessageA"
          ],
          [
            74260,
            "TranslateMessage"
          ],
          [
            74278,
            "DispatchMessageA"
          ],
          [
            74296,
            "GetClientRect"
          ],
          [
            74312,
            "CopyRect"
          ],
          [
            74322,
            "IsWindow"
          ],
          [
            74332,
            "MessageBoxA"
          ],
          [
            74346,
            "ShowWindow"
          ],
          [
            74370,
            "EnableWindow"
          ],
          [
            74384,
            "FindWindowExA"
          ],
          [
            74400,
            "wvsprintfA"
          ],
          [
            74412,
            "CharToOemBuffA"
          ],
          [
            74428,
            "LoadStringA"
          ],
          [
            74442,
            "SetWindowPos"
          ],
          [
            74456,
            "GetWindowTextA"
          ],
          [
            74472,
            "GetWindow"
          ],
          [
            74484,
            "GetSystemMetrics"
          ],
          [
            74502,
            "OemToCharBuffA"
          ],
          [
            74518,
            "DestroyWindow"
          ],
          [
            74760,
            "WINRAR.SFX"
          ],
          [
            74772,
            "RSDS"
          ],
          [
            74796,
            "d:\\Projects\\WinRAR\\SFX\\build\\sfxrar32\\Release\\sfxrar.pdb"
          ],
          [
            75304,
            "FFFE"
          ],
          [
            77216,
            "wide",
            "ASKNEXTVOL"
          ],
          [
            77240,
            "wide",
            "GETPASSWORD1\nLICENSEDLG\tRENAMEDLG"
          ],
          [
            77308,
            "wide",
            "REPLACEFILEDLG"
          ],
          [
            77338,
            "wide",
            "STARTDLG"
          ]
        ],
        "sz": 121794,
        "ts": [
          {
            "c": 1.0,
            "d": "Self-extracting archive (RAR)",
            "e": [
              "archive_type:rar"
            ],
            "i": "file/archive/self-extracting/rar",
            "l": 3
          },
          {
            "a": "T1105",
            "c": 0.800000011920929,
            "d": "Compact PE import table",
            "e": [
              "binary.import_count = 17.00",
              "binary.import_count = 45.00",
              "binary.import_count = 50.00",
              "binary.import_count = 38.00"
            ],
            "i": "objectives/command-and-control/dropper/delivery/download-execute::compact-import-table",
            "l": 1,
            "m": "E1105"
          },
          {
            "c": 1.0,
            "d": "Microsoft Corporation in resource section",
            "e": [
              "Microsoft Corporation. All rights reserved."
            ],
            "i": "well-known/malware/trojan/loader-s047t5g::microsoft-corp-resource",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "Regex component marker",
            "e": [
              "start"
            ],
            "i": "objectives/command-and-control/dropper/execution/batch::keyed-temp-payload-launch--rx-1",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "WinExec hidden-window flag immediate",
            "e": [
              "04 50 40 00"
            ],
            "i": "micro-behaviors/process/create/flags::winexec-sw-hide-immediate",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Tiny PE stub footprint",
            "e": [
              "miterINST.exe"
            ],
            "i": "well-known/malware/trojan/shellobject/revengerat::tiny-pe-footprint",
            "l": 1
          },
          {
            "c": 0.6000000238418579,
            "d": "Very few sections (merged/stripped)",
            "e": [
              "binary.section_count = 3.00",
              "binary.section_count = 2.00"
            ],
            "i": "metadata/binary/metrics/structural::few-sections",
            "l": 3
          },
          {
            "c": 0.949999988079071,
            "d": "PE checksum mismatch (modified binary)",
            "e": [
              "pe.checksum_mismatch = 1.00"
            ],
            "i": "metadata/binary/layout::pe-checksum-mismatch",
            "l": 3
          },
          {
            "c": 1.0,
            "d": "Binary has low average string entropy",
            "e": [
              "binary.avg_string_entropy = 3.37",
              "binary.avg_string_entropy = 3.28",
              "binary.avg_string_entropy = 3.31",
              "binary.avg_string_entropy = 3.35"
            ],
            "i": "metadata/binary/metrics/threshold::avg-string-entropy-4-max",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has low average complexity",
            "e": [
              "binary.avg_complexity = 6.40",
              "binary.avg_complexity = 12.55",
              "binary.avg_complexity = 13.15"
            ],
            "i": "metadata/binary/metrics/threshold::avg-complexity-15-max",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 20+ imports",
            "e": [
              "binary.import_count = 38.00",
              "binary.import_count = 50.00",
              "binary.import_count = 45.00"
            ],
            "i": "metadata/binary/metrics/threshold::many-imports-20",
            "l": 1
          },
          {
            "c": 0.8199999928474426,
            "d": "Query current process command line",
            "e": [
              "GetCommandLineA"
            ],
            "i": "micro-behaviors/process/info/commandline::get-command-line",
            "l": 2
          },
          {
            "c": 0.9599999785423279,
            "d": "Generic Host Process description",
            "e": [
              "Generic Host Process for Win32 Services"
            ],
            "i": "objectives/evasion/masquerade/version-resource/service-host::service-host-file-description",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Binary has low overall entropy",
            "e": [
              "binary.overall_entropy = 4.02",
              "binary.overall_entropy = 4.33",
              "binary.overall_entropy = 3.16",
              "binary.overall_entropy = 2.11"
            ],
            "i": "metadata/binary/metrics/threshold::low-overall-entropy-binary",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Get current process handle",
            "e": [
              "GetCurrentProcess"
            ],
            "i": "micro-behaviors/os/module/load::get-current-process",
            "l": 2
          },
          {
            "c": 0.8199999928474426,
            "d": "Elevated text section entropy",
            "e": [
              ".text (entropy: 6.30)",
              ".text (entropy: 6.55)"
            ],
            "i": "metadata/binary/section/metrics::elevated-text-entropy-section",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Read startup info via GetStartupInfoA",
            "e": [
              "GetStartupInfoA"
            ],
            "i": "micro-behaviors/os/sysinfo/process::get-startup-info-a",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Dense PE import table references",
            "e": [
              "binary.import_density = 6.80",
              "binary.import_density = 6.33"
            ],
            "i": "metadata/binary/metrics/structural::high-import-density",
            "l": 3
          },
          {
            "a": "T1113",
            "c": 0.800000011920929,
            "d": "Desktop window handle access",
            "e": [
              "GetDesktopWindow"
            ],
            "i": "micro-behaviors/hardware/display/screen::get-desktop-window",
            "l": 3,
            "m": "C0014"
          },
          {
            "c": 0.8999999761581421,
            "d": "Set standard I/O handle",
            "e": [
              "SetStdHandle"
            ],
            "i": "micro-behaviors/fs/file/handle::set-std-handle",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE resource section",
            "e": [
              ".rsrc"
            ],
            "i": "metadata/binary/section/names::pe-resource-section",
            "l": 1
          },
          {
            "d": ".vbs extension reference",
            "e": [
              ".vbs"
            ],
            "i": "micro-behaviors/fs/path/extension::vbs",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE file uses .exe extension",
            "e": [
              "instsrv.exe",
              "alark.exe",
              "miterINST.exe",
              "sysclr.exe"
            ],
            "i": "metadata/binary/framework::exe-extension",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Small PE resource section",
            "e": [
              "pe.rsrc_size = 0.00",
              "pe.rsrc_size = 1536.00"
            ],
            "i": "metadata/package/versioning::pe-small-rsrc",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "links MSVCRT.dll (close, stricmp, malloc, except_handler3, getmainargs, ... +16 more)",
            "e": [
              "MSVCRT.dll"
            ],
            "i": "metadata/dylib::msvcrt/dll",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.949999988079071,
            "d": "Program can create Windows services",
            "e": [
              "CreateServiceA"
            ],
            "i": "micro-behaviors/os/service/control::create-service-import",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Exit thread execution",
            "e": [
              "ExitThread"
            ],
            "i": "micro-behaviors/process/thread/create::exit-thread",
            "l": 2
          },
          {
            "a": "T1485",
            "c": 1.0,
            "d": "Windows forced quiet file deletion",
            "e": [
              "del /f /q"
            ],
            "i": "objectives/impact/system/directory::windows-recursive-delete-del",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "String claiming to be Microsoft Corporation",
            "e": [
              "Microsoft Corporation"
            ],
            "i": "objectives/evasion/masquerade/identity/vendor::microsoft-corporation-string",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Heap memory allocation",
            "e": [
              "HeapAlloc"
            ],
            "i": "micro-behaviors/mem/alloc/heap::heap-alloc",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Heap memory reallocation",
            "e": [
              "HeapReAlloc"
            ],
            "i": "micro-behaviors/mem/alloc/heap::heap-realloc",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "Filename has EXE extension",
            "e": [
              "miterINST.exe",
              "instsrv.exe",
              "alark.exe",
              "sysclr.exe"
            ],
            "i": "objectives/evasion/masquerade/file/double-ext::basename-is-exe",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "PE has low overall entropy",
            "e": [
              "binary.overall_entropy = 4.33",
              "binary.overall_entropy = 4.02",
              "binary.overall_entropy = 3.16",
              "binary.overall_entropy = 2.11"
            ],
            "i": "metadata/binary/layout::low-overall-entropy",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Close handle",
            "e": [
              "CloseHandle"
            ],
            "i": "micro-behaviors/process/create/spawn::close-handle-dup",
            "l": 2
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "GetProcAddress loader API string",
            "e": [
              "GetProcAddress"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-getprocaddress-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "a": "T1543.003",
            "c": 0.949999988079071,
            "d": "Program opens service control manager",
            "e": [
              "OpenSCManagerA"
            ],
            "i": "micro-behaviors/os/service/control::open-sc-manager-import",
            "l": 3
          },
          {
            "c": 0.699999988079071,
            "d": "PE has few sections",
            "e": [
              "binary.section_count = 2.00",
              "binary.section_count = 3.00"
            ],
            "i": "metadata/binary/layout::legacy-few-sections",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Unicode string locale mapping",
            "e": [
              "LCMapStringW"
            ],
            "i": "micro-behaviors/os/env/access::lcmap-string-w",
            "l": 2
          },
          {
            "a": "T1055",
            "c": 0.949999988079071,
            "d": "Huge null run in executable (128+ bytes)",
            "e": [
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00"
            ],
            "i": "objectives/anti-static/obfuscation/binary-structure::huge-null-run-text",
            "l": 1
          },
          {
            "a": "T1027.007",
            "c": 0.800000011920929,
            "d": "DLL name strings without LoadLibrary import",
            "e": [
              "binary.import_count = 38.00",
              "binary.import_count = 17.00"
            ],
            "i": "objectives/anti-static/obfuscation/string/runtime-decrypt::dll-names-no-loadlibrary",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "a": "T1543.003",
            "c": 0.9200000166893005,
            "d": "Service stop or delete chain",
            "e": [
              "OpenSCManager",
              "DeleteService",
              "OpenServiceA",
              "OpenService",
              "OpenSCManagerA"
            ],
            "i": "micro-behaviors/os/service/control::service-stop-control",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Allocate memory (C runtime)",
            "e": [
              "malloc"
            ],
            "i": "micro-behaviors/mem/c-runtime/functions::malloc",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Start minimized process",
            "e": [
              "start /MIN"
            ],
            "i": "objectives/command-and-control/dropper/execution/batch::start-hidden-dup",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Flush file buffer to disk",
            "e": [
              "FlushFileBuffers"
            ],
            "i": "micro-behaviors/fs/file/handle::flush-file-buffers",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Binary has many functions (\u003e30)",
            "e": [
              "binary.func_count = 34.00"
            ],
            "i": "metadata/binary/metrics/structural::many-functions",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Get environment strings",
            "e": [
              "FreeEnvironmentStringsW",
              "GetEnvironmentStrings",
              "GetEnvironmentStringsW"
            ],
            "i": "micro-behaviors/os/env/access::get-environment-strings",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Encoded HTML tag fragment",
            "e": [
              "[-a \u003cAccount Name\u003e] [-p \u003cAccount Password\u003e]",
              "INSTSRV \u003cservice name\u003e (\u003cexe location\u003e | REMOVE)"
            ],
            "i": "objectives/anti-static/obfuscation/encoding/content::encoded-html-tag-fragment",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.800000011920929,
            "d": "Few PE resource entries (no DIALOG/MENU/STRINGTABLE)",
            "e": [
              "pe.resource_count = 2.00",
              "pe.resource_count = 0.00"
            ],
            "i": "objectives/evasion/anti-av/heuristic::minimal-pe-resources",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "High-trust tool delivered via low-integrity packaging",
            "e": [
              "binary.has_signature = 0.00",
              "binary.has_overlay = 1.00"
            ],
            "i": "objectives/supply-chain/trojanized/app/monitor::low-integrity-installer-packaging",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Resolve exports with GetProcAddress",
            "e": [
              "GetProcAddress"
            ],
            "i": "micro-behaviors/os/module/load::get-proc-address-import",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 3+ functions",
            "e": [
              "binary.func_count = 20.00",
              "binary.func_count = 13.00",
              "binary.func_count = 5.00",
              "binary.func_count = 34.00"
            ],
            "i": "metadata/binary/metrics/threshold::few-functions-3",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Get module file path (ANSI)",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/os/module/load::get-module-filename-ansi",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Binary has many sentence-like strings",
            "e": [
              "binary.sentence_string_ratio = 0.33",
              "binary.sentence_string_ratio = 0.21",
              "binary.sentence_string_ratio = 0.38"
            ],
            "i": "metadata/binary/metrics/threshold::rich-sentence-strings-20pct",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE standard code/data section",
            "e": [
              ".code",
              ".data",
              ".text"
            ],
            "i": "metadata/binary/section/names::pe-code-data-standard-section",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Get file handle type",
            "e": [
              "GetFileType"
            ],
            "i": "micro-behaviors/fs/file/handle::get-file-type",
            "l": 2
          },
          {
            "c": 0.550000011920929,
            "d": "Stdout redirected to NUL",
            "e": [
              "\u003enul"
            ],
            "i": "micro-behaviors/os/console/io::windows-stdout-to-nul",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Release wide environment block",
            "e": [
              "FreeEnvironmentStringsW"
            ],
            "i": "micro-behaviors/os/env/access::free-environment-strings-wide",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Open named event object",
            "e": [
              "OpenEventA"
            ],
            "i": "micro-behaviors/process/sync/event::open-event",
            "l": 2,
            "m": "C0039"
          },
          {
            "c": 0.7200000286102295,
            "d": "Short uppercase mutex token",
            "e": [
              "DOSCALLS"
            ],
            "i": "micro-behaviors/process/sync/mutex::short-uppercase-token",
            "l": 1,
            "m": "C0042"
          },
          {
            "a": "T1082",
            "c": 1.0,
            "d": "Ping internal host list",
            "e": [
              "ping 127.0.0.1"
            ],
            "i": "objectives/discovery/system/domain-admin-prep::ping-internal-hosts",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Get system error code",
            "e": [
              "GetLastError"
            ],
            "i": "micro-behaviors/os/exception/error-handling::get-last-error",
            "l": 2
          },
          {
            "c": 0.6000000238418579,
            "d": "Start an executable",
            "e": [
              "start %windir%\\miter.exe",
              "start /D %windir%\\addins W72.exe"
            ],
            "i": "objectives/command-and-control/dropper/execution/batch::start-exe",
            "l": 1
          },
          {
            "c": 0.6499999761581421,
            "d": "Close dialog and return result",
            "e": [
              "EndDialog"
            ],
            "i": "micro-behaviors/ui/dialog/prompt::end-dialog",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 40+ imports",
            "e": [
              "binary.import_count = 45.00",
              "binary.import_count = 50.00"
            ],
            "i": "metadata/binary/metrics/threshold::many-imports-40",
            "l": 1
          },
          {
            "a": "T1014",
            "c": 0.9399999976158142,
            "d": "Regex component marker",
            "e": [
              ".EXE"
            ],
            "i": "objectives/evasion/kernel-hide/rootkit::executable-read-patch-markers--rx-7",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Free virtual memory",
            "e": [
              "VirtualFree"
            ],
            "i": "micro-behaviors/mem/protect/modify::virtual-free",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary is not digitally signed",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed/trust-level::unsigned",
            "l": 3
          },
          {
            "c": 0.699999988079071,
            "d": "Delay execution",
            "e": [
              "Sleep"
            ],
            "i": "micro-behaviors/time/timing/delay::sleep-dup",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Microsoft Visual string",
            "e": [
              "Microsoft Visual C++ Runtime Library"
            ],
            "i": "metadata/lang/compiler/native::ms-visual",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "PE has exactly two resource entries",
            "e": [
              "pe.resource_count = 2.00"
            ],
            "i": "metadata/binary/resource::pe-resource-count-two",
            "l": 2
          },
          {
            "d": ".dll extension reference",
            "e": [
              ".dll"
            ],
            "i": "micro-behaviors/fs/path/extension::dll-dup",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.949999988079071,
            "d": "Full Windows service dispatch triplet",
            "e": [
              "StartServiceCtrlDispatcherA",
              "SetServiceStatus",
              "RegisterServiceCtrlHandlerA"
            ],
            "i": "micro-behaviors/os/service/control::service-dispatch-triad",
            "l": 3
          },
          {
            "a": "T1106",
            "c": 0.949999988079071,
            "d": "Create process (ANSI)",
            "e": [
              "CreateProcessA"
            ],
            "i": "micro-behaviors/process/create/spawn::create-process-a",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Browser process termination API",
            "e": [
              "TerminateProcess"
            ],
            "i": "objectives/collection/stealer/browser::windows-browser-terminate-api",
            "l": 1
          },
          {
            "a": "T1036.005",
            "c": 0.9700000286102295,
            "d": "Windows operating system product string",
            "e": [
              "Microsoft® Windows® Operating System"
            ],
            "i": "objectives/evasion/masquerade/version-resource/claim::getmac-product-string",
            "l": 1
          },
          {
            "a": "T1070.004",
            "c": 0.949999988079071,
            "d": "Regex component marker",
            "e": [
              "127.0.0.1"
            ],
            "i": "objectives/evasion/self-delete/file/delay::ping-self-delete--rx-1",
            "l": 1
          },
          {
            "a": "T1587.001",
            "c": 0.8999999761581421,
            "d": "Allocate virtual memory",
            "e": [
              "VirtualAlloc"
            ],
            "i": "micro-behaviors/mem/protect/modify::virtual-alloc",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Claims Microsoft Corp in version resource",
            "e": [
              "Microsoft Corporation."
            ],
            "i": "metadata/binary/vendor::microsoft-corp-versioninfo",
            "l": 1
          },
          {
            "c": 0.8399999737739563,
            "d": "Invoke unhandled exception filter",
            "e": [
              "UnhandledExceptionFilter"
            ],
            "i": "micro-behaviors/os/exception/error-handling::unhandled-exception-filter-import",
            "l": 2
          },
          {
            "d": "password keyword",
            "e": [
              "Name:  %s;  Password:  %s",
              "Password that this newly installed service will use",
              "[-a \u003cAccount Name\u003e] [-p \u003cAccount Password\u003e]"
            ],
            "i": "micro-behaviors/data/text/keywords/lexicon::password",
            "l": 1
          },
          {
            "c": 0.75,
            "d": "Inline password token in lure",
            "e": [
              "Password that this newly"
            ],
            "i": "objectives/lateral-movement/social-engineering/lures::inline-password-token",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE mapped image under 768 KiB",
            "e": [
              "pe.size_of_image = 16384.00",
              "pe.size_of_image = 49152.00",
              "pe.size_of_image = 36864.00",
              "pe.size_of_image = 25088.00"
            ],
            "i": "metadata/binary/layout::image-under-768kb",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Get standard I/O handle",
            "e": [
              "GetStdHandle"
            ],
            "i": "micro-behaviors/fs/file/handle::get-std-handle",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "Process termination via TerminateProcess",
            "e": [
              "TerminateProcess"
            ],
            "i": "micro-behaviors/process/terminate/kill::terminate-process",
            "l": 3,
            "m": "B0033"
          },
          {
            "c": 0.699999988079071,
            "d": "Read file descriptor (read/pread)",
            "e": [
              "read"
            ],
            "i": "micro-behaviors/fs/file/read::read",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Five section PE layout",
            "e": [
              "binary.section_count = 5.00"
            ],
            "i": "metadata/binary/section/metrics::five-section-pe",
            "l": 1
          },
          {
            "c": 0.75,
            "d": "Binary exports no symbols",
            "e": [
              "binary.export_count = 0.00"
            ],
            "i": "metadata/binary/symbols/exports::no-exports",
            "l": 1
          },
          {
            "a": "T1574.002",
            "c": 0.8999999761581421,
            "d": "Hidden LoadLibraryA string reference",
            "e": [
              "LoadLibraryA"
            ],
            "i": "micro-behaviors/dylib/load/runtime::load-library-a-string-no-import",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Create modal dialog box (ANSI)",
            "e": [
              "DialogBoxParamA"
            ],
            "i": "micro-behaviors/ui/dialog/prompt::dialog-box-param-a",
            "l": 2
          },
          {
            "c": 0.9200000166893005,
            "d": "Overlay exceeds one-third",
            "e": [
              "binary.overlay_ratio = 0.48"
            ],
            "i": "metadata/binary/layout::overlay-dominates-third",
            "l": 3
          },
          {
            "c": 0.949999988079071,
            "d": "Signed PE checksum mismatch",
            "e": [
              "pe.checksum_mismatch = 1.00"
            ],
            "i": "metadata/binary/layout::signed-pe-checksum-mismatch",
            "l": 1
          },
          {
            "c": 1.0,
            "d": ".bat extension",
            "e": [
              ".bat"
            ],
            "i": "objectives/command-and-control/dropper/builder::bat-ext",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Heap memory deallocation",
            "e": [
              "HeapFree"
            ],
            "i": "micro-behaviors/mem/alloc/heap::heap-free",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Get process heap handle",
            "e": [
              "GetProcessHeap"
            ],
            "i": "micro-behaviors/mem/alloc/heap::get-process-heap",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 4 or fewer sections",
            "e": [
              "binary.section_count = 3.00",
              "binary.section_count = 2.00"
            ],
            "i": "objectives/command-and-control/infrastructure/config::max-sections-4",
            "l": 1
          },
          {
            "c": 0.6000000238418579,
            "d": "Copyright notice",
            "e": [
              "Copyright"
            ],
            "i": "metadata/package/license::copyright-word",
            "l": 2
          },
          {
            "a": "T1059.003",
            "c": 0.699999988079071,
            "d": "cmd launches batch script",
            "e": [
              "cmd /c start %windir%\\miter.exe -t3000 %windir%\\sysclr.bat"
            ],
            "i": "micro-behaviors/process/create/script/file::batch-script-exec-cmd",
            "l": 3
          },
          {
            "c": 0.8199999928474426,
            "d": "Regex component marker",
            "e": [
              "CloseHandle",
              "_close",
              "CloseServiceHandle",
              "RegCloseKey",
              "__imp___close",
              "CloseEventLog"
            ],
            "i": "objectives/discovery/system/ics-environment/register::ics-register-flow-rate--rx-75",
            "l": 1
          },
          {
            "a": "T1055",
            "c": 0.9200000166893005,
            "d": "Regex component marker",
            "e": [
              "binary.import_count = 50.00",
              "binary.import_count = 17.00",
              "binary.import_count = 45.00",
              "binary.import_count = 38.00"
            ],
            "i": "objectives/evasion/process/injection/vb6::vb6-process-injection-pattern-cond-1--inline-17571",
            "l": 1,
            "m": "C0041"
          },
          {
            "a": "T1543.003",
            "c": 0.9200000166893005,
            "d": "Windows service control dispatch",
            "e": [
              "StartServiceCtrlDispatcherA",
              "SetServiceStatus",
              "RegisterServiceCtrlHandlerA"
            ],
            "i": "micro-behaviors/os/service/control::service-control-dispatch",
            "l": 3
          },
          {
            "c": 0.8500000238418579,
            "d": "Runtime library unwind operation",
            "e": [
              "RtlUnwind"
            ],
            "i": "micro-behaviors/os/exception/error-handling::rtl-unwind",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Write data to file handle",
            "e": [
              "WriteFile"
            ],
            "i": "micro-behaviors/fs/file/write/direct::write-file",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "File is a compiled binary",
            "e": [
              "alark.exe",
              "miterINST.exe",
              "sysclr.exe",
              "instsrv.exe"
            ],
            "i": "metadata/binary/framework::is-binary",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Create window timer",
            "e": [
              "SetTimer"
            ],
            "i": "micro-behaviors/ui/window/manage/control::set-timer",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary is not position-independent (fixed load address)",
            "e": [
              "binary.is_pie = 0.00"
            ],
            "i": "metadata/hardening/layout::no-pie",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Tiny writable data section",
            "e": [
              ".data (size: 512)",
              ".data (size: 4096)",
              ".data (size: 5632)",
              ".data (size: 0)"
            ],
            "i": "metadata/binary/section/metrics::tiny-data-section",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "links KERNEL32.dll (GetLastError, FormatMessageA, HeapDestroy, ExitProcess, TerminateProcess, ... +37 more)",
            "e": [
              "kernel32.dll",
              "KERNEL32.dll"
            ],
            "i": "metadata/dylib::kernel32/dll",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE FileDescription metadata field",
            "e": [
              "FileDescription"
            ],
            "i": "metadata/package/versioning::pe-filedescription-field",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Close registry key",
            "e": [
              "RegCloseKey"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-close-key",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Switch current working directory",
            "e": [
              "SetCurrentDirectoryA"
            ],
            "i": "micro-behaviors/fs/traversal/drives::set-current-directory",
            "l": 3
          },
          {
            "a": "T1070.006",
            "c": 0.8999999761581421,
            "d": "Export timestamp is absent",
            "e": [
              "pe.export_timestamp_present = 0.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::export-timestamp-absent",
            "l": 2
          },
          {
            "a": "T1546.012",
            "c": 0.8999999761581421,
            "d": "IFEO registry path",
            "e": [
              "Image File Execution Options"
            ],
            "i": "objectives/persistence/login/ifeo/debugger::ifeo-registry-path",
            "l": 1,
            "m": "F0012"
          },
          {
            "a": "T1059.003",
            "c": 0.8999999761581421,
            "d": "ShellExecuteExA ANSI extended API",
            "e": [
              "ShellExecuteExA"
            ],
            "i": "micro-behaviors/process/create/system::shell-execute-ex-a",
            "l": 3,
            "m": "E1059.003"
          },
          {
            "c": 0.7599999904632568,
            "d": "PE entry in nonstandard section",
            "e": [
              "binary.entry_in_nonstandard_section = 1.00"
            ],
            "i": "metadata/binary/section/metrics::pe-nonstandard-entry",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Set event object state",
            "e": [
              "SetEvent"
            ],
            "i": "micro-behaviors/process/sync/event::set-event",
            "l": 2,
            "m": "C0039"
          },
          {
            "c": 1.0,
            "d": ".vbs extension",
            "e": [
              ".vbs"
            ],
            "i": "objectives/command-and-control/dropper/builder::vbs-ext",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "PE OriginalFilename metadata field",
            "e": [
              "OriginalFilename"
            ],
            "i": "metadata/package/versioning::pe-originalfilename-field",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "Binary imports ADVAPI32.dll",
            "e": [
              "ADVAPI32.dll"
            ],
            "i": "metadata/binary/symbols/imports::imports-advapi32-dll",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Regex component marker",
            "e": [
              "LCMapStringW",
              "FreeEnvironmentStringsW",
              "GetStringTypeA",
              "StringFileInfo",
              "GetEnvironmentStringsW",
              "GetEnvironmentStrings",
              "LCMapStringA",
              "FreeEnvironmentStringsA",
              "GetStringTypeW"
            ],
            "i": "micro-behaviors/communications/http/client/managed::webclient--rx-7",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Get module handle ANSI",
            "e": [
              "GetModuleHandleA"
            ],
            "i": "micro-behaviors/os/module/load::get-module-handle-ansi",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Show or hide window",
            "e": [
              "ShowWindow"
            ],
            "i": "micro-behaviors/ui/window/manage/control::show-window",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.8500000238418579,
            "d": "Open existing service handle",
            "e": [
              "OpenServiceA",
              "OpenService"
            ],
            "i": "micro-behaviors/os/service/control::open-service",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "PE ProductName metadata field",
            "e": [
              "ProductName"
            ],
            "i": "metadata/package/versioning::pe-productname-field",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE has many readable strings",
            "e": [
              "binary.string_count = 138.00",
              "binary.string_count = 193.00",
              "binary.string_count = 109.00"
            ],
            "i": "metadata/binary/layout::many-readable-strings",
            "l": 2
          },
          {
            "a": "T1027.007",
            "c": 1.0,
            "d": "WININET.DLL absent from PE import table",
            "e": [
              "pe.import_dll_count = 3.00",
              "pe.import_dll_count = 2.00",
              "pe.import_dll_count = 4.00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::wininet-import-absent",
            "l": 2,
            "m": "B0032"
          },
          {
            "c": 0.8999999761581421,
            "d": "PE Rich header present (MSVC toolchain)",
            "e": [
              "pe.rich_header_present = 1.00"
            ],
            "i": "metadata/binary/resource::rich-header-present",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links shell32.dll (ShellExecuteExA)",
            "e": [
              "shell32.dll"
            ],
            "i": "metadata/dylib::shell32/dll",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "msvcrt library (MSVC C runtime)",
            "e": [
              "MSVCR"
            ],
            "i": "metadata/lang/compiler/native::msvcrt",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "GetModuleFileName API call",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/process/info/current::get-module-filename",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "PE binary has trailing overlay data",
            "e": [
              "binary.has_overlay = 1.00"
            ],
            "i": "metadata/binary/layout::has-overlay",
            "l": 3
          },
          {
            "a": "T1070.004",
            "c": 0.949999988079071,
            "d": "Regex component marker",
            "e": [
              "\nping "
            ],
            "i": "objectives/evasion/self-delete/file/delay::ping-self-delete--rx-2",
            "l": 1
          },
          {
            "a": "T1053.005",
            "c": 0.9300000071525574,
            "d": "Regex component marker",
            "e": [
              "LocalSystem"
            ],
            "i": "objectives/persistence/login/scheduled-task/cmdlet::new-scheduledtask-principal-system--rx-7",
            "l": 1,
            "m": "F0012"
          },
          {
            "c": 0.800000011920929,
            "d": "Low-entropy rdata section",
            "e": [
              ".rdata (entropy: 3.47)"
            ],
            "i": "metadata/binary/section/metrics::low-entropy-rdata-section",
            "l": 1
          },
          {
            "a": "T1140",
            "c": 0.8999999761581421,
            "d": "Microsoft company string",
            "e": [
              "Microsoft Corporation. All rights reserved."
