{
  "ml": {
    "v": "4",
    "fs": [
      {
        "id": 0,
        "prob": 0.944420337677002,
        "class": 0
      }
    ],
    "prob": 0.94442034,
    "class": 0,
    "version": "v16.16",
    "thresholds": [
      0.9815004,
      0.99404883
    ],
    "analyzed_at": "2026-04-30T08:09:02Z"
  },
  "path": "EVP_MD-MD4.7",
  "raw": {
    "v": "4",
    "fs": [
      {
        "f": "O₂(As₂S)Md(Pa)",
        "x": 1,
        "id": 0,
        "is": [
          "C.SH.IX.All.PP"
        ],
        "ms": {
          "text": {
            "digit_ratio": 0.03,
            "space_count": 370.0,
            "total_lines": 86.0,
            "char_entropy": 5.17,
            "unique_chars": 82.0,
            "import_density": 1.16,
            "string_density": 0.67,
            "ascii_art_lines": 2.0,
            "avg_line_length": 27.45,
            "max_line_length": 77.0,
            "last_line_length": 46.0,
            "most_common_char": "e",
            "whitespace_ratio": 0.19,
            "most_common_ratio": 0.06,
            "identifier_density": 0.77,
            "line_length_stddev": 24.78,
            "normalized_import_count": 0.11,
            "normalized_string_count": 6.25,
            "repeated_char_sequences": 4.0,
            "suspicious_string_ratio": 0.05,
            "max_inline_whitespace_run": 12.0,
            "suspicious_identifier_ratio": 0.13,
            "normalized_unique_identifiers": 8.4
          },
          "imports": {
            "total": 1.0,
            "unique_modules": 1.0,
            "third_party_count": 1.0,
            "third_party_ratio": 1.0
          },
          "strings": {
            "total": 58.0,
            "avg_length": 57.14,
            "max_length": 1577.0,
            "avg_entropy": 2.57,
            "sql_strings": 1.0,
            "total_bytes": 3314.0,
            "entropy_stddev": 1.41,
            "very_long_strings": 1.0,
            "high_entropy_count": 1.0,
            "shell_command_strings": 2.0
          },
          "comments": {},
          "functions": {},
          "identifiers": {
            "total": 66.0,
            "avg_length": 4.72,
            "max_length": 13.0,
            "min_length": 1.0,
            "avg_entropy": 1.79,
            "reuse_ratio": 0.82,
            "unique_count": 54.0,
            "length_stddev": 2.92,
            "sequential_names": 6.0,
            "single_char_count": 6.0,
            "single_char_ratio": 0.11,
            "all_lowercase_ratio": 0.57,
            "all_uppercase_ratio": 0.09,
            "repeated_char_names": 1.0
          }
        },
        "ss": [
          [
            218,
            " Vertical space (when we can't use .PP)"
          ],
          [
            294,
            " Begin verbatim text"
          ],
          [
            347,
            " End verbatim text"
          ],
          [
            387,
            " and \\*(C' are quotes in nroff, nothing in troff, for use with C\u003c\u003e.\n.ie n \\{\\\n.    ds C"
          ],
          [
            388,
            " and "
          ],
          [
            395,
            "(C' are quotes in nroff, nothing in troff, for use with C\u003c\u003e.\n.ie n "
          ],
          [
            466,
            ".    ds C"
          ],
          [
            489,
            " \"\"\n"
          ],
          [
            490,
            " "
          ],
          [
            516,
            "\n.    ds C'\n'br\\}\n.\\\"\n.\\\" Escape single quotes in literal strings from groff's Unicode transform.\n.ie \\n(.g .ds Aq \\(aq\n.el     "
          ],
          [
            517,
            "\n.    ds C'\n'br"
          ],
          [
            534,
            "\n."
          ],
          [
            538,
            "\n."
          ],
          [
            542,
            " Escape single quotes in literal strings from groff's Unicode transform.\n.ie "
          ],
          [
            621,
            "(.g .ds Aq "
          ],
          [
            634,
            "aq\n.el       .ds Aq '\n."
          ],
          [
            659,
            "\n."
          ],
          [
            663,
            " If the F register is \u003e0, we'll generate index entries on stderr for\n."
          ],
          [
            735,
            " titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index\n."
          ],
          [
            810,
            " entries marked with X\u003c\u003e in POD.  Of course, you'll have to process the\n."
          ],
          [
            885,
            " output yourself in some meaningful fashion.\n."
          ],
          [
            933,
            "\n."
          ],
          [
            937,
            " Avoid warning from groff about undefined register 'F'.\n.de IX\n..\n.nr rF 0\n.if "
          ],
          [
            1018,
            "(.g .if rF .nr rF 1\n.if ("
          ],
          [
            1045,
            "(rF:("
          ],
          [
            1052,
            "(.g==0)) "
          ],
          [
            1065,
            ".    if "
          ],
          [
            1075,
            "F "
          ],
          [
            1081,
            ".        de IX\n.        tm Index:"
          ],
          [
            1116,
            "$1"
          ],
          [
            1122,
            "n%"
          ],
          [
            1129,
            "$2\"\n..\n.        if !"
