{
  "ml": {
    "v": "4",
    "fs": [
      {
        "id": 0,
        "prob": 0.9999905824661255,
        "class": 2
      },
      {
        "id": 1,
        "prob": 0.9999853372573853,
        "class": 2
      }
    ],
    "prob": 0.9999906,
    "class": 2,
    "models": [
      {
        "m": "az",
        "prob": 0.99992526,
        "class": 2
      },
      {
        "m": "az/native",
        "prob": 0.9999906,
        "class": 2
      },
      {
        "m": "az/pe",
        "prob": 0.9999901,
        "class": 2
      }
    ],
    "version": "v16.16",
    "thresholds": [
      0.9953178,
      0.9991311
    ],
    "analyzed_at": "2026-05-02T22:08:04Z"
  },
  "path": "479505",
  "raw": {
    "v": "4",
    "fs": [
      {
        "f": "K₃O₁₁(C₁₃Ca₅SAs₇Co₂I₅P₅XeDy₂Er₃Pr₂)H₈(Cm₃Db₃Ds₂FOs₄PoTiU)Md₅(Bi₄Pa)Th₄",
        "x": 633,
        "id": 0,
        "is": [
          "CIcos",
          "adj_fptan",
          "vbaVarMove",
          "vbaVarVargNofree",
          "vbaFreeVar",
          "vbaAryMove",
          "vbaLenBstr",
          "vbaStrVarMove",
          "vbaFreeVarList",
          "vbaEnd",
          "adj_fdiv_m64",
          "vbaFpCDblR8",
          "vbaNextEachVar",
          "vbaFreeObjList",
          "ORDINAL 516",
          "adj_fprem1",
          "vbaRecAnsiToUni",
          "ORDINAL 626",
          "vbaResume",
          "vbaStrCat",
          "vbaRecDestruct",
          "vbaSetSystemError",
          "vbaHresultCheckObj",
          "adj_fdiv_m32",
          "vbaAryVar",
          "ORDINAL 667",
          "vbaAryDestruct",
          "vbaBoolStr",
          "vbaExitProc",
          "vbaOnError",
          "vbaObjSet",
          "adj_fdiv_m16i",
          "vbaObjSetAddref",
          "adj_fdivr_m16i",
          "ORDINAL 598",
          "vbaFPFix",
          "vbaBoolVarNull",
          "CIsin",
          "ORDINAL 709",
          "ORDINAL 631",
          "vbaVarZero",
          "vbaChkstk",
          "vbaFileClose",
          "EVENT_SINK_AddRef",
          "ORDINAL 528",
          "vbaGenerateBoundsError",
          "vbaStrCmp",
          "vbaVarTstEq",
          "vbaR4Str",
          "DllFunctionCall",
          "vbaLbound",
          "adj_fpatan",
          "vbaRedim",
          "vbaRecUniToAnsi",
          "EVENT_SINK_Release",
          "ORDINAL 600",
          "CIsqrt",
          "vbaVarAnd",
          "EVENT_SINK_QueryInterface",
          "vbaExceptHandler",
          "ORDINAL 711",
          "vbaStrToUnicode",
          "ORDINAL 712",
          "ORDINAL 606",
          "adj_fprem",
          "adj_fdivr_m64",
          "vbaFPException",
          "ORDINAL 717",
          "vbaUbound",
          "vbaGetOwner3",
          "vbaVarCat",
          "ORDINAL 537",
          "CIlog",
          "vbaFileOpen",
          "vbaInStr",
          "vbaVarLateMemCallLdRf",
          "vbaNew2",
          "vbaVar2Vec",
          "ORDINAL 570",
          "adj_fdiv_m32i",
          "adj_fdivr_m32i",
          "vbaStrCopy",
          "vbaFreeStrList",
          "adj_fdivr_m32",
          "adj_fdiv_r",
          "ORDINAL 685",
          "ORDINAL 100",
          "vbaVarTstNe",
          "vbaAryLock",
          "vbaVarDup",
          "vbaStrToAnsi",
          "vbaVarLateMemCallLd",
          "ORDINAL 616",
          "vbaFpI4",
          "vbaRecDestructAnsi",
          "CIatan",
          "vbaStrMove",
          "vbaAryCopy",
          "vbaUI1Str",
          "vbaForEachVar",
          "vbaStrVarCopy",
          "allmul",
          "CItan",
          "vbaAryUnlock",
          "CIexp",
          "vbaFreeStr",
          "vbaFreeObj",
          "ORDINAL 580"
        ],
        "ms": {
          "pe": {
            "machine": 332.0,
            "checksum": 54098.0,
            "pdb_path": "C:\\Users\\World\\Desktop\\duck\\Zbw138ht2aeja2.pdb",
            "rsrc_size": 4096.0,
            "subsystem": 2.0,
            "timestamp": 1504708224.0,
            "image_base": 4194304.0,
            "codeview_age": 10.0,
            "rsrc_entropy": 2.45,
            "codeview_guid": "59b0038d",
            "entry_section": ".text",
            "size_of_image": 49152.0,
            "timestamp_day": 6.0,
            "file_alignment": 4096.0,
            "resource_count": 2.0,
            "timestamp_year": 2017.0,
            "characteristics": 271.0,
            "entry_point_rva": 5656.0,
            "size_of_headers": 4096.0,
            "timestamp_month": 9.0,
            "checksum_present": true,
            "export_timestamp": 0.0,
            "import_dll_count": 1.0,
            "checksum_mismatch": true,
            "computed_checksum": 2759177.0,
            "section_alignment": 4096.0,
            "unusual_alignment": true,
            "number_of_sections": 3.0,
            "resource_timestamp": 0.0,
            "debug_timestamp_max": 1504708224.0,
            "debug_timestamp_min": 1504708224.0,
            "rich_header_present": true,
            "linker_major_version": 6.0,
            "version_info_present": true,
            "debug_directory_types": [
              2.0
            ],
            "debug_directory_entries": 1.0,
            "export_timestamp_present": false,
            "debug_timestamp_consistent": true,
            "resource_timestamp_present": false,
            "debug_timestamp_unique_count": 1.0,
            "debug_timestamp_nonzero_count": 1.0
          },
          "binary": {
            "code_size": 36864.0,
            "file_size": 2738736.0,
            "entry_point": 5656.0,
            "has_overlay": true,
            "code_entropy": 5.66,
            "import_count": 108.0,
            "overlay_size": 2689584.0,
            "string_count": 6927.0,
            "overlay_ratio": 0.98,
            "section_count": 3.0,
            "avg_complexity": 5.28,
            "function_count": 43.0,
            "import_density": 3.0,
            "max_complexity": 60.0,
            "string_density": 192.42,
            "overall_entropy": 2.7,
            "overlay_entropy": 7.67,
            "avg_basic_blocks": 10.4,
            "avg_section_size": 15018.67,
            "dependency_count": 1.0,
            "entropy_variance": 2.32,
            "function_density": 1.19,
            "avg_function_size": 306.7,
            "avg_string_length": 14.02,
            "complexity_per_kb": 0.15,
            "max_string_length": 869.0,
            "wide_string_count": 58.0,
            "writable_sections": 1.0,
            "avg_string_entropy": 2.88,
            "code_to_data_ratio": 4.5,
            "data_to_file_ratio": 0.0,
            "entry_point_is_rva": true,
            "rsrc_to_file_ratio": 0.0,
            "text_to_file_ratio": 0.01,
            "total_basic_blocks": 447.0,
            "embedded_file_count": 1.0,
            "executable_sections": 1.0,
            "high_entropy_strings": 8.0,
            "string_length_stddev": 31.67,
            "debug_reference_count": 1.0,
            "embedded_binary_count": 1.0,
            "largest_section_ratio": 0.01,
            "sentence_string_count": 97.0,
            "sentence_string_ratio": 0.01,
            "function_analysis_depth": 2.0,
            "high_complexity_functions": 1.0
          }
        },
        "ss": [
          [
            77,
            "!This program cannot be run in DOS mode."
          ],
          [
            168,
            "Richya"
          ],
          [
            448,
            ".text"
          ],
          [
            528,
            ".rsrc"
          ],
          [
            5724,
            "Sample AddIn Project"
          ],
          [
            6516,
            "Zbw138ht2aeja2"
          ],
          [
            8816,
            "shola"
          ],
          [
            8860,
            "MSVBVM60"
          ],
          [
            8940,
            "kernel32"
          ],
          [
            8956,
            "VirtualProtect"
          ],
          [
            9044,
            "LoadLibraryA"
          ],
          [
            9116,
            "GetProcAddress"
          ],
          [
            9188,
            "SetProcessDEPPolicy"
          ],
          [
            9348,
            "wide",
            "USERPROFILE"
          ],
          [
            9412,
            "wide",
            "IntallingFonts.exe"
          ],
          [
            9532,
            "CreateWaitableTimerA"
          ],
          [
            9628,
            "OpenWaitableTimerA"
          ],
          [
            9704,
            "SetWaitableTimer"
          ],
          [
            9780,
            "CancelWaitableTimer"
          ],
          [
            9856,
            "CloseHandle"
          ],
          [
            9924,
            "WaitForSingleObject"
          ],
          [
            10000,
            "user32"
          ],
          [
            10012,
            "GetComputerNameA"
          ],
          [
            10036,
            "MsgWaitForMultipleObjects"
          ],
          [
            10164,
            "shell32.dll"
          ],
          [
            10180,
            "ShellExecuteExA"
          ],
          [
            10252,
            "advapi32.dll"
          ],
          [
            10272,
            "RegCreateKeyA"
          ],
          [
            10344,
            "RegSetValueExA"
          ],
          [
            10416,
            "RegCloseKey"
          ],
          [
            10540,
            "wide",
            "SandboxieDcomLaunch.exe"
          ],
          [
            10592,
            "wide",
            "SandboxieRpcSs.exe"
          ],
          [
            10752,
            "C:\\Program Files (x86)\\Microsoft Visual Studio\\VB98\\VB6.OLB"
          ],
          [
            10908,
            "Form"
          ],
          [
            10940,
            "DownloadFile"
          ],
          [
            11080,
            "VBA6.DLL"
          ],
          [
            11108,
            "__vbaExitProc"
          ],
          [
            11124,
            "__vbaResume"
          ],
          [
            11140,
            "wide",
            "NB8FNB7CNB3CNBA5NB1ENB34NBA3NBB5NB9FNBF5NBFANBFANBDBNB1CNB43NBB7NB9FNBF5NB2ANB3CNBD0NBDDNBF0NBC8NB8FNBF4NB06NBA5NB76NBE4NB70NBB5"
          ],
          [
            11948,
            "wide",
            "NB8FNB0ANB06NBB9NB60NB25NBF0NB4DNB9ENBFANBF6NB85NB60NB0ANB8CNB3ENBD0NBE1NB9ANB5CNB9ENBF5NB73NBEFNB77NB63NB72NBB5NB9FNB0ANB04NBB1"
          ],
          [
            12756,
            "wide",
            "NB9FNB7ENB7CNB4ANBEENBA1NB8CNBC0NB97NB0ANB04NBB1NB14NBA2NB7BNB4ANBADNB0ANBA3NB36NB67NBF5NB7CNB30NB88NBF4NB73NBB5NB14NBE2NB15NB3E"
          ],
          [
            13564,
            "wide",
            "NB9FNB88NBCENB3ENBD0NBE5NBB4NBB4NB98NBF5NB72NBB5NB14NBBANB67NB5CNB1FNBF4NB73NBB5NBC5NB1DNBA2NBB5NB9FNBF5NB8CNBC2NB8FNB7ENB24NBBD"
          ],
          [
            14372,
            "wide",
            "NBB7NB7CNB78NB3ENBD0NBE1NB9ANB88NB9ENBF5NB73NBEFNB77NB83NB73NBB5NB9FNB0ANB04NBA5NB14NBA2NB7BNB4ANBEDNBF1NB8CNB65NB1CNB0DNB73NBC0"
          ],
          [
            15180,
            "wide",
            "NB1CNB37NB7BNB3ENB9DNB3CNBB0NB3ENBD0NBDDNB9ANBB4NB9ENBF5NB73NBEFNB77NBFBNB73NBB5NB9FNB9FNB73NB3ENBC8NBFDNB8CNB87NB60NB25NB9ANB39"
          ],
          [
            15988,
            "wide",
            "NBFENB81NB16NBE5NBEDNB9ANB10NBD0NBECNB86NB24NBB5NB77NBE7NB8DNB4ANB60NBBBNB07NBE0NBF1NB98NB12NBC5NBC9NB9CNB16NBC2NBD0NB93NB20NBD0"
          ],
          [
            16796,
            "wide",
            "NBF0NB87NB0ANBB5NB77NB8ENB8DNB4ANB60NBBBNB07NBF2NBFANB81NB30NBDANBF1NB81NB16NBCDNBEBNBA1NB1BNBC7NBFANB94NB17NBB5NB77NB4BNB8DNB4A"
          ],
          [
            17604,
            "wide",
            "NBFANB81NB36NBCDNBF6NB81NB30NBDANBFBNB90NB23NBC7NBF0NB96NB16NBC6NBECNBF5NB9BNB5FNB63NB0ANB8CNBF2NBFANB81NB30NBDANBF2NB98NB12NBDB"
          ],
          [
            18172,
            "__vbaOnError"
          ],
          [
            18204,
            "__vbaFileClose"
          ],
          [
            18220,
            "__vbaGetOwner3"
          ],
          [
            18236,
            "__vbaFileOpen"
          ],
          [
            18252,
            "__vbaUbound"
          ],
          [
            18264,
            "__vbaLbound"
          ],
          [
            18288,
            "__vbaLenBstr"
          ],
          [
            18316,
            "__vbaEnd"
          ],
          [
            18328,
            "__vbaRedim"
          ],
          [
            18340,
            "__vbaStrCopy"
          ],
          [
            18356,
            "__vbaAryDestruct"
          ],
          [
            18376,
            "__vbaObjSetAddref"
          ],
          [
            18428,
            "__vbaBoolVarNull"
          ],
          [
            18448,
            "__vbaBoolStr"
          ],
          [
            18464,
            "__vbaAryUnlock"
          ],
          [
            18480,
            "__vbaGenerateBoundsError"
          ],
          [
            18508,
            "__vbaAryLock"
          ],
          [
            18540,
            "__vbaAryMove"
          ],
          [
            18556,
            "__vbaFreeVarList"
          ],
          [
            18588,
            "__vbaAryCopy"
          ],
          [
            18620,
            "__vbaSetSystemError"
          ],
          [
            18640,
            "__vbaFreeObj"
          ],
          [
            18656,
            "__vbaFreeStrList"
          ],
          [
            18676,
            "__vbaFreeVar"
          ],
          [
            18708,
            "wide",
            "Timer"
          ],
          [
            18732,
            "__vbaFreeStr"
          ],
          [
            18748,
            "__vbaHresultCheckObj"
          ],
          [
            18784,
            "__vbaStrMove"
          ],
          [
            18816,
            "__vbaFPFix"
          ],
          [
            18848,
            "wide",
            "SOFTWARE\\MICROSOFT\\WINDOWS\\CURRENTVERSION\\RUN"
          ],
          [
            18944,
            "wide",
            "Photo \u0026 Images Viewer"
          ],
          [
            18992,
            "wide",
            "Success"
          ],
          [
            19040,
            "__vbaStrToUnicode"
          ],
          [
            19060,
            "__vbaVarMove"
          ],
          [
            19080,
            "wide",
            "Schtasks"
          ],
          [
            19104,
            "wide",
            "/Create /SC ONSTART /DELAY 0000:12 /TN TrueTypeFonts /TR %userprofile%\\Documents\\IntallingFonts.exe /F"
          ],
          [
            19324,
            "__vbaRecDestructAnsi"
          ],
          [
            19352,
            "wide",
            "/k %windir%\\System32\\reg.exe ADD HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System /v EnableLUA /t REG_DWORD /d 0 /"
          ],
          [
            19616,
            "wide",
            "runas"
          ],
          [
            19632,
            "wide",
            "Open"
          ],
          [
            19644,
            "__vbaRecDestruct"
          ],
          [
            19708,
            "urlmon"
          ],
          [
            19720,
            "URLDownloadToFileA"
          ],
          [
            19828,
            "wide",
            "3100"
          ],
          [
            19840,
            "__vbaFreeObjList"
          ],
          [
            19876,
            "wide",
            "winmgmts://"
          ],
          [
            19904,
            "wide",
            "win32_process"
          ],
          [
            19932,
            "wide",
            "InstancesOf"
          ],
          [
            19956,
            "wide",
            "Name"
          ],
          [
            19968,
            "__vbaNextEachVar"
          ],
          [
            20036,
            "__vbaVarZero"
          ],
          [
            20068,
            "__vbaVarVargNofree"
          ],
          [
            20222,
            "Text Scroller"
          ],
          [
            21930,
            "UUUT"