            ],
            "i": "objectives/command-and-control/dropper/staging/encrypted::microsoft-company-string",
            "l": 1,
            "m": "B0023"
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "RegQueryValueEx API",
            "e": [
              "RegQueryValueExA"
            ],
            "i": "objectives/anti-static/obfuscation/payload/registry::reg-query-value",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.800000011920929,
            "d": "Hardcoded loopback IPv4 address",
            "e": [
              "127.0.0.1"
            ],
            "i": "micro-behaviors/communications/ip/literal::loopback-ipv4-source",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "Regex component marker",
            "e": [
              "Defender"
            ],
            "i": "objectives/privilege-escalation/exploit/vulnerabilities::redsun-cloud-tag-abuse--rx-7",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Limited string comparison",
            "e": [
              "strncmp"
            ],
            "i": "micro-behaviors/data/string/library::strncmp",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.8600000143051147,
            "d": "Services registry key fragment",
            "e": [
              "SYSTEM\\CurrentControlSet\\Services\\"
            ],
            "i": "objectives/persistence/system/service/install::service-registry-key-fragment",
            "l": 1,
            "m": "B0011.003"
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Registry key open and query chain",
            "e": [
              "RegQueryValueExA",
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/access::registry-read-api-chain",
            "l": 2
          },
          {
            "c": 0.8399999737739563,
            "d": "Read wide environment block",
            "e": [
              "GetEnvironmentStringsW"
            ],
            "i": "micro-behaviors/os/env/access::get-environment-strings-wide",
            "l": 2
          },
          {
            "c": 0.4000000059604645,
            "d": "Very few functions detected",
            "e": [
              "binary.func_count = 5.00"
            ],
            "i": "metadata/binary/metrics/structural::few-functions",
            "l": 3
          },
          {
            "a": "T1036.005",
            "c": 0.8999999761581421,
            "d": "Microsoft company string",
            "e": [
              "Microsoft Corporation. All rights reserved."
            ],
            "i": "objectives/evasion/masquerade/dll/task-scheduler::microsoft-company-string",
            "l": 1
          },
          {
            "a": "T1543.003",
            "c": 0.8999999761581421,
            "d": "Register service control handler",
            "e": [
              "RegisterServiceCtrlHandlerA"
            ],
            "i": "micro-behaviors/os/service/control::register-service-handler",
            "l": 3
          },
          {
            "c": 0.8500000238418579,
            "d": "Read current working directory",
            "e": [
              "GetCurrentDirectoryA"
            ],
            "i": "micro-behaviors/fs/traversal/drives::get-current-directory",
            "l": 2
          },
          {
            "a": "T1070.006",
            "c": 0.699999988079071,
            "d": "Debug timestamps internally consistent",
            "e": [
              "pe.debug_timestamp_consistent = 1.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::debug-timestamps-consistent",
            "l": 1
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "LoadLibraryA loader API string",
            "e": [
              "LoadLibraryA"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-loadlibrarya-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "c": 0.8799999952316284,
            "d": "Enumerate process environment block",
            "e": [
              "FreeEnvironmentStringsW",
              "GetEnvironmentStringsW"
            ],
            "i": "micro-behaviors/os/env/access::environment-block-enumeration",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Exit current process",
            "e": [
              "ExitProcess"
            ],
            "i": "micro-behaviors/process/terminate/kill::exit-process",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Get process exit code",
            "e": [
              "GetExitCodeProcess"
            ],
            "i": "micro-behaviors/process/create/spawn::get-exit-code-process",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.699999988079071,
            "d": "Network URL with domain name (binary)",
            "e": [
              "http://ntsecurity.nu/"
            ],
            "i": "objectives/command-and-control/infrastructure/domain/heuristic::http-url-binary",
            "l": 3,
            "m": "C0002"
          },
          {
            "c": 0.8500000238418579,
            "d": "Get Unicode character type",
            "e": [
              "GetStringTypeW"
            ],
            "i": "micro-behaviors/os/env/access::get-string-type-w",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "ASLR bit not set in DLL Characteristics",
            "e": [
              "pe.dll_characteristics = 256.00",
              "pe.dll_characteristics = 32768.00"
            ],
            "i": "metadata/hardening/mitigation::no-aslr-bit",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "PE CompanyName metadata field",
            "e": [
              "CompanyName"
            ],
            "i": "metadata/package/versioning::pe-companyname-field",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.8500000238418579,
            "d": "Create Windows service",
            "e": [
              "CreateServiceA",
              "CreateService"
            ],
            "i": "micro-behaviors/os/service/control::create-service",
            "l": 3
          },
          {
            "a": "T1486",
            "c": 1.0,
            "d": "Start launcher per host",
            "e": [
              "start /D"
            ],
            "i": "objectives/impact/ransom/staging::start-many-launch",
            "l": 1
          },
          {
            "a": "T1070.006",
            "c": 0.7799999713897705,
            "d": "PE header timestamp predates 2000",
            "e": [
              "pe.timestamp_pre_2000 = 1.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::header-timestamp-pre-2000",
            "l": 1
          },
          {
            "a": "T1485",
            "c": 0.8999999761581421,
            "d": "Preserves .exe .gho .bak files",
            "e": [
              ".EXE"
            ],
            "i": "objectives/impact/destroy/file-deletion::exe-gho-bak-whitelist",
            "l": 1,
            "m": "C0047"
          },
          {
            "c": 0.8999999761581421,
            "d": "CreateFile API string reference",
            "e": [
              "CreateFile"
            ],
            "i": "micro-behaviors/fs/file/open::createfile-api",
            "l": 2
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "VirtualAlloc loader API string",
            "e": [
              "VirtualAlloc"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-virtualalloc-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "a": "T1112",
            "c": 0.8500000238418579,
            "d": "Query registry value via import symbol",
            "e": [
              "RegQueryValueExA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-query-value-ex-a-symbol",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Query current module path",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/fs/path/check::get-module-filename",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Windows file creation/open API",
            "e": [
              "CreateFileA"
            ],
            "i": "micro-behaviors/fs/file/open::file-create-win",
            "l": 2
          },
          {
            "d": ".bat extension reference",
            "e": [
              ".bat"
            ],
            "i": "micro-behaviors/fs/path/extension::bat-dup",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Destroy window timer",
            "e": [
              "KillTimer"
            ],
            "i": "micro-behaviors/ui/window/manage/control::kill-timer",
            "l": 2
          },
          {
            "a": "T1027.007",
            "c": 0.8600000143051147,
            "d": "PE API hashing indicator present",
            "e": [
              "pe.api_hashing_indicators = 1.00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::pe-api-hashing-indicator-single",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "c": 0.8799999952316284,
            "d": "Small string table footprint",
            "e": [
              "binary.string_count = 52.00"
            ],
            "i": "well-known/malware/trojan/shellobject/revengerat::tiny-string-table",
            "l": 1
          },
          {
            "a": "T1543.003",
            "c": 0.8500000238418579,
            "d": "Open service control manager",
            "e": [
              "OpenSCManagerA",
              "OpenSCManager"
            ],
            "i": "micro-behaviors/os/service/control::open-sc-manager",
            "l": 1
          },
          {
            "a": "T1070.004",
            "c": 0.949999988079071,
            "d": "Self-delete via ping delay loop",
            "e": [
              "\nping ",
              "127.0.0.1"
            ],
            "i": "objectives/evasion/self-delete/file/delay::ping-self-delete",
            "l": 4
          },
          {
            "d": "hide keyword",
            "e": [
              "hide"
            ],
            "i": "micro-behaviors/data/text/keywords/lexicon::hide",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Free memory (C runtime)",
            "e": [
              "free"
            ],
            "i": "micro-behaviors/mem/c-runtime/functions::free-dup",
            "l": 2
          },
          {
            "c": 0.9399999976158142,
            "d": "PE overlay exceeds thirty-five percent",
            "e": [
              "binary.overlay_ratio = 0.48"
            ],
            "i": "metadata/binary/layout::overlay-over-35pct",
            "l": 3
          },
          {
            "c": 1.0,
            "d": "LoadLibrary symbol",
            "e": [
              "LoadLibraryA"
            ],
            "i": "objectives/anti-static/obfuscation/reflection/class::loadlibrary-sym",
            "l": 1
          },
          {
            "a": "T1027.003",
            "c": 0.9900000095367432,
            "d": "PE checksum mismatch",
            "e": [
              "pe.checksum_mismatch = 1.00"
            ],
            "i": "objectives/anti-static/obfuscation/payload/container::pe-checksum-mismatch-png",
            "l": 1,
            "m": "F0001.006"
          },
          {
            "c": 0.8999999761581421,
            "d": "Tiny C string section ratio",
            "e": [
              " = 0.0% of total (0 / 15872 bytes)",
              " = 0.0% of total (0 / 37888 bytes)",
              " = 0.0% of total (0 / 6144 bytes)"
            ],
            "i": "metadata/binary/section/metrics::tiny-cstring-section",
            "l": 1
          },
          {
            "a": "T1565.001",
            "c": 0.8500000238418579,
            "d": "Regex component marker",
            "e": [
              "[SRVANY] StartServiceCtrlDispatcher error = %d",
              "StartServiceCtrlDispatcherA",
              "__imp__StartServiceCtrlDispatcherA@4",
              "_StartServiceCtrlDispatcherA@4"
            ],
            "i": "objectives/evasion/hosts-file/block-security::escan-security-domain--rx-4",
            "l": 1,
            "m": "F0004"
          },
          {
            "c": 1.0,
            "d": "Binary has 30+ imports",
            "e": [
              "binary.import_count = 45.00",
              "binary.import_count = 50.00",
              "binary.import_count = 38.00"
            ],
            "i": "metadata/binary/metrics/threshold::many-imports-30",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Open registry key via import symbol ANSI",
            "e": [
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-open-key-ex-a-symbol",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE standard runtime section",
            "e": [
              ".reloc",
              ".rdata"
            ],
            "i": "metadata/binary/section/names::pe-runtime-standard-section",
            "l": 1
          },
          {
            "a": "T1070.006",
            "c": 0.699999988079071,
            "d": "PE header compile timestamp predates 2025",
            "e": [
              "pe.timestamp = 1012905799.00",
              "pe.timestamp = 944175276.00",
              "pe.timestamp = 841474940.00",
              "pe.timestamp = 1323089610.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::header-timestamp-pre-2025",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.8399999737739563,
            "d": "VB6 PE with three sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "objectives/anti-static/obfuscation/payload/string-sparse::three-section-vb6-layout",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.800000011920929,
            "d": "Binary lacks resource section entirely",
            "e": [
              "binary.rsrc_to_file_ratio = 0.00"
            ],
            "i": "metadata/binary/resource::no-resources",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.9900000095367432,
            "d": "PE version resource text",
            "e": [
              "VS_VERSION_INFO"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::anydesk-version-info",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.8999999761581421,
            "d": "PE .reloc section presence",
            "e": [
              ".reloc"
            ],
            "i": "metadata/binary/section/names::reloc-section-presence",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 25+ imports",
            "e": [
              "binary.import_count = 45.00",
              "binary.import_count = 38.00",
              "binary.import_count = 50.00"
            ],
            "i": "metadata/binary/metrics/threshold::many-imports-25",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "PE InternalName metadata field",
            "e": [
              "InternalName"
            ],
            "i": "metadata/package/versioning::pe-internalname-field",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links user32.dll (DialogBoxParamA, EndDialog, KillTimer, MessageBoxIndirectA, SetTimer, ... +1 more)",
            "e": [
              "USER32.dll",
              "user32.dll"
            ],
            "i": "metadata/dylib::user32/dll",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.8199999928474426,
            "d": "Packed loader largest section ratio above 0.65",
            "e": [
              "binary.largest_section_ratio = 0.69"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::packed-loader-largest-section-dominates",
            "l": 1,
            "m": "B0032"
          },
          {
            "d": "COMPUTERNAME environment variable",
            "e": [
              "Usage: clearlogs [\\\\computername] \u003c-app / -sec / -sys\u003e"
            ],
            "i": "micro-behaviors/os/env/vars/system-info::computername-var",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.699999988079071,
            "d": "Code section dominates file layout",
            "e": [
              "binary.largest_section_ratio = 0.69"
            ],
            "i": "objectives/anti-static/obfuscation/string/anomaly::dominant-text-section",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.8999999761581421,
            "d": "Local memory deallocation",
            "e": [
              "LocalFree"
            ],
            "i": "micro-behaviors/mem/alloc/heap::local-free",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "PE executable is unsigned",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed/trust-level::unsigned-pe-executable",
            "l": 3
          },
          {
            "c": 1.0,
            "d": "Call to GetDriveTypeA by raw bytes",
            "e": [
              "GetDriveTypeA"
            ],
            "i": "micro-behaviors/fs/traversal/drives::get-drive-type-raw",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Create private heap (HeapCreate)",
            "e": [
              "HeapCreate"
            ],
            "i": "micro-behaviors/mem/alloc/heap::heap-create",
            "l": 3
          },
          {
            "c": 0.699999988079071,
            "d": "Redirect output to null",
            "e": [
              "\u003enul"
            ],
            "i": "objectives/command-and-control/dropper/execution/batch::redirect-null",
            "l": 1
          },
          {
            "a": "T1027.007",
            "c": 0.8999999761581421,
            "d": "Kernel32 DLL resolution string",
            "e": [
              "kernel32.dll"
            ],
            "i": "micro-behaviors/os/api-resolution/manual::kernel32-resolver",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.949999988079071,
            "d": "Regex component marker",
            "e": [
              "binary.largest_section_ratio = 0.69"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::packed-loader-data-geometry-cond-1--inline-29188",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 1.0,
            "d": "Tiny PE by file size",
            "e": [
              "pe.machine = 332.00"
            ],
            "i": "metadata/binary/metrics/size::tiny-pe",
            "l": 3
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "RegOpenKeyEx API",
            "e": [
              "RegOpenKeyExA"
            ],
            "i": "objectives/anti-static/obfuscation/payload/registry::reg-open-key",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1543.003",
            "c": 0.9300000071525574,
            "d": "Program can open Windows services",
            "e": [
              "OpenServiceA"
            ],
            "i": "micro-behaviors/os/service/control::open-service-import",
            "l": 3
          },
          {
            "a": "T1543.003",
            "c": 0.8399999737739563,
            "d": "Delete installed service",
            "e": [
              "DeleteService"
            ],
            "i": "micro-behaviors/os/service/control::delete-service",
            "l": 3
          },
          {
            "a": "T1083",
            "c": 0.8999999761581421,
            "d": "Query drive type by symbol",
            "e": [
              "GetDriveTypeA"
            ],
            "i": "micro-behaviors/fs/traversal/drives::get-drive-type",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Microsoft vendor marker in resource section",
            "e": [
              "Microsoft Corporation"
            ],
            "i": "metadata/binary/vendor::microsoft-corp-marker-rsrc",
            "l": 1
          },
          {
            "c": 0.6600000262260437,
            "d": "Open files",
            "e": [
              "open"
            ],
            "i": "micro-behaviors/fs/file/open::open-base",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.8600000143051147,
            "d": "Long mixed-case identifiers cluster",
            "e": [
              "UnhandledExceptionFilter",
              "StartServiceCtrlDispatcher",
              "RegisterServiceCtrlHandler",
              "RegisterServiceCtrlHandlerA",
              "SetCurrentDirectoryA",
              "MultiByteToWideChar",
              "WideCharToMultiByte",
              "MessageBoxIndirectA",
              "GetModuleFileNameA",
              "StartServiceCtrlDispatcherA",
              "GetCurrentDirectoryA"
            ],
            "i": "objectives/anti-static/obfuscation/string/junking::long-mixedcase-identifiers",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 1.0,
            "d": "Compatibility alias",
            "e": [
              "ShellExecuteExA"
            ],
            "i": "micro-behaviors/process/create/exec::shell-execute-ex-a",
            "l": 1
          },
          {
            "a": "T1055.012",
            "c": 0.800000011920929,
            "d": "CreateProcess API string reference",
            "e": [
              "[SRVANY] CreateProcess(PMShell) failed, error %ld",
              "__imp__CreateProcessA@40",
              "[SRVANY] CreateProcess() failed, error %ld",
              "??_C@_0CN@IKPM@?5?$FLSRVANY?$FN?5CreateProcess?$CI?$CJ?5failed@",
              "_CreateProcessA@40",
              "CreateProcessA",
              "??_C@_0DE@GMPF@?5?$FLSRVANY?$FN?5CreateProcess?$CIPMShell?$CJ@"
            ],
            "i": "objectives/evasion/process/injection/hollowing::create-process-string",
            "l": 1,
            "m": "E1055.012"
          },
          {
            "c": 0.8799999952316284,
            "d": "Sparse function count stub",
            "e": [
              "binary.func_count = 5.00",
              "binary.func_count = 13.00"
            ],
            "i": "well-known/malware/trojan/shellobject/revengerat::sparse-function-stub",
            "l": 1
          },
          {
            "a": "T1543.003",
            "c": 0.8999999761581421,
            "d": "Start service control dispatcher",
            "e": [
              "StartServiceCtrlDispatcherA"
            ],
            "i": "micro-behaviors/os/service/control::start-service-dispatcher",
            "l": 3
          },
          {
            "c": 1.0,
            "d": "Binary has 50+ imports",
            "e": [
              "binary.import_count = 50.00"
            ],
            "i": "metadata/binary/metrics/threshold::many-imports-50",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Set file position",
            "e": [
              "SetFilePointer"
            ],
            "i": "micro-behaviors/fs/file/handle::set-file-pointer",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links ADVAPI32.dll (OpenEventLogA, ClearEventLogA, CloseEventLog)",
            "e": [
              "ADVAPI32.dll"
            ],
            "i": "metadata/dylib::advapi32/dll",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Five or more PE sections",
            "e": [
              "binary.section_count = 5.00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::five-plus-sections-pe",
            "l": 1
          },
          {
            "d": ".exe extension reference",
            "e": [
              ".exe",
              ".exe"
            ],
            "i": "micro-behaviors/fs/path/extension::exe-dup",
            "l": 2
          },
          {
            "a": "T1112",
            "c": 0.8399999737739563,
            "d": "Open registry key ANSI",
            "e": [
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-open-key-ex-a",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.8799999952316284,
            "d": "Report service status updates",
            "e": [
              "SetServiceStatus"
            ],
            "i": "micro-behaviors/os/service/control::set-service-status",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "RAR member contains shell script",
            "e": [
              ".bat"
            ],
            "i": "micro-behaviors/data/archive/rar::shell-script-member-extension",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "RAR v4 archive magic",
            "e": [
              "52 61 72 21 1A 07 00"
            ],
            "i": "metadata/file/magic::rar-v4",
            "l": 2
          },
          {
            "a": "T1105",
            "c": 0.8999999761581421,
            "d": "Windows executable filename in bytecode",
            "e": [
              "alark.exe"
            ],
            "i": "objectives/command-and-control/dropper/delivery/download::windows-exe-temp-staging",
            "l": 1,
            "m": "E1105"
          },
          {
            "c": 0.699999988079071,
            "d": "Destroy window",
            "e": [
              "DestroyWindow"
            ],
            "i": "micro-behaviors/ui/window/manage/control::destroy-window",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Unload dynamic library",
            "e": [
              "FreeLibrary"
            ],
            "i": "micro-behaviors/os/module/load::free-library",
            "l": 2
          },
          {
            "a": "T1105",
            "c": 0.8999999761581421,
            "d": "Dominant high entropy overlay",
            "e": [
              "binary.overlay_entropy = 7.99"
            ],
            "i": "objectives/command-and-control/dropper/execution/installer::dominant-overlay-high-entropy",
            "l": 1,
            "m": "B0022"
          },
          {
            "a": "T1562.001",
            "c": 0.8999999761581421,
            "d": "SafeBoot cleanup targets major EDR vendor",
            "e": [
              "eset"
            ],
            "i": "objectives/impact/degrade/edr/teardown::safeboot-edr-vendor--rx-3",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.8500000238418579,
            "d": "Set registry value via WinAPI ANSI",
            "e": [
              "RegSetValueExA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-set-value-ex-a",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "runas elevation verb",
            "e": [
              "runas"
            ],
            "i": "objectives/privilege-escalation/token-manipulation::runas-word",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "PE has RT_GROUP_ICON in resources list",
            "e": [
              "[RT_BITMAP, RT_ICON, RT_DIALOG, RT_STRING, RT_GROUP_ICON, RT_MANIFEST]"
            ],
            "i": "metadata/binary/resource::pe-resource-group-icon-list",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Set last error code",
            "e": [
              "SetLastError"
            ],
            "i": "micro-behaviors/os/exception/error-handling::set-last-error",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Convert Shell folder ID to path (ANSI)",
            "e": [
              "SHGetPathFromIDListA"
            ],
            "i": "micro-behaviors/fs/shell-ops::shell-get-path-from-idlist-a",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Uses temporary .tmp staging file",
            "e": [
              ".tmp"
            ],
            "i": "objectives/impact/infect/binary/rewrite::tmp-extension-staging",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "PE carries side-by-side assembly manifest",
            "e": [
              "{\"assembly_identity\":{\"version\":\"1.0.0.0\",\"processor_architecture\":\"*\",\"name\":\"WinRAR SFX\",\"type\":\"win32\"},\"description\":\"WinRAR"
            ],
            "i": "metadata/build/manifest::pe-has-manifest",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Move or rename file with options",
            "e": [
              "MoveFileExA"
            ],
            "i": "micro-behaviors/fs/file/move::move-file-ex",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "runas privilege elevation string",
            "e": [
              "runas"
            ],
            "i": "micro-behaviors/os/privilege/elevation::runas-string",
            "l": 3
          },
          {
            "c": 0.7200000286102295,
            "d": "WININIT rename section marker",
            "e": [
              "Rename"
            ],
            "i": "micro-behaviors/fs/config/system::wininit-rename-section",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 100+ imports",
            "e": [
              "binary.import_count = 163.00"
            ],
            "i": "metadata/binary/metrics/threshold::many-imports-100",
            "l": 1
          },
          {
            "c": 0.75,
            "d": "Initialize OLE/COM subsystem",
            "e": [
              "OleInitialize"
            ],
            "i": "micro-behaviors/os/com/invoke::ole-initialize",
            "l": 2
          },
          {
            "a": "T1614",
            "c": 0.6000000238418579,
            "d": "Country code ID token",
            "e": [
              " ID "
            ],
            "i": "objectives/anti-analysis/geofencing/region::country-code-id",
            "l": 1,
            "m": "B0007.003"
          },
          {
            "c": 0.800000011920929,
            "d": "Regex component marker",
            "e": [
              "folder is not accessiblelSome files could not be created.\nPlease close all applications, reboot Windows and restart this install"
            ],
            "i": "micro-behaviors/communications/http/client/managed::webclient--rx-5",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Post message to window",
            "e": [
              "PostMessageA"
            ],
            "i": "micro-behaviors/os/message/queue::post-message",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "NO_SEH (SafeSEH not used)",
            "e": [
              "true"
            ],
            "i": "metadata/hardening/mitigation::pe-no-seh",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Select GDI object",
            "e": [
              "SelectObject"
            ],
            "i": "micro-behaviors/ui/graphics/draw::select-object",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "GetClassNameA UI import",
            "e": [
              "GetClassNameA"
            ],
            "i": "well-known/malware/trojan/elex/clickfraud::get-class-name-a-import",
            "l": 1
          },
          {
            "a": "T1082",
            "c": 0.8999999761581421,
            "d": "Query Windows version info",
            "e": [
              "GetVersionExA"
            ],
            "i": "micro-behaviors/os/sysinfo/platform/locale::get-version-ex",
            "l": 2
          },
          {
            "c": 0.6399999856948853,
            "d": "Delete files (Windows API ANSI)",
            "e": [
              "DeleteFileA"
            ],
            "i": "micro-behaviors/fs/file/delete::deletefile-a-text",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "Create COM object instance",
            "e": [
              "CoCreateInstance"
            ],
            "i": "micro-behaviors/os/com/invoke::co-create-instance",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Tool identity claims WinRAR",
            "e": [
              "winrar",
              "WinRAR",
              "WINRAR"
            ],
            "i": "metadata/package/tooling::tool-identity-winrar",
            "l": 1
          },
          {
            "a": "T1005",
            "c": 0.75,
            "d": "Regex component marker",
            "e": [
              "binary.import_count = 163.00"
            ],
            "i": "micro-behaviors/fs/file/binary::file-manipulation-cond-0--inline-18739",
            "l": 1
          },
          {
            "c": 0.7799999713897705,
            "d": "Perform file operation through shell ANSI",
            "e": [
              "SHFileOperationA"
            ],
            "i": "micro-behaviors/fs/shell-ops::shell-file-operation-a",
            "l": 3
          },
          {
            "a": "T1547.001",
            "c": 0.800000011920929,
            "d": "Filters files by .lnk extension",
            "e": [
              ".lnk"
            ],
            "i": "objectives/persistence/login/startup/shortcut::lnk-endswith-filter",
            "l": 1
          },
          {
            "a": "T1572",
            "c": 1.0,
            "d": "DMW custom SSH tunneling tool password string",
            "e": [
              "password"
            ],
            "i": "objectives/command-and-control/channel/tunnel/dmw::dmw-tunnel-pwd",
            "l": 1
          },
          {
            "a": "T1204.002",
            "c": 0.7599999904632568,
            "d": "Short PDB marker",
            "e": [
              "sfxrar.pdb"
            ],
            "i": "objectives/command-and-control/dropper/execution/clickfix::short-pdb-marker",
            "l": 1,
            "m": "B0024"
          },
          {
            "c": 0.8999999761581421,
            "d": "Set file attributes (ANSI)",
            "e": [
              "SetFileAttributesA"
            ],
            "i": "micro-behaviors/fs/file/attributes::set-file-attributes-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Directory enumeration (ANSI)",
            "e": [
              "FindNextFileA"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-next-file-a",
            "l": 2
          },
          {
            "a": "T1082",
            "c": 0.8799999952316284,
            "d": "Query locale information",
            "e": [
              "GetLocaleInfoA"
            ],
            "i": "micro-behaviors/os/sysinfo/platform/locale::get-locale-info",
