{
  "ml": {
    "v": "4",
    "fs": [
      {
        "id": 0,
        "prob": 0.987034022808075,
        "class": 0
      }
    ],
    "prob": 0.987034,
    "class": 0,
    "models": [
      {
        "m": "az",
        "prob": 0.987034,
        "class": 0
      },
      {
        "m": "az/native",
        "prob": 0.8567708,
        "class": 0
      },
      {
        "m": "az/pe",
        "prob": 0.48165137,
        "class": 0
      }
    ],
    "version": "v16.16",
    "thresholds": [
      0.9961373,
      0.9998425
    ],
    "analyzed_at": "2026-05-12T15:35:18Z"
  },
  "path": "9514",
  "raw": {
    "v": "4",
    "fs": [
      {
        "f": "O(As)H₂(CmCr)Md₃(Bi₂HeSi)",
        "k": {
          "hash.imp": "835c960a33109b72a2ff4ab11631c722",
          "pe.timestamp": 1839644021,
          "hash.authenti": "0b6b341cb77343b91cc7e939825c9affb9fbcfa3bc07978a2914902721f54967",
          "hash.rich_header": "126e54c3005f10e22e0732dcbe4b7cc375bb85a815b197d8e7ab5ca7d6a74ec9",
          "build.target_arch": "x86",
          "pe.linker_version": "10.0",
          "pe.rich_header.xor_key": "0xda1926c5",
          "pe.inflated_sections[0]": "UPX2",
          "pe.data_directories[0].rva": 24576,
          "pe.data_directories[0].name": "import",
          "pe.data_directories[0].size": 440,
          "pe.rich_header_compids[0].count": 10,
          "pe.rich_header_compids[1].count": 29,
          "pe.rich_header_compids[2].count": 4,
          "pe.rich_header_compids[3].count": 2,
          "pe.rich_header_compids[4].count": 1,
          "pe.dll_characteristics.nx_compat": true,
          "pe.rich_header_compids[0].compid": 9664521,
          "pe.rich_header_compids[1].compid": 65536,
          "pe.rich_header_compids[3].compid": 11246875,
          "pe.rich_header_compids[4].compid": 10329371,
          "pe.rich_header_compids[1].product": "Unknown",
          "pe.rich_header_compids[2].product": "Unknown",
          "pe.section_characteristics[0].name": "UPX0",
          "pe.section_characteristics[1].name": "UPX1",
          "pe.section_characteristics[2].name": "UPX2",
          "pe.rich_header.entries[0].use_count": 10,
          "pe.rich_header.entries[1].use_count": 29,
          "pe.rich_header.entries[2].use_count": 4,
          "pe.rich_header.entries[3].use_count": 2,
          "pe.rich_header.entries[4].use_count": 1,
          "pe.rich_header.entries[0].product_id": 147,
          "pe.rich_header.entries[1].product_id": 1,
          "pe.rich_header.entries[3].product_id": 171,
          "pe.rich_header.entries[4].product_id": 157,
          "pe.rich_header.entries[0].build_number": 30729,
          "pe.rich_header.entries[0].product_name": "Linker_VS2008_LTCG_RTM",
          "pe.rich_header.entries[1].product_name": "Imp_VS_v6_or_earlier",
          "pe.rich_header.entries[2].product_name": "unknown",
          "pe.rich_header.entries[3].build_number": 40219,
          "pe.rich_header.entries[3].product_name": "unknown",
          "pe.rich_header.entries[4].build_number": 40219,
          "pe.rich_header.entries[4].product_name": "Linker_VS2010_LTCG",
          "pe.section_characteristics[1].raw_size": 2560,
          "pe.section_characteristics[2].raw_size": 512,
          "pe.section_characteristics[0].virtual_size": 16384,
          "pe.section_characteristics[1].virtual_size": 4096,
          "pe.section_characteristics[2].virtual_size": 4096,
          "pe.dll_characteristics.terminal_server_aware": true,