          ],
          [
            21993,
            "UUUUT"
          ],
          [
            22053,
            "pUUUUUSS"
          ],
          [
            22122,
            "TSXS"
          ],
          [
            22483,
            "YYPPP[[ss"
          ],
          [
            22613,
            "YPPPPZVV"
          ],
          [
            22677,
            "PPPPYZVV"
          ],
          [
            22688,
            "TUTS"
          ],
          [
            22759,
            "RSTX"
          ],
          [
            22777,
            "gxiSRRw"
          ],
          [
            22807,
            "YPPZZV"
          ],
          [
            22816,
            "TTTSS"
          ],
          [
            22880,
            "TTTSSX"
          ],
          [
            22936,
            "ZPVZV"
          ],
          [
            22944,
            "TUUSXXTX"
          ],
          [
            23008,
            "TTTTSSR"
          ],
          [
            23129,
            "ZZZV"
          ],
          [
            23193,
            "PZZV"
          ],
          [
            23209,
            "QyxiSSSl"
          ],
          [
            23272,
            "QoxiSSS"
          ],
          [
            23391,
            "UTTTxgQ"
          ],
          [
            23402,
            "XXSR"
          ],
          [
            23468,
            "ixyQQQQ"
          ],
          [
            23519,
            "UTTX"
          ],
          [
            23583,
            "UTTSXS"
          ],
          [
            23590,
            "SXSX"
          ],
          [
            23647,
            "UTTSSXXS"
          ],
          [
            23681,
            "a`YPPPPPPYj"
          ],
          [
            23711,
            "UTTS"
          ],
          [
            23745,
            "a`YPPPPPPPYj"
          ],
          [
            23775,
            "UUTS"
          ],
          [
            23809,
            ")`YPPPPPPPPYs"
          ],
          [
            23861,
            "RRRReeq"
          ],
          [
            23877,
            "PPPPPPPPPVY"
          ],
          [
            23903,
            "STTR"
          ],
          [
            23909,
            "dQQQQkg"
          ],
          [
            23943,
            "PPPPPPPPPPPjjjPPPPPPYZ"
          ],
          [
            24009,
            "YPPPPPPPYYYYYPPPPPsZ"
          ],
          [
            24075,
            "YPPPPPjjjjjPPPPPsZ"
          ],
          [
            24141,
            "PPPPPPPPPPPPPPsZ"
          ],
          [
            24207,
            "PPPPPPPPPPPPsZ"
          ],
          [
            24273,
            "YPPPPPPPPPsZ"
          ],
          [
            24287,
            "UTSR"
          ],
          [
            24339,
            "PPPPPPPPsZ"
          ],
          [
            24405,
            "PPPPPPsZ"
          ],
          [
            24805,
            "z__cbc"
          ],
          [
            24938,
            "__cbch"
          ],
          [
            25138,
            "zb}}~c_]]]r"
          ],
          [
            25153,
            "rrnnn}}}nr"
          ],
          [
            25204,
            "_cbbbrrcrrrr]]]]]]_"
          ],
          [
            25270,
            "___cccc]]]]]]h"
          ],
          [
            25966,
            "wide",
            "7Environ$(\"allusersprofile\") \u0026 \"\\\" \u0026 \"TrueTypeFonts.exe\""
          ],
          [
            26180,
            "Edit speed by setting the timer interval"
          ],
          [
            26253,
            "Vote for me please"
          ],
          [
            26298,
            "MS Sans Serif"
          ],
          [
            26331,
            "Some text here"
          ],
          [
            26380,
            "You can edit it's attributes by setting the frame1.top and frame1.left"
          ],
          [
            26483,
            "This is a scrolling text."
          ],
          [
            26796,
            "LocalFilename"
          ],
          [
            27051,
            "LSVW"
          ],
          [
            31051,
            "4SVW"
          ],
          [
            31787,
            "HSVW"
          ],
          [
            39408,
            "MSVBVM60.DLL"
          ],
          [
            39434,
            "_adj_fptan"
          ],
          [
            39656,
            "_adj_fprem1"
          ],
          [
            40012,
            "__vbaChkstk"
          ],
          [
            40044,
            "EVENT_SINK_AddRef"
          ],
          [
            40136,
            "DllFunctionCall"
          ],
          [
            40168,
            "_adj_fpatan"
          ],
          [
            40216,
            "EVENT_SINK_Release"
          ],
          [
            40238,
            "_CIsqrt"
          ],
          [
            40262,
            "EVENT_SINK_QueryInterface"
          ],
          [
            40290,
            "__vbaExceptHandler"
          ],
          [
            40332,
            "_adj_fprem"
          ],
          [
            40346,
            "_adj_fdivr_m64"
          ],
          [
            40364,
            "__vbaFPException"
          ],
          [
            40596,
            "_adj_fdivr_m32"
          ],
          [
            40614,
            "_adj_fdiv_r"
          ],
          [
            40752,
            "_CIatan"
          ],
          [
            40844,
            "_allmul"
          ],
          [
            45428,
            "wide",
            "`NBA5NB9FNBF5NBB4NBB1NBBBNBF5NB63NBB5NB9FNBA1NB19NBB5NB16NB12NB24NBDFNB60NB0ANBA3NB36NB67NBF5NB06"
          ],
          [
            45642,
            "wide",
            "CallWindowProcW"
          ],
          [
            45674,
            "wide",
            "user32"
          ],
          [
            45746,
            "wide",
            "NB64NBA1NB30NB00NB00NB00NB8BNB40NB0CNB8BNB40NB0CNB8BNB70NB28NB0FNBB7NB48NB24NB8BNB7CNB24NB04NB51NBFCNBF3NBA4NB59NB8BNB74NB24NB04"
          ],
          [
            46062,
            "wide",
            "NB55NB89NBE5NBE8NBA4NB03NB00NB00"
          ],
          [
            46130,
            "wide",
            "ALLUSERSPROFILE"
          ],
          [
            46162,
            "wide",
            "MNQWASMUEWQ"
          ],
          [
            46236,
            "wide",
            "SandboxieRpcSs.exe`NB5CNB49NBF7NB73NBB5NBC6NB7CNBB8NB5CNB46NBF7NB73NBB5NBC5NB1DNB12NBB7NB9FNBF5NB23NBDFNBDFNB9DNB73`NB7ANB14NBCA"
          ],
          [
            46858,
            "wide",
            "VS_VERSION_INFO"
          ],
          [
            46950,
            "wide",
            "StringFileInfo"
          ],
          [
            47010,
            "wide",
            "CompanyName"
          ],
          [
            47036,
            "wide",
            "Fantaisie Software"
          ],
          [
            47082,
            "wide",
            "ProductName"
          ],
          [
            47108,
            "wide",
            "PureBasic"
          ],
          [
            47134,
            "wide",
            "ProductVersion"
          ],
          [
            47164,
            "wide",
            "PureBasic 5.31 (Windows - x86) - (c) 2014 Fantaisie Software"
          ],
          [
            47294,
            "wide",
            "FileVersion"
          ],
          [
            47330,
            "wide",
            "FileDescription"
          ],
          [
            47364,
            "wide",
            "PureBasic Development Environment"
          ],
          [
            47438,
            "wide",
            "InternalName"
          ],
          [
            47464,
            "wide",
            "PureBasicIDE"
          ],
          [
            47498,
            "wide",
            "OriginalFilename"
          ],
          [
            47532,
            "wide",
            "PureBasic.exe"
          ],
          [
            47566,
            "wide",
            "LegalCopyright"
          ],
          [
            47596,
            "wide",
            "Copyright (c) 2004 Fantaisie Software"
          ],
          [
            47678,
            "wide",
            "Comment"
          ],
          [
            47696,
            "wide",
            "Build Date:  10/27/2014 - 13:38:31"
          ],
          [
            47774,
            "wide",
            "VarFileInfo"
          ],
          [
            47806,
            "wide",
            "Translation"
          ],
          [
            49152,
            "NB10"
          ],
          [
            49168,
            "C:\\Users\\World\\Desktop\\duck\\Zbw138ht2aeja2.pdb"
          ],
          [
            51216,
            "Begin69.3309724.7745100401.4.1778978.14349Begin67338462642..2586310.521383.485312358Begin83447027787768.2.1333767326105701490.Be"
          ],
          [
            51814,
            "AR@IRB.FS"
          ],
          [
            51828,
            "XPHMXCM"
          ],
          [
            51836,
            "KCCBEYBWA[QAP@IRF.ISIP^@DXPHMXCMWKYCCEY"
          ],
          [
            51876,
            "GAUN"
          ],
          [
            51892,
            "(-+p8?7$?6\u0026y.76=r5${#4\u003e`\u003c\u003c\"K;s"
          ],
          [
            51923,
            ") svUZlzXCMWKYCBUIRWA[QAP@IRF.ISY@N@DXPHMXCMWKYCRUIRWA[QAP@IRF.ICY@N@DXPHMXCMWKYSRUIRWA[QAP@IRF.YCY@N@DXPHMXCMWKISRUIRWA[QAP@IRF"
          ],
          [
            52072,
            "HZWX"
          ],
          [
            52091,
            "OYRQM"
          ],
          [
            52097,
            "EMGS_SRUIR"
          ],
          [
            52117,
            "8YCY"
          ],
          [
            52122,
            "N@TXPHOXCYG[ISRUIVWA[QAP@YrK\u003eYGY@}v[XRHMXS]W[I"
          ],
          [
            52169,
            "RUIRGA[AAPPYBV.YCY@N@DXPHMHCZG"
          ],
          [
            52232,
            "%ISRUIRWA[QQ@PYBV\u003eYCY@N@DXPX"
          ],
          [
            52261,
            "OSEG[ISRUIRWA[AQ@PYBV\u003eYCY@N@DX@X]HS]G[ISRUIRWAKAQ@PYBV}"
          ],
          [
            52333,
            "URUMRWQKAQ@PYBV\u003eYCy@N"
          ],
          [
            52364,
            "HISR"
          ],
          [
            52369,
            "ORGEKAQ"
          ],
          [
            52377,
            "VYBV\u003eYCY@NPTH@"
          ],
          [
            52398,
            "ISRUI"
          ],
          [
            52404,
            "LQKAQGPYBV\u003eY"
          ],
          [
            52444,
            "|BV\u003eIDYPxPTH"
          ],
          [
            52457,
            "^]HS]G[ISREYBG"
          ],
          [
            52489,
            "GX]HS]GYNSBEYBGQKAQ@PYBV\u003e"
          ],
          [
            52529,
            "\\IC@EYBEVKAQ@PYBV\u003eISIP"
          ],
          [
            52617,
            "YPTH@X]HS]WKYC"
          ],
          [
            52635,
            "GQKAQ@PYRF.IS"
          ],
          [
            52657,
            "@SMWKYCBEYBGQK"
          ],
          [
            52675,
            "IRF.ISIP^PTH@X]HCMWKYCBEYBGQKAQ@@IRF.ISIP^PTH@X]XCMWKYCBEYBGQKAQP@IRF.ISIP^PTH@XMXCMWKYCBEYBGQKAAP@IRF.ISIP^PTH@HMXCMWKYCBEYBGQK"
          ],
          [
            52842,
            ")A%6(\u003e_PTXPIMXCMG"
          ],
          [
            53022,
            "MWKYCRUIRWA[QAP@IRF.ICY@N@DXPL\\"
          ],
          [
            53054,
            "CIWKYSRUI"
          ],
          [
            53143,
            "74+2\"93-MXCMF[ISRUIRW"
          ],
          [
            53227,
            "ISWA[QAPPYBV\u003e"
          ],
          [
            53270,
            "BV\u003eYCY@N@DXPH]HS]G[ISRUIR"
          ],
          [
            54774,
            "YBBEY"
          ],
          [
            57086,
            "BUYB87"
          ],
          [
            57326,
            "PGIRF"
          ],
          [
            58474,
            "ARWA"
          ],
          [
            58637,
            "R_IRW"
          ],
          [
            58680,
            "k\\^PyY6uiS\\R"
          ],
          [
            58920,
            "RPTH"
          ],
          [
            58975,
            "uDkLN@iI\u0026eysLR"
          ],
          [
            59038,
            "QI4I"
          ],
          [
            59102,
            "MFQK"
          ]
        ],
        "sz": 2738736,
        "ts": [
          {
            "c": 1.0,
            "d": "Binary is not digitally signed",
            "i": "metadata/unsigned",
            "l": 3
          },
          {
            "a": "T1027.009",
            "c": 0.8999999761581421,
            "d": "Embedded PE binary at file offset 0x23c61e (~102400 bytes)",
            "e": [
              "kind=Pe32 estimated_size=102400"
            ],
            "i": "binary/embedded/pe",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Fareit Payload",
            "e": [
              "$string1"
            ],
            "i": "third_party/CAPE/Fareit",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "d": "Pony stealer malware",
            "e": [
              "signons.sqlite",
              "signons.txt",
              "signons2.txt",
              "signons3.txt",
              "WininetCacheCredentials",
              "moz_logins",
              "encryptedPassword",
              "FlashFXP",
              "FlashFXP",
              "FlashFXP",
              "FlashFXP",
              "FlashFXP",
              "BulletProof",
              "BulletProof",
              "BulletProof",
              "BulletProof"
            ],
            "i": "third_party/BinaryAlert/Windows/Pony/Stealer",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "d": "Detects executables referencing many file transfer clients. Observed in information stealers",
            "e": [
              "FTPWare\\COREFTP\\Sites",
              "Far\\Plugins\\FTP\\",
              "Far2\\Plugins\\FTP\\",
              "Ghisler\\Total Commander",
              "LinasFTP\\Site Manager",
              "FTP Explorer\\",
              "FTP Explorer\\",
              "FTP Explorer\\",
              "Far\\SavedDialogHistory\\",
              "Far2\\SavedDialogHistory\\",
              "GlobalSCAPE\\CuteFTP ",
              "GlobalSCAPE\\CuteFTP ",
              "GlobalSCAPE\\CuteFTP ",
              "GlobalSCAPE\\CuteFTP ",
              "GlobalSCAPE\\CuteFTP ",
              "GlobalSCAPE\\CuteFTP "
            ],
            "i": "third_party/Ditekshen/INDICATOR/SUSPICIOUS/EXE/Referenfces/File/Transfer/Clients",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "e": [
              "\\Global Downloader",
              "wiseftpsrvs.bin",
              "SiteServer %d\\SFTP",
              "%s\\Keychain",
              "Connections.txt",
              "ftpshell.fsi",
              "inetcomm server passwords"
            ],
            "i": "third_party/elastic/Windows_Trojan_Pony/windows/trojan/pony",
            "l": 5
          },
          {
            "d": "password keyword",
            "e": [
              "_Password",
              "FtpPassword",
              "_FtpPassword",
              "\u003cPOP3_Password2",
              "password1",
              "\"password\" : \"",
              "SELECT hostname, encryptedUsername, encryptedPassword FROM moz_logins",
              "password 51:b:",
              "MS IE FTP Passwords",
              "LastPassword",
              "Password",
              "PasswordType",
              "PassWord",
              "password_value",
              "FTP destination password",
              "password"
            ],
            "i": "micro-behaviors/data/text/keywords::password",
            "l": 1
          },
          {
            "a": "T1057",
            "d": "Browser app firefox",
            "e": [
              "Firefox",
              "Firefox"
            ],
            "i": "micro-behaviors/process/enumerate/apps::browser-apps-firefox",
            "l": 2,
            "m": "E1592"
          },
          {