            "l": 2
          },
          {
            "c": 0.6600000262260437,
            "d": "Create directories (Windows API Unicode)",
            "e": [
              "CreateDirectoryW"
            ],
            "i": "micro-behaviors/fs/directory/mkdir::create-directory-w",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "CreateWindowExA UI import",
            "e": [
              "CreateWindowExA"
            ],
            "i": "well-known/malware/trojan/elex/clickfraud::create-window-ex-a-import",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Check if window exists",
            "e": [
              "IsWindow"
            ],
            "i": "micro-behaviors/ui/window/manage/control::is-window",
            "l": 2
          },
          {
            "c": 0.6600000262260437,
            "d": "Delete files (Windows API ANSI)",
            "e": [
              "DeleteFileA"
            ],
            "i": "micro-behaviors/fs/file/delete::deletefile-a",
            "l": 3
          },
          {
            "c": 0.6600000262260437,
            "d": "Create directories (Windows API ANSI)",
            "e": [
              "CreateDirectoryA"
            ],
            "i": "micro-behaviors/fs/directory/mkdir::create-directory-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Read data from file handle",
            "e": [
              "ReadFile"
            ],
            "i": "micro-behaviors/fs/file/read::read-file",
            "l": 2
          },
          {
            "a": "T1071",
            "c": 0.8999999761581421,
            "d": "OLE automation DLL import",
            "e": [
              "OLEAUT32.dll"
            ],
            "i": "objectives/command-and-control/backdoor/shell/com::oleaut32-import-reference",
            "l": 1,
            "m": "B0025"
          },
          {
            "c": 0.800000011920929,
            "d": "Map a file section into memory",
            "e": [
              "MapViewOfFile"
            ],
            "i": "micro-behaviors/fs/memory/mmap::map-view-of-file",
            "l": 2
          },
          {
            "c": 0.6000000238418579,
            "d": "Generates HTML tags",
            "e": [
              "\u003chead\u003e",
              "\u003chtml"
            ],
            "i": "micro-behaviors/data/format/html::html-generator-tags",
            "l": 3
          },
          {
            "a": "T1565.001",
            "c": 0.8500000238418579,
            "d": "Regex component marker",
            "e": [
              "folder is not accessiblelSome files could not be created.\nPlease close all applications, reboot Windows and restart this install"
            ],
            "i": "objectives/evasion/hosts-file/block-security::escan-security-domain--rx-1",
            "l": 1,
            "m": "F0004"
          },
          {
            "c": 0.699999988079071,
            "d": "Send message to window (ANSI)",
            "e": [
              "SendMessageA"
            ],
            "i": "micro-behaviors/ui/window/manage/control::send-message-a",
            "l": 2
          },
          {
            "a": "T1112",
            "c": 0.699999988079071,
            "d": "HKCU\\Software path string",
            "e": [
              "Software\\M",
              "Software\\W"
            ],
            "i": "objectives/anti-static/obfuscation/payload/registry::hkcu-software-text",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.800000011920929,
            "d": "Read active window title text",
            "e": [
              "GetWindowTextA"
            ],
            "i": "micro-behaviors/ui/window/manage/control::get-window-text",
            "l": 2
          },
          {
            "c": 0.8799999952316284,
            "d": "Resolve CLSID from string",
            "e": [
              "CLSIDFromString"
            ],
            "i": "micro-behaviors/os/com/invoke::clsid-from-string",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "WinRAR SFX start dialog",
            "e": [
              "STARTDLG"
            ],
            "i": "metadata/binary/installer/sfx::dialog-start",
            "l": 1
          },
          {
            "c": 0.6600000262260437,
            "d": "Look up temp directory via GetTempPath",
            "e": [
              "GetTempPathA"
            ],
            "i": "micro-behaviors/fs/temp/directory::get-temp-path-dup",
            "l": 2
          },
          {
            "c": 0.8399999737739563,
            "d": "High basic block count in sparse binary",
            "e": [
              "binary.total_basic_blocks = 3399.00"
            ],
            "i": "metadata/binary/metrics/structural::dense-basic-blocks",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.6499999761581421,
            "d": "Windows runas verb token",
            "e": [
              "runas"
            ],
            "i": "objectives/impact/degrade/system/registry::runas-verb-token",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Convert FILETIME to SYSTEMTIME",
            "e": [
              "FileTimeToSystemTime"
            ],
            "i": "micro-behaviors/time/query::filetime-to-systemtime",
            "l": 2
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Set registry value ANSI",
            "e": [
              "RegSetValueExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-set-value-ex-a",
            "l": 3
          },
          {
            "c": 1.0,
            "d": "requestedExecutionLevel is asInvoker",
            "e": [
              "asInvoker"
            ],
            "i": "metadata/build/manifest::pe-as-invoker",
            "l": 2
          },
          {
            "c": 0.6499999761581421,
            "d": "Get dialog control handle",
            "e": [
              "GetDlgItem"
            ],
            "i": "micro-behaviors/ui/dialog/prompt::get-dialog-item",
            "l": 2
          },
          {
            "a": "T1113",
            "c": 0.8500000238418579,
            "d": "GDI compatible bitmap allocation",
            "e": [
              "CreateCompatibleBitmap"
            ],
            "i": "micro-behaviors/hardware/display/screen::gdi-create-compatible-bitmap",
            "l": 3,
            "m": "C0014"
          },
          {
            "c": 0.8999999761581421,
            "d": "Begin directory enumeration",
            "e": [
              "FindFirstFileW"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-first-file",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Truncate file via SetEndOfFile",
            "e": [
              "SetEndOfFile"
            ],
            "i": "micro-behaviors/fs/file/truncate::set-end-of-file-win",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "SaveToFile string fragment (eToF)",
            "e": [
              "SystemTimeToFileTime",
              "LocalFileTimeToFileTime",
              "DosDateTimeToFileTime"
            ],
            "i": "objectives/execution/interpreter/script/wsh-fragments::save-to-file-fragment-etof",
            "l": 1
          },
          {
            "a": "T1204.002",
            "c": 0.8999999761581421,
            "d": "PowerShell archive extraction command marker",
            "e": [
              "7z"
            ],
            "i": "objectives/command-and-control/dropper/staging/archive::powershell-archive-extract",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Peek message (ANSI)",
            "e": [
              "PeekMessageA"
            ],
            "i": "micro-behaviors/os/message/queue::peek-message-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Get tick count",
            "e": [
              "GetTickCount"
            ],
            "i": "micro-behaviors/time/query::get-tick-count",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Query system metrics",
            "e": [
              "GetSystemMetrics"
            ],
            "i": "micro-behaviors/ui/controls/widget::get-system-metrics",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Wait for process/object",
            "e": [
              "WaitForSingleObject"
            ],
            "i": "micro-behaviors/process/create/spawn::wait-for-single-object",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Check if window is visible",
            "e": [
              "IsWindowVisible"
            ],
            "i": "micro-behaviors/ui/window/manage/control::is-window-visible",
            "l": 2
          },
          {
            "c": 0.8600000143051147,
            "d": "PE has medium sized overlay",
            "e": [
              "binary.overlay_size = 33218.00"
            ],
            "i": "metadata/binary/section/metrics::medium-overlay-pe",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "DEP / NX enabled (NX_COMPAT)",
            "e": [
              "true"
            ],
            "i": "metadata/hardening/mitigation::pe-dep",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Uses Windows API for file mapping",
            "e": [
              "UnmapViewOfFile"
            ],
            "i": "micro-behaviors/fs/memory/mmap::win32-file-mapping",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Change window position/size",
            "e": [
              "SetWindowPos"
            ],
            "i": "micro-behaviors/ui/window/manage/control::set-window-pos",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Delete GDI object",
            "e": [
              "DeleteObject"
            ],
            "i": "micro-behaviors/ui/graphics/draw::delete-object",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Get message (ANSI)",
            "e": [
              "GetMessageA"
            ],
            "i": "micro-behaviors/os/message/queue::get-message-a",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Depends on Common-Controls v6",
            "e": [
              "[{\"type\":\"win32\",\"name\":\"Microsoft.Windows.Common-Controls\",\"version\":\"6.0.0.0\",\"processor_architecture\":\"*\",\"public_key_token\":"
            ],
            "i": "metadata/build/manifest::pe-common-controls-v6",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.8600000143051147,
            "d": "UUID formatted route segment",
            "e": [
              "e2011457-1546-43c5-a5fe-008deee3d3f0",
              "35138b9a-5d96-4fbd-8e2d-a2440225f93a"
            ],
            "i": "objectives/command-and-control/channel/http::uuid-format-route-segment",
            "l": 1,
            "m": "B0030"
          },
          {
            "c": 0.8500000238418579,
            "d": "Query file attributes or existence",
            "e": [
              "GetFileAttributesW",
              "GetFileAttributesA"
            ],
            "i": "micro-behaviors/fs/path/check::get-file-attributes",
            "l": 2
          },
          {
            "c": 0.8399999737739563,
            "d": "High PE import count",
            "e": [
              "binary.import_count = 163.00"
            ],
            "i": "metadata/binary/section/metrics::high-import-count-pe",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "High number of imported symbols (\u003e80)",
            "e": [
              "binary.import_count = 163.00"
            ],
            "i": "metadata/binary/metrics/structural::many-imports",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Open named file mapping",
            "e": [
              "OpenFileMappingA"
            ],
            "i": "micro-behaviors/communications/ipc/file-mapping::open-file-mapping-a",
            "l": 3
          },
          {
            "c": 0.699999988079071,
            "d": "Release device context",
            "e": [
              "ReleaseDC"
            ],
            "i": "micro-behaviors/ui/window/manage/control::release-dc",
            "l": 2
          },
          {
            "c": 0.9800000190734863,
            "d": "WinRAR SFX registry key",
            "e": [
              "Software\\WinRAR SFX"
            ],
            "i": "metadata/binary/installer/sfx::registry-key",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Get module file path",
            "e": [
              "GetModuleFileNameW"
            ],
            "i": "micro-behaviors/os/module/load::get-module-filename-dup",
            "l": 2
          },
          {
            "c": 0.75,
            "d": "Uninitialize OLE/COM subsystem",
            "e": [
              "OleUninitialize"
            ],
            "i": "micro-behaviors/os/com/invoke::ole-uninitialize",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Register window class",
            "e": [
              "RegisterClassExA"
            ],
            "i": "micro-behaviors/ui/window/manage/control::register-class",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "CTS CreateFileW import",
            "e": [
              "CreateFileW"
            ],
            "i": "well-known/malware/worm/cts::create-file-w-import",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Enable/disable window",
            "e": [
              "EnableWindow"
            ],
            "i": "micro-behaviors/ui/window/manage/control::enable-window",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Get device context",
            "e": [
              "GetDC"
            ],
            "i": "micro-behaviors/ui/window/manage/control::get-dc",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Directory enumeration",
            "e": [
              "FindNextFileW"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-next-file",
            "l": 2
          },
          {
            "c": 0.6600000262260437,
            "d": "Delete files (Windows API)",
            "e": [
              "DeleteFileW"
            ],
            "i": "micro-behaviors/fs/file/delete::deletefile-w",
            "l": 3
          },
          {
            "a": "T1053.005",
            "c": 0.8799999952316284,
            "d": "Regex component marker",
            "e": [
              "GetFullPathNameA",
              "Path",
              "SavePath",
              "SHGetPathFromIDListA",
              "GetTempPathA"
            ],
            "i": "objectives/persistence/login/scheduled-task/com::task-action-principal-properties--rx-5",
            "l": 1,
            "m": "F0012"
          },
          {
            "c": 0.699999988079071,
            "d": "Display message box (ANSI)",
            "e": [
              "MessageBoxA"
            ],
            "i": "micro-behaviors/ui/dialog/prompt::message-box-a",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Notify shell of file changes",
            "e": [
              "SHChangeNotify"
            ],
            "i": "micro-behaviors/ui/window/notify::shell-change-notify",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Convert SYSTEMTIME to FILETIME",
            "e": [
              "SystemTimeToFileTime"
            ],
            "i": "micro-behaviors/time/query::systemtime-to-filetime",
            "l": 2
          },
          {
            "a": "T1027.009",
            "c": 0.800000011920929,
            "d": "Locate PE resource entry (ANSI)",
            "e": [
              "FindResourceA"
            ],
            "i": "micro-behaviors/data/embedded/payload/resource::find-resource-a",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Query device capabilities",
            "e": [
              "GetDeviceCaps"
            ],
            "i": "micro-behaviors/ui/graphics/draw::get-device-caps",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Close directory enumeration handle",
            "e": [
              "FindClose"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-close",
            "l": 2
          },
          {
            "c": 0.75,
            "d": "Open process access token",
            "e": [
              "OpenProcessToken"
            ],
            "i": "micro-behaviors/os/privilege/token::open-process-token",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Get window rectangle",
            "e": [
              "GetWindowRect"
            ],
            "i": "micro-behaviors/ui/window/manage/control::get-window-rect",
            "l": 2
          },
          {
            "a": "T1573",
            "c": 0.800000011920929,
            "d": "Regex component marker",
            "e": [
              "PA\u003c?xml version=\"1.0\" encoding=\"UTF-8\" standalone=\"yes\"?\u003e\r\n\u003cassembly xmlns=\"urn:schemas-microsoft-com:asm.v1\" manifestVersion=\"1",
              "publicKeyToken=\"6595b64144ccf1df\""
            ],
            "i": "micro-behaviors/crypto/asymmetric/kem::encrypted-trailer-terms--rx-4",
            "l": 1,
            "m": "C0027"
          },
          {
            "c": 0.8999999761581421,
            "d": "Get system time",
            "e": [
              "GetSystemTime"
            ],
            "i": "micro-behaviors/time/query::get-system-time",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Resolve special folder location via Shell32",
            "e": [
              "SHGetSpecialFolderLocation"
            ],
            "i": "micro-behaviors/fs/shell-ops::shell-get-special-folder-location",
            "l": 2
          },
          {
            "a": "T1112",
            "c": 0.8799999952316284,
            "d": "Create registry key ANSI",
            "e": [
              "RegCreateKeyExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-create-key-ex-a",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Move or rename file",
            "e": [
              "MoveFileA"
            ],
            "i": "micro-behaviors/fs/file/move::move-file",
            "l": 2
          },
          {
            "a": "T1204.002",
            "c": 0.8500000238418579,
            "d": "PowerShell archive file extension marker",
            "e": [
              ".rar"
            ],
            "i": "objectives/command-and-control/dropper/staging/archive::powershell-archive-extension",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Set file attributes (Unicode)",
            "e": [
              "SetFileAttributesW"
            ],
            "i": "micro-behaviors/fs/file/attributes::set-file-attributes-w",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "GUI binary declares DPI awareness",
            "e": [
              "true"
            ],
            "i": "metadata/build/manifest::pe-dpi-aware",
            "l": 2
          },
          {
            "a": "T1027,T1112,T1059.001",
            "c": 0.8999999761581421,
            "d": "Regex component marker",
            "e": [
              "RegSetValueExA"
            ],
            "i": "objectives/command-and-control/dropper/staging/embedded::registry-powershell-byte-payload--rx-4",
            "l": 1
          },
          {
            "a": "T1113",
            "c": 0.8500000238418579,
            "d": "GDI compatible device context",
            "e": [
              "CreateCompatibleDC"
            ],
            "i": "micro-behaviors/hardware/display/screen::gdi-create-compatible-dc",
            "l": 3,
            "m": "C0014"
          },
          {
            "c": 0.8999999761581421,
            "d": "Begin directory enumeration ANSI",
            "e": [
              "FindFirstFileA"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-first-file-a",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 50+ functions",
            "e": [
              "binary.func_count = 217.00"
            ],
            "i": "metadata/binary/metrics/threshold::many-functions-50",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Modify file creation/access/write times",
            "e": [
              "SetFileTime"
            ],
            "i": "micro-behaviors/fs/sync/fsync::set-file-time",
            "l": 3
          },
          {
            "c": 1.0,
            "d": "PE has RT_ICON in resources list",
            "e": [
              "[RT_BITMAP, RT_ICON, RT_DIALOG, RT_STRING, RT_GROUP_ICON, RT_MANIFEST]"
            ],
            "i": "metadata/binary/resource::pe-resource-icon-list",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Enable/disable privileges in access token",
            "e": [
              "AdjustTokenPrivileges"
            ],
            "i": "micro-behaviors/os/privilege/token::adjust-token-privileges",
            "l": 3
          },
          {
            "a": "T1027.009",
            "c": 0.800000011920929,
            "d": "High entropy overlay data",
            "e": [
              "binary.overlay_entropy = 7.99"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics/shape::high-entropy-overlay-raw",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1027",
            "d": "Binary has overlay data",
            "e": [
              "binary.has_overlay = 1.00"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics/shape::has-overlay",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.699999988079071,
            "d": "High function count over 200",
            "e": [
              "binary.func_count = 217.00"
            ],
            "i": "metadata/binary/metrics/threshold::high-function-count-200",
            "l": 2
          },
          {
            "c": 0.8799999952316284,
            "d": "Apply file security descriptor",
            "e": [
              "SetFileSecurityW"
            ],
            "i": "micro-behaviors/os/security/descriptor::set-file-security",
            "l": 3
          },
          {
            "c": 1.0,
            "d": "Manifest declares only Vista support",
            "e": [
              "[{\"guid\":\"{e2011457-1546-43c5-a5fe-008deee3d3f0}\",\"name\":\"vista\"}, {\"guid\":\"{35138b9a-5d96-4fbd-8e2d-a2440225f93a}\",\"name\":\"win7"
            ],
            "i": "metadata/build/manifest::pe-vista-only-manifest",
            "l": 3
          },
          {
            "a": "T1071",
            "c": 1.0,
            "d": "GetWindowText import (ANSI or wide)",
            "e": [
              "GetWindowTextA"
            ],
            "i": "objectives/command-and-control/backdoor/shell/com::get-window-text-import",
            "l": 1,
            "m": "B0025"
          },
          {
            "a": "T1071",
            "c": 1.0,
            "d": "IsWindowVisible / IsWindowEnabled import",
            "e": [
              "IsWindowVisible"
            ],
            "i": "objectives/command-and-control/backdoor/shell/com::is-window-state-import",
            "l": 1,
            "m": "B0025"
          },
          {
            "c": 0.8500000238418579,
            "d": "Repeated GetTickCount with small-constant comparisons",
            "e": [
              "5c 22 41 00",
              "68 21 41 00",
              "84 21 41 00"
            ],
            "i": "objectives/anti-static/obfuscation/instruction/junk::gettickcount-junk-branches",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Create window (extended)",
            "e": [
              "CreateWindowExA"
            ],
            "i": "micro-behaviors/ui/window/manage/control::create-window-ex",
            "l": 2
          },
          {
            "c": 0.75,
            "d": "Lookup privilege name to LUID",
            "e": [
              "LookupPrivilegeValueA"
            ],
            "i": "micro-behaviors/os/privilege/token::lookup-privilege-value",
            "l": 3
          },
          {
            "a": "T1071",
            "c": 1.0,
            "d": "GetWindow / GetWindowRect import",
            "e": [
              "GetWindow",
              "GetWindowRect"
            ],
            "i": "objectives/command-and-control/backdoor/shell/com::get-window-rect-import",
            "l": 1,
            "m": "B0025"
          },
          {
            "a": "T1027",
            "c": 0.7200000286102295,
            "d": "Overlay large enough for stage data",
            "e": [
              "binary.overlay_size = 33218.00"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics/shape::medium-overlay-size",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.949999988079071,
            "d": "links OLEAUT32.dll (ORDINAL 8)",
            "e": [
              "OLEAUT32.dll"
            ],
            "i": "metadata/dylib::oleaut32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links ole32.dll (CreateStreamOnHGlobal, OleInitialize, CoCreateInstance, OleUninitialize, CLSIDFromString)",
            "e": [
              "ole32.dll"
            ],
            "i": "metadata/dylib::ole32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links COMDLG32.dll (GetSaveFileNameA, CommDlgExtendedError, GetOpenFileNameA)",
            "e": [
              "COMDLG32.dll"
            ],
            "i": "metadata/dylib::comdlg32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links COMCTL32.dll (ORDINAL 17)",
            "e": [
              "COMCTL32.dll"
            ],
            "i": "metadata/dylib::comctl32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links GDI32.dll (GetDeviceCaps, GetObjectA, CreateCompatibleBitmap, SelectObject, StretchBlt, ... +3 more)",
            "e": [
              "GDI32.dll"
            ],
            "i": "metadata/dylib::gdi32/dll",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Temp directory staging primitives",
            "e": [
              "MoveFileExA",
              "GetTempPathA"
            ],
            "i": "micro-behaviors/fs/temp/directory::temp-file-staging-primitives",
            "l": 3
          },
          {
            "a": "T1070.006",
            "c": 0.8500000238418579,
            "d": "File timestamp modification with file operations",
            "e": [
              "CreateFileA",
              "FindFirstFileW",
              "WriteFile",
              "GetModuleFileNameA",
              "SetFileTime"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::timestomp-with-file-copy",
            "l": 2,
            "m": "F0006"
          },
          {
            "c": 0.8500000238418579,
            "d": "Drop and execute file from Temp directory",
            "e": [
              "WriteFile",
              "GetTempPathA",
              "CreateProcessA"
            ],
            "i": "objectives/command-and-control/dropper/staging/temp::temp-file-execution",
            "l": 2
          },
          {
            "c": 0.9700000286102295,
            "d": "WinRAR self-extractor footprint",
            "e": [
              "Software\\WinRAR SFX",
              "STARTDLG"
            ],
            "i": "metadata/binary/installer/sfx::winrar-sfx-footprint",
            "l": 1
          },
          {
            "c": 0.9200000166893005,
            "d": "Directory walker using Win32 find APIs",
            "e": [
              "FindNextFileA",
              "FindFirstFileA",
              "FindClose"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-file-walker",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Has file operation capabilities",
            "e": [
              "MoveFileExA",
              "FindFirstFileW"
            ],
            "i": "objectives/impact/ransom/file-operations::has-file-operations",
            "l": 1
          },
          {
            "c": 0.9200000166893005,
            "d": "Dynamically resolve own modules and exports",
            "e": [
              "GetProcAddress",
              "GetModuleHandleA"
            ],
            "i": "micro-behaviors/os/module/load::dynamic-self-resolution-imports",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "Standard MSVC CRT linkage (rich header + many imports)",
            "e": [
              "pe.rich_header_present = 1.00",
              "binary.import_count = 163.00"
            ],
            "i": "objectives/evasion/process/injection/module-stomping::msvc-crt-full-linkage",
            "l": 1
          },
          {
            "c": 0.9200000166893005,
            "d": "Directory walker using Win32 wide APIs",
            "e": [
              "FindClose",
              "FindFirstFileW",
              "FindNextFileW"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-file-walker-wide",
            "l": 2
          },
          {
            "c": 0.75,
            "d": "Legacy rich PE with broad imports",
            "e": [
              "pe.rich_header_present = 1.00",
              "binary.section_count = 3.00",
              "binary.string_count = 109.00",
              "binary.import_count = 163.00",
              "binary.overall_entropy = 4.02"
            ],
            "i": "metadata/binary/layout::rich-imported-low-entropy-layout",
            "l": 2
          },
          {
            "a": "T1083",
            "c": 0.8600000143051147,
            "d": "Drive context switching via cwd APIs",
            "e": [
              "GetDriveTypeA",
              "SetCurrentDirectoryA",
              "GetCurrentDirectoryA"
            ],
            "i": "micro-behaviors/fs/traversal/drives::drive-context-switching",
            "l": 3
          },
          {
            "a": "T1027",
            "c": 0.8799999952316284,
            "d": "Timing API junk branches in minimal stub",
            "e": [
              "68 21 41 00",
              "GetTickCount",
              "84 21 41 00",
              "5c 22 41 00"
            ],
            "i": "objectives/anti-static/obfuscation/instruction/junk::timing-junk-code-stub",
            "l": 2
          },
          {
            "a": "T1070.004",
            "c": 0.8199999928474426,
            "d": "Resolve own path then delete file",
            "e": [
              "DeleteFileW",
              "GetModuleFileNameA",
              "DeleteFileA",
              "DeleteFileA"
            ],
            "i": "objectives/evasion/self-delete/file/script::module-path-delete",
            "l": 2,
            "m": "F0007"
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Registry key and value write chain",
            "e": [
              "RegSetValueExA",
              "RegOpenKeyExA",
              "RegCreateKeyExA"
            ],
            "i": "micro-behaviors/os/registry/access::registry-write-api-chain",
            "l": 2
          },
          {
            "a": "T1083",
            "c": 0.8500000238418579,
            "d": "File system enumeration pattern",
            "e": [
              "FindFirstFileW",
              "FindNextFileW"
            ],
            "i": "objectives/collection/file-targeting::file-enumeration-targeting",
            "l": 1,
            "m": "C0000"
          },
          {
            "a": "T1134.001",
            "c": 0.8799999952316284,
            "d": "Dynamic token privilege adjustment chain",
            "e": [
              "AdjustTokenPrivileges",
              "OpenProcessToken",
              "LookupPrivilegeValueA"
            ],
            "i": "objectives/privilege-escalation/token-manipulation::dynamic-token-privilege-chain",
            "l": 1
          },
          {
            "a": "T1543.003",
            "c": 0.9599999785423279,
            "d": "Installs service and dispatches",
            "e": [
              "StartServiceCtrlDispatcherA",
              "SYSTEM\\CurrentControlSet\\Services\\",
              "RegisterServiceCtrlHandlerA",
              "CreateService",
              "CreateServiceA",
              "OpenSCManagerA",
              "SetServiceStatus",
              "OpenSCManager"
            ],
            "i": "objectives/persistence/system/service/install::service-install-dispatch-chain",
            "l": 4,
            "m": "B0011.003"
          },
          {
            "a": "T1112",
            "c": 0.9200000166893005,
            "d": "Registry open create and write APIs",
            "e": [
              "RegOpenKeyExA",
              "RegSetValueExA",
              "RegQueryValueExA",
              "RegCreateKeyExA",
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::registry-write-api-chain",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Trojanized system utility or hardware monitor dropper",
            "e": [
              "WinRAR",
              "winrar",
              "WINRAR",
              "binary.has_overlay = 1.00",
              "binary.has_signature = 0.00"
            ],
            "i": "objectives/supply-chain/trojanized/app/monitor::trojanized-system-utility-dropper",
            "l": 4
          },
          {
            "c": 0.8999999761581421,
            "d": "Unusual PE section alignment",
            "e": [
              "pe.unusual_alignment = 1.00"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::unusual-alignment-pe",
            "l": 4
          },
          {
            "a": "T1055.001",
            "c": 0.949999988079071,
            "d": "References LoadLibraryA dynamic module loading",
            "e": [
              "LoadLibraryA"
            ],
            "i": "micro-behaviors/process/inject/dll::load-library-a-remote-resolution",