          "pe.section_characteristics[0].virtual_address": 4096,
          "pe.section_characteristics[1].virtual_address": 20480,
          "pe.section_characteristics[2].virtual_address": 24576,
          "pe.section_characteristics[0].characteristics_hex": "e0000080",
          "pe.section_characteristics[1].characteristics_hex": "e0000040",
          "pe.section_characteristics[2].characteristics_hex": "c0000040"
        },
        "x": 8,
        "id": 0,
        "is": [
          "LoadLibraryA",
          "GetProcAddress",
          "VirtualProtect",
          "VirtualAlloc",
          "VirtualFree",
          "ExitProcess",
          "CryptHashData",
          "wtoi",
          "CreateStreamOnHGlobal",
          "wsprintfA",
          "WinHttpOpen"
        ],
        "ms": {
          "pe": {
            "entry": 22400.0,
            "machine": 332.0,
            "checksum": 0.0,
            "subsystem": 2.0,
            "timestamp": 1839644021.0,
            "image_base": 4194304.0,
            "entry_section": "UPX1",
            "size_of_image": 28672.0,
            "file_alignment": 512.0,
            "characteristics": 259.0,
            "has_rich_header": true,
            "size_of_headers": 4096.0,
            "export_timestamp": 0.0,
            "import_dll_count": 6.0,
            "computed_checksum": 4169.0,
            "section_alignment": 4096.0,
            "timestamp_anomaly": true,
            "resource_timestamp": 0.0,
            "dll_characteristics": 33024.0,
            "timestamp_in_future": true,
            "has_export_timestamp": false,
            "linker_major_version": 10.0,
            "bss_like_section_count": 1.0,
            "has_resource_timestamp": false,
            "number_of_rva_and_sizes": 16.0,
            "entry_in_writable_section": true,
            "api_hashing_indicator_count": 1.0,
            "max_section_inflation_ratio": 8.0,
            "entry_in_nonstandard_section": true
          },
          "file": {
            "size": 4096.0
          },
          "binary": {
            "code_size": 2560.0,
            "func_count": 3.0,
            "code_entropy": 3.59,
            "func_density": 1.2,
            "import_count": 11.0,
            "string_count": 40.0,
            "avg_func_size": 4221.0,
            "section_count": 3.0,
            "avg_complexity": 9.33,
            "import_density": 4.4,
            "max_complexity": 26.0,
            "string_density": 16.0,
            "overall_entropy": 3.55,
            "avg_basic_blocks": 16.0,
            "avg_section_size": 1024.0,
            "dependency_count": 6.0,
            "entropy_variance": 2.93,
            "wx_section_count": 2.0,
            "avg_string_length": 10.13,
            "complexity_per_kb": 3.73,
            "max_string_length": 40.0,
            "avg_string_entropy": 2.8,
            "code_to_data_ratio": 5.0,
            "total_basic_blocks": 48.0,
            "func_analysis_depth": 2.0,
            "string_length_stddev": 6.21,
            "largest_section_ratio": 0.63,
            "sentence_string_count": 1.0,
            "sentence_string_ratio": 0.03,
            "writable_section_count": 3.0,
            "behavioral_import_ratio": 0.45,
            "entry_in_writable_region": true,
            "executable_section_count": 2.0,
            "nonstandard_section_count": 3.0
          }
        },
        "ss": [
          [
            77,
            "!This program cannot be run in DOS mode."