            "a": "T1105",
            "c": 0.7200000286102295,
            "d": ".NET DownloadFile method token",
            "e": [
              "DownloadFile"
            ],
            "i": "objectives/command-and-control/dropper/delivery/download-execute::dotnet-downloadfile-token",
            "l": 3
          },
          {
            "a": "T1071.001",
            "d": "User-Agent header",
            "e": [
              "User-Agent:",
              "User-Agent:",
              "User-Agent:"
            ],
            "i": "micro-behaviors/communications/http/request::user-agent-header",
            "l": 2,
            "m": "C0002"
          },
          {
            "c": 0.8999999761581421,
            "d": "Valid PE/MZ binary found embedded in file",
            "e": [
              "4D 5A 90 00"
            ],
            "i": "metadata/binary/layout::pe-embedded",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "PE binary has trailing overlay data",
            "e": [
              "binary.has_overlay = 1.00"
            ],
            "i": "metadata/binary/layout::has-overlay",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "FileVersion field marker",
            "e": [
              "FileVersion"
            ],
            "i": "well-known/malware/worm/ludbaruma::fileversion-field",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Tool identity claims PuTTY",
            "e": [
              "PuTTY"
            ],
            "i": "metadata/package/tooling::tool-identity-putty",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 4 or fewer sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "objectives/command-and-control/infrastructure/config::max-sections-4",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "PE overlay exceeds ninety percent",
            "e": [
              "binary.overlay_ratio = 0.98"
            ],
            "i": "metadata/binary/layout::overlay-over-90pct",
            "l": 3
          },
          {
            "a": "T1204.002",
            "c": 0.7599999904632568,
            "d": "Short PDB marker",
            "e": [
              "Zbw138ht2aeja2.pdb"
            ],
            "i": "objectives/command-and-control/dropper/execution/clickfix::short-pdb-marker",
            "l": 1,
            "m": "B0024"
          },
          {
            "c": 1.0,
            "d": "Path-like string pattern",
            "e": [
              "c:\\\\\\\\\\\\/\\/\\/\\/\\//\\\\\\\\\\\\\\\\\\\\\\\\\\\\//////\\\\/\\/\\/windows\\\\\\\\\\\\/\\/\\/\\/\\//\\\\\\\\\\\\\\\\\\\\\\\\\\\\//////\\\\/\\/\\/system32\\\\\\\\\\\\/\\/\\/\\/\\//\\\\\\\\\\"
            ],
            "i": "micro-behaviors/data/text/malware::path-like-pattern",
            "l": 2
          },
          {
            "a": "T1112",
            "c": 0.8500000238418579,
            "d": "Create registry key via WinAPI",
            "e": [
              "RegCreateKeyA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-create-key-a",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "HTTP User-Agent header",
            "e": [
              "…ntent-Encoding: binary\r\nUser-Agent: Mozilla/4.0 (compatible…",
              "…q=0\r\nConnection: close\r\nUser-Agent: Mozilla/4.0 (compatible…",
              "User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows 98)"
            ],
            "i": "micro-behaviors/communications/http/user-agent::user-agent-header-dup",
            "l": 2
          },
          {
            "c": 0.6000000238418579,
            "d": "winmgmts WMI moniker string",
            "e": [
              "winmgmts://"
            ],
            "i": "objectives/execution/interpreter/scripting/host::winmgmts-string",
            "l": 3
          },
          {
            "c": 0.8500000238418579,
            "d": "Explicit Desktop path token in content",
            "e": [
              "Users\\World\\Desktop\\"
            ],
            "i": "objectives/collection/stealer/wallet::desktop-path-token",
            "l": 1
          },
          {
            "c": 0.30000001192092896,
            "d": "secret keyword",
            "e": [
              "secret"
            ],
            "i": "micro-behaviors/data/text/keywords::secret",
            "l": 1
          },
          {
            "a": "T1071.001",
            "c": 0.7799999713897705,
            "d": "HTTP POST request line",
            "e": [
              "POST %s HTTP/1.0"
            ],
            "i": "micro-behaviors/communications/http/post::post-request-line",
            "l": 3,
            "m": "C0002"
          },
          {
            "a": "T1572",
            "c": 1.0,
            "d": "DMW custom SSH tunneling tool password string",
            "e": [
              "password",
              "password",
              "password",
              "password"
            ],
            "i": "objectives/command-and-control/channel/tunnel::dmw-tunnel-pwd",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.9200000166893005,
            "d": "VB6 __vbaVarCat string concatenation",
            "e": [
              "vbaVarCat"
            ],
            "i": "micro-behaviors/data/string::vb6-string-construction-cat",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 1.0,
            "d": "Binary has 1000 or more strings",
            "e": [
              "binary.string_count = 6927.00"
            ],
            "i": "metadata/binary/metrics::string-count-1000-plus",
            "l": 2
          },
          {
            "a": "T1555",
            "c": 0.8999999761581421,
            "d": "FileZilla main config file",
            "e": [
              "\\filezilla.xml"
            ],
            "i": "objectives/credential-access/ftp/filezilla::filezilla-xml",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.9900000095367432,
            "d": "PE version resource text",
            "e": [
              "VS_VERSION_INFO"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::anydesk-version-info",
            "l": 1,
            "m": "B0032"
          },
          {
            "d": "USERPROFILE environment variable",
            "e": [
              "USERPROFILE"
            ],
            "i": "micro-behaviors/os/env/vars/user-info::userprofile-var",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE standard code/data section",
            "e": [
              ".text",
              ".data"
            ],
            "i": "metadata/binary/section/names::pe-code-data-standard-section",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "runas privilege elevation string",
            "e": [
              "runas"
            ],
            "i": "micro-behaviors/os/privilege/elevation::runas-string",
            "l": 3
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Set registry value ANSI",
            "e": [
              "RegSetValueExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-set-value-ex-a",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "NCapture launches explorer",
            "e": [
              "explorer.exe"
            ],
            "i": "well-known/app/graphics::ncapture-explorer",
            "l": 1
          },
          {
            "a": "T1082",
            "c": 0.8799999952316284,
            "d": "Query locale information",
            "e": [
              "GetLocaleInfoA"
            ],
            "i": "micro-behaviors/os/sysinfo/platform::get-locale-info",
            "l": 2
          },
          {
            "d": "COMPUTERNAME environment variable",
            "e": [
              "GetComputerNameA"
            ],
            "i": "micro-behaviors/os/env/vars/system-info::computername-var",
            "l": 2
          },
          {
            "a": "T1082",
            "c": 0.6499999761581421,
            "d": "Hostname in binary",
            "e": [
              "Hostname"
            ],
            "i": "micro-behaviors/os/sysinfo/hostname::hostname-string-raw",
            "l": 1,
            "m": "E1082"
          },
          {
            "c": 0.800000011920929,
            "d": "High number of imported symbols (\u003e80)",
            "e": [
              "binary.import_count = 108.00"
            ],
            "i": "metadata/binary/metrics::many-imports",
            "l": 2
          },
          {
            "a": "T1485",
            "c": 0.699999988079071,
            "d": "Windows Shell Folders registry path",
            "e": [
              "Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders"
            ],
            "i": "objectives/impact/destroy/file-deletion::shell-folders-personal-targeting",
            "l": 2,
            "m": "C0047"
          },
          {
            "a": "T1005",
            "c": 0.550000011920929,
            "d": "Generic database extension",
            "e": [
              ".db",
              ".db",
              ".db"
            ],
            "i": "objectives/collection/file-targeting/filter::db-extension",
            "l": 1,
            "m": "B0024"
          },
          {
            "c": 1.0,
            "d": "Binary has 25+ imports",
            "e": [
              "binary.import_count = 108.00"
            ],
            "i": "metadata/binary/metrics::many-imports-25",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 100+ imports",
            "e": [
              "binary.import_count = 108.00"
            ],
            "i": "metadata/binary/metrics::many-imports-100",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Uses Windows API for file mapping",
            "e": [
              "CreateFileMappingA"
            ],
            "i": "micro-behaviors/fs/memory/mmap::win32-file-mapping",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Low ratio of sentence-like strings",
            "e": [
              "binary.sentence_string_ratio = 0.01"
            ],
            "i": "metadata/binary/metrics/pe-details::low-sentence-string-ratio",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary file larger than 1MB",
            "e": [
              "479505"
            ],
            "i": "metadata/binary/metrics::large-binary-1mb",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE FileDescription metadata field",
            "e": [
              "FileDescription"
            ],
            "i": "metadata/package/versioning::pe-filedescription-field",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE OriginalFilename metadata field",
            "e": [
              "OriginalFilename"
            ],
            "i": "metadata/package/versioning::pe-originalfilename-field",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE imports from one DLL",
            "e": [
              "pe.import_dll_count = 1.00"
            ],
            "i": "metadata/binary/symbols::pe-single-import-dll",
            "l": 1
          },
          {
            "c": 0.7200000286102295,
            "d": "Winsock connect API string",
            "e": [
              "connect"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-connect-api-string",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has low average complexity",
            "e": [
              "binary.avg_complexity = 5.28"
            ],
            "i": "metadata/binary/metrics::avg-complexity-15-max",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Close handle",
            "e": [
              "CloseHandle"
            ],
            "i": "micro-behaviors/process/create/spawn::close-handle-dup",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Tool identity claims WinRAR",
            "e": [
              "WinRAR"
            ],
            "i": "metadata/package/tooling::tool-identity-winrar",
            "l": 1
          },
          {
            "d": "Content-Type header string",
            "e": [
              "…%lu\r\nConnection: close\r\nContent-Type: application/octet-strea…",
              "Content-Type: application/octet-stream"
            ],
            "i": "micro-behaviors/communications/http/request::content-type-header",
            "l": 1
          },
          {
            "c": 0.7200000286102295,
            "d": "Winsock socket API string",
            "e": [
              "socket"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-socket-api-string",
            "l": 1
          },
          {
            "c": 0.7200000286102295,
            "d": "WinForms Timer control token",
            "e": [
              "Timer"
            ],
            "i": "micro-behaviors/ui/controls/widget::winforms-timer",
            "l": 1
          },
          {
            "a": "T1555.003",
            "c": 0.949999988079071,
            "d": "Firefox PK11SDR_Decrypt function",
            "e": [
              "PK11SDR_Decrypt"
            ],
            "i": "objectives/credential-access/browser/firefox::pk11-decrypt",
            "l": 4,
            "m": "B0028"
          },
          {
            "a": "T1046",
            "c": 0.6000000238418579,
            "d": "Kerberos port 88",
            "e": [
              "88"
            ],
            "i": "objectives/discovery/network/scan::kerberos-port",
            "l": 1,
            "m": "E1046"
          },
          {
            "a": "T1071.001",
            "d": "HTTP header syntax marker",
            "e": [
              "HTTP/1.0\r\nHost: "
            ],
            "i": "objectives/command-and-control/channel/http/protocol::http-delimiter",
            "l": 1
          },
          {
            "a": "T1555",
            "c": 0.8500000238418579,
            "d": "FileZilla application directory",
            "e": [
              "Software\\FileZilla",
              "Software\\FileZilla Client"
            ],
            "i": "objectives/credential-access/ftp/filezilla::application-path",
            "l": 1
          },
          {
            "a": "T1082",
            "c": 0.8999999761581421,
            "d": "Query computer/host name",
            "e": [
              "GetComputerNameA"
            ],
            "i": "micro-behaviors/os/sysinfo/hostname::get-computer-name",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.8199999928474426,
            "d": "Large PE with dense string corpus",
            "e": [
              "binary.string_density = 192.42"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics::high-string-density-large-pe",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1106",
            "c": 0.8799999952316284,
            "d": "Call window procedure",
            "e": [
              "CallWindowProcW"
            ],
            "i": "micro-behaviors/ui/window/manage::call-window-proc",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE ProductName metadata field",
            "e": [
              "ProductName"
            ],
            "i": "metadata/package/versioning::pe-productname-field",
            "l": 2
          },
          {
            "c": 0.9399999976158142,
            "d": "VB6 DllFunctionCall thunk",
            "e": [
              "DllFunctionCall"
            ],
            "i": "micro-behaviors/dylib/lookup::vb6-dll-function-call",
            "l": 3
          },
          {
            "c": 0.9599999785423279,
            "d": "Overlay size at least 1 MiB",
            "e": [
              "binary.overlay_size = 2689584.00"
            ],
            "i": "metadata/binary/layout::large-overlay-1mb",
            "l": 2
          },
          {
            "a": "T1070.006",
            "c": 0.699999988079071,
            "d": "Debug timestamps internally consistent",
            "e": [
              "pe.debug_timestamp_consistent = 1.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::debug-timestamps-consistent",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "PuTTY identity string",
            "e": [
              "Software\\SimonTatham\\PuTTY\\Sessions"
            ],
            "i": "objectives/supply-chain/trojanized/application/monitor::putty-identity-string",
            "l": 1
          },
          {
            "a": "T1110.001",
            "c": 0.20000000298023224,
            "d": "admin keyword",
            "e": [
              "admin"
            ],
            "i": "micro-behaviors/data/text/keywords/username::admin-keyword",
            "l": 2,