            "l": 3,
            "m": "F0003"
          }
        ],
        "sha": "420469da49baf616368cbefe8b23b73cb8d5bd743708a818d45431cce79f1f22",
        "path": "502438",
        "type": "pe"
      },
      {
        "f": "O₆(ErC₂DyI₂PPr)",
        "x": 39,
        "dp": 1,
        "id": 1,
        "ms": {
          "file": {
            "size": 887.0
          },
          "text": {
            "digit_ratio": 0.03,
            "space_count": 73.0,
            "total_lines": 28.0,
            "char_entropy": 5.12,
            "unique_chars": 63.0,
            "avg_line_length": 29.68,
            "max_line_length": 194.0,
            "empty_line_ratio": 0.04,
            "last_line_length": 13.0,
            "most_common_char": "e",
            "whitespace_ratio": 0.15,
            "most_common_ratio": 0.1,
            "line_length_stddev": 35.04,
            "max_inline_whitespace_run": 1.0
          }
        },
        "ss": [
          [
            0,
            "cd %windir%"
          ],
          [
            13,
            "ping 127.0.0.1 -n 4"
          ],
          [
            34,
            "reg delete \"HKLM\\SYSTEM\\CurrentControlSet\\services\\alark\" /f"
          ],
          [
            96,
            "sc stop VSS"
          ],
          [
            109,
            "sc delete VSS"
          ],
          [
            124,
            "sc stop swprv"
          ],
          [
            139,
            "sc delete swprv"
          ],
          [
            156,
            "sc stop WindowsDefender"
          ],
          [
            181,
            "sc delete WindowsDefender"
          ],
          [
            208,
            "reg delete \"HKLM\\SYSTEM\\CurrentControlSet\\services\\swprv\" /f"
          ],
          [
            270,
            "reg delete \"HKLM\\SYSTEM\\CurrentControlSet\\services\\VSS\" /f"
          ],
          [
            330,
            "Reg Add \"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\ProcessHacker.exe\" /v \"debugger\" /t REG_"
          ],
          [
            528,
            "%windir%\\sysclr.exe -sys"
          ],
          [
            554,
            "%windir%\\sysclr.exe -sec"
          ],
          [
            580,
            "%windir%\\sysclr.exe -app"
          ],
          [
            606,
            "if not exist %windir%\\addins\\W72.exe (goto exit)"
          ],
          [
            656,
            "start /D %windir%\\addins W72.exe"
          ],
          [
            690,
            "ping 127.0.0.1 -n 2"
          ],
          [
            796,
            "net stop alark"
          ],
          [
            812,
            "sc delete alark"
          ],
          [
            829,
            "del /f /q miter.exe"
          ],
          [
            850,
            "del /f /q sysclr.exe"
          ]
        ],
        "sz": 887,
        "ts": [
          {
            "a": "T1546.012",
            "c": 0.8999999761581421,
            "d": "IFEO registry path",
            "e": [
              "Image File Execution Options"
            ],
            "i": "objectives/persistence/login/ifeo/debugger::ifeo-registry-path",
            "l": 1,
            "m": "F0012"
          },
          {
            "c": 0.949999988079071,
            "d": "Regex component marker",
            "e": [
              "start"
            ],
            "i": "objectives/command-and-control/dropper/execution/batch::keyed-temp-payload-launch--rx-1",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Redirect output to null",
            "e": [
              "\u003enul"
            ],
            "i": "objectives/command-and-control/dropper/execution/batch::redirect-null",
            "l": 1
          },
          {
            "c": 0.6000000238418579,
            "d": "Start an executable",
            "e": [
              "start /D %windir%\\addins W72.exe"
            ],
            "i": "objectives/command-and-control/dropper/execution/batch::start-exe",
            "l": 1
          },
          {
            "d": ".vbs extension reference",
            "e": [
              ".vbs"
            ],
            "i": "micro-behaviors/fs/path/extension::vbs",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Start minimized process",
            "e": [
              "start /MIN"
            ],
            "i": "objectives/command-and-control/dropper/execution/batch::start-hidden-dup",
            "l": 1
          },
          {
            "a": "T1082",
            "c": 1.0,
            "d": "Ping internal host list",
            "e": [
              "ping 127.0.0.1"
            ],
            "i": "objectives/discovery/system/domain-admin-prep::ping-internal-hosts",
            "l": 1
          },
          {
            "c": 0.550000011920929,
            "d": "Stdout redirected to NUL",
            "e": [
              "\u003enul"
            ],
            "i": "micro-behaviors/os/console/io::windows-stdout-to-nul",
            "l": 2
          },
          {
            "a": "T1070.004",
            "c": 0.949999988079071,
            "d": "Regex component marker",
            "e": [
              "127.0.0.1"
            ],
            "i": "objectives/evasion/self-delete/file/delay::ping-self-delete--rx-1",
            "l": 1
          },
          {
            "a": "T1486",
            "c": 1.0,
            "d": "Start launcher per host",
            "e": [
              "start /D"
            ],
            "i": "objectives/impact/ransom/staging::start-many-launch",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "Regex component marker",
            "e": [
              "Defender"
            ],
            "i": "objectives/privilege-escalation/exploit/vulnerabilities::redsun-cloud-tag-abuse--rx-7",
            "l": 1
          },
          {
            "a": "T1070.004",
            "c": 0.949999988079071,
            "d": "Regex component marker",
            "e": [
              "\nping "
            ],
            "i": "objectives/evasion/self-delete/file/delay::ping-self-delete--rx-2",
            "l": 1
          },
          {
            "c": 1.0,
            "d": ".vbs extension",
            "e": [
              ".vbs"
            ],
            "i": "objectives/command-and-control/dropper/builder::vbs-ext",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Hardcoded loopback IPv4 address",
            "e": [
              "127.0.0.1"
            ],
            "i": "micro-behaviors/communications/ip/literal::loopback-ipv4-source",
            "l": 2
          },
          {
            "d": ".exe extension reference",
            "e": [
              ".exe"
            ],
            "i": "micro-behaviors/fs/path/extension::exe-dup",
            "l": 2
          },
          {
            "a": "T1485",
            "c": 1.0,
            "d": "Windows forced quiet file deletion",
            "e": [
              "del /f /q"
            ],
            "i": "objectives/impact/system/directory::windows-recursive-delete-del",
            "l": 1
          },
          {
            "a": "T1070.004",
            "c": 0.949999988079071,
            "d": "Self-delete via ping delay loop",
            "e": [
              "\nping ",
              "127.0.0.1"
            ],
            "i": "objectives/evasion/self-delete/file/delay::ping-self-delete",
            "l": 4
          }
        ],
        "sha": "bca011fc53ea727c59f3dcec13118452ced8fb8b3c4cee8b9a01b6e558301f7a",
        "path": "502438!!sysclr.bat",
        "type": "batch"
      },
      {
        "f": "O₅(As₅C₄CoDyEr₃)H₄(MgPo₃CmDs)Md₃(Bi₆SiPa)",
        "x": 44,
        "dp": 1,
        "id": 2,
        "is": [
          "GetLastError",
          "FormatMessageA",
          "HeapDestroy",
          "ExitProcess",
          "TerminateProcess",
          "GetCurrentProcess",
          "GetCommandLineA",
          "GetVersion",
          "UnhandledExceptionFilter",
          "GetModuleFileNameA",
          "FreeEnvironmentStringsA",
          "FreeEnvironmentStringsW",
          "WideCharToMultiByte",
          "GetEnvironmentStrings",
          "GetEnvironmentStringsW",
          "SetHandleCount",
          "GetStdHandle",
          "GetFileType",
          "GetStartupInfoA",
          "LocalFree",
          "HeapCreate",
          "VirtualFree",
          "HeapFree",
          "RtlUnwind",
          "WriteFile",
          "HeapAlloc",
          "GetCPInfo",
          "GetACP",
          "GetOEMCP",
          "VirtualAlloc",
          "HeapReAlloc",
          "GetProcAddress",
          "LoadLibraryA",
          "FlushFileBuffers",
          "SetFilePointer",
          "MultiByteToWideChar",
          "LCMapStringA",
          "LCMapStringW",
          "GetStringTypeA",
          "GetStringTypeW",
          "SetStdHandle",
          "CloseHandle",
          "OpenEventLogA",
          "ClearEventLogA",
          "CloseEventLog"
        ],
        "ms": {
          "pe": {
            "machine": 332.0,
            "checksum": 0.0,
            "subsystem": 3.0,
            "timestamp": 1012905799.0,
            "image_base": 4194304.0,
            "entry_section": ".text",
            "size_of_image": 36864.0,
            "timestamp_day": 5.0,
            "file_alignment": 4096.0,
            "timestamp_year": 2002.0,
            "characteristics": 271.0,
            "entry_point_rva": 5646.0,
            "size_of_headers": 4096.0,
            "timestamp_month": 2.0,
            "checksum_missing": true,
            "checksum_present": false,
            "export_timestamp": 0.0,
            "import_dll_count": 2.0,
            "computed_checksum": 60720.0,
            "section_alignment": 4096.0,
            "unusual_alignment": true,
            "number_of_sections": 3.0,
            "resource_timestamp": 0.0,
            "rich_header_present": true,
            "linker_major_version": 6.0,
            "api_hashing_indicators": 1.0,
            "export_timestamp_present": false,
            "resource_timestamp_present": false
          },
          "file": {
            "size": 28672.0
          },
          "binary": {
            "code_size": 16384.0,
            "func_count": 34.0,
            "entry_point": 5646.0,
            "code_entropy": 6.55,
            "data_entropy": 2.75,
            "func_density": 2.13,
            "import_count": 45.0,
            "string_count": 109.0,
            "avg_func_size": 342.5,
            "section_count": 3.0,
            "avg_complexity": 16.94,
            "import_density": 2.81,
            "max_complexity": 106.0,
            "string_density": 6.81,
            "overall_entropy": 4.02,
            "avg_basic_blocks": 26.29,
            "avg_section_size": 8192.0,
            "dependency_count": 2.0,
            "entropy_variance": 1.88,
            "avg_string_length": 19.87,
            "complexity_per_kb": 1.06,
            "max_string_length": 69.0,
            "wide_string_count": 1.0,
            "writable_sections": 1.0,
            "avg_string_entropy": 3.31,
            "code_to_data_ratio": 2.0,
            "data_to_file_ratio": 0.14,
            "entry_point_is_rva": true,
            "text_to_file_ratio": 0.57,
            "total_basic_blocks": 894.0,
            "executable_sections": 1.0,
            "func_analysis_depth": 2.0,
            "string_length_stddev": 13.5,
            "high_complexity_funcs": 1.0,
            "largest_section_ratio": 0.57,
            "sentence_string_count": 36.0,
            "sentence_string_ratio": 0.33,
            "behavioral_import_ratio": 0.07
          }
        },
        "ss": [
          [
            77,
            "!This program cannot be run in DOS mode."
          ],
          [
            448,
            ".text"
          ],
          [
            527,
            "@.data"
          ],
          [
            6672,
            "HHtpHHtl"
          ],
          [
            7592,
            "RPWV"
          ],
          [
            8963,
            "QQS3"
          ],
          [
            9027,
            "PSSW"
          ],
          [
            10598,
            "SVWU"
          ],
          [
            11518,
            "SVW3"
          ],
          [
            12932,
            "90tr"
          ],
          [
            19939,
            "SUVW"
          ],
          [
            20725,
            "700WP"
          ],
          [
            20741,
            "`h````"
          ],
          [
            20776,
            "wide",
            "(null)"
          ],
          [
            20792,
            "(null)"
          ],
          [
            20800,
            "runtime error"
          ],
          [
            20820,
            "TLOSS error"
          ],
          [
            20836,
            "SING error"
          ],
          [
            20852,
            "DOMAIN error"
          ],
          [
            20868,
            "R6028\r\n- unable to initialize heap"
          ],
          [
            20875,
            "- unable to initialize heap"
          ],
          [
            20908,
            "R6027\r\n- not enough space for lowio initialization"
          ],
          [
            20915,
            "- not enough space for lowio initialization"
          ],
          [
            20964,
            "R6026\r\n- not enough space for stdio initialization"
          ],
          [
            20971,
            "- not enough space for stdio initialization"
          ],
          [
            21020,
            "R6025\r\n- pure virtual function call"
          ],
          [
            21027,
            "- pure virtual function call"
          ],
          [
            21060,
            "R6024\r\n- not enough space for _onexit/atexit table"
          ],
          [
            21067,
            "- not enough space for _onexit/atexit table"
          ],
          [
            21116,
            "R6019\r\n- unable to open console device"
          ],
          [
            21123,
            "- unable to open console device"
          ],
          [
            21160,
            "R6018\r\n- unexpected heap error"
          ],
          [
            21167,
            "- unexpected heap error"
          ],
          [
            21196,
            "R6017\r\n- unexpected multithread lock error"
          ],
          [
            21203,
            "- unexpected multithread lock error"
          ],
          [
            21244,
            "R6016\r\n- not enough space for thread data"
          ],
          [
            21251,
            "- not enough space for thread data"
          ],
          [
            21288,
            "abnormal program termination"
          ],
          [
            21324,
            "R6009\r\n- not enough space for environment"
          ],
          [
            21331,
            "- not enough space for environment"
          ],
          [
            21368,
            "R6008\r\n- not enough space for arguments"
          ],
          [
            21375,
            "- not enough space for arguments"
          ],
          [
            21412,
            "R6002\r\n- floating point not loaded"
          ],
          [
            21419,
            "- floating point not loaded"
          ],
          [
            21452,
            "Microsoft Visual C++ Runtime Library"
          ],
          [
            21496,
            "Runtime Error!\n\nProgram:"
          ],
          [
            21528,
            "\u003cprogram name unknown\u003e"
          ],
          [
            21552,
            "GetLastActivePopup"
          ],
          [
            21572,
            "GetActiveWindow"
          ],
          [
            21588,
            "MessageBoxA"
          ],
          [
            21600,
            "user32.dll"
          ],
          [
            21910,
            "LocalFree"
          ],
          [
            21922,
            "FormatMessageA"
          ],
          [
            21940,
            "GetLastError"
          ],
          [
            21954,
            "KERNEL32.dll"
          ],
          [
            21970,
            "CloseEventLog"
          ],
          [
            21986,
            "ClearEventLogA"
          ],
          [
            22004,
            "OpenEventLogA"
          ],
          [
            22018,
            "ADVAPI32.dll"
          ],
          [
            22034,
            "ExitProcess"
          ],
          [
            22048,
            "TerminateProcess"
          ],
          [
            22068,
            "GetCurrentProcess"
          ],
          [
            22088,
            "GetCommandLineA"
          ],
          [
            22106,
            "GetVersion"
          ],
          [
            22120,
            "UnhandledExceptionFilter"
          ],
          [
            22148,
            "GetModuleFileNameA"
          ],
          [
            22170,
            "FreeEnvironmentStringsA"
          ],
          [
            22196,
            "FreeEnvironmentStringsW"
          ],
          [
            22222,
            "WideCharToMultiByte"
          ],
          [
            22244,
            "GetEnvironmentStrings"
          ],
          [
            22268,
            "GetEnvironmentStringsW"
          ],
          [
            22294,
            "SetHandleCount"
          ],
          [
            22312,
            "GetStdHandle"
          ],
          [
            22328,
            "GetFileType"
          ],
          [
            22342,
            "GetStartupInfoA"
          ],
          [
            22360,
            "HeapDestroy"
          ],
          [
            22374,
            "HeapCreate"
          ],
          [
            22388,
            "VirtualFree"
          ],
          [
            22402,
            "HeapFree"
          ],
          [
            22414,
            "RtlUnwind"
          ],
          [
            22426,
            "WriteFile"
          ],
          [
            22438,
            "HeapAlloc"
          ],
          [
            22450,
            "GetCPInfo"
          ],
          [
            22472,
            "GetOEMCP"
          ],
          [
            22484,
            "VirtualAlloc"
          ],
          [
            22500,
            "HeapReAlloc"
          ],
          [
            22514,
            "GetProcAddress"
          ],
          [
            22532,
            "LoadLibraryA"
          ],
          [
            22548,
            "FlushFileBuffers"
          ],
          [
            22568,
            "SetFilePointer"
          ],
          [
            22586,
            "MultiByteToWideChar"
          ],
          [
            22608,
            "LCMapStringA"
          ],
          [
            22624,
            "LCMapStringW"
          ],
          [
            22640,
            "GetStringTypeA"
          ],
          [
            22658,
            "GetStringTypeW"
          ],
          [
            22676,
            "SetStdHandle"
          ],
          [
            22692,
            "CloseHandle"
          ],
          [
            24624,
            "Success: The log has been cleared"
          ],
          [
            24660,
            "Error: Unable to clear log -"
          ],
          [
            24696,
            "Error: Unable to open log -"
          ],
          [
            24728,
            "-sys = system log"
          ],
          [
            24756,
            "-sec = security log"
          ],
          [
            24788,
            "-app = application log"
          ],
          [
            24820,
            "Usage: clearlogs [\\\\computername] \u003c-app / -sec / -sys\u003e"
          ],
          [
            24880,
            "System"
          ],
          [
            24896,
            "Security"
          ],
          [
            24916,
            "Application"
          ],
          [
            24936,
            "- http://ntsecurity.nu/toolbox/clearlogs/"
          ],
          [
            24996,
            "ClearLogs 1.0 - (c) 2002, Arne Vidstrom (arne.vidstrom@ntsecurity.nu)"
          ]
        ],
        "sz": 28672,
        "ts": [
          {
            "c": 0.8999999761581421,
            "d": "PE standard runtime section",
            "e": [
              ".rdata"
            ],
            "i": "metadata/binary/section/names::pe-runtime-standard-section",
            "l": 1
          },
          {
            "c": 0.8199999928474426,
            "d": "Elevated text section entropy",
            "e": [
              ".text (entropy: 6.55)"
            ],
            "i": "metadata/binary/section/metrics::elevated-text-entropy-section",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE standard code/data section",
            "e": [
              ".data",
              ".text"
            ],
            "i": "metadata/binary/section/names::pe-code-data-standard-section",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 4 or fewer sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "objectives/command-and-control/infrastructure/config::max-sections-4",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary is not position-independent (fixed load address)",
            "e": [
              "binary.is_pie = 0.00"
            ],
            "i": "metadata/hardening/layout::no-pie",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Heap memory deallocation",
            "e": [
              "HeapFree"
            ],
            "i": "micro-behaviors/mem/alloc/heap::heap-free",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Binary has low overall entropy",
            "e": [
              "binary.overall_entropy = 4.02"
            ],
            "i": "metadata/binary/metrics/threshold::low-overall-entropy-binary",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Close handle",
            "e": [
              "CloseHandle"
            ],
            "i": "micro-behaviors/process/create/spawn::close-handle-dup",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE has few sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "metadata/binary/layout::legacy-few-sections",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Exit current process",
            "e": [
              "ExitProcess"
            ],
            "i": "micro-behaviors/process/terminate/kill::exit-process",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Get file handle type",
            "e": [
              "GetFileType"
            ],
            "i": "micro-behaviors/fs/file/handle::get-file-type",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Get system error code",
            "e": [
              "GetLastError"
            ],
            "i": "micro-behaviors/os/exception/error-handling::get-last-error",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Get current process handle",
            "e": [
              "GetCurrentProcess"
            ],
            "i": "micro-behaviors/os/module/load::get-current-process",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 25+ imports",
            "e": [
              "binary.import_count = 45.00"
            ],
            "i": "metadata/binary/metrics/threshold::many-imports-25",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE file uses .exe extension",
            "e": [
              "sysclr.exe"
            ],
            "i": "metadata/binary/framework::exe-extension",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Set file position",
            "e": [
              "SetFilePointer"
            ],
            "i": "micro-behaviors/fs/file/handle::set-file-pointer",
            "l": 2
          },
          {
            "c": 0.75,
            "d": "Binary exports no symbols",
            "e": [
              "binary.export_count = 0.00"
            ],
            "i": "metadata/binary/symbols/exports::no-exports",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "Process termination via TerminateProcess",
            "e": [
              "TerminateProcess"
            ],
            "i": "micro-behaviors/process/terminate/kill::terminate-process",
            "l": 3,
            "m": "B0033"
          },
          {
            "a": "T1070.006",
            "c": 0.699999988079071,
            "d": "PE header compile timestamp predates 2025",
            "e": [
              "pe.timestamp = 1012905799.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::header-timestamp-pre-2025",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Binary has many sentence-like strings",
            "e": [
              "binary.sentence_string_ratio = 0.33"
            ],
            "i": "metadata/binary/metrics/threshold::rich-sentence-strings-20pct",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Set standard I/O handle",
            "e": [
              "SetStdHandle"
            ],
            "i": "micro-behaviors/fs/file/handle::set-std-handle",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Heap memory reallocation",
            "e": [
              "HeapReAlloc"
            ],
            "i": "micro-behaviors/mem/alloc/heap::heap-realloc",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Low-entropy rdata section",
            "e": [
              ".rdata (entropy: 3.47)"
            ],
            "i": "metadata/binary/section/metrics::low-entropy-rdata-section",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Get standard I/O handle",
            "e": [
              "GetStdHandle"
            ],
            "i": "micro-behaviors/fs/file/handle::get-std-handle",
            "l": 2
          },
          {
            "d": "COMPUTERNAME environment variable",
            "e": [
              "Usage: clearlogs [\\\\computername] \u003c-app / -sec / -sys\u003e"
            ],
            "i": "micro-behaviors/os/env/vars/system-info::computername-var",
            "l": 2
          },
          {
            "a": "T1027.007",
            "c": 1.0,
            "d": "WININET.DLL absent from PE import table",
            "e": [
              "pe.import_dll_count = 2.00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::wininet-import-absent",
            "l": 2,
            "m": "B0032"
          },
          {
            "c": 0.8999999761581421,
            "d": "PE Rich header present (MSVC toolchain)",
            "e": [
              "pe.rich_header_present = 1.00"
            ],
            "i": "metadata/binary/resource::rich-header-present",
            "l": 2
          },
          {
            "c": 0.8399999737739563,
            "d": "Read wide environment block",
            "e": [
              "GetEnvironmentStringsW"
            ],
            "i": "micro-behaviors/os/env/access::get-environment-strings-wide",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "LoadLibrary symbol",
            "e": [
              "LoadLibraryA"
            ],
            "i": "objectives/anti-static/obfuscation/reflection/class::loadlibrary-sym",
            "l": 1
          },
          {
            "a": "T1055",
            "c": 0.9200000166893005,
            "d": "Regex component marker",
            "e": [
              "binary.import_count = 45.00"
            ],
            "i": "objectives/evasion/process/injection/vb6::vb6-process-injection-pattern-cond-1--inline-17571",
            "l": 1,
            "m": "C0041"
          },
          {
            "c": 0.8999999761581421,
            "d": "Flush file buffer to disk",
            "e": [
              "FlushFileBuffers"
            ],
            "i": "micro-behaviors/fs/file/handle::flush-file-buffers",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Heap memory allocation",
            "e": [
              "HeapAlloc"
            ],
            "i": "micro-behaviors/mem/alloc/heap::heap-alloc",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Release wide environment block",
            "e": [
              "FreeEnvironmentStringsW"
            ],
            "i": "micro-behaviors/os/env/access::free-environment-strings-wide",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Regex component marker",
            "e": [
              "FreeEnvironmentStringsW",
              "GetEnvironmentStringsW",
              "GetStringTypeA",
              "FreeEnvironmentStringsA",
              "GetEnvironmentStrings",
              "GetStringTypeW",
              "LCMapStringA",
              "LCMapStringW"
            ],
            "i": "micro-behaviors/communications/http/client/managed::webclient--rx-7",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "Binary imports ADVAPI32.dll",
            "e": [
              "ADVAPI32.dll"
            ],
            "i": "metadata/binary/symbols/imports::imports-advapi32-dll",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Free virtual memory",
            "e": [
              "VirtualFree"
            ],
            "i": "micro-behaviors/mem/protect/modify::virtual-free",
            "l": 2
          },
          {
            "c": 0.8199999928474426,
            "d": "Query current process command line",
            "e": [
              "GetCommandLineA"
            ],
            "i": "micro-behaviors/process/info/commandline::get-command-line",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Tiny writable data section",
            "e": [
              ".data (size: 4096)"
            ],
            "i": "metadata/binary/section/metrics::tiny-data-section",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 30+ imports",
            "e": [
              "binary.import_count = 45.00"
            ],
            "i": "metadata/binary/metrics/threshold::many-imports-30",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "WinExec hidden-window flag immediate",
            "e": [
              "04 50 40 00"
            ],
            "i": "micro-behaviors/process/create/flags::winexec-sw-hide-immediate",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Write data to file handle",
            "e": [
              "WriteFile"
            ],
            "i": "micro-behaviors/fs/file/write/direct::write-file",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE has low overall entropy",
            "e": [
              "binary.overall_entropy = 4.02"
            ],
            "i": "metadata/binary/layout::low-overall-entropy",
            "l": 2
          },
          {
            "d": ".dll extension reference",
            "e": [
              ".dll"
            ],
            "i": "micro-behaviors/fs/path/extension::dll-dup",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Get module file path (ANSI)",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/os/module/load::get-module-filename-ansi",
            "l": 2
          },
          {
            "c": 0.8399999737739563,
            "d": "Invoke unhandled exception filter",
            "e": [
              "UnhandledExceptionFilter"
            ],
            "i": "micro-behaviors/os/exception/error-handling::unhandled-exception-filter-import",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has low average string entropy",
            "e": [
              "binary.avg_string_entropy = 3.31"
            ],
            "i": "metadata/binary/metrics/threshold::avg-string-entropy-4-max",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Runtime library unwind operation",
            "e": [
              "RtlUnwind"
            ],
            "i": "micro-behaviors/os/exception/error-handling::rtl-unwind",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "GetModuleFileName API call",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/process/info/current::get-module-filename",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.8399999737739563,
            "d": "VB6 PE with three sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "objectives/anti-static/obfuscation/payload/string-sparse::three-section-vb6-layout",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.800000011920929,
            "d": "Small PE resource section",
            "e": [
              "pe.rsrc_size = 0.00"
            ],
            "i": "metadata/package/versioning::pe-small-rsrc",
            "l": 1
          },
          {
            "a": "T1587.001",
            "c": 0.8999999761581421,
            "d": "Allocate virtual memory",
            "e": [
              "VirtualAlloc"
            ],
            "i": "micro-behaviors/mem/protect/modify::virtual-alloc",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Get environment strings",
            "e": [
              "GetEnvironmentStrings",
              "FreeEnvironmentStringsW",
              "GetEnvironmentStringsW"
            ],
            "i": "micro-behaviors/os/env/access::get-environment-strings",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 20+ imports",