          ],
          [
            1151,
            "F==2 "
          ],
          [
            1160,
            ".            nr % 0\n.            nr F 2\n.        "
          ],
          [
            1211,
            "\n.    "
          ],
          [
            1219,
            "\n."
          ],
          [
            1223,
            "\n.rr rF\n."
          ],
          [
            1234,
            " ========================================================================\n."
          ],
          [
            1311,
            "\n.IX Title \"EVP_MD-MD4 7ossl\"\n.TH EVP_MD-MD4 7ossl 2025-09-30 3.5.4 OpenSSL\n."
          ],
          [
            1390,
            " For nroff, turn off justification.  Always turn off hyphenation; it makes\n."
          ],
          [
            1468,
            " way too many mistakes in technical documents.\n.if n .ad l\n.nh\n.SH NAME\nEVP_MD"
          ],
          [
            1548,
            "MD4 "
          ],
          [
            1554,
            " The MD4 EVP_MD implementation\n.SH DESCRIPTION\n.IX Header \"DESCRIPTION\"\nSupport for computing MD4 digests through the "
          ],
          [
            1674,
            "BEVP_MD"
          ],
          [
            1683,
            "R API.\n.SS Identity\n.IX Subsection \"Identity\"\nThis implementation is only available with the legacy provider, and is\nidentified "
          ],
          [
            1970,
            "BEVP_MD"
          ],
          [
            1979,
            "common"
          ],
          [
            1987,
            "R"
          ],
          [
            1990,
            "(7).\n.SH \"SEE ALSO\"\n.IX Header \"SEE ALSO\"\n"
          ],
          [
            2036,
            "Bprovider"
          ],
          [
            2047,
            "digest"
          ],
          [
            2055,
            "R"
          ],
          [
            2058,
            "(7), "
          ],
          [
            2065,
            "BOSSL_PROVIDER"
          ],
          [
            2081,
            "default"
          ],
          [
            2090,
            "R"
          ],
          [
            2246,
            "License"
          ],
          [
            2247,
            "License"
          ]
        ],
        "sz": 2447,
        "ts": [
          {
            "c": 0.8999999761581421,
            "d": "Unix manual page or bundled manpage example",
            "e": [
              "EVP_MD-MD4.7"
            ],
            "i": "metadata/package/documentation::unix-manpage",
            "l": 2
          },
          {
            "c": 0.20000000298023224,
            "d": "output keyword",
            "e": [
              "output"
            ],
            "i": "micro-behaviors/data/text/keywords::output",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Path-like string pattern",
            "e": [
              "x:\\\\$1\\t\\\\n%\\t\"\\\\$2\""
            ],
            "i": "micro-behaviors/data/text/malware::path-like-pattern",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "File has 30 or more lines",
            "e": [
              "text.total_lines = 86.00"
            ],
            "i": "metadata/package/metrics::file-has-30-plus-lines",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.8999999761581421,
            "d": "Low string density base64 context",
            "e": [
              "text.string_density = 0.67"
            ],
            "i": "objectives/anti-static/obfuscation/code-metrics::js-base64-candidate-low-string-density",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.30000001192092896,
            "d": "stderr string reference",
            "e": [
              "\n.    ds C'\n'br\\}\n.\\\"\n.\\\" Escape single quotes in literal strings from groff's Unicode transform.\n.ie \\n(.g .ds Aq \\(aq\n.el     ",
              " If the F register is \u003e0, we'll generate index entries on stderr for\n."
            ],
            "i": "micro-behaviors/process/fd/stdio::stderr-string",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.6000000238418579,
            "d": "No comments in code",
            "e": [
              "comments.total = 0.00"
            ],
            "i": "objectives/anti-static/obfuscation/code-metrics/structure::no-comments",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1027",
            "c": 0.800000011920929,
            "d": "Sequential identifiers (a, b, c,",
            "e": [
              "identifiers.sequential_names = 6.00"
            ],
            "i": "objectives/anti-static/obfuscation/code-metrics/identifiers::sequential-identifiers",
            "l": 2,
            "m": "B0032"
          },
          {
            "c": 0.699999988079071,
            "d": "Small file under 5KB",
            "e": [
              "EVP_MD-MD4.7"
            ],
            "i": "objectives/supply-chain/metadata-anomaly/markers/npm::small-file-5k",
            "l": 1
          }
        ],
        "sha": "b63397cd8b56e3cb8aecc4f012a65e1f08c293f78ac750ccaed015e4240e9064",
        "path": "/data/samples/good/freebsd/usr/src/secure/lib/libcrypto/man/man7/EVP_MD-MD4.7",
        "type": "javascript"
      }
    ],
    "tv": "f6eaa"
  }
}