            "m": "B0028"
          },
          {
            "c": 1.0,
            "d": ".bat extension",
            "e": [
              ".bat"
            ],
            "i": "objectives/command-and-control/dropper/builder::bat-ext",
            "l": 1
          },
          {
            "c": 0.9399999976158142,
            "d": "PE overlay exceeds thirty-five percent",
            "e": [
              "binary.overlay_ratio = 0.98"
            ],
            "i": "metadata/binary/layout::overlay-over-35pct",
            "l": 2
          },
          {
            "c": 0.6000000238418579,
            "d": "System32 substring reference",
            "e": [
              "/k %windir%\\System32\\reg.exe ADD HKLM\\SOFTWA…"
            ],
            "i": "micro-behaviors/fs/path/system::system32-substr",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 20+ imports",
            "e": [
              "binary.import_count = 108.00"
            ],
            "i": "metadata/binary/metrics::many-imports-20",
            "l": 1
          },
          {
            "c": 0.7200000286102295,
            "d": "Short uppercase mutex token",
            "e": [
              "USERPROFILE",
              "YPPPPZVV",
              "PPPPYZVV",
              "TUUSXXTX",
              "UTTSSXXS",
              "PPPPPPPPPVY",
              "MNQWASMUEWQ",
              "CIWKYSRUI",
              "ISRUIBGQK",
              "GZISREYB",
              "GZICBEYB",
              "GZYCBEYB",
              "TIPHMXCM",
              "PUXPHMXC",
              "XCMWKYCBE",
              "SKYCGEYB"
            ],
            "i": "micro-behaviors/process/sync/mutex::short-uppercase-token",
            "l": 1,
            "m": "C0042"
          },
          {
            "a": "T1027",
            "c": 0.8399999737739563,
            "d": "VB6 PE with three sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "objectives/anti-static/obfuscation/payload::three-section-vb6-layout",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.800000011920929,
            "d": "Tiny writable data section",
            "e": [
              ".data (size: 4096)"
            ],
            "i": "metadata/binary/section/metrics::tiny-data-section",
            "l": 1
          },
          {
            "a": "T1071.001",
            "d": "Old Mozilla 4.0 User-Agent",
            "e": [
              "…ng: binary\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 5.0; …",
              "…ion: close\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 5.0; …",
              "User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows 98)"
            ],
            "i": "micro-behaviors/communications/http/headers::ua-mozilla-old",
            "l": 2,
            "m": "C0002"
          },
          {
            "a": "T1555",
            "c": 0.8999999761581421,
            "d": "FileZilla recentservers.xml config",
            "e": [
              "\\recentservers.xml"
            ],
            "i": "objectives/credential-access/ftp/filezilla::recentservers-xml",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE mapped image under 768 KiB",
            "e": [
              "pe.size_of_image = 49152.00"
            ],
            "i": "metadata/binary/layout::image-under-768kb",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 40+ imports",
            "e": [
              "binary.import_count = 108.00"
            ],
            "i": "metadata/binary/metrics::many-imports-40",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.8399999737739563,
            "d": "Open registry key ANSI",
            "e": [
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-open-key-ex-a",
            "l": 2
          },
          {
            "c": 0.9300000071525574,
            "d": "VB6 runtime file open helper",
            "e": [
              "vbaFileOpen"
            ],
            "i": "micro-behaviors/fs/file/write::vb6-file-open",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE has many readable strings",
            "e": [
              "binary.string_count = 6927.00"
            ],
            "i": "metadata/binary/layout::many-readable-strings",
            "l": 2
          },
          {
            "a": "T1105",
            "c": 0.800000011920929,
            "d": "Numbered DAT payload filename",
            "e": [
              "ESTdb2.dat"
            ],
            "i": "objectives/command-and-control/dropper/staging::numbered-dat-payload-name",
            "l": 1,
            "m": "B0024"
          },
          {
            "c": 0.20000000298023224,
            "d": "command keyword",
            "e": [
              "Opera.HTML\\shell\\open\\command",
              "FTP++.Link\\shell\\open\\command"
            ],
            "i": "micro-behaviors/data/text/keywords::command-dup",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Tool identity claims FileZilla",
            "e": [
              "filezilla",
              "FileZilla",
              "FileZilla"
            ],
            "i": "metadata/package/tooling::tool-identity-filezilla",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.699999988079071,
            "d": "HKCU\\Software path string",
            "e": [
              "Software\\W",
              "Software\\M",
              "Software\\F",
              "Software\\F",
              "Software\\F",
              "Software\\F",
              "Software\\F",
              "Software\\F",
              "Software\\G",
              "Software\\G",
              "Software\\G",
              "Software\\G",
              "Software\\G",
              "Software\\G",
              "Software\\G",
              "Software\\G"
            ],
            "i": "objectives/anti-static/obfuscation/payload::hkcu-software-text",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.8999999761581421,
            "d": "Padodor COM instance string",
            "e": [
              "CoCreateInstance"
            ],
            "i": "well-known/malware/trojan/shellobject/padodor::padodor-cocreateinstance-string",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Binary has low overall entropy",
            "e": [
              "binary.overall_entropy = 2.70"
            ],
            "i": "metadata/binary/metrics::low-overall-entropy-binary",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.6499999761581421,
            "d": "Windows runas verb token",
            "e": [
              "runas"
            ],
            "i": "objectives/impact/degrade/system::runas-verb-token",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "runas elevation verb",
            "e": [
              "runas"
            ],
            "i": "objectives/privilege-escalation/token-manipulation::runas-word",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Check if running under WoW64",
            "e": [
              "IsWow64Process"
            ],
            "i": "micro-behaviors/os/compat/wow64::is-wow64-process",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Get module file path (ANSI)",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/os/module/load::get-module-filename-ansi",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "Sandboxie product marker",
            "e": [
              "SandboxieRpcSs.exe`NB5CNB49NBF7NB73NBB5NBC6NB7CNBB8NB5CNB46NBF7NB73NBB5NBC5NB1DNB12NBB7NB9FNBF5NB23NBDFNBDFNB9DNB73`NB7ANB14NBCA"
            ],
            "i": "well-known/tool/sysadmin/sandboxie::sandboxie-product-marker",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "sqlite3 string",
            "e": [
              "sqlite3"
            ],
            "i": "micro-behaviors/data/db/conn/sqlite::sqlite3-string",
            "l": 2
          },
          {
            "c": 0.9900000095367432,
            "d": "MSVBVM60 runtime marker",
            "e": [
              "MSVBVM60.DLL"
            ],
            "i": "well-known/malware/trojan/shellobject::msvbvm60-runtime",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Sample AddIn Project marker",
            "e": [
              "Sample AddIn Project"
            ],
            "i": "well-known/malware/worm/ludbaruma::sample-addin-project",
            "l": 1
          },
          {
            "a": "T1005",
            "c": 0.75,
            "d": "SQLite extension",
            "e": [
              ".sqlite",
              ".sqlite",
              ".sqlite"
            ],
            "i": "objectives/collection/file-targeting/filter::sqlite-extension",
            "l": 1,
            "m": "B0024"
          },
          {
            "c": 0.9599999785423279,
            "d": "PE overlay exceeds 1 MiB",
            "e": [
              "binary.overlay_size = 2689584.00"
            ],
            "i": "metadata/binary/layout::overlay-over-1mb",
            "l": 2
          },
          {
            "c": 0.6000000238418579,
            "d": "Copyright notice",
            "e": [
              "Copyright",
              "Copyright",
              "Copyright"
            ],
            "i": "metadata/package/license::copyright-word",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "File is a compiled binary",
            "e": [
              "binary.file_size = 2738736.00"
            ],
            "i": "metadata/binary/framework::is-binary",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE file larger than 2 MiB",
            "e": [
              "binary.file_size = 2738736.00"
            ],
            "i": "metadata/binary/layout::file-over-2mb",
            "l": 1
          },
          {
            "a": "T1071.001",
            "c": 0.6000000238418579,
            "d": "HTTP Connection close header",
            "e": [
              "Connection: close"
            ],
            "i": "objectives/command-and-control/channel/http-beacon::http-connection-close-header",
            "l": 1,
            "m": "B0030"
          },
          {
            "a": "T1036.005",
            "c": 0.75,
            "d": "C2 gate.php endpoint",
            "e": [
              "gate.php"
            ],
            "i": "objectives/command-and-control/beacon/network::c2-gate-php-endpoint",
            "l": 1,
            "m": "B0030"
          },
          {
            "c": 0.8399999737739563,
            "d": "High basic block count in sparse binary",
            "e": [
              "binary.total_basic_blocks = 447.00"
            ],
            "i": "metadata/binary/metrics::dense-basic-blocks",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Small PE resource section",
            "e": [
              "pe.rsrc_size = 4096.00"
            ],
            "i": "metadata/package/versioning::pe-small-rsrc",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "Binary imports ADVAPI32.dll",
            "e": [
              "advapi32.dll"
            ],
            "i": "metadata/binary/symbols::imports-advapi32-dll",
            "l": 1
          },
          {
            "a": "T1552.004",
            "c": 0.75,
            "d": "Remote Desktop Protocol extension",
            "e": [
              ".rdp"
            ],
            "i": "objectives/collection/file-targeting/filter::rdp-extension",
            "l": 3,
            "m": "B0024"
          },
          {
            "c": 0.800000011920929,
            "d": "PE version resource structure",
            "e": [
              "VS_VERSION_INFO"
            ],
            "i": "metadata/package/versioning::pe-version-resource",
            "l": 2
          },
          {
            "a": "T1555.003",
            "c": 0.8999999761581421,
            "d": "Firefox logins database",
            "e": [
              "SELECT hostname, encryptedUsername, encryptedPassword FROM moz_logins"
            ],
            "i": "micro-behaviors/fs/path/sensitive/browser::firefox-logins",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "High-risk token privilege name",
            "e": [
              "SeImpersonatePrivilege",
              "SeTcbPrivilege",
              "SeAssignPrimaryTokenPrivilege"
            ],
            "i": "objectives/privilege-escalation/token-manipulation::dangerous-privilege-name",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary is not position-independent (fixed load address)",
            "e": [
              "binary.is_pie = 0.00"
            ],
            "i": "metadata/hardening::no-pie",
            "l": 2
          },
          {
            "c": 0.6399999856948853,
            "d": "Delete files (Windows API ANSI)",
            "e": [
              "DeleteFileA"
            ],
            "i": "micro-behaviors/fs/file/delete::deletefile-a-text",
            "l": 2
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "LoadLibraryA loader API string",
            "e": [
              "LoadLibraryA"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-loadlibrarya-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "a": "T1082",
            "c": 0.8500000238418579,
            "d": "UAC EnableLUA policy registry query",
            "e": [
              "…sion\\Policies\\System /v EnableLUA /t REG_DWORD /d 0 /f"
            ],
            "i": "objectives/discovery/host/security::uac-policy-query",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 3+ functions",
            "e": [
              "binary.function_count = 43.00"
            ],
            "i": "metadata/binary/metrics::few-functions-3",
            "l": 1
          },
          {
            "a": "T1195.002",
            "c": 0.550000011920929,
            "d": "Plaintext hello beacon token",
            "e": [
              "hello"
            ],
            "i": "objectives/command-and-control/backdoor/binary::plaintext-hello-beacon-token",
            "l": 1,
            "m": "B0025"
          },
          {
            "c": 1.0,
            "d": "Binary has 30+ imports",
            "e": [
              "binary.import_count = 108.00"
            ],
            "i": "metadata/binary/metrics::many-imports-30",
            "l": 1
          },
          {
            "c": 0.8199999928474426,
            "d": "GetWindowsDirectory API string",
            "e": [
              "GetWindowsDirectoryA"
            ],
            "i": "micro-behaviors/os/sysinfo/directories::get-windows-directory-string",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE has low overall entropy",
            "e": [
              "binary.overall_entropy = 2.70"
            ],
            "i": "metadata/binary/layout::low-overall-entropy",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.8500000238418579,
            "d": "Suspicious PHP endpoint URL (gate/upload/etc)",
            "e": [
              "http://don.service-master.eu/gate.php"
            ],
            "i": "objectives/command-and-control/infrastructure/domain::suspicious-php-filename",
            "l": 4,
            "m": "C0002"
          },
          {
            "a": "T1071.001",
            "d": "HTTP/1.x version string",
            "e": [
              "GET %s HTTP/1.0\r\nHost: %s\r\nAccept: */*…",
              "POST %s HTTP/1.0\r\nHost: %s\r\nAccept: */*…"
            ],
            "i": "micro-behaviors/communications/http/request::http-version",
            "l": 2,
            "m": "C0002"
          },
          {
            "c": 0.75,
            "d": "HTTP protocol version strings",
            "e": [
              "HTTP/1.0",
              "HTTP/1.0"
            ],
            "i": "micro-behaviors/communications/http/request::http-versions",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Microsoft Visual string",
            "e": [
              "C:\\Program Files (x86)\\Microsoft Visual Studio\\VB98\\VB6.OLB"
            ],
            "i": "metadata/lang/compiler/native::ms-visual",
            "l": 2
          },
          {
            "c": 0.9900000095367432,
            "d": "MSVBVM60 runtime marker",
            "e": [
              "MSVBVM60.DLL"
            ],
            "i": "well-known/malware/worm/ludbaruma::msvbvm60-runtime",
            "l": 1
          },
          {
            "a": "T1485",
            "c": 0.8999999761581421,
            "d": "Preserves .exe .gho .bak files",
            "e": [
              ".exe"
            ],