            "e": [
              "binary.import_count = 45.00"
            ],
            "i": "metadata/binary/metrics/threshold::many-imports-20",
            "l": 1
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "LoadLibraryA loader API string",
            "e": [
              "LoadLibraryA"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-loadlibrarya-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "c": 0.699999988079071,
            "d": "Read startup info via GetStartupInfoA",
            "e": [
              "GetStartupInfoA"
            ],
            "i": "micro-behaviors/os/sysinfo/process::get-startup-info-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Local memory deallocation",
            "e": [
              "LocalFree"
            ],
            "i": "micro-behaviors/mem/alloc/heap::local-free",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE has many readable strings",
            "e": [
              "binary.string_count = 109.00"
            ],
            "i": "metadata/binary/layout::many-readable-strings",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "File is a compiled binary",
            "e": [
              "sysclr.exe"
            ],
            "i": "metadata/binary/framework::is-binary",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE mapped image under 768 KiB",
            "e": [
              "pe.size_of_image = 36864.00"
            ],
            "i": "metadata/binary/layout::image-under-768kb",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Query current module path",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/fs/path/check::get-module-filename",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Get Unicode character type",
            "e": [
              "GetStringTypeW"
            ],
            "i": "micro-behaviors/os/env/access::get-string-type-w",
            "l": 2
          },
          {
            "c": 0.8199999928474426,
            "d": "Regex component marker",
            "e": [
              "CloseEventLog",
              "CloseHandle"
            ],
            "i": "objectives/discovery/system/ics-environment/register::ics-register-flow-rate--rx-75",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Binary has many functions (\u003e30)",
            "e": [
              "binary.func_count = 34.00"
            ],
            "i": "metadata/binary/metrics/structural::many-functions",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.699999988079071,
            "d": "Network URL with domain name (binary)",
            "e": [
              "http://ntsecurity.nu/"
            ],
            "i": "objectives/command-and-control/infrastructure/domain/heuristic::http-url-binary",
            "l": 3,
            "m": "C0002"
          },
          {
            "c": 1.0,
            "d": "Binary has 3+ functions",
            "e": [
              "binary.func_count = 34.00"
            ],
            "i": "metadata/binary/metrics/threshold::few-functions-3",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Unicode string locale mapping",
            "e": [
              "LCMapStringW"
            ],
            "i": "micro-behaviors/os/env/access::lcmap-string-w",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 40+ imports",
            "e": [
              "binary.import_count = 45.00"
            ],
            "i": "metadata/binary/metrics/threshold::many-imports-40",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Resolve exports with GetProcAddress",
            "e": [
              "GetProcAddress"
            ],
            "i": "micro-behaviors/os/module/load::get-proc-address-import",
            "l": 2
          },
          {
            "a": "T1070.006",
            "c": 0.8999999761581421,
            "d": "Export timestamp is absent",
            "e": [
              "pe.export_timestamp_present = 0.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::export-timestamp-absent",
            "l": 2
          },
          {
            "a": "T1055",
            "c": 0.949999988079071,
            "d": "Huge null run in executable (128+ bytes)",
            "e": [
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00"
            ],
            "i": "objectives/anti-static/obfuscation/binary-structure::huge-null-run-text",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.800000011920929,
            "d": "Few PE resource entries (no DIALOG/MENU/STRINGTABLE)",
            "e": [
              "pe.resource_count = 0.00"
            ],
            "i": "objectives/evasion/anti-av/heuristic::minimal-pe-resources",
            "l": 1
          },
          {
            "a": "T1027.007",
            "c": 0.8600000143051147,
            "d": "PE API hashing indicator present",
            "e": [
              "pe.api_hashing_indicators = 1.00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::pe-api-hashing-indicator-single",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "c": 1.0,
            "d": "Binary is not digitally signed",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed/trust-level::unsigned",
            "l": 3
          },
          {
            "a": "T1574.002",
            "c": 0.8999999761581421,
            "d": "Hidden LoadLibraryA string reference",
            "e": [
              "LoadLibraryA"
            ],
            "i": "micro-behaviors/dylib/load/runtime::load-library-a-string-no-import",
            "l": 1
          },
          {
            "c": 0.6000000238418579,
            "d": "Very few sections (merged/stripped)",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "metadata/binary/metrics/structural::few-sections",
            "l": 3
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "GetProcAddress loader API string",
            "e": [
              "GetProcAddress"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-getprocaddress-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "a": "T1027",
            "c": 0.8600000143051147,
            "d": "Long mixed-case identifiers cluster",
            "e": [
              "GetModuleFileNameA",
              "MultiByteToWideChar",
              "UnhandledExceptionFilter",
              "WideCharToMultiByte"
            ],
            "i": "objectives/anti-static/obfuscation/string/junking::long-mixedcase-identifiers",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "VirtualAlloc loader API string",
            "e": [
              "VirtualAlloc"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-virtualalloc-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "c": 0.8999999761581421,
            "d": "Browser process termination API",
            "e": [
              "TerminateProcess"
            ],
            "i": "objectives/collection/stealer/browser::windows-browser-terminate-api",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Unusual PE section alignment",
            "e": [
              "pe.unusual_alignment = 1.00"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::unusual-alignment-pe",
            "l": 4
          },
          {
            "c": 0.949999988079071,
            "d": "Filename has EXE extension",
            "e": [
              "sysclr.exe"
            ],
            "i": "objectives/evasion/masquerade/file/double-ext::basename-is-exe",
            "l": 1
          },
          {
            "a": "T1055.001",
            "c": 0.949999988079071,
            "d": "References LoadLibraryA dynamic module loading",
            "e": [
              "LoadLibraryA"
            ],
            "i": "micro-behaviors/process/inject/dll::load-library-a-remote-resolution",
            "l": 3,
            "m": "F0003"
          },
          {
            "c": 0.800000011920929,
            "d": "Binary lacks resource section entirely",
            "e": [
              "binary.rsrc_to_file_ratio = 0.00"
            ],
            "i": "metadata/binary/resource::no-resources",
            "l": 2
          },
          {
            "a": "T1105",
            "c": 0.800000011920929,
            "d": "Compact PE import table",
            "e": [
              "binary.import_count = 45.00"
            ],
            "i": "objectives/command-and-control/dropper/delivery/download-execute::compact-import-table",
            "l": 1,
            "m": "E1105"
          },
          {
            "c": 0.8999999761581421,
            "d": "Create private heap (HeapCreate)",
            "e": [
              "HeapCreate"
            ],
            "i": "micro-behaviors/mem/alloc/heap::heap-create",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "PE executable is unsigned",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed/trust-level::unsigned-pe-executable",
            "l": 3
          },
          {
            "c": 0.949999988079071,
            "d": "links ADVAPI32.dll (OpenEventLogA, ClearEventLogA, CloseEventLog)",
            "e": [
              "ADVAPI32.dll"
            ],
            "i": "metadata/dylib::advapi32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links KERNEL32.dll (GetLastError, FormatMessageA, HeapDestroy, ExitProcess, TerminateProcess, ... +37 more)",
            "e": [
              "KERNEL32.dll"
            ],
            "i": "metadata/dylib::kernel32/dll",
            "l": 2
          },
          {
            "c": 0.8799999952316284,
            "d": "Enumerate process environment block",
            "e": [
              "FreeEnvironmentStringsW",
              "GetEnvironmentStringsW"
            ],
            "i": "micro-behaviors/os/env/access::environment-block-enumeration",
            "l": 2
          }
        ],
        "sha": "6bfd95e5a8a977912163297dea82e1cf8cadd08c8cbf50baf0802d5558029774",
        "path": "502438!!sysclr.exe",
        "type": "pe"
      },
      {
        "f": "KO₄(As₄C₂CoEr₇)H₄(Po₃CmDbOs)Md₃(Bi₈SiHe)",
        "x": 8,
        "dp": 1,
        "id": 3,
        "is": [
          "ExitProcess",
          "GetCommandLineA",
          "GetCurrentDirectoryA",
          "GetExitCodeProcess",
          "GetModuleHandleA",
          "GetProcessHeap",
          "HeapAlloc",
          "HeapFree",
          "TerminateProcess",
          "lstrcatA",
          "DialogBoxParamA",
          "EndDialog",
          "KillTimer",
          "MessageBoxIndirectA",
          "SetTimer",
          "ShowWindow",
          "ShellExecuteExA"
        ],
        "ms": {
          "pe": {
            "machine": 332.0,
            "checksum": 13075.0,
            "rsrc_size": 1536.0,
            "subsystem": 2.0,
            "timestamp": 1323089610.0,
            "image_base": 4194304.0,
            "rsrc_entropy": 2.61,
            "entry_section": "",
            "size_of_image": 25088.0,
            "timestamp_day": 5.0,
            "file_alignment": 512.0,
            "resource_count": 2.0,
            "resource_types": [
              "RT_DIALOG",
              "RT_VERSION"
            ],
            "timestamp_year": 2011.0,
            "characteristics": 271.0,
            "entry_point_rva": 24576.0,
            "size_of_headers": 1024.0,
            "timestamp_month": 12.0,
            "checksum_present": true,
            "export_timestamp": 0.0,
            "import_dll_count": 3.0,
            "checksum_mismatch": true,
            "computed_checksum": 12815.0,
            "section_alignment": 4096.0,
            "number_of_sections": 5.0,
            "resource_timestamp": 1323089610.0,
            "dll_characteristics": 256.0,
            "linker_major_version": 1.0,
            "linker_minor_version": 69.0,
            "version_info_present": true,
            "resource_timestamp_day": 5.0,
            "resource_timestamp_year": 2011.0,
            "export_timestamp_present": false,
            "resource_timestamp_month": 12.0,
            "resource_timestamp_present": true,
            "entry_in_nonstandard_section": true
          },
          "file": {
            "size": 6144.0
          },
          "binary": {
            "code_size": 2560.0,
            "func_count": 5.0,
            "entry_point": 24576.0,
            "code_entropy": 2.68,
            "data_entropy": 1.3,
            "func_density": 2.0,
            "import_count": 17.0,
            "string_count": 52.0,
            "avg_func_size": 153.0,
            "section_count": 5.0,
            "avg_complexity": 6.4,
            "import_density": 6.8,
            "max_complexity": 14.0,
            "string_density": 20.8,
            "overall_entropy": 2.11,
            "avg_basic_blocks": 10.6,
            "avg_section_size": 1024.0,
            "dependency_count": 3.0,
            "entropy_variance": 1.84,
            "avg_string_length": 23.94,
            "complexity_per_kb": 2.56,
            "max_string_length": 378.0,
            "wide_string_count": 18.0,
            "writable_sections": 2.0,
            "avg_string_entropy": 3.28,
            "code_to_data_ratio": 1.0,
            "entry_point_is_rva": true,
            "rsrc_to_file_ratio": 0.25,
            "total_basic_blocks": 53.0,
            "executable_sections": 2.0,
            "func_analysis_depth": 2.0,
            "string_length_stddev": 50.78,
            "largest_section_ratio": 0.33,
            "sentence_string_count": 11.0,
            "sentence_string_ratio": 0.21,
            "behavioral_import_ratio": 0.06,
            "entry_in_nonstandard_section": true,
            "nonstandard_section_name_count": 2.0
          }
        },
        "ss": [
          [
            77,
            "!This program cannot be run in DOS mode."
          ],
          [
            376,
            ".data"
          ],
          [
            416,
            ".code"
          ],
          [
            496,
            ".rsrc"
          ],
          [
            1894,
            "SRV1"
          ],
          [
            2227,
            "Delayed Start"
          ],
          [
            2241,
            "Delayed Start 1.3\r\n\r\nCopyright (C) ManHunter / PCL\r\nhttp://www.manhunter.ru\r\n\r\n----------------------------------------\r\nUsage: "
          ],
          [
            2262,
            "Copyright (C) ManHunter / PCL"
          ],
          [
            2293,
            "http://www.manhunter.ru"
          ],
          [
            2417,
            "-t - time delay for NNN seconds"
          ],
          [
            2452,
            "-k - terminate process after NNN seconds"
          ],
          [
            2496,
            "-w - hide application window"
          ],
          [
            2528,
            "-s - suppress error messages if an error occurs"
          ],
          [
            2579,
            "path [params] - full path to application"
          ],
          [
            3152,
            "kernel32.dll"
          ],
          [
            3166,
            "user32.dll"
          ],
          [
            3178,
            "shell32.dll"
          ],
          [
            3282,
            "ExitProcess"
          ],
          [
            3296,
            "GetCommandLineA"
          ],
          [
            3314,
            "GetCurrentDirectoryA"
          ],
          [
            3338,
            "GetExitCodeProcess"
          ],
          [
            3360,
            "GetModuleHandleA"
          ],
          [
            3380,
            "GetProcessHeap"
          ],
          [
            3398,
            "HeapAlloc"
          ],
          [
            3410,
            "HeapFree"
          ],
          [
            3422,
            "TerminateProcess"
          ],
          [
            3442,
            "lstrcatA"
          ],
          [
            3510,
            "DialogBoxParamA"
          ],
          [
            3528,
            "EndDialog"
          ],
          [
            3540,
            "KillTimer"
          ],
          [
            3552,
            "MessageBoxIndirectA"
          ],
          [
            3574,
            "SetTimer"
          ],
          [
            3586,
            "ShowWindow"
          ],
          [
            3618,
            "ShellExecuteExA"
          ],
          [
            4278,
            "wide",
            "Delayed Start"
          ],
          [
            4306,
            "wide",
            "Verdana"
          ],
          [
            4330,
            "wide",
            "VS_VERSION_INFO"
          ],
          [
            4422,
            "wide",
            "StringFileInfo"
          ],
          [
            4482,
            "wide",
            "CompanyName"
          ],
          [
            4508,
            "wide",
            "Microsoft® Windows® Operating System"
          ],
          [
            4590,
            "wide",
            "FileDescription"
          ],
          [
            4624,
            "wide",
            "Generic Host Process for Win32 Services"
          ],
          [
            4710,
            "wide",
            "FileVersion"
          ],
          [
            4758,
            "wide",
            "InternalName"
          ],
          [
            4784,
            "wide",
            "apsql.exe"
          ],
          [
            4810,
            "wide",
            "LegalCopyright"
          ],
          [
            4840,
            "wide",
            "Microsoft Corporation. All rights reserved."
          ],
          [
            4934,
            "wide",
            "OriginalFilename"
          ],
          [
            4994,
            "wide",
            "ProductName"
          ],
          [
            5102,
            "wide",
            "ProductVersion"
          ],
          [
            5154,
            "wide",
            "VarFileInfo"
          ],
          [
            5186,
            "wide",
            "Translation"
          ]
        ],
        "sz": 6144,
        "ts": [
          {
            "c": 0.699999988079071,
            "d": "Destroy window timer",
            "e": [
              "KillTimer"
            ],
            "i": "micro-behaviors/ui/window/manage/control::kill-timer",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE standard code/data section",
            "e": [
              ".code",
              ".data"
            ],
            "i": "metadata/binary/section/names::pe-code-data-standard-section",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Microsoft vendor marker in resource section",
            "e": [
              "Microsoft Corporation"
            ],
            "i": "metadata/binary/vendor::microsoft-corp-marker-rsrc",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Five section PE layout",
            "e": [
              "binary.section_count = 5.00"
            ],
            "i": "metadata/binary/section/metrics::five-section-pe",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "String claiming to be Microsoft Corporation",
            "e": [
              "Microsoft Corporation"
            ],
            "i": "objectives/evasion/masquerade/identity/vendor::microsoft-corporation-string",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary is not position-independent (fixed load address)",
            "e": [
              "binary.is_pie = 0.00"
            ],
            "i": "metadata/hardening/layout::no-pie",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Tiny PE stub footprint",
            "e": [
              "miterINST.exe"
            ],
            "i": "well-known/malware/trojan/shellobject/revengerat::tiny-pe-footprint",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "PE InternalName metadata field",
            "e": [
              "InternalName"
            ],
            "i": "metadata/package/versioning::pe-internalname-field",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Heap memory deallocation",
            "e": [
              "HeapFree"
            ],
            "i": "micro-behaviors/mem/alloc/heap::heap-free",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Binary has low overall entropy",
            "e": [
              "binary.overall_entropy = 2.11"
            ],
            "i": "metadata/binary/metrics/threshold::low-overall-entropy-binary",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Get module handle ANSI",
            "e": [
              "GetModuleHandleA"
            ],
            "i": "micro-behaviors/os/module/load::get-module-handle-ansi",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Exit current process",
            "e": [
              "ExitProcess"
            ],
            "i": "micro-behaviors/process/terminate/kill::exit-process",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE file uses .exe extension",
            "e": [
              "miterINST.exe"
            ],
            "i": "metadata/binary/framework::exe-extension",
            "l": 1
          },
          {
            "c": 0.9599999785423279,
            "d": "Generic Host Process description",
            "e": [
              "Generic Host Process for Win32 Services"
            ],
            "i": "objectives/evasion/masquerade/version-resource/service-host::service-host-file-description",
            "l": 1
          },
          {
            "c": 0.75,
            "d": "Binary exports no symbols",
            "e": [
              "binary.export_count = 0.00"
            ],
            "i": "metadata/binary/symbols/exports::no-exports",
            "l": 1
          },
          {
            "c": 0.8799999952316284,
            "d": "Sparse function count stub",
            "e": [
              "binary.func_count = 5.00"
            ],
            "i": "well-known/malware/trojan/shellobject/revengerat::sparse-function-stub",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "Process termination via TerminateProcess",
            "e": [
              "TerminateProcess"
            ],
            "i": "micro-behaviors/process/terminate/kill::terminate-process",
            "l": 3,
            "m": "B0033"
          },
          {
            "a": "T1070.006",
            "c": 0.699999988079071,
            "d": "PE header compile timestamp predates 2025",
            "e": [
              "pe.timestamp = 1323089610.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::header-timestamp-pre-2025",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Binary has many sentence-like strings",
            "e": [
              "binary.sentence_string_ratio = 0.21"
            ],
            "i": "metadata/binary/metrics/threshold::rich-sentence-strings-20pct",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Get process heap handle",
            "e": [
              "GetProcessHeap"
            ],
            "i": "micro-behaviors/mem/alloc/heap::get-process-heap",
            "l": 2
          },
          {
            "c": 0.4000000059604645,
            "d": "Very few functions detected",
            "e": [
              "binary.func_count = 5.00"
            ],
            "i": "metadata/binary/metrics/structural::few-functions",
            "l": 3
          },
          {
            "c": 0.7599999904632568,
            "d": "PE entry in nonstandard section",
            "e": [
              "binary.entry_in_nonstandard_section = 1.00"
            ],
            "i": "metadata/binary/section/metrics::pe-nonstandard-entry",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Get process exit code",
            "e": [
              "GetExitCodeProcess"
            ],
            "i": "micro-behaviors/process/create/spawn::get-exit-code-process",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE ProductName metadata field",
            "e": [
              "ProductName"
            ],
            "i": "metadata/package/versioning::pe-productname-field",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Read current working directory",
            "e": [
              "GetCurrentDirectoryA"
            ],
            "i": "micro-behaviors/fs/traversal/drives::get-current-directory",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Show or hide window",
            "e": [
              "ShowWindow"
            ],
            "i": "micro-behaviors/ui/window/manage/control::show-window",
            "l": 2
          },
          {
            "a": "T1027.007",
            "c": 1.0,
            "d": "WININET.DLL absent from PE import table",
            "e": [
              "pe.import_dll_count = 3.00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::wininet-import-absent",
            "l": 2,
            "m": "B0032"
          },
          {
            "c": 1.0,
            "d": "Microsoft Corporation in resource section",
            "e": [
              "Microsoft Corporation. All rights reserved."
            ],
            "i": "well-known/malware/trojan/loader-s047t5g::microsoft-corp-resource",
            "l": 1
          },
          {
            "a": "T1055",
            "c": 0.9200000166893005,
            "d": "Regex component marker",
            "e": [
              "binary.import_count = 17.00"
            ],
            "i": "objectives/evasion/process/injection/vb6::vb6-process-injection-pattern-cond-1--inline-17571",
            "l": 1,
            "m": "C0041"
          },
          {
            "d": "hide keyword",
            "e": [
              "hide"
            ],
            "i": "micro-behaviors/data/text/keywords/lexicon::hide",
            "l": 1
          },
          {
            "c": 0.8799999952316284,
            "d": "Small string table footprint",
            "e": [
              "binary.string_count = 52.00"
            ],
            "i": "well-known/malware/trojan/shellobject/revengerat::tiny-string-table",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Heap memory allocation",
            "e": [
              "HeapAlloc"
            ],
            "i": "micro-behaviors/mem/alloc/heap::heap-alloc",
            "l": 2
          },
          {
            "c": 0.6499999761581421,
            "d": "Close dialog and return result",
            "e": [
              "EndDialog"
            ],
            "i": "micro-behaviors/ui/dialog/prompt::end-dialog",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Regex component marker",
            "e": [
              "StringFileInfo"
            ],
            "i": "micro-behaviors/communications/http/client/managed::webclient--rx-7",
            "l": 1
          },
          {
            "c": 0.8199999928474426,
            "d": "Query current process command line",
            "e": [
              "GetCommandLineA"
            ],
            "i": "micro-behaviors/process/info/commandline::get-command-line",
            "l": 2
          },
          {
            "a": "T1140",
            "c": 0.8999999761581421,
            "d": "Microsoft company string",
            "e": [
              "Microsoft Corporation. All rights reserved."
            ],
            "i": "objectives/command-and-control/dropper/staging/encrypted::microsoft-company-string",
            "l": 1,
            "m": "B0023"
          },
          {
            "c": 0.699999988079071,
            "d": "Create modal dialog box (ANSI)",
            "e": [
              "DialogBoxParamA"
            ],
            "i": "micro-behaviors/ui/dialog/prompt::dialog-box-param-a",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Tiny writable data section",
            "e": [
              ".data (size: 0)"
            ],
            "i": "metadata/binary/section/metrics::tiny-data-section",
            "l": 1
          },
          {
            "c": 0.6000000238418579,
            "d": "Copyright notice",
            "e": [
              "Copyright"
            ],
            "i": "metadata/package/license::copyright-word",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE resource section",
            "e": [
              ".rsrc"
            ],
            "i": "metadata/binary/section/names::pe-resource-section",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "PE has low overall entropy",
            "e": [
              "binary.overall_entropy = 2.11"
            ],
            "i": "metadata/binary/layout::low-overall-entropy",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Create window timer",
            "e": [
              "SetTimer"
            ],
            "i": "micro-behaviors/ui/window/manage/control::set-timer",
            "l": 2
          },
          {
            "d": ".dll extension reference",
            "e": [
              ".dll"
            ],
            "i": "micro-behaviors/fs/path/extension::dll-dup",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Tiny PE by file size",
            "e": [
              "pe.machine = 332.00"
            ],
            "i": "metadata/binary/metrics/size::tiny-pe",
            "l": 3
          },
          {
            "c": 0.699999988079071,
            "d": "PE CompanyName metadata field",
            "e": [
              "CompanyName"
            ],
            "i": "metadata/package/versioning::pe-companyname-field",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE FileDescription metadata field",
            "e": [
              "FileDescription"
            ],
            "i": "metadata/package/versioning::pe-filedescription-field",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has low average string entropy",
            "e": [
              "binary.avg_string_entropy = 3.28"
            ],
            "i": "metadata/binary/metrics/threshold::avg-string-entropy-4-max",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has low average complexity",
            "e": [
              "binary.avg_complexity = 6.40"
            ],
            "i": "metadata/binary/metrics/threshold::avg-complexity-15-max",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Small PE resource section",
            "e": [
              "pe.rsrc_size = 1536.00"
            ],
            "i": "metadata/package/versioning::pe-small-rsrc",
            "l": 1
          },
          {
            "a": "T1036.005",
            "c": 0.9700000286102295,
            "d": "Windows operating system product string",
            "e": [
              "Microsoft® Windows® Operating System"
            ],
            "i": "objectives/evasion/masquerade/version-resource/claim::getmac-product-string",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Dense PE import table references",
            "e": [
              "binary.import_density = 6.80"
            ],
            "i": "metadata/binary/metrics/structural::high-import-density",
            "l": 3
          },
          {
            "a": "T1027",
            "c": 0.9900000095367432,
            "d": "PE version resource text",
            "e": [
              "VS_VERSION_INFO"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::anydesk-version-info",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 1.0,
            "d": "File is a compiled binary",
            "e": [
              "miterINST.exe"
            ],
            "i": "metadata/binary/framework::is-binary",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE mapped image under 768 KiB",
            "e": [
              "pe.size_of_image = 25088.00"
            ],
            "i": "metadata/binary/layout::image-under-768kb",
            "l": 1
          },
          {
            "a": "T1027.003",
            "c": 0.9900000095367432,
            "d": "PE checksum mismatch",
            "e": [
              "pe.checksum_mismatch = 1.00"
            ],
            "i": "objectives/anti-static/obfuscation/payload/container::pe-checksum-mismatch-png",
            "l": 1,
            "m": "F0001.006"
          },
          {
            "c": 1.0,
            "d": "PE has exactly two resource entries",
            "e": [
              "pe.resource_count = 2.00"
            ],
            "i": "metadata/binary/resource::pe-resource-count-two",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE OriginalFilename metadata field",
            "e": [
              "OriginalFilename"
            ],
            "i": "metadata/package/versioning::pe-originalfilename-field",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 3+ functions",
            "e": [
              "binary.func_count = 5.00"
            ],
            "i": "metadata/binary/metrics/threshold::few-functions-3",
            "l": 1
          },
          {
            "a": "T1059.003",
            "c": 0.8999999761581421,
            "d": "ShellExecuteExA ANSI extended API",
            "e": [
              "ShellExecuteExA"
            ],
            "i": "micro-behaviors/process/create/system::shell-execute-ex-a",
            "l": 3,
            "m": "E1059.003"
          },
          {
            "a": "T1036.005",
            "c": 0.8999999761581421,
            "d": "Microsoft company string",
            "e": [
              "Microsoft Corporation. All rights reserved."