          ],
          [
            184,
            "Rich"
          ],
          [
            456,
            "UPX0"
          ],
          [
            496,
            "UPX1"
          ],
          [
            536,
            "UPX2"
          ],
          [
            987,
            "3.09"
          ],
          [
            2022,
            "Cont"
          ],
          [
            2032,
            "-Dispositi"
          ],
          [
            2043,
            ": form-data"
          ],
          [
            2058,
            "; name=\"apikey\""
          ],
          [
            2086,
            "xt/plain"
          ],
          [
            2140,
            "acb6aa"
          ],
          [
            2197,
            "D/x-msdownload"
          ],
          [
            2221,
            "er-Encodg4b"
          ],
          [
            2396,
            "Sige"
          ],
          [
            2508,
            "ileSizeRead"
          ],
          [
            2531,
            "ocess#TickCount"
          ],
          [
            2547,
            "Modu"
          ],
          [
            2567,
            "rtualFree"
          ],
          [
            2620,
            "yptAcquBe"
          ],
          [
            2718,
            "wspriDfA"
          ],
          [
            2771,
            "Open"
          ],
          [
            2779,
            "XBHB8"
          ],
          [
            3308,
            "XPTPSW"
          ],
          [
            3792,
            "KERNEL32.DLL"
          ],
          [
            3805,
            "ADVAPI32.dll"
          ],
          [
            3818,
            "ntdll.dll"
          ],
          [
            3828,
            "ole32.dll"
          ],
          [
            3838,
            "USER32.dll"
          ],
          [
            3849,
            "WINHTTP.dll"
          ],
          [
            3862,
            "LoadLibraryA"
          ],
          [
            3876,
            "GetProcAddress"
          ],
          [
            3892,
            "VirtualProtect"
          ],
          [
            3908,
            "VirtualAlloc"
          ],
          [
            3922,
            "VirtualFree"
          ],
          [
            3936,
            "ExitProcess"
          ],
          [
            3950,
            "CryptHashData"
          ],
          [
            3974,
            "CreateStreamOnHGlobal"
          ],
          [
            3998,
            "wsprintfA"
          ],
          [
            4010,
            "WinHttpOpen"
          ]
        ],
        "sz": 4096,
        "ts": [
          {
            "a": "T1027.002",
            "c": 0.9900000095367432,
            "d": "UPX magic byte sequence",
            "e": [
              "UPX!"
            ],
            "i": "objectives/anti-static/pack/upx::upx-magic-bytes",
            "l": 1,
            "m": "F0001.008"
          },
          {
            "c": 0.699999988079071,
            "d": "PE has few sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "metadata/binary/layout::legacy-few-sections",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "UPX1 section name",
            "e": [
              "UPX1"
            ],
            "i": "metadata/binary/section/names::upx1-section-name",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Exit current process",
            "e": [
              "ExitProcess"
            ],
            "i": "micro-behaviors/process/terminate/kill::exit-process",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Hash data using crypto provider",
            "e": [
              "CryptHashData"
            ],
            "i": "micro-behaviors/crypto/library/provider::crypt-hash-data",
            "l": 3
          },
          {
            "c": 1.0,
            "d": "LoadLibrary symbol",
            "e": [
              "LoadLibraryA"
            ],
            "i": "objectives/anti-static/obfuscation/reflection/class::loadlibrary-sym",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "PE built after 2020-01-01",
            "e": [
              "pe.timestamp = 1839644021.00"
            ],
            "i": "metadata/hardening/mitigation::post-2020-pe",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Dense PE import table references",
            "e": [
              "binary.import_density = 4.40"
            ],
            "i": "metadata/binary/metrics/structural::high-import-density",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "Regex component marker",
            "e": [
              "D/x-msdownload"
            ],
            "i": "micro-behaviors/communications/http/client/managed::webclient--rx-5",
            "l": 1
          },
          {
            "c": 0.7599999904632568,
            "d": "PE entry in nonstandard section",
            "e": [
              "pe.entry_in_nonstandard_section = 1.00"
            ],
            "i": "metadata/binary/section/metrics::pe-nonstandard-entry",
            "l": 1