            "i": "objectives/impact/destroy/file-deletion::exe-gho-bak-whitelist",
            "l": 1,
            "m": "C0047"
          },
          {
            "a": "T1027.003",
            "c": 0.9900000095367432,
            "d": "PE checksum mismatch",
            "e": [
              "pe.checksum_mismatch = 1.00"
            ],
            "i": "objectives/anti-static/obfuscation/payload/container::pe-checksum-mismatch-png",
            "l": 1,
            "m": "F0001.006"
          },
          {
            "a": "T1005",
            "c": 0.4000000059604645,
            "d": "Generic data extension",
            "e": [
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat"
            ],
            "i": "objectives/collection/file-targeting/filter::dat-extension",
            "l": 1,
            "m": "B0024"
          },
          {
            "c": 0.8999999761581421,
            "d": "VB6 event sink helper",
            "e": [
              "EVENT_SINK_AddRef",
              "EVENT_SINK_Release",
              "EVENT_SINK_QueryInterface"
            ],
            "i": "metadata/binary/framework::vb6-runtime-event-helper",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has low average string entropy",
            "e": [
              "binary.avg_string_entropy = 2.88"
            ],
            "i": "metadata/binary/metrics::avg-string-entropy-4-max",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "CompanyName field marker",
            "e": [
              "CompanyName"
            ],
            "i": "well-known/malware/worm/ludbaruma::companyname-field",
            "l": 1
          },
          {
            "a": "T1053.005",
            "c": 0.8799999952316284,
            "d": "Task action principal properties",
            "e": [
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path"
            ],
            "i": "objectives/persistence/login/scheduled-task::task-action-principal-properties",
            "l": 1,
            "m": "F0012"
          },
          {
            "c": 0.7599999904632568,
            "d": "Winsock startup API string",
            "e": [
              "WSAStartup"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-startup-api-string",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Binary has many functions (\u003e30)",
            "e": [
              "binary.function_count = 43.00"
            ],
            "i": "metadata/binary/metrics::many-functions",
            "l": 2
          },
          {
            "c": 0.9599999785423279,
            "d": "Elex Internet Explorer product resource",
            "e": [
              "Internet Explorer"
            ],
            "i": "well-known/malware/trojan/elex/worm::elex-internet-explorer-product-resource",
            "l": 2
          },
          {
            "c": 0.9399999976158142,
            "d": "VB6 runtime DLL reference",
            "e": [
              "MSVBVM60.DLL"
            ],
            "i": "metadata/binary/framework::vb6-runtime-dll",
            "l": 2
          },
          {
            "a": "T1555.003",
            "c": 0.699999988079071,
            "d": "Chromium Login Data database reference",
            "e": [
              "Login Data"
            ],
            "i": "objectives/credential-access/browser/chromium::logins-table",
            "l": 3
          },
          {
            "c": 0.9200000166893005,
            "d": "VB6 runtime helper import",
            "e": [
              "__vbaExceptHandler"
            ],
            "i": "metadata/binary/framework::vb6-runtime-core-helper",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE resource section",
            "e": [
              ".rsrc"
            ],
            "i": "metadata/binary/section/names::pe-resource-section",
            "l": 1
          },
          {
            "a": "T1555",
            "c": 0.8999999761581421,
            "d": "FileZilla sitemanager.xml config",
            "e": [
              "\\sitemanager.xml"
            ],
            "i": "objectives/credential-access/ftp/filezilla::sitemanager-xml",
            "l": 1
          },
          {
            "c": 0.8799999952316284,
            "d": "Native runtime binary is large",
            "e": [
              "binary.file_size = 2738736.00"
            ],
            "i": "metadata/lang/compiler/aot::native-runtime-large-file",
            "l": 2
          },
          {
            "a": "T1555.003",
            "c": 0.949999988079071,
            "d": "Java DPAPI unprotect call",
            "e": [
              "UnprotectData"
            ],
            "i": "objectives/credential-access/discord/token::java-crypt-unprotect-data",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "Overlay size at least 64 KiB",
            "e": [
              "binary.overlay_size = 2689584.00"
            ],
            "i": "metadata/binary/layout::large-overlay-64k",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary is 500KB+",
            "e": [
              "binary.file_size = 2738736.00"
            ],
            "i": "metadata/binary/metrics::large-binary-500k",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "ProductVersion field marker",
            "e": [
              "ProductVersion"
            ],
            "i": "well-known/malware/worm/ludbaruma::productversion-field",
            "l": 1
          },
          {
            "a": "T1082",
            "c": 0.8999999761581421,
            "d": "Query Windows version info",
            "e": [
              "GetVersionExA"
            ],
            "i": "micro-behaviors/os/sysinfo/platform::get-version-ex",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.8999999761581421,
            "d": "URLDownloadToFile API name as string",
            "e": [
              "URLDownloadToFileA"
            ],
            "i": "micro-behaviors/communications/http/get::url-download-to-file-str",
            "l": 3
          },
          {
            "c": 0.699999988079071,
            "d": "PE FileVersion metadata field",
            "e": [
              "FileVersion"
            ],
            "i": "metadata/package/versioning::pe-fileversion-field",
            "l": 2
          },
          {
            "a": "T1071",
            "c": 0.6000000238418579,
            "d": "URL with .php endpoint",
            "e": [
              "http://don.service-master.eu/gate.php"
            ],
            "i": "objectives/command-and-control/infrastructure/domain::php-endpoint-url",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Wait for process/object",
            "e": [
              "WaitForSingleObject"
            ],
            "i": "micro-behaviors/process/create/spawn::wait-for-single-object",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "gethostbyname import string",
            "e": [
              "gethostbyname"
            ],
            "i": "micro-behaviors/communications/ip/resolve::resolve-gethostbyname-import",
            "l": 2
          },
          {
            "a": "T1036.005",
            "c": 0.800000011920929,
            "d": "explorer.exe process name",
            "e": [
              "explorer.exe"
            ],
            "i": "objectives/evasion/masquerade/process::explorer-name",
            "l": 1,
            "m": "F0004"
          },
          {
            "a": "T1053.005",
            "c": 0.75,
            "d": "Task triggers on system boot",
            "e": [
              "ONSTART"
            ],
            "i": "objectives/persistence/login/scheduled-task/masquerade::boot-trigger",
            "l": 1,
            "m": "F0012"
          },
          {
            "c": 0.6600000262260437,
            "d": "Look up temp directory via GetTempPath",
            "e": [
              "GetTempPathA"
            ],
            "i": "micro-behaviors/fs/temp/directory::get-temp-path-dup",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE has few sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "metadata/binary/layout::legacy-few-sections",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE ProductVersion metadata field",
            "e": [
              "ProductVersion"
            ],
            "i": "metadata/package/versioning::pe-productversion-field",
            "l": 2
          },
          {
            "a": "T1053.005",
            "c": 0.8999999761581421,
            "d": "Task Scheduler builder methods",
            "e": [
              "GetFolder",
              "Connect",
              "Connect",
              "Connect",
              "Connect",
              "Connect"
            ],
            "i": "objectives/persistence/login/scheduled-task::task-scheduler-builder-methods",
            "l": 1,
            "m": "F0012"
          },
          {
            "c": 1.0,
            "d": "Binary has 2000+ strings",
            "e": [
              "binary.string_count = 6927.00"
            ],
            "i": "metadata/binary/metrics::many-strings-2000",
            "l": 1
          },
          {
            "a": "T1053.005",
            "c": 0.800000011920929,
            "d": "Scheduled task naming context",
            "e": [
              "/TN "
            ],
            "i": "objectives/persistence/login/scheduled-task/masquerade::task-name-context",
            "l": 1,
            "m": "F0012"
          },
          {
            "c": 0.800000011920929,
            "d": "High import density (\u003e3 imports/KB)",
            "e": [
              "binary.import_density = 3.00"
            ],
            "i": "metadata/binary/metrics::high-import-density",
            "l": 2
          },
          {
            "c": 0.9800000190734863,
            "d": "user32 dynamic dispatch target",
            "e": [
              "user32"
            ],
            "i": "well-known/malware/trojan/shellobject/hijack::user32-dispatch-target",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Multiple embedded MZ headers",
            "e": [
              "4D 5A",
              "4D 5A",
              "4D 5A",
              "4D 5A",
              "4D 5A",
              "4D 5A",
              "4D 5A",
              "4D 5A",
              "4D 5A",
              "4D 5A",
              "4D 5A",
              "4D 5A",
              "4D 5A",
              "4D 5A",
              "4D 5A"
            ],
            "i": "metadata/binary/layout::multiple-pe-embedded-loose",
            "l": 1
          },
          {
            "a": "T1548.002",
            "c": 0.699999988079071,
            "d": "Shell Open command registry key",
            "e": [
              "\\shell\\open\\command"
            ],
            "i": "objectives/privilege-escalation/elevation-control/uac-bypass/hijack::shell-open-command-reg",
            "l": 1
          },
          {
            "a": "T1071.001",
            "c": 0.6600000262260437,
            "d": "Accept-Encoding header",
            "e": [
              "Accept-Encoding: identity, *;q=0",
              "…\nHost: %s\r\nAccept: */*\r\nAccept-Encoding: identity, *;q=0\r\nConte…",
              "…\nHost: %s\r\nAccept: */*\r\nAccept-Encoding: identity, *;q=0\r\nConne…"
            ],
            "i": "micro-behaviors/communications/http/headers::headers-encoding",
            "l": 2,
            "m": "C0002"
          },
          {
            "c": 0.8999999761581421,
            "d": "SQLite format header",
            "e": [
              "SQLite format 3"
            ],
            "i": "micro-behaviors/data/db/conn/sqlite::sqlite-format",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "PE Rich header present (MSVC toolchain)",
            "e": [
              "pe.rich_header_present = 1.00"
            ],
            "i": "metadata/binary/resource::rich-header-present",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "HTTP GET method",
            "e": [
              "GET %s HTTP/1.0"
            ],
            "i": "micro-behaviors/communications/http/get::get",
            "l": 3
          },
          {
            "c": 0.699999988079071,
            "d": "PE CompanyName metadata field",
            "e": [
              "CompanyName"
            ],
            "i": "metadata/package/versioning::pe-companyname-field",
            "l": 2
          },
          {
            "c": 0.75,
            "d": "Binary exports no symbols",
            "e": [
              "binary.export_count = 0.00"
            ],
            "i": "metadata/binary/symbols::no-exports",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Skips Windows installation directories",
            "e": [
              "WINDOWS"
            ],
            "i": "objectives/impact/infect/binary::skip-windows-install-dir",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "OriginalFilename field marker",
            "e": [
              "OriginalFilename"
            ],
            "i": "well-known/malware/worm/ludbaruma::originalfilename-field",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "PE InternalName metadata field",
            "e": [
              "InternalName"
            ],
            "i": "metadata/package/versioning::pe-internalname-field",
            "l": 2
          },
          {
            "d": "windir environment variable",
            "e": [
              "/k %windir%\\System32\\reg.exe ADD H…"
            ],
            "i": "micro-behaviors/os/env/vars/system-info::windir-var",
            "l": 2
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "VirtualProtect loader API string",
            "e": [
              "VirtualProtect"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-virtualprotect-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "d": ".bat extension reference",
            "e": [
              ".bat"
            ],
            "i": "micro-behaviors/fs/path/extension::bat-dup",
            "l": 1
          },
          {
            "a": "T1070.006",
            "c": 0.699999988079071,
            "d": "PE header compile timestamp predates 2025",
            "e": [
              "pe.timestamp = 1504708224.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::header-timestamp-pre-2025",
            "l": 1
          },
          {
            "c": 0.6000000238418579,
            "d": "SELECT SQL keyword in query",
            "e": [
              "SELECT hostname, encryptedUsername, encryptedPassword FROM"
            ],
            "i": "micro-behaviors/data/db/conn/sql::sql-select",
            "l": 2
          },
          {
            "a": "T1499",
            "c": 0.8999999761581421,
            "d": "Shutdown prank markers",
            "e": [
              "Shutdown"
            ],
            "i": "objectives/impact/ui/manipulation::shutdown-prank-markers",
            "l": 3
          },
          {
            "a": "T1041",
            "c": 0.6000000238418579,
            "d": "PHP gate endpoint",
            "e": [
              "http://don.service-master.eu/gate.php"
            ],
            "i": "objectives/command-and-control/infrastructure/domain::php-gate",
            "l": 4,
            "m": "C0002"
          },
          {
            "d": ".dll extension reference",
            "e": [
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll"
            ],
            "i": "micro-behaviors/fs/path/extension::dll-dup",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 50+ imports",
            "e": [
              "binary.import_count = 108.00"
            ],
            "i": "metadata/binary/metrics::many-imports-50",
            "l": 1
          },
          {
            "c": 0.9200000166893005,
            "d": "Overlay exceeds one-third",
            "e": [
              "binary.overlay_ratio = 0.98"
            ],
            "i": "metadata/binary/layout::overlay-dominates-third",
            "l": 3
          },
          {
            "a": "T1055",
            "c": 0.949999988079071,
            "d": "Huge null run in executable (128+ bytes)",
            "e": [
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00",
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00",
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00"
            ],
            "i": "objectives/anti-static/obfuscation/binary-structure::huge-null-run-text",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.8999999761581421,