            ],
            "i": "objectives/evasion/masquerade/dll/task-scheduler::microsoft-company-string",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "ASLR bit not set in DLL Characteristics",
            "e": [
              "pe.dll_characteristics = 256.00"
            ],
            "i": "metadata/hardening/mitigation::no-aslr-bit",
            "l": 1
          },
          {
            "a": "T1070.006",
            "c": 0.8999999761581421,
            "d": "Export timestamp is absent",
            "e": [
              "pe.export_timestamp_present = 0.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::export-timestamp-absent",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.800000011920929,
            "d": "Few PE resource entries (no DIALOG/MENU/STRINGTABLE)",
            "e": [
              "pe.resource_count = 2.00"
            ],
            "i": "objectives/evasion/anti-av/heuristic::minimal-pe-resources",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Compatibility alias",
            "e": [
              "ShellExecuteExA"
            ],
            "i": "micro-behaviors/process/create/exec::shell-execute-ex-a",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Five or more PE sections",
            "e": [
              "binary.section_count = 5.00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::five-plus-sections-pe",
            "l": 1
          },
          {
            "a": "T1027.007",
            "c": 0.8999999761581421,
            "d": "Kernel32 DLL resolution string",
            "e": [
              "kernel32.dll"
            ],
            "i": "micro-behaviors/os/api-resolution/manual::kernel32-resolver",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary is not digitally signed",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed/trust-level::unsigned",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Tiny C string section ratio",
            "e": [
              " = 0.0% of total (0 / 6144 bytes)"
            ],
            "i": "metadata/binary/section/metrics::tiny-cstring-section",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.8600000143051147,
            "d": "Long mixed-case identifiers cluster",
            "e": [
              "GetCurrentDirectoryA",
              "MessageBoxIndirectA"
            ],
            "i": "objectives/anti-static/obfuscation/string/junking::long-mixedcase-identifiers",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1027.007",
            "c": 0.800000011920929,
            "d": "DLL name strings without LoadLibrary import",
            "e": [
              "binary.import_count = 17.00"
            ],
            "i": "objectives/anti-static/obfuscation/string/runtime-decrypt::dll-names-no-loadlibrary",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "c": 0.8999999761581421,
            "d": "Browser process termination API",
            "e": [
              "TerminateProcess"
            ],
            "i": "objectives/collection/stealer/browser::windows-browser-terminate-api",
            "l": 1
          },
          {
            "d": ".exe extension reference",
            "e": [
              ".exe"
            ],
            "i": "micro-behaviors/fs/path/extension::exe-dup",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "Filename has EXE extension",
            "e": [
              "miterINST.exe"
            ],
            "i": "objectives/evasion/masquerade/file/double-ext::basename-is-exe",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Claims Microsoft Corp in version resource",
            "e": [
              "Microsoft Corporation."
            ],
            "i": "metadata/binary/vendor::microsoft-corp-versioninfo",
            "l": 1
          },
          {
            "a": "T1105",
            "c": 0.800000011920929,
            "d": "Compact PE import table",
            "e": [
              "binary.import_count = 17.00"
            ],
            "i": "objectives/command-and-control/dropper/delivery/download-execute::compact-import-table",
            "l": 1,
            "m": "E1105"
          },
          {
            "c": 0.949999988079071,
            "d": "Signed PE checksum mismatch",
            "e": [
              "pe.checksum_mismatch = 1.00"
            ],
            "i": "metadata/binary/layout::signed-pe-checksum-mismatch",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "PE checksum mismatch (modified binary)",
            "e": [
              "pe.checksum_mismatch = 1.00"
            ],
            "i": "metadata/binary/layout::pe-checksum-mismatch",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "PE executable is unsigned",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed/trust-level::unsigned-pe-executable",
            "l": 3
          },
          {
            "c": 0.949999988079071,
            "d": "links shell32.dll (ShellExecuteExA)",
            "e": [
              "shell32.dll"
            ],
            "i": "metadata/dylib::shell32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links user32.dll (DialogBoxParamA, EndDialog, KillTimer, MessageBoxIndirectA, SetTimer, ... +1 more)",
            "e": [
              "user32.dll"
            ],
            "i": "metadata/dylib::user32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links kernel32.dll (ExitProcess, GetCommandLineA, GetCurrentDirectoryA, GetExitCodeProcess, GetModuleHandleA, ... +5 more)",
            "e": [
              "kernel32.dll"
            ],
            "i": "metadata/dylib::kernel32/dll",
            "l": 2
          }
        ],
        "sha": "faba8fb6857a74c0b56cfe7ad26ec4a3ed182b21ffd09fe4f428d77dbc969ab4",
        "path": "502438!!miterINST.exe",
        "type": "pe"
      },
      {
        "f": "O₆(As₇C₃CoDyEr₃La)H₅(OsPo₂CmDbDs)Md₃(Bi₄SiPa)",
        "x": 8,
        "dp": 1,
        "id": 4,
        "is": [
          "CreateServiceA",
          "DeleteService",
          "OpenServiceA",
          "EnumServicesStatusA",
          "OpenSCManagerA",
          "CloseServiceHandle",
          "CreateFileA",
          "GetDriveTypeA",
          "lstrcmpiA",
          "lstrcpyA",
          "lstrlenA",
          "GetLastError",
          "GetCommandLineA",
          "GetVersion",
          "ExitProcess",
          "TerminateProcess",
          "GetCurrentProcess",
          "RtlUnwind",
          "UnhandledExceptionFilter",
          "GetModuleFileNameA",
          "FreeEnvironmentStringsA",
          "MultiByteToWideChar",
          "GetEnvironmentStrings",
          "FreeEnvironmentStringsW",
          "GetEnvironmentStringsW",
          "WideCharToMultiByte",
          "GetCPInfo",
          "GetACP",
          "GetOEMCP",
          "SetHandleCount",
          "GetFileType",
          "GetStdHandle",
          "GetStartupInfoA",
          "HeapDestroy",
          "HeapCreate",
          "VirtualFree",
          "WriteFile",
          "HeapFree",
          "HeapAlloc",
          "VirtualAlloc",
          "GetProcAddress",
          "LoadLibraryA",
          "LCMapStringA",
          "LCMapStringW",
          "FlushFileBuffers",
          "SetFilePointer",
          "GetStringTypeA",
          "GetStringTypeW",
          "SetStdHandle",
          "CloseHandle"
        ],
        "ms": {
          "pe": {
            "machine": 332.0,
            "checksum": 42245.0,
            "subsystem": 3.0,
            "timestamp": 841474940.0,
            "image_base": 16777216.0,
            "entry_section": ".text",
            "size_of_image": 49152.0,
            "timestamp_day": 31.0,
            "checksum_valid": true,
            "file_alignment": 512.0,
            "timestamp_year": 1996.0,
            "characteristics": 270.0,
            "entry_point_rva": 9744.0,
            "size_of_headers": 512.0,
            "timestamp_month": 8.0,
            "checksum_matches": true,
            "checksum_present": true,
            "export_timestamp": 0.0,
            "import_dll_count": 2.0,
            "computed_checksum": 42245.0,
            "section_alignment": 4096.0,
            "number_of_sections": 3.0,
            "resource_timestamp": 0.0,
            "timestamp_pre_2000": true,
            "linker_major_version": 3.0,
            "linker_minor_version": 10.0,
            "api_hashing_indicators": 1.0,
            "export_timestamp_present": false,
            "resource_timestamp_present": false
          },
          "file": {
            "size": 37888.0
          },
          "binary": {
            "code_size": 26112.0,
            "func_count": 20.0,
            "entry_point": 9744.0,
            "code_entropy": 6.28,
            "data_entropy": 1.47,
            "func_density": 0.78,
            "import_count": 50.0,
            "string_count": 138.0,
            "avg_func_size": 674.8,
            "section_count": 3.0,
            "avg_complexity": 12.55,
            "import_density": 1.96,
            "max_complexity": 113.0,
            "string_density": 5.41,
            "overall_entropy": 4.33,
            "avg_basic_blocks": 18.5,
            "avg_section_size": 11264.0,
            "dependency_count": 2.0,
            "entropy_variance": 2.07,
            "avg_string_length": 22.68,
            "complexity_per_kb": 0.49,
            "max_string_length": 76.0,
            "wide_string_count": 24.0,
            "writable_sections": 1.0,
            "avg_string_entropy": 3.35,
            "code_to_data_ratio": 3.4,
            "data_to_file_ratio": 0.15,
            "entry_point_is_rva": true,
            "text_to_file_ratio": 0.69,
            "total_basic_blocks": 370.0,
            "executable_sections": 1.0,
            "func_analysis_depth": 2.0,
            "string_length_stddev": 16.48,
            "high_complexity_funcs": 1.0,
            "largest_section_ratio": 0.69,
            "sentence_string_count": 53.0,
            "sentence_string_ratio": 0.38,
            "behavioral_import_ratio": 0.06
          }
        },
        "ss": [
          [
            77,
            "!This program cannot be run in DOS mode."
          ],
          [
            376,
            ".text"
          ],
          [
            456,
            ".reloc"
          ],
          [
            4304,
            "wide",
            "for its Security Context."
          ],
          [
            4360,
            "wide",
            "Password that this newly installed service will use"
          ],
          [
            4468,
            "wide",
            "the Services applet to change the Account Name and"
          ],
          [
            4572,
            "wide",
            "Make sure that you go into the Control Panel and use"
          ],
          [
            4680,
            "wide",
            "The service was successfuly added!"
          ],
          [
            4756,
            "%s: Error %d from %s on line %d"
          ],
          [
            4792,
            "g:\\ntrk\\source\\instsrv\\instsrv.c"
          ],
          [
            4828,
            "CreateService"
          ],
          [
            4844,
            "Name:  %s;  Password:  %s"
          ],
          [
            5008,
            "DeleteService"
          ],
          [
            5024,
            "OpenService"
          ],
          [
            5034,
            "wide",
            "e\nThe service does not exits, so it cannot be removed."
          ],
          [
            5148,
            "wide",
            "Panel's services applet."
          ],
          [
            5204,
            "wide",
            "To stop this service, use the Stop button in the Control"
          ],
          [
            5324,
            "wide",
            "can be removed."
          ],
          [
            5360,
            "wide",
            "This service is still active.  It must be stopped before it"
          ],
          [
            5484,
            "EnumServicesStatus"
          ],
          [
            5504,
            "OpenSCManager"
          ],
          [
            5520,
            "remove"
          ],
          [
            5528,
            "wide",
            "The service name cannot be longer than %d characters"
          ],
          [
            5644,
            "wide",
            "Remove service example:\n\n    INSTSRV MyService REMOVE"
          ],
          [
            5928,
            "wide",
            "Install service example:\n\n    INSTSRV MyService C:\\MyDir\\DiskService.Exe"
          ],
          [
            6084,
            "wide",
            "[-a \u003cAccount Name\u003e] [-p \u003cAccount Password\u003e]"
          ],
          [
            6180,
            "wide",
            "INSTSRV \u003cservice name\u003e (\u003cexe location\u003e | REMOVE)"
          ],
          [
            6284,
            "wide",
            "Installs and removes system services from NT"
          ],
          [
            6388,
            "runtime error"
          ],
          [
            6408,
            "TLOSS error"
          ],
          [
            6424,
            "SING error"
          ],
          [
            6440,
            "DOMAIN error"
          ],
          [
            6456,
            "R6028\r\n- unable to initialize heap"
          ],
          [
            6463,
            "- unable to initialize heap"
          ],
          [
            6496,
            "R6027\r\n- not enough space for lowio initialization"
          ],
          [
            6503,
            "- not enough space for lowio initialization"
          ],
          [
            6552,
            "R6026\r\n- not enough space for stdio initialization"
          ],
          [
            6559,
            "- not enough space for stdio initialization"
          ],
          [
            6608,
            "R6025\r\n- pure virtual function call"
          ],
          [
            6615,
            "- pure virtual function call"
          ],
          [
            6648,
            "R6024\r\n- not enough space for _onexit/atexit table"
          ],
          [
            6655,
            "- not enough space for _onexit/atexit table"
          ],
          [
            6704,
            "R6019\r\n- unable to open console device"
          ],
          [
            6711,
            "- unable to open console device"
          ],
          [
            6748,
            "R6018\r\n- unexpected heap error"
          ],
          [
            6755,
            "- unexpected heap error"
          ],
          [
            6784,
            "R6017\r\n- unexpected multithread lock error"
          ],
          [
            6791,
            "- unexpected multithread lock error"
          ],
          [
            6832,
            "R6016\r\n- not enough space for thread data"
          ],
          [
            6839,
            "- not enough space for thread data"
          ],
          [
            6876,
            "abnormal program termination"
          ],
          [
            6912,
            "R6009\r\n- not enough space for environment"
          ],
          [
            6919,
            "- not enough space for environment"
          ],
          [
            6956,
            "R6008\r\n- not enough space for arguments"
          ],
          [
            6963,
            "- not enough space for arguments"
          ],
          [
            7000,
            "R6002\r\n- floating point not loaded"
          ],
          [
            7007,
            "- floating point not loaded"
          ],
          [
            7040,
            "Microsoft Visual C++ Runtime Library"
          ],
          [
            7084,
            "Runtime Error!\n\nProgram:"
          ],
          [
            7116,
            "\u003cprogram name unknown\u003e"
          ],
          [
            7140,
            "wide",
            "(null)"
          ],
          [
            7156,
            "(null)"
          ],
          [
            7209,
            "700WP"
          ],
          [
            7225,
            "`h````"
          ],
          [
            7260,
            "GetLastActivePopup"
          ],
          [
            7280,
            "GetActiveWindow"
          ],
          [
            7296,
            "MessageBoxA"
          ],
          [
            7308,
            "user32.dll"
          ],
          [
            11369,
            "SVW3"
          ],
          [
            12647,
            "SVWUP"
          ],
          [
            13914,
            "SVWU"
          ],
          [
            14213,
            "VWU9"
          ],
          [
            14673,
            "IQRV"
          ],
          [
            16631,
            "WRQP"
          ],
          [
            17314,
            "PQWR"
          ],
          [
            23070,
            "PQRV"
          ],
          [
            25572,
            "VRPQ"
          ],
          [
            25716,
            "USPQ"
          ],
          [
            25768,
            "PUSQR"
          ],
          [
            25843,
            "WUSPQ"
          ],
          [
            27803,
            "PSQR"
          ],
          [
            29186,
            "CloseServiceHandle"
          ],
          [
            29208,
            "CreateServiceA"
          ],
          [
            29242,
            "OpenServiceA"
          ],
          [
            29258,
            "EnumServicesStatusA"
          ],
          [
            29280,
            "OpenSCManagerA"
          ],
          [
            29296,
            "ADVAPI32.dll"
          ],
          [
            29312,
            "GetLastError"
          ],
          [
            29328,
            "CreateFileA"
          ],
          [
            29342,
            "GetDriveTypeA"
          ],
          [
            29358,
            "lstrcmpiA"
          ],
          [
            29370,
            "lstrcpyA"
          ],
          [
            29382,
            "lstrlenA"
          ],
          [
            29394,
            "GetCommandLineA"
          ],
          [
            29412,
            "GetVersion"
          ],
          [
            29426,
            "ExitProcess"
          ],
          [
            29440,
            "TerminateProcess"
          ],
          [
            29460,
            "GetCurrentProcess"
          ],
          [
            29480,
            "RtlUnwind"
          ],
          [
            29492,
            "UnhandledExceptionFilter"
          ],
          [
            29520,
            "GetModuleFileNameA"
          ],
          [
            29542,
            "FreeEnvironmentStringsA"
          ],
          [
            29568,
            "MultiByteToWideChar"
          ],
          [
            29590,
            "GetEnvironmentStrings"
          ],
          [
            29614,
            "FreeEnvironmentStringsW"
          ],
          [
            29640,
            "GetEnvironmentStringsW"
          ],
          [
            29666,
            "WideCharToMultiByte"
          ],
          [
            29688,
            "GetCPInfo"
          ],
          [
            29710,
            "GetOEMCP"
          ],
          [
            29722,
            "SetHandleCount"
          ],
          [
            29740,
            "GetFileType"
          ],
          [
            29754,
            "GetStdHandle"
          ],
          [
            29770,
            "GetStartupInfoA"
          ],
          [
            29788,
            "HeapDestroy"
          ],
          [
            29802,
            "HeapCreate"
          ],
          [
            29816,
            "VirtualFree"
          ],
          [
            29830,
            "WriteFile"
          ],
          [
            29842,
            "HeapFree"
          ],
          [
            29854,
            "HeapAlloc"
          ],
          [
            29866,
            "VirtualAlloc"
          ],
          [
            29882,
            "GetProcAddress"
          ],
          [
            29900,
            "LoadLibraryA"
          ],
          [
            29916,
            "LCMapStringA"
          ],
          [
            29932,
            "LCMapStringW"
          ],
          [
            29948,
            "FlushFileBuffers"
          ],
          [
            29968,
            "SetFilePointer"
          ],
          [
            29986,
            "GetStringTypeA"
          ],
          [
            30004,
            "GetStringTypeW"
          ],
          [
            30022,
            "SetStdHandle"
          ],
          [
            30038,
            "CloseHandle"
          ],
          [
            30050,
            "KERNEL32.dll"
          ],
          [
            30256,
            "wide",
            "You are not authorized to do this - please contact your system Administrator"
          ],
          [
            30416,
            "wide",
            "- The fully qualified path to the .EXE must be given"
          ],
          [
            30528,
            "wide",
            "- The executable must be on a fixed disk (e.g., not a net drive)"
          ],
          [
            30664,
            "wide",
            "Unable to find the file at the given path."
          ],
          [
            30752,
            "wide",
            "This service has already been started!"
          ],
          [
            30832,
            "wide",
            "The account name does not exist."
          ],
          [
            30904,
            "wide",
            "The specified name is invalid."
          ]
        ],
        "sz": 37888,
        "ts": [
          {
            "c": 0.8999999761581421,
            "d": "PE standard runtime section",
            "e": [
              ".reloc"
            ],
            "i": "metadata/binary/section/names::pe-runtime-standard-section",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE standard code/data section",
            "e": [
              ".text",
              ".data"
            ],
            "i": "metadata/binary/section/names::pe-code-data-standard-section",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 4 or fewer sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "objectives/command-and-control/infrastructure/config::max-sections-4",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary is not position-independent (fixed load address)",
            "e": [
              "binary.is_pie = 0.00"
            ],
            "i": "metadata/hardening/layout::no-pie",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Heap memory deallocation",
            "e": [
              "HeapFree"
            ],
            "i": "micro-behaviors/mem/alloc/heap::heap-free",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Binary has low overall entropy",
            "e": [
              "binary.overall_entropy = 4.33"
            ],
            "i": "metadata/binary/metrics/threshold::low-overall-entropy-binary",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Close handle",
            "e": [
              "CloseHandle"
            ],
            "i": "micro-behaviors/process/create/spawn::close-handle-dup",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE has few sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "metadata/binary/layout::legacy-few-sections",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Call to GetDriveTypeA by raw bytes",
            "e": [
              "GetDriveTypeA"
            ],
            "i": "micro-behaviors/fs/traversal/drives::get-drive-type-raw",
            "l": 1
          },
          {
            "a": "T1543.003",
            "c": 0.949999988079071,
            "d": "Program can create Windows services",
            "e": [
              "CreateServiceA"
            ],
            "i": "micro-behaviors/os/service/control::create-service-import",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Exit current process",
            "e": [
              "ExitProcess"
            ],
            "i": "micro-behaviors/process/terminate/kill::exit-process",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.699999988079071,
            "d": "Code section dominates file layout",
            "e": [
              "binary.largest_section_ratio = 0.69"
            ],
            "i": "objectives/anti-static/obfuscation/string/anomaly::dominant-text-section",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.8999999761581421,
            "d": "Get file handle type",
            "e": [
              "GetFileType"
            ],
            "i": "micro-behaviors/fs/file/handle::get-file-type",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Get system error code",
            "e": [
              "GetLastError"
            ],
            "i": "micro-behaviors/os/exception/error-handling::get-last-error",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Get current process handle",
            "e": [
              "GetCurrentProcess"
            ],
            "i": "micro-behaviors/os/module/load::get-current-process",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 25+ imports",
            "e": [
              "binary.import_count = 50.00"
            ],
            "i": "metadata/binary/metrics/threshold::many-imports-25",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE file uses .exe extension",
            "e": [
              "instsrv.exe"
            ],
            "i": "metadata/binary/framework::exe-extension",
            "l": 1
          },
          {
            "a": "T1083",
            "c": 0.8999999761581421,
            "d": "Query drive type by symbol",
            "e": [
              "GetDriveTypeA"
            ],
            "i": "micro-behaviors/fs/traversal/drives::get-drive-type",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Set file position",
            "e": [
              "SetFilePointer"
            ],
            "i": "micro-behaviors/fs/file/handle::set-file-pointer",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 50+ imports",
            "e": [
              "binary.import_count = 50.00"
            ],
            "i": "metadata/binary/metrics/threshold::many-imports-50",
            "l": 1
          },
          {
            "c": 0.75,
            "d": "Binary exports no symbols",
            "e": [
              "binary.export_count = 0.00"
            ],
            "i": "metadata/binary/symbols/exports::no-exports",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "Process termination via TerminateProcess",
            "e": [
              "TerminateProcess"
            ],
            "i": "micro-behaviors/process/terminate/kill::terminate-process",
            "l": 3,
            "m": "B0033"
          },
          {
            "a": "T1070.006",
            "c": 0.699999988079071,
            "d": "PE header compile timestamp predates 2025",
            "e": [
              "pe.timestamp = 841474940.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::header-timestamp-pre-2025",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Binary has many sentence-like strings",
            "e": [
              "binary.sentence_string_ratio = 0.38"
            ],
            "i": "metadata/binary/metrics/threshold::rich-sentence-strings-20pct",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Set standard I/O handle",
            "e": [
              "SetStdHandle"
            ],
            "i": "micro-behaviors/fs/file/handle::set-std-handle",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Get standard I/O handle",
            "e": [
              "GetStdHandle"
            ],
            "i": "micro-behaviors/fs/file/handle::get-std-handle",
            "l": 2
          },
          {
            "a": "T1027.007",
            "c": 1.0,
            "d": "WININET.DLL absent from PE import table",
            "e": [
              "pe.import_dll_count = 2.00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::wininet-import-absent",
            "l": 2,
            "m": "B0032"
          },
          {
            "a": "T1543.003",
            "c": 0.9300000071525574,
            "d": "Program can open Windows services",
            "e": [
              "OpenServiceA"
            ],
            "i": "micro-behaviors/os/service/control::open-service-import",
            "l": 3
          },
          {
            "c": 0.699999988079071,
            "d": "Encoded HTML tag fragment",
            "e": [
              "[-a \u003cAccount Name\u003e] [-p \u003cAccount Password\u003e]",
              "INSTSRV \u003cservice name\u003e (\u003cexe location\u003e | REMOVE)"
            ],
            "i": "objectives/anti-static/obfuscation/encoding/content::encoded-html-tag-fragment",
            "l": 1
          },
          {
            "c": 0.8399999737739563,
            "d": "Read wide environment block",
            "e": [
              "GetEnvironmentStringsW"
            ],
            "i": "micro-behaviors/os/env/access::get-environment-strings-wide",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "LoadLibrary symbol",
            "e": [
              "LoadLibraryA"
            ],
            "i": "objectives/anti-static/obfuscation/reflection/class::loadlibrary-sym",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE .reloc section presence",
            "e": [
              ".reloc"
            ],
            "i": "metadata/binary/section/names::reloc-section-presence",
            "l": 2
          },
          {
            "a": "T1055",
            "c": 0.9200000166893005,
            "d": "Regex component marker",
            "e": [
              "binary.import_count = 50.00"
            ],
            "i": "objectives/evasion/process/injection/vb6::vb6-process-injection-pattern-cond-1--inline-17571",
            "l": 1,
            "m": "C0041"
          },
          {
            "c": 0.8999999761581421,
            "d": "Flush file buffer to disk",
            "e": [
              "FlushFileBuffers"
            ],
            "i": "micro-behaviors/fs/file/handle::flush-file-buffers",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Heap memory allocation",
            "e": [
              "HeapAlloc"
            ],
            "i": "micro-behaviors/mem/alloc/heap::heap-alloc",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Release wide environment block",
            "e": [
              "FreeEnvironmentStringsW"
            ],
            "i": "micro-behaviors/os/env/access::free-environment-strings-wide",
            "l": 2
          },
          {
            "d": "password keyword",
            "e": [
              "Name:  %s;  Password:  %s",
              "[-a \u003cAccount Name\u003e] [-p \u003cAccount Password\u003e]",
              "Password that this newly installed service will use"
            ],
            "i": "micro-behaviors/data/text/keywords/lexicon::password",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Regex component marker",
            "e": [
              "GetStringTypeA",
              "LCMapStringW",
              "LCMapStringA",
              "GetEnvironmentStringsW",