          },
          {
            "d": "Few detected functions (stub-like or analysis-limited)",
            "e": [
              "binary.func_count = 3.00"
            ],
            "i": "metadata/binary/metrics/structural::no-functions",
            "l": 2
          },
          {
            "a": "T1027.002",
            "c": 0.800000011920929,
            "d": "Entry point in non-standard section",
            "e": [
              "UPX1 (size: 2560, entropy: 7.18, perms: rwx)"
            ],
            "i": "objectives/anti-static/pack/polymorphic::unusual-entry-point-section",
            "l": 1,
            "m": "F0001"
          },
          {
            "c": 0.8999999761581421,
            "d": "Tiny PE stub footprint",
            "e": [
              "9514"
            ],
            "i": "well-known/malware/trojan/shellobject/revengerat::tiny-pe-footprint",
            "l": 1
          },
          {
            "a": "T1055.012",
            "c": 1.0,
            "d": "Lacks substantial data section",
            "e": [
              "binary.data_to_file_ratio = 0.00"
            ],
            "i": "objectives/evasion/process/injection/hollowing::lacks-substantial-data",
            "l": 1,
            "m": "E1055.012"
          },
          {
            "c": 0.8600000143051147,
            "d": "Inflated PE data section",
            "e": [
              "pe.max_section_inflation_ratio = 8.00"
            ],
            "i": "metadata/binary/section/metrics::inflated-data-section",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Reference to ADVAPI32.dll",
            "e": [
              "ADVAPI32.dll"
            ],
            "i": "micro-behaviors/os/module/load::advapi32-dll-reference",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.8399999737739563,
            "d": "VB6 PE with three sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "objectives/anti-static/obfuscation/payload/string-sparse::three-section-vb6-layout",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1071.001",
            "c": 0.8999999761581421,
            "d": "Initialize WinHTTP session",
            "e": [
              "WinHttpOpen"
            ],
            "i": "micro-behaviors/communications/http/client/winhttp::winhttp-open",
            "l": 3,
            "m": "C0002"
          },
          {
            "c": 1.0,
            "d": "Binary has 3+ functions",
            "e": [
              "binary.func_count = 3.00"
            ],
            "i": "metadata/binary/metrics/threshold::few-functions-3",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Tiny PE by file size",
            "e": [
              "pe.machine = 332.00"
            ],
            "i": "metadata/binary/metrics/size::tiny-pe",
            "l": 3
          },
          {
            "c": 1.0,
            "d": "Suspicious combination of imported APIs",
            "e": [
              "pe.api_hashing_indicator_count = 1.00"
            ],
            "i": "metadata/binary/metrics/anomaly::suspicious-import-combo-marker",
            "l": 1
          },
          {
            "a": "T1553.002",
            "c": 0.8500000238418579,
            "d": "PE lacks VS_VERSION_INFO resource",
            "e": [
              "field 'pe.version_info.file_version' does not exist"
            ],
            "i": "objectives/evasion/masquerade/cert::pe-no-version-info-resource",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 4 or fewer sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "objectives/command-and-control/infrastructure/config::max-sections-4",
            "l": 1
          },
          {
            "a": "T1027.007",
            "c": 1.0,
            "d": "WININET.DLL absent from PE import table",
            "e": [
              "pe.import_dll_count = 6.00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::wininet-import-absent",
            "l": 2,
            "m": "B0032"
          },
          {
            "c": 0.8799999952316284,
            "d": "Sparse function count stub",
            "e": [
              "binary.func_count = 3.00"
            ],
            "i": "well-known/malware/trojan/shellobject/revengerat::sparse-function-stub",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "File is a compiled binary",
            "e": [
              "9514"
            ],
            "i": "metadata/binary/framework::is-binary",
            "l": 1
          },
          {
            "a": "T1587.001",
            "c": 0.8999999761581421,
            "d": "Allocate virtual memory",
            "e": [
              "VirtualAlloc"
            ],
            "i": "micro-behaviors/mem/protect/modify::virtual-alloc",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has low average string entropy",
            "e": [
              "binary.avg_string_entropy = 2.80"
            ],
            "i": "metadata/binary/metrics/threshold::avg-string-entropy-4-max",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "CompanyName field absent from PE version info",
            "e": [