            "d": "Low behavioral-import ratio",
            "e": [
              "binary.behavioral_import_ratio = 0.00"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics/sparse-imports::low-behavioral-import-ratio",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1082",
            "c": 0.699999988079071,
            "d": "hwid string",
            "e": [
              "HWID"
            ],
            "i": "objectives/discovery/system/fingerprint/machine-id::hwid-string",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "GUID-formatted mutex name",
            "e": [
              "{CB1F2C0F-8094-4AAC-BCF5-41A64E27F777}",
              "{9EA55529-E122-4757-BC79-E4825F80732C}",
              "{11C1D741-A95B-11d2-8A80-0080ADB32FF4}",
              "{F9043C88-F6F2-101A-A3C9-08002B2F49FB}",
              "{74FF1730-B1F2-4D88-926B-1568FAE61DB7}"
            ],
            "i": "micro-behaviors/process/sync/mutex::guid-mutex",
            "l": 2,
            "m": "C0042"
          },
          {
            "c": 0.949999988079071,
            "d": "PE checksum mismatch (modified binary)",
            "e": [
              "pe.checksum_mismatch = 1.00"
            ],
            "i": "metadata/binary/layout::pe-checksum-mismatch",
            "l": 3
          },
          {
            "a": "T1027",
            "c": 0.699999988079071,
            "d": "Overlay large enough to contain payload",
            "e": [
              "binary.overlay_size = 2689584.00"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics::large-overlay-size",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.699999988079071,
            "d": "Registry Run key",
            "e": [
              "\\RUN"
            ],
            "i": "objectives/persistence/login/registry/autostart::run-key",
            "l": 3
          },
          {
            "a": "T1027",
            "c": 0.7200000286102295,
            "d": "Overlay large enough for stage data",
            "e": [
              "binary.overlay_size = 2689584.00"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics::medium-overlay-size",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1027",
            "d": "Binary has overlay data",
            "e": [
              "binary.has_overlay = 1.00"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics::has-overlay",
            "l": 1,
            "m": "B0032"
          },
          {
            "d": ".exe extension reference",
            "e": [
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe"
            ],
            "i": "micro-behaviors/fs/path/extension::exe-dup",
            "l": 1
          },
          {
            "c": 0.8399999737739563,
            "d": "Open waitable timer handle",
            "e": [
              "OpenWaitableTimerA"
            ],
            "i": "micro-behaviors/time/schedule/waitable::open-waitable-timer",
            "l": 3
          },
          {
            "a": "T1547.001",
            "c": 0.699999988079071,
            "d": "SOFTWARE CurrentVersion Run path",
            "e": [
              "SOFTWARE\\MICROSOFT\\WINDOWS\\CURRENTVERSION\\RUN"
            ],
            "i": "objectives/persistence/login/startup/registry::software-run-key",
            "l": 3
          },
          {
            "a": "T1574.002",
            "c": 0.8999999761581421,
            "d": "Hidden LoadLibraryA string reference",
            "e": [
              "LoadLibraryA"
            ],
            "i": "micro-behaviors/dylib/load::load-library-a-string-no-import",
            "l": 1
          },
          {
            "c": 0.6000000238418579,
            "d": "Very few sections (merged/stripped)",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "metadata/binary/metrics::few-sections",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.800000011920929,
            "d": "Few PE resource entries (no DIALOG/MENU/STRINGTABLE)",
            "e": [
              "pe.resource_count = 2.00"
            ],
            "i": "objectives/evasion/anti-av/heuristic::minimal-pe-resources",
            "l": 1
          },
          {
            "a": "T1027.009",
            "c": 0.800000011920929,
            "d": "High entropy overlay data",
            "e": [
              "binary.overlay_entropy = 7.67"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics::high-entropy-overlay-raw",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1555.003",
            "c": 0.949999988079071,
            "d": "Firefox moz_logins SQL query",
            "e": [
              "SELECT hostname, encryptedUsername, encryptedPassword FROM moz_logins"
            ],
            "i": "objectives/credential-access/browser/firefox::moz-logins-sql",
            "l": 4,
            "m": "B0028"
          },
          {
            "a": "T1027.009",
            "c": 0.699999988079071,
            "d": "Large overlay relative to file",
            "e": [
              "binary.overlay_ratio = 0.98"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics::large-overlay",
            "l": 2,
            "m": "B0032"
          },
          {
            "c": 0.949999988079071,
            "d": "Signed PE checksum mismatch",
            "e": [
              "pe.checksum_mismatch = 1.00"
            ],
            "i": "metadata/binary/layout::signed-pe-checksum-mismatch",
            "l": 1
          },
          {
            "a": "T1055",
            "c": 0.8500000238418579,
            "d": "Large null run in executable (64+ bytes)",
            "e": [
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00",
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00",
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00",
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00",
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00",
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00",
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00",
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00",
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00",
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00",
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00",
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00",
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00"
            ],
            "i": "objectives/anti-static/obfuscation/binary-structure::large-null-run-text",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "CreateFile API string reference",
            "e": [
              "CreateFile",
              "CreateFile"
            ],
            "i": "micro-behaviors/fs/file/open::createfile-api",
            "l": 2
          },
          {
            "a": "T1546.015",
            "c": 0.8199999928474426,
            "d": "InprocServer32 registry write",
            "e": [
              "CLSID\\{11C1D741-A95B-11d2-8A80-0080ADB32FF4}\\InProcServer32"
            ],
            "i": "objectives/persistence/system/registry/com-hijack::inprocserver32-write",
            "l": 3
          },
          {
            "c": 0.8799999952316284,
            "d": "CLSID registry path manipulation",
            "e": [
              "CLSID\\{11C1D741-A95B-11d2-8A80-0080ADB32FF4}"
            ],
            "i": "objectives/persistence/system/registry/com-hijack::clsid-registry-path",
            "l": 3
          },
          {
            "a": "T1027",
            "c": 0.8500000238418579,
            "d": "Sparse import table",
            "e": [
              "binary.import_count = 108.00"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics/sparse-imports::low-import-count",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 1.0,
            "d": "PE with many long base64/hex-like strings",
            "e": [
              "NB8FNB7CNB3CNBA5NB1ENB34NBA3NBB5NB9FNBF5NBFANBFANBDBNB1CNB43NBB7NB9FNBF5NB2ANB3CNBD0NBDDNBF0NBC8NB8FNBF4NB06NBA5NB76NBE4NB70NBB5",
              "NB8FNB0ANB06NBB9NB60NB25NBF0NB4DNB9ENBFANBF6NB85NB60NB0ANB8CNB3ENBD0NBE1NB9ANB5CNB9ENBF5NB73NBEFNB77NB63NB72NBB5NB9FNB0ANB04NBB1",
              "NB9FNB7ENB7CNB4ANBEENBA1NB8CNBC0NB97NB0ANB04NBB1NB14NBA2NB7BNB4ANBADNB0ANBA3NB36NB67NBF5NB7CNB30NB88NBF4NB73NBB5NB14NBE2NB15NB3E",
              "NB9FNB88NBCENB3ENBD0NBE5NBB4NBB4NB98NBF5NB72NBB5NB14NBBANB67NB5CNB1FNBF4NB73NBB5NBC5NB1DNBA2NBB5NB9FNBF5NB8CNBC2NB8FNB7ENB24NBBD",
              "NBB7NB7CNB78NB3ENBD0NBE1NB9ANB88NB9ENBF5NB73NBEFNB77NB83NB73NBB5NB9FNB0ANB04NBA5NB14NBA2NB7BNB4ANBEDNBF1NB8CNB65NB1CNB0DNB73NBC0",
              "NB1CNB37NB7BNB3ENB9DNB3CNBB0NB3ENBD0NBDDNB9ANBB4NB9ENBF5NB73NBEFNB77NBFBNB73NBB5NB9FNB9FNB73NB3ENBC8NBFDNB8CNB87NB60NB25NB9ANB39",
              "NBFENB81NB16NBE5NBEDNB9ANB10NBD0NBECNB86NB24NBB5NB77NBE7NB8DNB4ANB60NBBBNB07NBE0NBF1NB98NB12NBC5NBC9NB9CNB16NBC2NBD0NB93NB20NBD0",
              "NBF0NB87NB0ANBB5NB77NB8ENB8DNB4ANB60NBBBNB07NBF2NBFANB81NB30NBDANBF1NB81NB16NBCDNBEBNBA1NB1BNBC7NBFANB94NB17NBB5NB77NB4BNB8DNB4A",
              "NBFANB81NB36NBCDNBF6NB81NB30NBDANBFBNB90NB23NBC7NBF0NB96NB16NBC6NBECNBF5NB9BNB5FNB63NB0ANB8CNBF2NBFANB81NB30NBDANBF2NB98NB12NBDB"
            ],
            "i": "metadata/file/encoded::pe-dense-base64-like-blobs",
            "l": 3
          },
          {
            "a": "T1071",
            "c": 0.75,
            "d": "PHP URL endpoint (often used for C2)",
            "e": [
              "http://don.service-master.eu/gate.php"
            ],
            "i": "objectives/command-and-control/infrastructure/domain::php-url",
            "l": 3,
            "m": "C0002"
          },
          {
            "a": "T1027.007",
            "c": 0.8999999761581421,
            "d": "Kernel32 DLL resolution string",
            "e": [
              "kernel32.dll"
            ],
            "i": "micro-behaviors/os/api-resolution/manual::kernel32-resolver",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary is not digitally signed",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed::unsigned",
            "l": 2
          },
          {
            "a": "T1489",
            "c": 0.699999988079071,
            "d": "Versioned service stop context",
            "e": [
              "VS_VERSION_INFO"
            ],
            "i": "objectives/impact/services/stop::versioned-service-stop-context",
            "l": 1
          },
          {
            "a": "T1105",
            "c": 0.9599999785423279,
            "d": "Large overlay bundle component",
            "e": [
              "binary.overlay_size = 2689584.00"
            ],
            "i": "objectives/command-and-control/dropper/execution/installer::large-overlay-bundle",
            "l": 1,
            "m": "B0022"
          },
          {
            "c": 1.0,
            "d": "Android Pictures folder",
            "e": [
              "My Pictures"
            ],
            "i": "objectives/impact/wipe/disk/mass-delete::android-pictures",
            "l": 1
          },
          {
            "c": 0.8799999952316284,
            "d": "Configure waitable timer",
            "e": [
              "SetWaitableTimer"
            ],
            "i": "micro-behaviors/time/schedule/waitable::set-waitable-timer",
            "l": 3
          },
          {
            "a": "T1070.006",
            "c": 0.8999999761581421,
            "d": "Export timestamp is absent",
            "e": [
              "pe.export_timestamp_present = 0.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::export-timestamp-absent",
            "l": 2
          },
          {
            "a": "T1055.001",
            "c": 0.949999988079071,
            "d": "Dynamic LoadLibraryA resolution for remote injection",
            "e": [
              "LoadLibraryA"
            ],
            "i": "micro-behaviors/process/inject/dll::load-library-a-remote-resolution",
            "l": 3,
            "m": "F0003"
          },
          {
            "c": 0.8999999761581421,
            "d": "Unusual PE section alignment",
            "e": [
              "pe.unusual_alignment = 1.00"
            ],
            "i": "objectives/anti-static/obfuscation/payload::unusual-alignment-pe",
            "l": 3
          },
          {
            "a": "T1552.004",
            "c": 0.800000011920929,
            "d": "PuTTY sessions registry reference",
            "e": [
              "Software\\SimonTatham\\PuTTY\\Sessions"
            ],
            "i": "objectives/credential-access/ssh/key::putty-sessions",
            "l": 4
          },
          {
            "c": 0.8999999761581421,
            "d": "NetUserEnum remote user enumeration",
            "e": [
              "NetUserEnum"
            ],
            "i": "micro-behaviors/os/service/remote::net-user-enum-source",
            "l": 3
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "GetProcAddress loader API string",
            "e": [
              "GetProcAddress"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-getprocaddress-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "a": "T1027",
            "c": 0.8799999952316284,
            "d": "Resource section entropy is unusually low",
            "e": [
              "pe.rsrc_entropy = 2.45"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::low-entropy-rsrc",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1027",
            "c": 0.8600000143051147,
            "d": "Long mixed-case identifiers cluster",
            "e": [
              "SetProcessDEPPolicy",
              "MsgWaitForMultipleObjects",
              "SandboxieDcomLaunch",
              "ProcessIdToSessionId",
              "AllocateAndInitializeSid",
              "CheckTokenMembership",
              "ImpersonateLoggedOnUser",
              "ConvertSidToStringSidA",
              "AdjustTokenPrivileges",
              "CryptAcquireCertificatePrivateKey",
              "GetNativeSystemInfo",
              "WininetCacheCredentials",
              "WideCharToMultiByte",
              "GetWindowsDirectoryA",
              "GetPrivateProfileStringA",
              "SetCurrentDirectoryA"
            ],
            "i": "objectives/anti-static/obfuscation/string::long-mixedcase-identifiers",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1027",
            "c": 1.0,
            "d": "Binary is 1MB or larger",
            "e": [
              "binary.file_size = 2738736.00"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics::file-size-1m-plus",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.699999988079071,
            "d": "High string count over 1000",
            "e": [
              "binary.string_count = 6927.00"
            ],
            "i": "metadata/binary/metrics::high-string-count-1000",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "Standard MSVC CRT linkage (rich header + many imports)",
            "e": [
              "pe.rich_header_present = 1.00",
              "binary.import_count = 108.00"
            ],
            "i": "objectives/evasion/process/injection::msvc-crt-full-linkage",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE version resource metadata",
            "e": [
              "ProductVersion",
              "VS_VERSION_INFO",
              "FileVersion"
            ],
            "i": "metadata/package/versioning::version-resource-metadata",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "Visual Basic 6 application framework",
            "e": [
              "EVENT_SINK_Release",
              "__vbaExceptHandler",
              "MSVBVM60.DLL",
              "EVENT_SINK_QueryInterface",
              "EVENT_SINK_AddRef"
            ],
            "i": "metadata/binary/framework::vb6-application-framework",
            "l": 2
          },
          {
            "a": "T1555",
            "c": 0.949999988079071,
            "d": "FileZilla credential stealer detected",
            "e": [
              "\\filezilla.xml",
              "\\recentservers.xml",
              "Software\\FileZilla",
              "Software\\FileZilla Client",
              "\\sitemanager.xml"
            ],
            "i": "objectives/credential-access/ftp/filezilla::filezilla-stealer",
            "l": 4
          },
          {
            "c": 0.75,
            "d": "Legacy rich PE with broad imports",