              "FreeEnvironmentStringsA",
              "GetEnvironmentStrings",
              "FreeEnvironmentStringsW",
              "GetStringTypeW"
            ],
            "i": "micro-behaviors/communications/http/client/managed::webclient--rx-7",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Free virtual memory",
            "e": [
              "VirtualFree"
            ],
            "i": "micro-behaviors/mem/protect/modify::virtual-free",
            "l": 2
          },
          {
            "c": 0.8199999928474426,
            "d": "Query current process command line",
            "e": [
              "GetCommandLineA"
            ],
            "i": "micro-behaviors/process/info/commandline::get-command-line",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Tiny writable data section",
            "e": [
              ".data (size: 5632)"
            ],
            "i": "metadata/binary/section/metrics::tiny-data-section",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 30+ imports",
            "e": [
              "binary.import_count = 50.00"
            ],
            "i": "metadata/binary/metrics/threshold::many-imports-30",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Write data to file handle",
            "e": [
              "WriteFile"
            ],
            "i": "micro-behaviors/fs/file/write/direct::write-file",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE has low overall entropy",
            "e": [
              "binary.overall_entropy = 4.33"
            ],
            "i": "metadata/binary/layout::low-overall-entropy",
            "l": 2
          },
          {
            "d": ".dll extension reference",
            "e": [
              ".dll"
            ],
            "i": "micro-behaviors/fs/path/extension::dll-dup",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Get module file path (ANSI)",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/os/module/load::get-module-filename-ansi",
            "l": 2
          },
          {
            "c": 0.8399999737739563,
            "d": "Invoke unhandled exception filter",
            "e": [
              "UnhandledExceptionFilter"
            ],
            "i": "micro-behaviors/os/exception/error-handling::unhandled-exception-filter-import",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has low average string entropy",
            "e": [
              "binary.avg_string_entropy = 3.35"
            ],
            "i": "metadata/binary/metrics/threshold::avg-string-entropy-4-max",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Runtime library unwind operation",
            "e": [
              "RtlUnwind"
            ],
            "i": "micro-behaviors/os/exception/error-handling::rtl-unwind",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has low average complexity",
            "e": [
              "binary.avg_complexity = 12.55"
            ],
            "i": "metadata/binary/metrics/threshold::avg-complexity-15-max",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Microsoft Visual string",
            "e": [
              "Microsoft Visual C++ Runtime Library"
            ],
            "i": "metadata/lang/compiler/native::ms-visual",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "GetModuleFileName API call",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/process/info/current::get-module-filename",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.8399999737739563,
            "d": "VB6 PE with three sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "objectives/anti-static/obfuscation/payload/string-sparse::three-section-vb6-layout",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.800000011920929,
            "d": "Small PE resource section",
            "e": [
              "pe.rsrc_size = 0.00"
            ],
            "i": "metadata/package/versioning::pe-small-rsrc",
            "l": 1
          },
          {
            "a": "T1587.001",
            "c": 0.8999999761581421,
            "d": "Allocate virtual memory",
            "e": [
              "VirtualAlloc"
            ],
            "i": "micro-behaviors/mem/protect/modify::virtual-alloc",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Get environment strings",
            "e": [
              "GetEnvironmentStrings",
              "GetEnvironmentStringsW",
              "FreeEnvironmentStringsW"
            ],
            "i": "micro-behaviors/os/env/access::get-environment-strings",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 20+ imports",
            "e": [
              "binary.import_count = 50.00"
            ],
            "i": "metadata/binary/metrics/threshold::many-imports-20",
            "l": 1
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "LoadLibraryA loader API string",
            "e": [
              "LoadLibraryA"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-loadlibrarya-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "c": 0.699999988079071,
            "d": "Read startup info via GetStartupInfoA",
            "e": [
              "GetStartupInfoA"
            ],
            "i": "micro-behaviors/os/sysinfo/process::get-startup-info-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Windows file creation/open API",
            "e": [
              "CreateFileA"
            ],
            "i": "micro-behaviors/fs/file/open::file-create-win",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE has many readable strings",
            "e": [
              "binary.string_count = 138.00"
            ],
            "i": "metadata/binary/layout::many-readable-strings",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "File is a compiled binary",
            "e": [
              "instsrv.exe"
            ],
            "i": "metadata/binary/framework::is-binary",
            "l": 1
          },
          {
            "a": "T1543.003",
            "c": 0.949999988079071,
            "d": "Program opens service control manager",
            "e": [
              "OpenSCManagerA"
            ],
            "i": "micro-behaviors/os/service/control::open-sc-manager-import",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "PE mapped image under 768 KiB",
            "e": [
              "pe.size_of_image = 49152.00"
            ],
            "i": "metadata/binary/layout::image-under-768kb",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Query current module path",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/fs/path/check::get-module-filename",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Get Unicode character type",
            "e": [
              "GetStringTypeW"
            ],
            "i": "micro-behaviors/os/env/access::get-string-type-w",
            "l": 2
          },
          {
            "c": 0.8199999928474426,
            "d": "Regex component marker",
            "e": [
              "CloseServiceHandle",
              "CloseHandle"
            ],
            "i": "objectives/discovery/system/ics-environment/register::ics-register-flow-rate--rx-75",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 3+ functions",
            "e": [
              "binary.func_count = 20.00"
            ],
            "i": "metadata/binary/metrics/threshold::few-functions-3",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Unicode string locale mapping",
            "e": [
              "LCMapStringW"
            ],
            "i": "micro-behaviors/os/env/access::lcmap-string-w",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 40+ imports",
            "e": [
              "binary.import_count = 50.00"
            ],
            "i": "metadata/binary/metrics/threshold::many-imports-40",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Resolve exports with GetProcAddress",
            "e": [
              "GetProcAddress"
            ],
            "i": "micro-behaviors/os/module/load::get-proc-address-import",
            "l": 2
          },
          {
            "a": "T1070.006",
            "c": 0.8999999761581421,
            "d": "Export timestamp is absent",
            "e": [
              "pe.export_timestamp_present = 0.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::export-timestamp-absent",
            "l": 2
          },
          {
            "a": "T1070.006",
            "c": 0.7799999713897705,
            "d": "PE header timestamp predates 2000",
            "e": [
              "pe.timestamp_pre_2000 = 1.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::header-timestamp-pre-2000",
            "l": 1
          },
          {
            "a": "T1055",
            "c": 0.949999988079071,
            "d": "Huge null run in executable (128+ bytes)",
            "e": [
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00"
            ],
            "i": "objectives/anti-static/obfuscation/binary-structure::huge-null-run-text",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.800000011920929,
            "d": "Few PE resource entries (no DIALOG/MENU/STRINGTABLE)",
            "e": [
              "pe.resource_count = 0.00"
            ],
            "i": "objectives/evasion/anti-av/heuristic::minimal-pe-resources",
            "l": 1
          },
          {
            "a": "T1027.007",
            "c": 0.8600000143051147,
            "d": "PE API hashing indicator present",
            "e": [
              "pe.api_hashing_indicators = 1.00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::pe-api-hashing-indicator-single",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "c": 1.0,
            "d": "Binary is not digitally signed",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed/trust-level::unsigned",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "CreateFile API string reference",
            "e": [
              "CreateFile"
            ],
            "i": "micro-behaviors/fs/file/open::createfile-api",
            "l": 2
          },
          {
            "a": "T1574.002",
            "c": 0.8999999761581421,
            "d": "Hidden LoadLibraryA string reference",
            "e": [
              "LoadLibraryA"
            ],
            "i": "micro-behaviors/dylib/load/runtime::load-library-a-string-no-import",
            "l": 1
          },
          {
            "c": 0.6000000238418579,
            "d": "Very few sections (merged/stripped)",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "metadata/binary/metrics/structural::few-sections",
            "l": 3
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "GetProcAddress loader API string",
            "e": [
              "GetProcAddress"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-getprocaddress-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "c": 0.8999999761581421,
            "d": "Tiny C string section ratio",
            "e": [
              " = 0.0% of total (0 / 37888 bytes)"
            ],
            "i": "metadata/binary/section/metrics::tiny-cstring-section",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.8600000143051147,
            "d": "Long mixed-case identifiers cluster",
            "e": [
              "WideCharToMultiByte",
              "UnhandledExceptionFilter",
              "MultiByteToWideChar",
              "GetModuleFileNameA"
            ],
            "i": "objectives/anti-static/obfuscation/string/junking::long-mixedcase-identifiers",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "VirtualAlloc loader API string",
            "e": [
              "VirtualAlloc"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-virtualalloc-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "c": 0.8999999761581421,
            "d": "Browser process termination API",
            "e": [
              "TerminateProcess"
            ],
            "i": "objectives/collection/stealer/browser::windows-browser-terminate-api",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "Filename has EXE extension",
            "e": [
              "instsrv.exe"
            ],
            "i": "objectives/evasion/masquerade/file/double-ext::basename-is-exe",
            "l": 1
          },
          {
            "a": "T1055.001",
            "c": 0.949999988079071,
            "d": "References LoadLibraryA dynamic module loading",
            "e": [
              "LoadLibraryA"
            ],
            "i": "micro-behaviors/process/inject/dll::load-library-a-remote-resolution",
            "l": 3,
            "m": "F0003"
          },
          {
            "c": 0.800000011920929,
            "d": "Binary lacks resource section entirely",
            "e": [
              "binary.rsrc_to_file_ratio = 0.00"
            ],
            "i": "metadata/binary/resource::no-resources",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.8500000238418579,
            "d": "Open existing service handle",
            "e": [
              "OpenServiceA",
              "OpenService"
            ],
            "i": "micro-behaviors/os/service/control::open-service",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.8199999928474426,
            "d": "Packed loader largest section ratio above 0.65",
            "e": [
              "binary.largest_section_ratio = 0.69"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::packed-loader-largest-section-dominates",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1543.003",
            "c": 0.8399999737739563,
            "d": "Delete installed service",
            "e": [
              "DeleteService"
            ],
            "i": "micro-behaviors/os/service/control::delete-service",
            "l": 3
          },
          {
            "a": "T1543.003",
            "c": 0.8500000238418579,
            "d": "Create Windows service",
            "e": [
              "CreateService",
              "CreateServiceA"
            ],
            "i": "micro-behaviors/os/service/control::create-service",
            "l": 3
          },
          {
            "a": "T1105",
            "c": 0.800000011920929,
            "d": "Compact PE import table",
            "e": [
              "binary.import_count = 50.00"
            ],
            "i": "objectives/command-and-control/dropper/delivery/download-execute::compact-import-table",
            "l": 1,
            "m": "E1105"
          },
          {
            "c": 0.75,
            "d": "Inline password token in lure",
            "e": [
              "Password that this newly"
            ],
            "i": "objectives/lateral-movement/social-engineering/lures::inline-password-token",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Create private heap (HeapCreate)",
            "e": [
              "HeapCreate"
            ],
            "i": "micro-behaviors/mem/alloc/heap::heap-create",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.8500000238418579,
            "d": "Open service control manager",
            "e": [
              "OpenSCManager",
              "OpenSCManagerA"
            ],
            "i": "micro-behaviors/os/service/control::open-sc-manager",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.949999988079071,
            "d": "Regex component marker",
            "e": [
              "binary.largest_section_ratio = 0.69"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::packed-loader-data-geometry-cond-1--inline-29188",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.800000011920929,
            "d": "PE executable is unsigned",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed/trust-level::unsigned-pe-executable",
            "l": 3
          },
          {
            "c": 0.949999988079071,
            "d": "links ADVAPI32.dll (CreateServiceA, DeleteService, OpenServiceA, EnumServicesStatusA, OpenSCManagerA, ... +1 more)",
            "e": [
              "ADVAPI32.dll"
            ],
            "i": "metadata/dylib::advapi32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links KERNEL32.dll (CreateFileA, GetDriveTypeA, lstrcmpiA, lstrcpyA, lstrlenA, ... +39 more)",
            "e": [
              "KERNEL32.dll"
            ],
            "i": "metadata/dylib::kernel32/dll",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.9200000166893005,
            "d": "Service stop or delete chain",
            "e": [
              "OpenServiceA",
              "OpenSCManager",
              "OpenSCManagerA",
              "OpenService",
              "DeleteService"
            ],
            "i": "micro-behaviors/os/service/control::service-stop-control",
            "l": 3
          },
          {
            "c": 0.8799999952316284,
            "d": "Enumerate process environment block",
            "e": [
              "GetEnvironmentStringsW",
              "FreeEnvironmentStringsW"
            ],
            "i": "micro-behaviors/os/env/access::environment-block-enumeration",
            "l": 2
          }
        ],
        "sha": "9fe0f7f2c11f583dba91dc8e002f77f0c27ca4ce5c6e913b8d8b113084fd7e60",
        "path": "502438!!instsrv.exe",
        "type": "pe"
      },
      {
        "f": "O₄(ErC₂DyP)H(Po)",
        "x": 40,
        "dp": 1,
        "id": 5,
        "ms": {
          "file": {
            "size": 1293.0
          },
          "text": {
            "digit_ratio": 0.04,
            "space_count": 120.0,
            "total_lines": 29.0,
            "char_entropy": 5.26,
            "unique_chars": 64.0,
            "avg_line_length": 42.59,
            "max_line_length": 159.0,
            "empty_line_ratio": 0.28,
            "last_line_length": 4.0,
            "most_common_char": "e",
            "whitespace_ratio": 0.14,
            "most_common_ratio": 0.07,
            "line_length_stddev": 48.9,
            "max_inline_whitespace_run": 2.0
          }
        },
        "ss": [
          [
            0,
            "taskkill /f /im miter.exe"
          ],
          [
            27,
            "copy /y miterINST.exe miter.exe"
          ],
          [
            60,
            "instsrv.exe alark %windir%\\alark.exe"
          ],
          [
            98,
            "ping 127.0.0.1 -n 2"
          ],
          [
            123,
            "Reg Add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\alark\" /v \"Description\" /t REG_SZ /d \"Alarm service for default browser.\" /f"
          ],
          [
            251,
            "Reg Add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\alark\" /v \"DisplayName\" /t REG_SZ /d \"Alarm Key Service\" /f"
          ],
          [
            360,
            "Reg Add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\alark\" /v \"ObjectName\" /t REG_SZ /d \"LocalSystem\" /f"
          ],
          [
            464,
            "reg add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\alark\" /v \"Start\" /t REG_DWORD /d \"2\" /f"
          ],
          [
            554,
            "reg add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\alark\" /v \"Type\" /t REG_DWORD /d \"16\" /f"
          ],
          [
            644,
            "reg add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\alark\" /v \"ErrorControl\" /t REG_DWORD /d \"1\" /f"
          ],
          [
            741,
            "reg add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\alark\" /v \"ImagePath\" /t REG_EXPAND_SZ /d \"%windir%\\alark.exe\" /f"
          ],
          [
            858,
            "Reg Add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\alark\\Parameters\" /v \"Application\" /t REG_SZ /d \"cmd /c start %windir%\\miter.exe"
          ],
          [
            1021,
            "::Reg Add \"HKLM\\SYSTEM\\CurrentControlSet\\services\\alark\\Parameters\" /v \"AppParameters\" /t REG_SZ /d \"-t3000 %windir%\\sysclr.bat\""
          ],
          [
            1186,
            "net start alark"
          ],
          [
            1203,
            "ping 127.0.0.1 -n 4"
          ],
          [
            1224,
            "timeout 4  /NOBREAK"
          ],
          [
            1245,
            "taskkill /f /im alark.exe"
          ],
          [
            1287,
            "exit"
          ]
        ],
        "sz": 1293,
        "ts": [
          {
            "d": ".bat extension reference",
            "e": [
              ".bat"
            ],
            "i": "micro-behaviors/fs/path/extension::bat-dup",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "Regex component marker",
            "e": [
              "start"
            ],
            "i": "objectives/command-and-control/dropper/execution/batch::keyed-temp-payload-launch--rx-1",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Redirect output to null",
            "e": [
              "\u003enul"
            ],
            "i": "objectives/command-and-control/dropper/execution/batch::redirect-null",
            "l": 1
          },
          {
            "c": 0.6000000238418579,
            "d": "Start an executable",
            "e": [
              "start %windir%\\miter.exe"
            ],
            "i": "objectives/command-and-control/dropper/execution/batch::start-exe",
            "l": 1
          },
          {
            "a": "T1082",
            "c": 1.0,
            "d": "Ping internal host list",
            "e": [
              "ping 127.0.0.1"
            ],
            "i": "objectives/discovery/system/domain-admin-prep::ping-internal-hosts",
            "l": 1
          },
          {
            "c": 0.550000011920929,
            "d": "Stdout redirected to NUL",
            "e": [
              "\u003enul"
            ],
            "i": "micro-behaviors/os/console/io::windows-stdout-to-nul",
            "l": 2
          },
          {
            "a": "T1070.004",
            "c": 0.949999988079071,
            "d": "Regex component marker",
            "e": [
              "127.0.0.1"
            ],
            "i": "objectives/evasion/self-delete/file/delay::ping-self-delete--rx-1",
            "l": 1
          },
          {
            "c": 1.0,
            "d": ".bat extension",
            "e": [
              ".bat"
            ],
            "i": "objectives/command-and-control/dropper/builder::bat-ext",
            "l": 1
          },
          {
            "a": "T1070.004",
            "c": 0.949999988079071,
            "d": "Regex component marker",
            "e": [
              "\nping "
            ],
            "i": "objectives/evasion/self-delete/file/delay::ping-self-delete--rx-2",
            "l": 1
          },
          {
            "a": "T1053.005",
            "c": 0.9300000071525574,
            "d": "Regex component marker",
            "e": [
              "LocalSystem"
            ],
            "i": "objectives/persistence/login/scheduled-task/cmdlet::new-scheduledtask-principal-system--rx-7",
            "l": 1,
            "m": "F0012"
          },
          {
            "a": "T1059.003",
            "c": 0.699999988079071,
            "d": "cmd launches batch script",
            "e": [
              "cmd /c start %windir%\\miter.exe -t3000 %windir%\\sysclr.bat"
            ],
            "i": "micro-behaviors/process/create/script/file::batch-script-exec-cmd",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "Hardcoded loopback IPv4 address",
            "e": [
              "127.0.0.1"
            ],
            "i": "micro-behaviors/communications/ip/literal::loopback-ipv4-source",
            "l": 2
          },
          {
            "d": ".exe extension reference",
            "e": [
              ".exe"
            ],
            "i": "micro-behaviors/fs/path/extension::exe-dup",
            "l": 2
          },
          {
            "a": "T1070.004",
            "c": 0.949999988079071,
            "d": "Self-delete via ping delay loop",
            "e": [
              "\nping ",
              "127.0.0.1"
            ],
            "i": "objectives/evasion/self-delete/file/delay::ping-self-delete",
            "l": 4
          }
        ],
        "sha": "7c110eb6cb8057259842bc69d7fd41063cb5dff8ea6e18c33e01c17d4a2a47d8",
        "path": "502438!!clrinst.bat",
        "type": "batch"
      },
      {
        "f": "KO₈(As₃C₂CoDyEr₆IPS)H₄(FHfOsPo₃)Md₄(Bi₆SiHePa)",
        "x": 11,
        "dp": 1,
        "id": 6,
        "is": [
          "wsprintfA",
          "GetDesktopWindow",
          "SetCurrentDirectoryA",
          "ExitThread",
          "SetEvent",
          "OpenEventA",
          "CreateProcessA",
          "Sleep",
          "TerminateProcess",
          "ExitProcess",
          "GetLastError",
          "close",
          "stricmp",
          "malloc",
          "except_handler3",
          "getmainargs",
          "free",
          "XcptFilter",
          "exit",
          "p___initenv",
          "strncmp",
          "initterm",
          "setusermatherr",
          "adjust_fdiv",
          "p__commode",
          "p__fmode",
          "set_app_type",
          "controlfp",
          "open",
          "lseek",
          "read",
          "exit",
          "RegCloseKey",
          "RegisterServiceCtrlHandlerA",
          "RegQueryValueExA",
          "SetServiceStatus",
          "StartServiceCtrlDispatcherA",
          "RegOpenKeyExA"
        ],
        "ms": {
          "pe": {
            "machine": 332.0,
            "checksum": 79119.0,
            "subsystem": 3.0,
            "timestamp": 944175276.0,
            "image_base": 16777216.0,
            "entry_section": ".text",
            "size_of_image": 16384.0,
            "timestamp_day": 2.0,
            "checksum_valid": true,
            "file_alignment": 512.0,
            "timestamp_year": 1999.0,
            "characteristics": 263.0,
            "entry_point_rva": 8800.0,
            "size_of_headers": 1536.0,
            "timestamp_month": 12.0,
            "checksum_matches": true,
            "checksum_present": true,
            "export_timestamp": 0.0,
            "import_dll_count": 4.0,
            "computed_checksum": 79119.0,
            "section_alignment": 4096.0,
            "number_of_sections": 2.0,
            "resource_timestamp": 0.0,
            "timestamp_pre_2000": true,
            "debug_timestamp_max": 944175276.0,
            "debug_timestamp_min": 944175276.0,
            "dll_characteristics": 32768.0,
            "rich_header_present": true,
            "linker_major_version": 5.0,
            "linker_minor_version": 12.0,
            "debug_directory_types": [
              1.0,
              3.0,
              4.0
            ],
            "debug_directory_entries": 3.0,
            "export_timestamp_present": false,
            "debug_timestamp_consistent": true,
            "resource_timestamp_present": false,
            "debug_timestamp_unique_count": 1.0,
            "debug_timestamp_nonzero_count": 3.0
          },
          "file": {
            "size": 15872.0
          },
          "binary": {
            "code_size": 6144.0,
            "func_count": 13.0,
            "entry_point": 8800.0,
            "has_overlay": true,
            "code_entropy": 6.3,
            "data_entropy": 0.02,
            "func_density": 2.17,
            "import_count": 38.0,
            "overlay_size": 7680.0,
            "string_count": 193.0,
            "avg_func_size": 1122.92,
            "overlay_ratio": 0.48,
            "section_count": 2.0,
            "avg_complexity": 13.15,
            "import_density": 6.33,
            "max_complexity": 85.0,
            "string_density": 32.17,
            "overall_entropy": 3.16,
            "overlay_entropy": 4.78,
            "avg_basic_blocks": 22.92,
            "avg_section_size": 3328.0,
            "dependency_count": 4.0,
            "entropy_variance": 3.14,
            "avg_string_length": 21.49,
            "complexity_per_kb": 2.19,
            "max_string_length": 67.0,
            "writable_sections": 1.0,
            "avg_string_entropy": 3.37,
            "code_to_data_ratio": 12.0,
            "data_to_file_ratio": 0.03,
            "entry_point_is_rva": true,
            "text_to_file_ratio": 0.39,
            "total_basic_blocks": 298.0,
            "executable_sections": 1.0,
            "func_analysis_depth": 2.0,
            "string_length_stddev": 14.82,
            "debug_reference_count": 3.0,
            "high_complexity_funcs": 2.0,
            "largest_section_ratio": 0.39,
            "sentence_string_count": 18.0,
            "sentence_string_ratio": 0.09,
            "behavioral_import_ratio": 0.03
          }
        },
        "ss": [
          [
            77,
            "!This program cannot be run in DOS mode."
          ],
          [
            464,
            ".text"
          ],
          [
            1796,
            "[SRVANY] StartServiceCtrlDispatcher error = %d"
          ],
          [
            1848,
            "MyService"
          ],
          [
            1860,
            "[SRVANY] SetServiceStatus error %ld"
          ],
          [
            1900,
            "[SRVANY] CreateProcess() failed, error %ld"
          ],
          [
            1948,
            "[SRVANY] CreateProcess(PMShell) failed, error %ld"
          ],
          [
            2000,
            "OS2.EXE /S /P C:\\OS2\\PMSHELL.EXE /C C:\\OS2\\PMSHELL.EXE"
          ],
          [
            2056,
            "[SRVANY] RegQueryValEx() failed rc = %d"
          ],
          [
            2100,
            "AppEnvironment"
          ],
          [
            2116,
            "Os2AppDirectory"
          ],
          [
            2132,
            "AppDirectory"
          ],
          [
            2148,
            "Os2AppParameters"
          ],
          [
            2168,
            "AppParameters"
          ],
          [
            2192,
            "Application"
          ],
          [
            2216,
            "StartPMShell"
          ],
          [
            2232,
            "[SRVANY] RegOpenKeyEx() failed rc = %d"
          ],
          [
            2276,
            "\\Parameters\\"
          ],
          [
            2292,
            "SYSTEM\\CurrentControlSet\\Services\\"
          ],
          [
            2340,
            "OS2.EXE /S /P"
          ],
          [
            2364,
            "[SRVANY] RegisterServiceCtrlHandler failed %d"
          ],
          [
            2412,
            "[SRVANY] MyServiceStart: GetDesktopWindow call failed %d"
          ],
          [
            2476,
            "[SRVANY] MyServiceCtrlHandler failed to terminate process, error=%d"
          ],
          [
            2560,
            "[SRVANY] MyServiceCtrlHandler failed to SetEvent(%x),"
          ],
          [
            2616,
            "[SRVANY] MyServiceCtrlHandler failed to open handle, error=%d"
          ],
          [
            2680,
            "OS2SSService-%d"
          ],
          [
            2696,
            "[SRVANY] Unrecognized opcode %ld"
          ],
          [
            2732,
            "[SRVANY] MyServiceCtrlHandler received Opcode=%x"
          ],
          [
            2784,
            "DOSCALLS"
          ],
          [
            2828,
            "Copyright (C) Rational Systems, Inc."
          ],
          [
            2868,
            "Phar Lap Software, Inc."