              "field 'pe.version_info.company_name' does not exist"
            ],
            "i": "metadata/binary/anomaly/format::version-info-company-name-absent",
            "l": 1
          },
          {
            "a": "T1036.005",
            "c": 0.9700000286102295,
            "d": "PE has no Authenticode signature",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "objectives/evasion/masquerade/version-resource/microsoft-utility::dw20-host-unsigned",
            "l": 1,
            "m": "F0004"
          },
          {
            "c": 1.0,
            "d": "Binary has low average complexity",
            "e": [
              "binary.avg_complexity = 9.33"
            ],
            "i": "metadata/binary/metrics/threshold::avg-complexity-15-max",
            "l": 2
          },
          {
            "a": "T1055.012",
            "c": 1.0,
            "d": "Lacks substantial resources",
            "e": [
              "binary.rsrc_to_file_ratio = 0.00"
            ],
            "i": "objectives/evasion/process/injection/hollowing::lacks-substantial-resources",
            "l": 1,
            "m": "E1055.012"
          },
          {
            "c": 0.8999999761581421,
            "d": "PE mapped image under 768 KiB",
            "e": [
              "pe.size_of_image = 28672.00"
            ],
            "i": "metadata/binary/layout::image-under-768kb",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "DEP / NX enabled (NX_COMPAT)",
            "e": [
              "true"
            ],
            "i": "metadata/hardening/mitigation::pe-dep",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE has low overall entropy",
            "e": [
              "binary.overall_entropy = 3.55"
            ],
            "i": "metadata/binary/layout::low-overall-entropy",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Reference to USER32.dll",
            "e": [
              "USER32.dll"
            ],
            "i": "micro-behaviors/os/module/load::user32-dll-reference",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Free virtual memory",
            "e": [
              "VirtualFree"
            ],
            "i": "micro-behaviors/mem/protect/modify::virtual-free",
            "l": 2
          },
          {
            "a": "T1222.001",
            "c": 0.949999988079071,
            "d": "Modify memory page protection",
            "e": [
              "VirtualProtect"
            ],
            "i": "micro-behaviors/mem/protect/modify::virtual-protect",
            "l": 2,
            "m": "C0021"
          },
          {
            "a": "T1027",
            "c": 0.8999999761581421,
            "d": "VB6 binary with very few strings",
            "e": [
              "binary.string_count = 40.00"
            ],
            "i": "objectives/anti-static/obfuscation/payload/string-sparse::low-string-count-vb6",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.9900000095367432,
            "d": "WINHTTP.dll string",
            "e": [
              "WINHTTP.dll"
            ],
            "i": "objectives/command-and-control/dropper/elex-loader::winhttp-dll-string",
            "l": 1
          },
          {
            "d": ".dll extension reference",
            "e": [
              ".dll"
            ],
            "i": "micro-behaviors/fs/path/extension::dll-dup",
            "l": 2
          },
          {
            "c": 0.75,
            "d": "Binary exports no symbols",
            "e": [
              "binary.export_count = 0.00"
            ],
            "i": "metadata/binary/symbols/exports::no-exports",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Small PE resource section",
            "e": [
              "pe.rsrc_size = 0.00"
            ],
            "i": "metadata/package/versioning::pe-small-rsrc",
            "l": 1
          },
          {
            "c": 0.8799999952316284,
            "d": "Small string table footprint",
            "e": [
              "binary.string_count = 40.00"
            ],
            "i": "well-known/malware/trojan/shellobject/revengerat::tiny-string-table",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "PE checksum field not set",
            "e": [
              "pe.has_checksum = 0.00"
            ],
            "i": "metadata/binary/layout::pe-checksum-absent",
            "l": 1
          },
          {
            "a": "T1106",
            "c": 0.8999999761581421,
            "d": "FFI GetProcAddress API name",
            "e": [
              "GetProcAddress"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::ffi-getprocaddress-api",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE Rich header present (MSVC toolchain)",
            "e": [
              "pe.has_rich_header = 1.00"
            ],
            "i": "metadata/binary/resource::rich-header-present",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Binary has low overall entropy",
            "e": [
              "binary.overall_entropy = 3.55"
            ],