            "e": [
              "binary.section_count = 3.00",
              "binary.overall_entropy = 2.70",
              "binary.import_count = 108.00",
              "pe.rich_header_present = 1.00",
              "binary.string_count = 6927.00"
            ],
            "i": "metadata/binary/layout::rich-imported-low-entropy-layout",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "VB6 runtime API dispatch",
            "e": [
              "EVENT_SINK_Release",
              "__vbaExceptHandler",
              "MSVBVM60.DLL",
              "EVENT_SINK_QueryInterface",
              "EVENT_SINK_AddRef",
              "DllFunctionCall"
            ],
            "i": "micro-behaviors/dylib/lookup::vb6-runtime-api-dispatch",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "High-trust tool delivered via low-integrity packaging",
            "e": [
              "binary.has_overlay = 1.00"
            ],
            "i": "objectives/supply-chain/trojanized/application/monitor::low-integrity-installer-packaging",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.9200000166893005,
            "d": "Registry open create and write APIs",
            "e": [
              "RegOpenKeyExA",
              "RegSetValueExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::registry-write-api-chain",
            "l": 3
          },
          {
            "a": "T1027.009",
            "c": 0.800000011920929,
            "d": "Large high-entropy overlay",
            "e": [
              "binary.overlay_size = 2689584.00",
              "binary.overlay_entropy = 7.67"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics::high-entropy-overlay",
            "l": 3,
            "m": "B0032"
          },
          {
            "c": 1.0,
            "d": "Contains Windows executable file path",
            "e": [
              ".exe",
              "c:\\\\\\\\\\\\/\\/\\/\\/\\//\\\\\\\\\\\\\\\\\\\\\\\\\\\\//////\\\\/\\/\\/windows\\\\\\\\\\\\/\\/\\/\\/\\//\\\\\\\\\\\\\\\\\\\\\\\\\\\\//////\\\\/\\/\\/system32\\\\\\\\\\\\/\\/\\/\\/\\//\\\\\\\\\\"
            ],
            "i": "micro-behaviors/data/text/malware::exe-extension-string",
            "l": 2
          },
          {
            "a": "T1027.009",
            "c": 0.8500000238418579,
            "d": "Binary with encrypted overlay payload",
            "e": [
              "binary.has_overlay = 1.00",
              "binary.overlay_size = 2689584.00",
              "binary.overlay_entropy = 7.67"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics::binary-encrypted-overlay",
            "l": 3,
            "m": "B0032"
          },
          {
            "c": 0.8999999761581421,
            "d": "Trojanized system utility or hardware monitor dropper",
            "e": [
              "WinRAR",
              "PuTTY",
              "FileZilla",
              "filezilla",
              "binary.has_overlay = 1.00"
            ],
            "i": "objectives/supply-chain/trojanized/application/monitor::trojanized-system-utility-dropper",
            "l": 4
          },
          {
            "c": 0.8999999761581421,
            "d": "Encoded payload detected: xor",
            "e": [
              "`5~qgh\u0026xGp+CXv)@C6=epv1Zrdv2[q,M,GdSKg\u003eO \u003cxor\u003e",
              "dv\u0026KnL6C_ojive!@u\u00260NRfpqUN-\"Gb$4 \u003cxor\u003e",
              "}\\/[\u003cn2iaa#Cs(`Qp{ '|v%[U53=u;4g1s,CtR/O \u003cxor\u003e",
              "hm/Kwe+5efjRM((kNwueyL%ZPx.JKm-M \u003cxor\u003e",
              "ho36Ui6.Zef'\u003eZm)yb{:RU~7@xkg`W(q4^g+2z^6 \u003cxor\u003e",
              "r\u003cC}pwdx^*F}t/]cWdH|w0\\ho3ZhO6IQ \u003cxor\u003e",
              "93^kwhoxX$g-\u0026D}z:2mx'Hhc=iv4)+oc\u003ezF#.KS] \u003cxor\u003e",
              "4JOL/;UbA$~?wo}p.\":;6.|p%B1l*Bwc3Pm$?Z}8 \u003cxor\u003e",
              "1\u0026bb1;Io_4#ly?S~2QRv}2\u003cJX*\"p'\u003ebm\"-Sfy;Rc \u003cxor\u003e",
              "G662Ak2Be:\"BHep9Rh$edx%Zbu/=pV=w \u003cxor\u003e",
              "+YRh!qCq\u003eSCD1 b`;cX1?Hg$-`N\u00262$jXR+IG,~N! \u003cxor\u003e",
              "\u0026cGL1\"a:/SZb1?nl6.so6soN'qhi/$Yl\\B \u003cxor\u003e",
              "g!R[p?eak70|L\"\\gE5Hhw-\\u/7\u003cGx'?vDnb|u0KF \u003cxor\u003e",
              "s.@h3\"ZNx8%+g62kg2*aajioR5@eM$OC6;3Tu/KJ \u003cxor\u003e",
              "V\u003cRew\u0026dOn7/Ot\"]@/1/OF0\\uT.Zu~\u0026Iw \u003cxor\u003e",
              "=1BpP26uw70x9/wU,tXl?$%3u3JGy+Yo \u003cxor\u003e",
              "u7%\"z::SO}\"ijj9Plj0_tj(Z{$3=t- 4)btyipwd \u003cxor\u003e",
              "\u003eAJy2\"i\u002695l16Kf^;Ch\u003c/C]B(P`tudNv1#Dj\u003e-[s \u003cxor\u003e",
              "ncCO1Kq`ghaW=0sE6sv!/rMO=p^g\"Cwx\\x!m?Eup \u003cxor\u003e",
              "#,Cx*g6az:Fij!%f+!Idn=fS1=3ei\u0026cnJ+.ld8Jt \u003cxor\u003e",
              "QRDr.Uu6*=B)ob/o-CTzr;jI.jC%6KW\\9SRk6[ge \u003cxor\u003e",
              "y7\u0026aQx*C_bjiM'pzVi07K\\ppQOfaqa=L \u003cxor\u003e",
              "r}K9BM\\rCcs7@u%\u003cpNz44yO62Ah+*x\";CD?p9}\u0026u \u003cxor\u003e",
              "%,V6w+0xAxzb\u0026,lJoqtAoYm#$iw\u0026b+I1\u003e@SMg\"Rk \u003cxor\u003e",
              "p%Sapwdx\\.FBM3\\~`1XBq-]e.3\u003cu\u00267YQ \u003cxor\u003e",
              "oJm/'!pb4$bx*Bk5\u003ePd#/\"^g94e)naLN:%q*2C~t \u003cxor\u003e",
              "a\u003cS[pwdB_.lq{#:fs/0}E0\\#c.`uw?YA \u003cxor\u003e",
              "b\u003cBWwg6SuoGR];fgE,r|~=fhr\u003eK[i; jK'HC48-p \u003cxor\u003e",
              "#?yipwdOho}agj]E3dHB}0Me/',d$\u0026 c \u003cxor\u003e",
              "r,4qd2Niu6FB615kW%cGU=fds7ayx+/c \u003cxor\u003e",
              "w/+RP2tSx70ey/5sW%?^c$\\xu7JO\"60sH6se$iq} \u003cxor\u003e",
              "lw\u0026asy\":l2jind8Qhm07e'5ard.Kyluw \u003cxor\u003e",
              "W\u003c;Wu\"_Ok*/O{jgE3dHK=4\\u!/JxL\u0026bvD%cxx(\"S \u003cxor\u003e",
              "ph+pE22CdVj*Hc5)xxuey78JI47alW4; \u003cxor\u003e",
              "/qv3\\nm5IuG,*eW3`mu+0YL\u0026Xe51aSo2*/f=0{E/ \u003cxor\u003e",
              "/Ct#LsG-Ypwewa/.KtL;IrKnbuL(aZ-,*ho1Wza/ \u003cxor\u003e",
              "\u0026bFy2\"[a6hVl=0vq+1{77/v{=J[%\u0026ir\u003c\\x!m?,e| \u003cxor\u003e",
              "`%Ra{g6i\"'VR\u0026!gEF5/hr \\}G\u003e3`*%bk \u003cxor\u003e",
              "`m6qv%\u0026S2rzyvs+k}9 OCN``~f?-iw-\\4F-Buj\u0026\u0026 \u003cxor\u003e",
              "1}f=6soo6Ybv4`SL6Sg4X$fa\u003e3[\u0026.Kl)*HF|=Rji \u003cxor\u003e",
              "Bv'KYu\u0026%u*;CL?8ARf07Vi5ZE_3aR,$\\ \u003cxor\u003e",
              "3\u003cBayw\u0026:i./F6+LwV1sJ}-*`nfaux/0jZ?Yxz(a} \u003cxor\u003e",
              "3k`o/=W\u0026$5Rg/Kj_+5i:1:!+5ANx$O|v8qby#2ZE \u003cxor\u003e",
              "2`:2lC'Hxl|;A7:;]p#9e;6K+iqL`d5pwds:qs/C \u003cxor\u003e",
              ",!R\"pwden:}mm?gEF1YK\u003cevmUvp|\\?cbD;Hd\"(Kx \u003cxor\u003e",
              "\u003eKux'!OY9BDebSIi?Pht6Z^h0\\uO?ar:;RxG2Ck7 \u003cxor\u003e",
              "?X`uyZZ\"65m,\u003cF@u+YI3+HsM$Jhi?iv3\\xfl\u0026ThH \u003cxor\u003e",
              "=Zxg6yYlXx!m\u0026nl0o2t9*.u=livf+4wm#Ph#\"qpu \u003cxor\u003e",
              "\u003c\u003c;_ywdx%7/qx+M\\nd0a=4wVl3#i\"50fZ?\u003edz1aa \u003cxor\u003e",
              "sdhmi\u0026\u0026p\\6FB7zvvbtc^g4\\u/3\u003cpO6IcL+Hu*,aa \u003cxor\u003e",
              "a=Repwd|**V:t\"Lo3ds7qe5hn.aqw? M\\nYGLya^ \u003cxor\u003e",
              "Go7KpR7H`r$4rf'B]%7Qi$?Kxu(C}662gi+h[b\"C \u003cxor\u003e",
              "]:B@If)#3\u0026-Nv4\\C75pwd25}`?*Le;9Vju'dypqc \u003cxor\u003e",
              "G,Rmg/_p:*lOv15vm%HxcufNr3aG\u0026/I$ \u003cxor\u003e",
              "p5R2d/NVL.0Cw+Lbc\u003cI}-\u003cLiG3[N://{ \u003cxor\u003e",
              "Rf\u0026aYw8:Os2yft)@dx0utf1Kfj#2\"/4; \u003cxor\u003e",
              "+,CtQ2OdL*Fq!2vsW%c_,ugFs3Kux6Is \u003cxor\u003e",
              "U2UxX.aqh7XiH$hs(:yn=.jVf?q[La\\;x+K~%6C| \u003cxor\u003e",
              "Szq6\u003cN[*aB(71`y)BA8r;v=-kZo\u0026Zd{94hi~qb^2 \u003cxor\u003e",
              "lqi*wSzH\\xAU\u003c,uz\u003e[*w\u003eHy[lS{]*BMn\u003ePmO6Ja\\ \u003cxor\u003e",
              "s%BhB\u0026Oan*FxMz5jn1IaF.5dc7ZG\"/Xc \u003cxor\u003e",
              "l%Ry,6_uw\u0026 Sj;gA3,HN/=\\hp'Jan%bH1?Yq5!p} \u003cxor\u003e",
              "},hmk/_ut*VF62L~?\u003cHRmufhr7K|://c \u003cxor\u003e",
              ";XB\"1Kyl?%x.-VP96YH!6HLt)Z3x/yn\"\\xzn?Ta~ \u003cxor\u003e",
              "\u0026HqN!2q}\u003e%CF5|Pn+I~!%bbo|#O4gxbZ\\$~c2Ep! \u003cxor\u003e",
              "-!;ew.)`:\u003e?qm?MEF,ImF=%y\u003e=3W2?cvK?HuN8-N \u003cxor\u003e",
              "\"q?.1dr|y~z#;vH.)d3?q|z$Lhj+Jr%(*t,\"CLe` \u003cxor\u003e",
              "m]+pEg+Rib?Cg(`jyM=^lx%qby7KKlef5w1Cu`66 \u003cxor\u003e",
              "+ME\"ox0'2mw'bSY4R\\u7+I5vze;2Z^4q \u003cxor\u003e",
              "F5+K\u003c\u0026e}i.F:t/wng=Ipg0wde.Jh://f!+1|ky\"a \u003cxor\u003e",
              "m\u003cS^B\u0026eOk.Ge}j%sG1YKG.5[.3JlO\u0026YTK\u0026\u003ext(`e \u003cxor\u003e",
              ", bc+1Em'IXe-#ht6B bABfl.UOm6Kmh \u003cxor\u003e",
              "+1V6\u003cKO*,ha\"?/Hs;!z1\u0026Ibk%Z}\\\u0026B{xHhLr.UR. \u003cxor\u003e",
              "nYCOy\"\u0026a6hVbtlvr/Hkb/s~{$Kdd?S~J\\xYUw,lJ \u003cxor\u003e",
              "ncGOy`Sl\u0026x`pd}ba6I{a5rIO-J}N6x{l@Rz`\"na\u0026 \u003cxor\u003e",
              "lSHl#$k}.P^o?[B 4%}96pwdciycj*Lepz^j=_q8 \u003cxor\u003e",
              "6Im_i2Ov/ieVtWMG\u0026cb?\u0026cre=qVd?RwsHRj+/ \u003cxor\u003e",
              "\u00262y^:!U07Iihh3|~\u003eC}s-}sb'cw\u003e'X{g5ayz3xg[ \u003cxor\u003e",
              "+Sjz8Phf-^Vf([@7#[lG +$V%Ch@?dB_.Fq!j]@/ \u003cxor\u003e",
              "a%Byy?O}e\u003e}uk;Mfqd0uG4wiU=q[j;Yj0?b}Lyah \u003cxor\u003e",
              "\u0026bpyyaao\":F*1}na7.Ik7YHv5\u003cu4gygb\\;g,w,i\u0026 \u003cxor\u003e",
              "Vd6qAi+ieo#Cvh(Qd}$Oy68q\\u7Jug0f \u003cxor\u003e",
              "lf6qr\\+Cec/xfs(@Fyuepx%,nzv2_p4$ \u003cxor\u003e",
              "`i6-c6+Rao/xj+(AG6\u003e'py!3byv2[+e\\9~,BKe.) \u003cxor\u003e",
              "1?|)Bf{:xg!.k`k\u003e[l|$LVg+2f%ci}ojin?5@[9= \u003cxor\u003e",
              "7@Zogali9Shm/pD$ciZV2xjw(P[M$dN{;3\\u#KW| \u003cxor\u003e",
              "IGH=Szh7+En.Qm%?Ky8)\\dt\u0026Zow*ChV?*fc!@a\u0026e \u003cxor\u003e",
              "ph+pEk6hl\"\"5Hc5kNwu_Bwp3I47alW4; \u003cxor\u003e",
              "s=Rh@weqg*VF62LI#1slp4wde7Zqu6Is \u003cxor\u003e",
              "Go'Jd7:!eY4Bbu;RUy#9uO/atg9SW\\/2b_;xKr/C \u003cxor\u003e",
              "ll9+*k#,0B+,\\dn7ZNN+0fZnYxtya}b.5df?/jq/ \u003cxor\u003e",
              "%99=wbbM%99=\u003ewbbM+9=wbbM\"=(?,M:,#)c),9M \u003cxor\u003e",
              "\"7$!!,M```M+9=wbbM%99=wbbM%99=\u003ewbbM+9=cM \u003cxor\u003e"
            ],
            "i": "metadata/encoded-payload/xor",
            "l": 3
          }
        ],
        "sha": "c15ba5a161b91de4d0c88b60a3b2b9289022534c652b0d55617ef5451567008e",
        "path": "/data/samples/bad/datasets/pe-machine-learning-dataset/479505",
        "type": "pe"
      },
      {
        "f": "K₂O₁₀(As₈C₉Ca₅SCoDy₂I₂P₂Er₄Pr₂)H₆(Cm₃Db₂F₂Os₅Po₅Ds)Md₅(PtSiBi₄Pa₂)",
        "x": 237,
        "dp": 1,
        "id": 1,
        "is": [
          "CreateFileA",
          "ReadFile",
          "CloseHandle",
          "WriteFile",
          "lstrlenA",
          "GlobalLock",
          "GlobalUnlock",
          "LocalFree",
          "LocalAlloc",
          "GetTickCount",
          "lstrcpyA",
          "lstrcatA",
          "GetFileAttributesA",
          "ExpandEnvironmentStringsA",
          "GetFileSize",
          "CreateFileMappingA",
          "MapViewOfFile",
          "UnmapViewOfFile",
          "LoadLibraryA",
          "GetProcAddress",
          "GetTempPathA",
          "CreateDirectoryA",
          "DeleteFileA",
          "GetCurrentProcess",
          "WideCharToMultiByte",
          "GetLastError",
          "lstrcmpA",
          "CreateToolhelp32Snapshot",
          "Process32First",
          "OpenProcess",
          "Process32Next",
          "FindFirstFileA",
          "lstrcmpiA",
          "FindNextFileA",
          "FindClose",
          "GetModuleHandleA",
          "GetVersionExA",
          "GetLocaleInfoA",
          "GetSystemInfo",
          "GetWindowsDirectoryA",
          "GetPrivateProfileStringA",
          "SetCurrentDirectoryA",
          "GetPrivateProfileSectionNamesA",
          "GetPrivateProfileIntA",
          "GetCurrentDirectoryA",
          "lstrlenW",
          "MultiByteToWideChar",
          "Sleep",
          "GetModuleFileNameA",
          "LCMapStringA",
          "ExitProcess",
          "SetUnhandledExceptionFilter",
          "RegOpenKeyExA",
          "RegQueryValueExA",
          "RegCloseKey",
          "RegOpenKeyA",
          "RegEnumKeyExA",
          "RegCreateKeyA",
          "RegSetValueExA",
          "IsTextUnicode",
          "RegOpenCurrentUser",
          "RegEnumValueA",
          "GetUserNameA",
          "CreateStreamOnHGlobal",
          "GetHGlobalFromStream",
          "CoCreateGuid",
          "CoTaskMemFree",
          "CoCreateInstance",
          "OleInitialize",
          "ShellExecuteA",
          "StrStrIA",
          "StrRChrIA",
          "StrToIntA",
          "StrStrA",
          "StrCmpNIA",
          "StrStrIW",
          "wsprintfA",
          "LoadUserProfileA",
          "UnloadUserProfile",
          "InternetCrackUrlA",
          "InternetCreateUrlA",
          "inet_addr",
          "gethostbyname",
          "socket",
          "connect",
          "closesocket",
          "send",
          "select",
          "recv",
          "setsockopt",
          "WSAStartup"
        ],
        "ms": {
          "pe": {
            "machine": 332.0,
            "checksum": 0.0,
            "subsystem": 2.0,
            "timestamp": 1442649594.0,
            "image_base": 4194304.0,
            "entry_section": ".text",
            "size_of_image": 102400.0,
            "timestamp_day": 19.0,
            "file_alignment": 512.0,
            "timestamp_year": 2015.0,
            "characteristics": 271.0,
            "entry_point_rva": 67105.0,
            "size_of_headers": 4096.0,
            "timestamp_month": 9.0,
            "checksum_missing": true,
            "checksum_present": false,
            "export_timestamp": 0.0,
            "import_dll_count": 9.0,
            "computed_checksum": 135030.0,
            "section_alignment": 4096.0,
            "number_of_sections": 3.0,
            "resource_timestamp": 0.0,
            "linker_major_version": 2.0,
            "linker_minor_version": 50.0,
            "api_hashing_indicators": 1.0,
            "export_timestamp_present": false,
            "resource_timestamp_present": false
          },
          "binary": {
            "code_size": 72704.0,
            "file_size": 102400.0,
            "entry_point": 67105.0,
            "has_overlay": true,
            "code_entropy": 6.06,
            "data_entropy": 4.12,
            "import_count": 91.0,
            "overlay_size": 9728.0,
            "string_count": 841.0,
            "overlay_ratio": 0.09,
            "section_count": 3.0,
            "avg_complexity": 4.97,
            "function_count": 441.0,
            "import_density": 1.28,
            "max_complexity": 107.0,
            "string_density": 11.85,
            "overall_entropy": 4.77,
            "overlay_entropy": 7.13,
            "avg_basic_blocks": 7.55,
            "avg_section_size": 30720.0,
            "dependency_count": 9.0,
            "entropy_variance": 1.27,
            "function_density": 6.21,
            "avg_function_size": 158.38,
            "avg_string_length": 14.35,
            "complexity_per_kb": 0.07,
            "max_string_length": 243.0,
            "wide_string_count": 1.0,
            "writable_sections": 1.0,
            "avg_string_entropy": 3.03,
            "code_to_data_ratio": 3.74,
            "data_to_file_ratio": 0.19,
            "entry_point_is_rva": true,
            "text_to_file_ratio": 0.71,
            "total_basic_blocks": 3329.0,
            "executable_sections": 1.0,
            "string_length_stddev": 15.65,
            "largest_section_ratio": 0.71,
            "sentence_string_count": 61.0,
            "sentence_string_ratio": 0.07,
            "behavioral_import_ratio": 0.08,
            "function_analysis_depth": 2.0,
            "high_complexity_functions": 1.0
          }
        },
        "ss": [
          [
            77,
            "!This program cannot be run in DOS mode."