          ],
          [
            2892,
            "16STUB"
          ],
          [
            4924,
            "WSSSPS"
          ],
          [
            6950,
            "GetDesktopWindow"
          ],
          [
            6970,
            "wsprintfA"
          ],
          [
            6980,
            "USER32.dll"
          ],
          [
            6994,
            "ExitProcess"
          ],
          [
            7008,
            "GetLastError"
          ],
          [
            7024,
            "ExitThread"
          ],
          [
            7038,
            "Sleep"
          ],
          [
            7046,
            "CreateProcessA"
          ],
          [
            7064,
            "SetCurrentDirectoryA"
          ],
          [
            7088,
            "TerminateProcess"
          ],
          [
            7108,
            "SetEvent"
          ],
          [
            7120,
            "OpenEventA"
          ],
          [
            7132,
            "KERNEL32.dll"
          ],
          [
            7148,
            "free"
          ],
          [
            7156,
            "malloc"
          ],
          [
            7166,
            "_stricmp"
          ],
          [
            7178,
            "strncmp"
          ],
          [
            7188,
            "_except_handler3"
          ],
          [
            7208,
            "_close"
          ],
          [
            7218,
            "_lseek"
          ],
          [
            7252,
            "_XcptFilter"
          ],
          [
            7266,
            "exit"
          ],
          [
            7274,
            "__p___initenv"
          ],
          [
            7290,
            "__getmainargs"
          ],
          [
            7306,
            "_initterm"
          ],
          [
            7318,
            "__setusermatherr"
          ],
          [
            7338,
            "_adjust_fdiv"
          ],
          [
            7354,
            "__p__commode"
          ],
          [
            7370,
            "__p__fmode"
          ],
          [
            7384,
            "__set_app_type"
          ],
          [
            7400,
            "MSVCRT.dll"
          ],
          [
            7414,
            "_controlfp"
          ],
          [
            7428,
            "StartServiceCtrlDispatcherA"
          ],
          [
            7458,
            "SetServiceStatus"
          ],
          [
            7478,
            "RegCloseKey"
          ],
          [
            7492,
            "RegQueryValueExA"
          ],
          [
            7512,
            "RegOpenKeyExA"
          ],
          [
            7528,
            "RegisterServiceCtrlHandlerA"
          ],
          [
            7556,
            "ADVAPI32.dll"
          ],
          [
            8224,
            "@comp.id"
          ],
          [
            8350,
            "@id.comp"
          ],
          [
            9394,
            "header"
          ],
          [
            11320,
            "___xc_a"
          ],
          [
            11338,
            "___xc_z"
          ],
          [
            11356,
            "___xi_a"
          ],
          [
            11374,
            "___xi_z"
          ],
          [
            11482,
            "__fmode"
          ],
          [
            11608,
            "__ldusedv"
          ],
          [
            11666,
            "_mainCRTStartup"
          ],
          [
            11682,
            "??_C@_0DB@JOGJ@?5?$FLSRVANY?$FN?5StartServiceCtrlDispat@"
          ],
          [
            11739,
            "??_C@_09GDJD@MyService?$AA@"
          ],
          [
            11785,
            "??_C@_0CG@LAA@?5?$FLSRVANY?$FN?5SetServiceStatus?5error@"
          ],
          [
            11842,
            "??_C@_0CN@IKPM@?5?$FLSRVANY?$FN?5CreateProcess?$CI?$CJ?5failed@"
          ],
          [
            11906,
            "??_C@_0DE@GMPF@?5?$FLSRVANY?$FN?5CreateProcess?$CIPMShell?$CJ@"
          ],
          [
            12028,
            "??_C@_0CK@EONC@?5?$FLSRVANY?$FN?5RegQueryValEx?$CI?$CJ?5failed@"
          ],
          [
            12092,
            "??_C@_0P@GLLI@AppEnvironment?$AA@"
          ],
          [
            12162,
            "??_C@_0N@FLCE@AppDirectory?$AA@"
          ],
          [
            12194,
            "??_C@_0BB@LJEM@Os2AppParameters?$AA@"
          ],
          [
            12231,
            "??_C@_0O@PMNO@AppParameters?$AA@"
          ],
          [
            12289,
            "??_C@_0M@DAJ@Application?$AA@"
          ],
          [
            12319,
            "??_C@_02PHBM@on?$AA@"
          ],
          [
            12360,
            "??_C@_03LGKI@yes?$AA@"
          ],
          [
            12382,
            "??_C@_0N@IDAD@StartPMShell?$AA@"
          ],
          [
            12479,
            "??_C@_0N@BKBE@?2Parameters?2?$AA@"
          ],
          [
            12513,
            "??_C@_0CD@HOED@SYSTEM?2CurrentControlSet?2Service@"
          ],
          [
            12564,
            "??_C@_01FCOA@?5?$AA@"
          ],
          [
            12692,
            "??_C@_0DA@DCG@?5?$FLSRVANY?$FN?5RegisterServiceCtrlHan@"
          ],
          [
            12823,
            "_MyServiceCtrlHandler@4"
          ],
          [
            12847,
            "??_C@_0EG@CPJK@?5?$FLSRVANY?$FN?5MyServiceCtrlHandler?5f@"
          ],
          [
            12938,
            "??_C@_0DI@LFAH@?5?$FLSRVANY?$FN?5MyServiceCtrlHandler?5f@"
          ],
          [
            12996,
            "??_C@_0EA@KNIJ@?5?$FLSRVANY?$FN?5MyServiceCtrlHandler?5f@"
          ],
          [
            13094,
            "??_C@_0CD@FPHF@?5?$FLSRVANY?$FN?5Unrecognized?5opcode?5?$CFl@"
          ],
          [
            13156,
            "??_C@_0DD@CKFH@?5?$FLSRVANY?$FN?5MyServiceCtrlHandler?5r@"
          ],
          [
            13229,
            "_CheckEnvironment@8"
          ],
          [
            13249,
            "_PrintEnvironment@4"
          ],
          [
            13269,
            "_Os2Application"
          ],
          [
            13295,
            "_MyServiceStatusHandle"
          ],
          [
            13318,
            "_MyServiceStatus"
          ],
          [
            13335,
            "__imp__ExitProcess@4"
          ],
          [
            13378,
            "__imp__StartServiceCtrlDispatcherA@4"
          ],
          [
            13415,
            "__imp__ExitThread@4"
          ],
          [
            13435,
            "__imp__SetServiceStatus@8"
          ],
          [
            13461,
            "__imp__Sleep@4"
          ],
          [
            13476,
            "__imp__CreateProcessA@40"
          ],
          [
            13522,
            "__imp__free"
          ],
          [
            13534,
            "__imp__malloc"
          ],
          [
            13611,
            "__imp__SetCurrentDirectoryA@4"
          ],
          [
            13641,
            "__imp___stricmp"
          ],
          [
            13657,
            "__imp__RegisterServiceCtrlHandlerA@8"
          ],
          [
            13694,
            "__imp__GetDesktopWindow@0"
          ],
          [
            13720,
            "__imp__TerminateProcess@8"
          ],
          [
            13764,
            "__imp__OpenEventA@12"
          ],
          [
            13785,
            "__imp__wsprintfA"
          ],
          [
            13821,
            "??_C@_08MMCC@DOSCALLS?$AA@"
          ],
          [
            13848,
            "_MiVerifyImageHeader@12"
          ],
          [
            13911,
            "??_C@_0CF@HDNL@Copyright?5?$CIC?$CJ?5Rational?5Systems?0?5@"
          ],
          [
            14020,
            "??_C@_06EDKM@16STUB?$AA@"
          ],
          [
            14045,
            "__imp__strncmp"
          ],
          [
            14060,
            "__except_list"
          ],
          [
            14074,
            "__except_handler3"
          ],
          [
            14092,
            "__imp___close"
          ],
          [
            14106,
            "__imp___lseek"
          ],
          [
            14120,
            "__imp___read"
          ],
          [
            14133,
            "__imp___open"
          ],
          [
            14146,
            "_GetDesktopWindow@0"
          ],
          [
            14166,
            "__IMPORT_DESCRIPTOR_USER32"
          ],
          [
            14193,
            "_wsprintfA"
          ],
          [
            14204,
            "__NULL_IMPORT_DESCRIPTOR"
          ],
          [
            14230,
            "USER32_NULL_THUNK_DATA"
          ],
          [
            14253,
            "_ExitProcess@4"
          ],
          [
            14268,
            "__IMPORT_DESCRIPTOR_KERNEL32"
          ],
          [
            14327,
            "_CreateProcessA@40"
          ],
          [
            14346,
            "_SetCurrentDirectoryA@4"
          ],
          [
            14370,
            "_TerminateProcess@8"
          ],
          [
            14418,
            "KERNEL32_NULL_THUNK_DATA"
          ],
          [
            14443,
            "___defaultmatherr"
          ],
          [
            14461,
            "__imp___exit"
          ],
          [
            14474,
            "__XcptFilter"
          ],
          [
            14487,
            "__imp__exit"
          ],
          [
            14499,
            "__imp____p___initenv"
          ],
          [
            14520,
            "__imp____getmainargs"
          ],
          [
            14541,
            "__dowildcard"
          ],
          [
            14554,
            "__newmode"
          ],
          [
            14564,
            "__initterm"
          ],
          [
            14575,
            "__setdefaultprecision"
          ],
          [
            14597,
            "__imp____setusermatherr"
          ],
          [
            14621,
            "__matherr"
          ],
          [
            14631,
            "__setargv"
          ],
          [
            14641,
            "__adjust_fdiv"
          ],
          [
            14655,
            "__imp___adjust_fdiv"
          ],
          [
            14675,
            "__commode"
          ],
          [
            14685,
            "__imp____p__commode"
          ],
          [
            14705,
            "__imp____p__fmode"
          ],
          [
            14723,
            "___onexitbegin"
          ],
          [
            14738,
            "___onexitend"
          ],
          [
            14751,
            "__imp____set_app_type"
          ],
          [
            14773,
            "__IMPORT_DESCRIPTOR_MSVCRT"
          ],
          [
            14800,
            "__stricmp"
          ],
          [
            14810,
            "__fltused"
          ],
          [
            14820,
            "__imp___except_handler3"
          ],
          [
            14844,
            "__imp___XcptFilter"
          ],
          [
            14863,
            "___p___initenv"
          ],
          [
            14878,
            "___getmainargs"
          ],
          [
            14893,
            "__imp___initterm"
          ],
          [
            14910,
            "__controlfp"
          ],
          [
            14922,
            "___setusermatherr"
          ],
          [
            14940,
            "___p__commode"
          ],
          [
            14954,
            "___p__fmode"
          ],
          [
            14966,
            "___dllonexit"
          ],
          [
            14979,
            "__imp___onexit"
          ],
          [
            14994,
            "___set_app_type"
          ],
          [
            15011,
            "MSVCRT_NULL_THUNK_DATA"
          ],
          [
            15034,
            "__imp___controlfp"
          ],
          [
            15052,
            "__imp____dllonexit"
          ],
          [
            15071,
            "_StartServiceCtrlDispatcherA@4"
          ],
          [
            15102,
            "__IMPORT_DESCRIPTOR_ADVAPI32"
          ],
          [
            15131,
            "_SetServiceStatus@8"
          ],
          [
            15205,
            "_RegisterServiceCtrlHandlerA@8"
          ],
          [
            15237,
            "ADVAPI32_NULL_THUNK_DATA"
          ],
          [
            15276,
            "obj\\i386\\srvany.exe"
          ]
        ],
        "sz": 15872,
        "ts": [
          {
            "c": 0.8199999928474426,
            "d": "Elevated text section entropy",
            "e": [
              ".text (entropy: 6.30)"
            ],
            "i": "metadata/binary/section/metrics::elevated-text-entropy-section",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE standard code/data section",
            "e": [
              ".data",
              ".text"
            ],
            "i": "metadata/binary/section/names::pe-code-data-standard-section",
            "l": 1
          },
          {
            "a": "T1565.001",
            "c": 0.8500000238418579,
            "d": "Regex component marker",
            "e": [
              "__imp__StartServiceCtrlDispatcherA@4",
              "[SRVANY] StartServiceCtrlDispatcher error = %d",
              "StartServiceCtrlDispatcherA",
              "_StartServiceCtrlDispatcherA@4"
            ],
            "i": "objectives/evasion/hosts-file/block-security::escan-security-domain--rx-4",
            "l": 1,
            "m": "F0004"
          },
          {
            "c": 1.0,
            "d": "Binary has 4 or fewer sections",
            "e": [
              "binary.section_count = 2.00"
            ],
            "i": "objectives/command-and-control/infrastructure/config::max-sections-4",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary is not position-independent (fixed load address)",
            "e": [
              "binary.is_pie = 0.00"
            ],
            "i": "metadata/hardening/layout::no-pie",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Allocate memory (C runtime)",
            "e": [
              "malloc"
            ],
            "i": "micro-behaviors/mem/c-runtime/functions::malloc",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Binary has low overall entropy",
            "e": [
              "binary.overall_entropy = 3.16"
            ],
            "i": "metadata/binary/metrics/threshold::low-overall-entropy-binary",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "PE has few sections",
            "e": [
              "binary.section_count = 2.00"
            ],
            "i": "metadata/binary/layout::legacy-few-sections",
            "l": 2
          },
          {
            "c": 0.6600000262260437,
            "d": "Open files",
            "e": [
              "open"
            ],
            "i": "micro-behaviors/fs/file/open::open-base",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Close registry key",
            "e": [
              "RegCloseKey"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-close-key",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Exit current process",
            "e": [
              "ExitProcess"
            ],
            "i": "micro-behaviors/process/terminate/kill::exit-process",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Get system error code",
            "e": [
              "GetLastError"
            ],
            "i": "micro-behaviors/os/exception/error-handling::get-last-error",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 25+ imports",
            "e": [
              "binary.import_count = 38.00"
            ],
            "i": "metadata/binary/metrics/threshold::many-imports-25",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE file uses .exe extension",
            "e": [
              "alark.exe"
            ],
            "i": "metadata/binary/framework::exe-extension",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.8399999737739563,
            "d": "Open registry key ANSI",
            "e": [
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-open-key-ex-a",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Open named event object",
            "e": [
              "OpenEventA"
            ],
            "i": "micro-behaviors/process/sync/event::open-event",
            "l": 2,
            "m": "C0039"
          },
          {
            "c": 0.75,
            "d": "Binary exports no symbols",
            "e": [
              "binary.export_count = 0.00"
            ],
            "i": "metadata/binary/symbols/exports::no-exports",
            "l": 1
          },
          {
            "a": "T1070.006",
            "c": 0.699999988079071,
            "d": "Debug timestamps internally consistent",
            "e": [
              "pe.debug_timestamp_consistent = 1.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::debug-timestamps-consistent",
            "l": 1
          },
          {
            "c": 0.7200000286102295,
            "d": "Short uppercase mutex token",
            "e": [
              "DOSCALLS"
            ],
            "i": "micro-behaviors/process/sync/mutex::short-uppercase-token",
            "l": 1,
            "m": "C0042"
          },
          {
            "c": 0.8799999952316284,
            "d": "Sparse function count stub",
            "e": [
              "binary.func_count = 13.00"
            ],
            "i": "well-known/malware/trojan/shellobject/revengerat::sparse-function-stub",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "Process termination via TerminateProcess",
            "e": [
              "TerminateProcess"
            ],
            "i": "micro-behaviors/process/terminate/kill::terminate-process",
            "l": 3,
            "m": "B0033"
          },
          {
            "a": "T1070.006",
            "c": 0.699999988079071,
            "d": "PE header compile timestamp predates 2025",
            "e": [
              "pe.timestamp = 944175276.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::header-timestamp-pre-2025",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "RegOpenKeyEx API",
            "e": [
              "RegOpenKeyExA"
            ],
            "i": "objectives/anti-static/obfuscation/payload/registry::reg-open-key",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.9399999976158142,
            "d": "PE overlay exceeds thirty-five percent",
            "e": [
              "binary.overlay_ratio = 0.48"
            ],
            "i": "metadata/binary/layout::overlay-over-35pct",
            "l": 3
          },
          {
            "a": "T1027.007",
            "c": 1.0,
            "d": "WININET.DLL absent from PE import table",
            "e": [
              "pe.import_dll_count = 4.00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::wininet-import-absent",
            "l": 2,
            "m": "B0032"
          },
          {
            "c": 0.8999999761581421,
            "d": "Exit thread execution",
            "e": [
              "ExitThread"
            ],
            "i": "micro-behaviors/process/thread/create::exit-thread",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE Rich header present (MSVC toolchain)",
            "e": [
              "pe.rich_header_present = 1.00"
            ],
            "i": "metadata/binary/resource::rich-header-present",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Limited string comparison",
            "e": [
              "strncmp"
            ],
            "i": "micro-behaviors/data/string/library::strncmp",
            "l": 2
          },
          {
            "a": "T1112",
            "c": 0.8500000238418579,
            "d": "Query registry value via import symbol",
            "e": [
              "RegQueryValueExA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-query-value-ex-a-symbol",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "msvcrt library (MSVC C runtime)",
            "e": [
              "MSVCR"
            ],
            "i": "metadata/lang/compiler/native::msvcrt",
            "l": 2
          },
          {
            "a": "T1055",
            "c": 0.9200000166893005,
            "d": "Regex component marker",
            "e": [
              "binary.import_count = 38.00"
            ],
            "i": "objectives/evasion/process/injection/vb6::vb6-process-injection-pattern-cond-1--inline-17571",
            "l": 1,
            "m": "C0041"
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "RegQueryValueEx API",
            "e": [
              "RegQueryValueExA"
            ],
            "i": "objectives/anti-static/obfuscation/payload/registry::reg-query-value",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1485",
            "c": 0.8999999761581421,
            "d": "Preserves .exe .gho .bak files",
            "e": [
              ".EXE"
            ],
            "i": "objectives/impact/destroy/file-deletion::exe-gho-bak-whitelist",
            "l": 1,
            "m": "C0047"
          },
          {
            "c": 0.800000011920929,
            "d": "Tiny writable data section",
            "e": [
              ".data (size: 512)"
            ],
            "i": "metadata/binary/section/metrics::tiny-data-section",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 30+ imports",
            "e": [
              "binary.import_count = 38.00"
            ],
            "i": "metadata/binary/metrics/threshold::many-imports-30",
            "l": 1
          },
          {
            "c": 0.6000000238418579,
            "d": "Copyright notice",
            "e": [
              "Copyright"
            ],
            "i": "metadata/package/license::copyright-word",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Set event object state",
            "e": [
              "SetEvent"
            ],
            "i": "micro-behaviors/process/sync/event::set-event",
            "l": 2,
            "m": "C0039"
          },
          {
            "a": "T1055.012",
            "c": 0.800000011920929,
            "d": "CreateProcess API string reference",
            "e": [
              "CreateProcessA",
              "??_C@_0CN@IKPM@?5?$FLSRVANY?$FN?5CreateProcess?$CI?$CJ?5failed@",
              "[SRVANY] CreateProcess() failed, error %ld",
              "__imp__CreateProcessA@40",
              "??_C@_0DE@GMPF@?5?$FLSRVANY?$FN?5CreateProcess?$CIPMShell?$CJ@",
              "[SRVANY] CreateProcess(PMShell) failed, error %ld",
              "_CreateProcessA@40"
            ],
            "i": "objectives/evasion/process/injection/hollowing::create-process-string",
            "l": 1,
            "m": "E1055.012"
          },
          {
            "c": 0.699999988079071,
            "d": "PE has low overall entropy",
            "e": [
              "binary.overall_entropy = 3.16"
            ],
            "i": "metadata/binary/layout::low-overall-entropy",
            "l": 2
          },
          {
            "d": ".dll extension reference",
            "e": [
              ".dll"
            ],
            "i": "micro-behaviors/fs/path/extension::dll-dup",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has low average string entropy",
            "e": [
              "binary.avg_string_entropy = 3.37"
            ],
            "i": "metadata/binary/metrics/threshold::avg-string-entropy-4-max",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has low average complexity",
            "e": [
              "binary.avg_complexity = 13.15"
            ],
            "i": "metadata/binary/metrics/threshold::avg-complexity-15-max",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Free memory (C runtime)",
            "e": [
              "free"
            ],
            "i": "micro-behaviors/mem/c-runtime/functions::free-dup",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "PE binary has trailing overlay data",
            "e": [
              "binary.has_overlay = 1.00"
            ],
            "i": "metadata/binary/layout::has-overlay",
            "l": 3
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Open registry key via import symbol ANSI",
            "e": [
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-open-key-ex-a-symbol",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Small PE resource section",
            "e": [
              "pe.rsrc_size = 0.00"
            ],
            "i": "metadata/package/versioning::pe-small-rsrc",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 20+ imports",
            "e": [
              "binary.import_count = 38.00"
            ],
            "i": "metadata/binary/metrics/threshold::many-imports-20",
            "l": 1
          },
          {
            "a": "T1106",
            "c": 0.949999988079071,
            "d": "Create process (ANSI)",
            "e": [
              "CreateProcessA"
            ],
            "i": "micro-behaviors/process/create/spawn::create-process-a",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "Dense PE import table references",
            "e": [
              "binary.import_density = 6.33"
            ],
            "i": "metadata/binary/metrics/structural::high-import-density",
            "l": 3
          },
          {
            "a": "T1014",
            "c": 0.9399999976158142,
            "d": "Regex component marker",
            "e": [
              ".EXE"
            ],
            "i": "objectives/evasion/kernel-hide/rootkit::executable-read-patch-markers--rx-7",
            "l": 1
          },
          {
            "a": "T1543.003",
            "c": 0.8600000143051147,
            "d": "Services registry key fragment",
            "e": [
              "SYSTEM\\CurrentControlSet\\Services\\"
            ],
            "i": "objectives/persistence/system/service/install::service-registry-key-fragment",
            "l": 1,
            "m": "B0011.003"
          },
          {
            "c": 0.699999988079071,
            "d": "PE has many readable strings",
            "e": [
              "binary.string_count = 193.00"
            ],
            "i": "metadata/binary/layout::many-readable-strings",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "File is a compiled binary",
            "e": [
              "alark.exe"
            ],
            "i": "metadata/binary/framework::is-binary",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE mapped image under 768 KiB",
            "e": [
              "pe.size_of_image = 16384.00"
            ],
            "i": "metadata/binary/layout::image-under-768kb",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Read file descriptor (read/pread)",
            "e": [
              "read"
            ],
            "i": "micro-behaviors/fs/file/read::read",
            "l": 2
          },
          {
            "a": "T1113",
            "c": 0.800000011920929,
            "d": "Desktop window handle access",
            "e": [
              "GetDesktopWindow"
            ],
            "i": "micro-behaviors/hardware/display/screen::get-desktop-window",
            "l": 3,
            "m": "C0014"
          },
          {
            "c": 0.8199999928474426,
            "d": "Regex component marker",
            "e": [
              "_close",
              "RegCloseKey",
              "__imp___close"
            ],
            "i": "objectives/discovery/system/ics-environment/register::ics-register-flow-rate--rx-75",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 3+ functions",
            "e": [
              "binary.func_count = 13.00"
            ],
            "i": "metadata/binary/metrics/threshold::few-functions-3",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Delay execution",
            "e": [
              "Sleep"
            ],
            "i": "micro-behaviors/time/timing/delay::sleep-dup",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.8999999761581421,
            "d": "Start service control dispatcher",
            "e": [
              "StartServiceCtrlDispatcherA"
            ],
            "i": "micro-behaviors/os/service/control::start-service-dispatcher",
            "l": 3
          },
          {
            "c": 1.0,
            "d": "ASLR bit not set in DLL Characteristics",
            "e": [
              "pe.dll_characteristics = 32768.00"
            ],
            "i": "metadata/hardening/mitigation::no-aslr-bit",
            "l": 1
          },
          {
            "a": "T1070.006",
            "c": 0.8999999761581421,
            "d": "Export timestamp is absent",
            "e": [
              "pe.export_timestamp_present = 0.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::export-timestamp-absent",
            "l": 2
          },
          {
            "a": "T1070.006",
            "c": 0.7799999713897705,
            "d": "PE header timestamp predates 2000",
            "e": [
              "pe.timestamp_pre_2000 = 1.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::header-timestamp-pre-2000",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.800000011920929,
            "d": "Few PE resource entries (no DIALOG/MENU/STRINGTABLE)",
            "e": [
              "pe.resource_count = 0.00"
            ],
            "i": "objectives/evasion/anti-av/heuristic::minimal-pe-resources",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary is not digitally signed",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed/trust-level::unsigned",
            "l": 3
          },
          {
            "a": "T1543.003",
            "c": 0.8799999952316284,
            "d": "Report service status updates",
            "e": [
              "SetServiceStatus"
            ],
            "i": "micro-behaviors/os/service/control::set-service-status",
            "l": 3
          },
          {
            "c": 0.6000000238418579,
            "d": "Very few sections (merged/stripped)",
            "e": [
              "binary.section_count = 2.00"
            ],
            "i": "metadata/binary/metrics/structural::few-sections",
            "l": 3
          },
          {
            "c": 0.9200000166893005,
            "d": "Overlay exceeds one-third",
            "e": [
              "binary.overlay_ratio = 0.48"
            ],
            "i": "metadata/binary/layout::overlay-dominates-third",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Tiny C string section ratio",
            "e": [
              " = 0.0% of total (0 / 15872 bytes)"
            ],
            "i": "metadata/binary/section/metrics::tiny-cstring-section",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.8600000143051147,
            "d": "Long mixed-case identifiers cluster",
            "e": [
              "RegisterServiceCtrlHandler",
              "SetCurrentDirectoryA",
              "RegisterServiceCtrlHandlerA",
              "StartServiceCtrlDispatcherA",
              "StartServiceCtrlDispatcher"
            ],
            "i": "objectives/anti-static/obfuscation/string/junking::long-mixedcase-identifiers",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1027.007",
            "c": 0.800000011920929,
            "d": "DLL name strings without LoadLibrary import",
            "e": [
              "binary.import_count = 38.00"
            ],
            "i": "objectives/anti-static/obfuscation/string/runtime-decrypt::dll-names-no-loadlibrary",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "c": 0.8999999761581421,
            "d": "Browser process termination API",
            "e": [
              "TerminateProcess"
            ],
            "i": "objectives/collection/stealer/browser::windows-browser-terminate-api",
            "l": 1
          },
          {
            "d": ".exe extension reference",
            "e": [
              ".exe"
            ],
            "i": "micro-behaviors/fs/path/extension::exe-dup",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "Filename has EXE extension",
            "e": [
              "alark.exe"
            ],
            "i": "objectives/evasion/masquerade/file/double-ext::basename-is-exe",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Binary lacks resource section entirely",
            "e": [
              "binary.rsrc_to_file_ratio = 0.00"
            ],
            "i": "metadata/binary/resource::no-resources",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.8999999761581421,
            "d": "Register service control handler",
            "e": [
              "RegisterServiceCtrlHandlerA"
            ],
            "i": "micro-behaviors/os/service/control::register-service-handler",
            "l": 3
          },
          {
            "a": "T1105",
            "c": 0.800000011920929,
            "d": "Compact PE import table",
            "e": [
              "binary.import_count = 38.00"
            ],
            "i": "objectives/command-and-control/dropper/delivery/download-execute::compact-import-table",
            "l": 1,
            "m": "E1105"
          },
          {
            "c": 0.8999999761581421,
            "d": "Switch current working directory",
            "e": [
              "SetCurrentDirectoryA"
            ],
            "i": "micro-behaviors/fs/traversal/drives::set-current-directory",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "PE executable is unsigned",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed/trust-level::unsigned-pe-executable",
            "l": 3
          },
          {
            "c": 0.949999988079071,
            "d": "links USER32.dll (wsprintfA, GetDesktopWindow)",
            "e": [
              "USER32.dll"
            ],
            "i": "metadata/dylib::user32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links KERNEL32.dll (SetCurrentDirectoryA, ExitThread, SetEvent, OpenEventA, CreateProcessA, ... +4 more)",
            "e": [
              "KERNEL32.dll"
            ],
            "i": "metadata/dylib::kernel32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links ADVAPI32.dll (RegCloseKey, RegisterServiceCtrlHandlerA, RegQueryValueExA, SetServiceStatus, StartServiceCtrlDispatcherA, ... +1 more)",
            "e": [
              "ADVAPI32.dll"
            ],
            "i": "metadata/dylib::advapi32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links MSVCRT.dll (close, stricmp, malloc, except_handler3, getmainargs, ... +16 more)",
            "e": [
              "MSVCRT.dll"
            ],
            "i": "metadata/dylib::msvcrt/dll",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.949999988079071,
            "d": "Full Windows service dispatch triplet",
            "e": [
              "RegisterServiceCtrlHandlerA",
              "SetServiceStatus",
              "StartServiceCtrlDispatcherA"
            ],
            "i": "micro-behaviors/os/service/control::service-dispatch-triad",
            "l": 3
          },
          {
            "a": "T1543.003",
            "c": 0.9200000166893005,
            "d": "Windows service control dispatch",
            "e": [
              "StartServiceCtrlDispatcherA",
              "RegisterServiceCtrlHandlerA",
              "SetServiceStatus"
            ],
            "i": "micro-behaviors/os/service/control::service-control-dispatch",
            "l": 3
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Registry key open and query chain",
            "e": [
              "RegQueryValueExA",
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/access::registry-read-api-chain",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "High-trust tool delivered via low-integrity packaging",
            "e": [
              "binary.has_signature = 0.00",
              "binary.has_overlay = 1.00"
            ],
            "i": "objectives/supply-chain/trojanized/app/monitor::low-integrity-installer-packaging",
            "l": 1
          }
        ],
        "sha": "576911063b10114a4844a039c771bc4eef631a457ae3775d7645604ef2950f4f",
        "path": "502438!!alark.exe",
        "type": "pe"
      }
    ],
    "tv": "84923"
  }
}