            "i": "metadata/binary/metrics/threshold::low-overall-entropy-binary",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "UPX0 section name",
            "e": [
              "UPX0"
            ],
            "i": "metadata/binary/section/names::upx0-section-name",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Direct NT API access",
            "e": [
              "ntdll.dll"
            ],
            "i": "micro-behaviors/os/syscall/invoke::ntdll-import",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "VirtualProtect symbol",
            "e": [
              "VirtualProtect"
            ],
            "i": "objectives/anti-static/obfuscation/reflection/class::virtualprotect-sym",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.800000011920929,
            "d": "UPX section naming marker",
            "e": [
              "UPX0",
              "UPX2",
              "UPX1"
            ],
            "i": "objectives/anti-static/obfuscation/payload/encrypted::upx-section-marker",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1562.001",
            "c": 1.0,
            "d": "ntdll.dll string reference",
            "e": [
              "ntdll.dll"
            ],
            "i": "objectives/evasion/anti-av/platform/defender::ntdll-dll-str",
            "l": 1
          },
          {
            "a": "T1612",
            "c": 0.8500000238418579,
            "d": "PE has few icon resources",
            "e": [
              "pe.icon_count = 0.00"
            ],
            "i": "objectives/anti-static/obfuscation/payload/resource::icon-count-under-six",
            "l": 1,
            "m": "B0023"
          },
          {
            "a": "T1105",
            "c": 0.800000011920929,
            "d": "Compact PE import table",
            "e": [
              "binary.import_count = 11.00"
            ],
            "i": "objectives/command-and-control/dropper/delivery/download-execute::compact-import-table",
            "l": 1,
            "m": "E1105"
          },
          {
            "c": 0.8999999761581421,
            "d": "Tiny C string section ratio",
            "e": [
              " = 0.0% of total (0 / 4096 bytes)"
            ],
            "i": "metadata/binary/section/metrics::tiny-cstring-section",
            "l": 1
          },
          {
            "c": 0.6000000238418579,
            "d": "Very few sections (merged/stripped)",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "metadata/binary/metrics/structural::few-sections",
            "l": 3
          },
          {
            "a": "T1027",
            "c": 0.8600000143051147,
            "d": "Long mixed-case identifiers cluster",
            "e": [
              "CreateStreamOnHGlobal"
            ],
            "i": "objectives/anti-static/obfuscation/string/junking::long-mixedcase-identifiers",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1027.007",
            "c": 0.8600000143051147,
            "d": "PE API hashing indicator present",
            "e": [
              "pe.api_hashing_indicator_count = 1.00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::pe-api-hashing-indicator-single",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "c": 0.9599999785423279,
            "d": "Empty RWX UPX0 decoy section",
            "e": [
              "UPX0 (size: 0, perms: rwx)"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::empty-rwx-upx0",
            "l": 1
          },
          {
            "a": "T1027.007",
            "c": 1.0,
            "d": "ntdll.dll as wide string (runtime resolver)",
            "e": [
              "ntdll.dll"
            ],
            "i": "objectives/anti-static/obfuscation/string/runtime-decrypt::ntdll-wide-string",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "c": 0.8999999761581421,
            "d": "Resolve exports with GetProcAddress",
            "e": [
              "GetProcAddress"
            ],
            "i": "micro-behaviors/os/module/load::get-proc-address-import",
            "l": 2
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "GetProcAddress loader API string",
            "e": [
              "GetProcAddress"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-getprocaddress-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "a": "T1027",
            "c": 0.800000011920929,
            "d": "Few PE resource entries (no DIALOG/MENU/STRINGTABLE)",
            "e": [
              "pe.resource_count = 0.00"
            ],
            "i": "objectives/evasion/anti-av/heuristic::minimal-pe-resources",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "UPX packed section name",
            "e": [
              "UPX0",
              "UPX1",
              "UPX2"
            ],
            "i": "metadata/binary/section/names::upx-section",
            "l": 2,
            "m": "F0001.008"
          },
          {
            "c": 0.800000011920929,
            "d": "UPX packer marker string",
            "e": [
              "UPX0",
              "UPX1"
            ],
            "i": "objectives/anti-static/pack/detect::upx-marker",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary is not digitally signed",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed/trust-level::unsigned",
            "l": 3
          },
          {
            "a": "T1070.006",
            "c": 0.699999988079071,
            "d": "PE timestamp anomaly detected",
            "e": [
              "pe.timestamp_anomaly = 1.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::timestamp-anomaly",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "ASLR bit not set in DLL Characteristics",
            "e": [
              "pe.dll_characteristics = 33024.00"
            ],
            "i": "metadata/hardening/mitigation::no-aslr-bit",
            "l": 1
          },
          {
            "a": "T1070.006",
            "c": 0.8999999761581421,
            "d": "Export timestamp is absent",
            "e": [
              "pe.has_export_timestamp = 0.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::export-timestamp-absent",
            "l": 2
          },
          {
            "a": "T1587.001",
            "c": 0.8999999761581421,
            "d": "VirtualAlloc API string reference",
            "e": [
              "VirtualAlloc"
            ],
            "i": "micro-behaviors/mem/protect/modify::virtual-alloc-string",
            "l": 1
          },
          {
            "a": "T1055",
            "c": 0.9200000166893005,
            "d": "Regex component marker",
            "e": [
              "binary.import_count = 11.00"
            ],
            "i": "objectives/evasion/process/injection/vb6::vb6-process-injection-pattern-cond-1--inline-17571",
            "l": 1,
            "m": "C0041"
          },
          {
            "c": 0.800000011920929,
            "d": "PE executable is unsigned",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed/trust-level::unsigned-pe-executable",
            "l": 3
          },
          {
            "a": "T1027",
            "c": 0.8500000238418579,
            "d": "Regex component marker",
            "e": [
              "UPX0",
              "UPX1",
              "UPX2"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::packed-loader-largest-section-benign-cond-7--inline-29169",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.949999988079071,
            "d": "links KERNEL32.DLL (LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ... +1 more)",
            "e": [
              "KERNEL32.DLL"
            ],
            "i": "metadata/dylib::kernel32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links ADVAPI32.dll (CryptHashData)",
            "e": [
              "ADVAPI32.dll"
            ],
            "i": "metadata/dylib::advapi32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links ntdll.dll (wtoi)",
            "e": [
              "ntdll.dll"
            ],
            "i": "metadata/dylib::ntdll/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links USER32.dll (wsprintfA)",
            "e": [
              "USER32.dll"
            ],
            "i": "metadata/dylib::user32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links WINHTTP.dll (WinHttpOpen)",
            "e": [
              "WINHTTP.dll"
            ],
            "i": "metadata/dylib::winhttp/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links ole32.dll (CreateStreamOnHGlobal)",
            "e": [
              "ole32.dll"
            ],
            "i": "metadata/dylib::ole32/dll",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Modern PE without ASLR enabled",
            "e": [
              "pe.dll_characteristics = 33024.00",
              "pe.timestamp = 1839644021.00"
            ],
            "i": "metadata/hardening/mitigation::modern-pe-without-aslr",
            "l": 3
          },
          {
            "c": 0.949999988079071,
            "d": "UPX0 and UPX1 section pair",
            "e": [
              "UPX0",
              "UPX1"
            ],
            "i": "well-known/malware/trojan/shellobject/strings::misleading-upx-sections",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "UPX0 and UPX1 section pair",
            "e": [
              "UPX0",
              "UPX1"
            ],
            "i": "metadata/binary/section/names::upx-section-pair",
            "l": 2
          },
          {
            "a": "T1027.002",
            "c": 0.949999988079071,
            "d": "UPX dynamic loader stub",
            "e": [
              "UPX0",
              "VirtualProtect",
              "GetProcAddress",
              "VirtualAlloc",
              "binary.func_count = 3.00",
              "pe.entry_in_nonstandard_section = 1.00",
              "UPX1",
              "VirtualFree"
            ],
            "i": "objectives/anti-static/pack/detect::upx-dynamic-loader-stub",
            "l": 3,
            "m": "F0001"
          }
        ],
        "sha": "878e44bc394d185cd0caf217e620f381fb7a34e4caef980e48a80a92f02f5d8b",
        "path": "9514",
        "type": "pe"
      }
    ],
    "tv": "4872c"
  }
}