          ],
          [
            376,
            ".text"
          ],
          [
            455,
            "@.data"
          ],
          [
            5521,
            "5KHA"
          ],
          [
            8312,
            "PSQRWV"
          ],
          [
            8451,
            "VWPSQR"
          ],
          [
            64539,
            "UVW3"
          ],
          [
            70713,
            "33331"
          ],
          [
            72697,
            "PPSV"
          ],
          [
            73216,
            "\r\n\r\naPLib v1.01  -  the smaller the better :)\r\nCopyright (c) 1998-2009 by Joergen Ibsen, All Rights Reserved.\r\n\r\nMore informatio"
          ],
          [
            73220,
            "aPLib v1.01  -  the smaller the better :)"
          ],
          [
            73263,
            "Copyright (c) 1998-2009 by Joergen Ibsen, All Rights Reserved."
          ],
          [
            73329,
            "More information: http://www.ibsensoftware.com/"
          ],
          [
            73728,
            "123456"
          ],
          [
            73735,
            "password"
          ],
          [
            73750,
            "qwerty"
          ],
          [
            73757,
            "12345"
          ],
          [
            73763,
            "jesus"
          ],
          [
            73778,
            "1234"
          ],
          [
            73783,
            "abc123"
          ],
          [
            73790,
            "letmein"
          ],
          [
            73798,
            "test"
          ],
          [
            73803,
            "love"
          ],
          [
            73812,
            "password1"
          ],
          [
            73822,
            "hello"
          ],
          [
            73828,
            "monkey"
          ],
          [
            73835,
            "dragon"
          ],
          [
            73842,
            "trustno1"
          ],
          [
            73858,
            "iloveyou"
          ],
          [
            73867,
            "1234567"
          ],
          [
            73875,
            "shadow"
          ],
          [
            73892,
            "christ"
          ],
          [
            73899,
            "sunshine"
          ],
          [
            73908,
            "master"
          ],
          [
            73915,
            "computer"
          ],
          [
            73924,
            "princess"
          ],
          [
            73933,
            "tigger"
          ],
          [
            73940,
            "football"
          ],
          [
            73949,
            "angel"
          ],
          [
            73955,
            "jesus1"
          ],
          [
            73962,
            "123123"
          ],
          [
            73969,
            "whatever"
          ],
          [
            73978,
            "freedom"
          ],
          [
            73986,
            "killer"
          ],
          [
            73998,
            "soccer"
          ],
          [
            74005,
            "superman"
          ],
          [
            74014,
            "michael"
          ],
          [
            74022,
            "cheese"
          ],
          [
            74029,
            "internet"
          ],
          [
            74038,
            "joshua"
          ],
          [
            74045,
            "fuckyou"
          ],
          [
            74053,
            "blessed"
          ],
          [
            74061,
            "baseball"
          ],
          [
            74070,
            "starwars"
          ],
          [
            74086,
            "purple"
          ],
          [
            74093,
            "jordan"
          ],
          [
            74100,
            "faith"
          ],
          [
            74106,
            "summer"
          ],
          [
            74113,
            "ashley"
          ],
          [
            74120,
            "buster"
          ],
          [
            74127,
            "heaven"
          ],
          [
            74134,
            "pepper"
          ],
          [
            74149,
            "hunter"
          ],
          [
            74156,
            "lovely"
          ],
          [
            74163,
            "andrew"
          ],
          [
            74170,
            "thomas"
          ],
          [
            74177,
            "angels"
          ],
          [
            74184,
            "charlie"
          ],
          [
            74192,
            "daniel"
          ],
          [
            74204,
            "jennifer"
          ],
          [
            74213,
            "single"
          ],
          [
            74220,
            "hannah"
          ],
          [
            74227,
            "qazwsx"
          ],
          [
            74240,
            "matrix"
          ],
          [
            74259,
            "654321"
          ],
          [
            74266,
            "amanda"
          ],
          [
            74273,
            "nothing"
          ],
          [
            74281,
            "ginger"
          ],
          [
            74288,
            "mother"
          ],
          [
            74295,
            "snoopy"
          ],
          [
            74302,
            "jessica"
          ],
          [
            74310,
            "welcome"
          ],
          [
            74318,
            "pokemon"
          ],
          [
            74326,
            "iloveyou1"
          ],
          [
            74342,
            "mustang"
          ],
          [
            74350,
            "helpme"
          ],
          [
            74357,
            "justin"
          ],
          [
            74364,
            "jasmine"
          ],
          [
            74372,
            "orange"
          ],
          [
            74379,
            "testing"
          ],
          [
            74387,
            "apple"
          ],
          [
            74393,
            "michelle"
          ],
          [
            74402,
            "peace"
          ],
          [
            74408,
            "secret"
          ],
          [
            74417,
            "grace"
          ],
          [
            74423,
            "william"
          ],
          [
            74431,
            "iloveyou2"
          ],
          [
            74441,
            "nicole"
          ],
          [
            74455,
            "muffin"
          ],
          [
            74462,
            "gateway"
          ],
          [
            74470,
            "fuckyou1"
          ],
          [
            74479,
            "asshole"
          ],
          [
            74487,
            "hahaha"
          ],
          [
            74494,
            "poop"
          ],
          [
            74499,
            "blessing"
          ],
          [
            74508,
            "blahblah"
          ],
          [
            74517,
            "myspace1"
          ],
          [
            74526,
            "matthew"
          ],
          [
            74534,
            "canada"
          ],
          [
            74541,
            "silver"
          ],
          [
            74548,
            "robert"
          ],
          [
            74555,
            "forever"
          ],
          [
            74563,
            "asdfgh"
          ],
          [
            74570,
            "rachel"
          ],
          [
            74577,
            "rainbow"
          ],
          [
            74585,
            "guitar"
          ],
          [
            74592,
            "peanut"
          ],
          [
            74599,
            "batman"
          ],
          [
            74606,
            "cookie"
          ],
          [
            74613,
            "bailey"
          ],
          [
            74620,
            "soccer1"
          ],
          [
            74628,
            "mickey"
          ],
          [
            74635,
            "biteme"
          ],
          [
            74642,
            "hello1"
          ],
          [
            74649,
            "eminem"
          ],
          [
            74656,
            "dakota"
          ],
          [
            74663,
            "samantha"
          ],
          [
            74672,
            "compaq"
          ],
          [
            74679,
            "diamond"
          ],
          [
            74687,
            "taylor"
          ],
          [
            74694,
            "forum"
          ],
          [
            74700,
            "john316"
          ],
          [
            74708,
            "richard"
          ],
          [
            74716,
            "blink182"
          ],
          [
            74725,
            "peaches"
          ],
          [
            74733,
            "cool"
          ],
          [
            74738,
            "flower"
          ],
          [
            74745,
            "scooter"
          ],
          [
            74753,
            "banana"
          ],
          [
            74760,
            "james"
          ],
          [
            74766,
            "asdfasdf"
          ],
          [
            74775,
            "victory"
          ],
          [
            74783,
            "london"
          ],
          [
            74790,
            "123qwe"
          ],
          [
            74797,
            "123321"
          ],
          [
            74804,
            "startrek"
          ],
          [
            74813,
            "george"
          ],
          [
            74820,
            "winner"
          ],
          [
            74827,
            "maggie"
          ],
          [
            74834,
            "trinity"
          ],
          [
            74842,
            "online"
          ],
          [
            74849,
            "123abc"
          ],
          [
            74856,
            "chicken"
          ],
          [
            74864,
            "junior"
          ],
          [
            74877,
            "passw0rd"
          ],
          [
            74886,
            "austin"
          ],
          [
            74893,
            "sparky"
          ],
          [
            74900,
            "admin"
          ],
          [
            74906,
            "merlin"
          ],
          [
            74913,
            "google"
          ],
          [
            74920,
            "friends"
          ],
          [
            74928,
            "hope"
          ],
          [
            74933,
            "shalom"
          ],
          [
            74940,
            "nintendo"
          ],
          [
            74949,
            "looking"
          ],
          [
            74957,
            "harley"
          ],
          [
            74964,
            "smokey"
          ],
          [
            74976,
            "joseph"
          ],
          [
            74989,
            "digital"
          ],
          [
            74999,
            "thunder"
          ],
          [
            75007,
            "spirit"
          ],
          [
            75014,
            "bandit"
          ],
          [
            75021,
            "enter"
          ],
          [
            75027,
            "anthony"
          ],
          [
            75035,
            "corvette"
          ],
          [
            75044,
            "hockey"
          ],
          [
            75051,
            "power"
          ],
          [
            75057,
            "benjamin"
          ],
          [
            75083,
            "viper"
          ],
          [
            75089,
            "genesis"
          ],
          [
            75097,
            "knight"
          ],
          [
            75104,
            "qwerty1"
          ],
          [
            75112,
            "creative"
          ],
          [
            75121,
            "foobar"
          ],
          [
            75128,
            "adidas"
          ],
          [
            75135,
            "rotimi"
          ],
          [
            75142,
            "slayer"
          ],
          [
            75149,
            "wisdom"
          ],
          [
            75192,
            "http://don.service-master.eu/gate.php"
          ],
          [
            75448,
            "http://don.service-master.eu/shit.exe"
          ],
          [
            75705,
            "YUIPWDFILE0YUIPKDFILE0YUICRYPTED0YUI1.0"
          ],
          [
            75749,
            "68.85.1.1:19791"
          ],
          [
            75751,
            "MODU"
          ],
          [
            75765,
            "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall"
          ],
          [
            75817,
            "UninstallString"
          ],
          [
            75833,
            "DisplayName"
          ],
          [
            75855,
            ".exe"
          ],
          [
            75860,
            "Software\\WinRAR"
          ],
          [
            75876,
            "open"
          ],
          [
            75885,
            "kernel32.dll"
          ],
          [
            75898,
            "WTSGetActiveConsoleSessionId"
          ],
          [
            75927,
            "ProcessIdToSessionId"
          ],
          [
            75949,
            "netapi32.dll"
          ],
          [
            75962,
            "NetApiBufferFree"
          ],
          [
            75979,
            "NetUserEnum"
          ],
          [
            75992,
            "ole32.dll"
          ],
          [
            76002,
            "StgOpenStorage"
          ],
          [
            76018,
            "advapi32.dll"
          ],
          [
            76031,
            "AllocateAndInitializeSid"
          ],
          [
            76056,
            "CheckTokenMembership"
          ],
          [
            76077,
            "FreeSid"
          ],
          [
            76085,
            "CredEnumerateA"
          ],
          [
            76100,
            "CredFree"
          ],
          [
            76109,
            "CryptGetUserKey"
          ],
          [
            76125,
            "CryptExportKey"
          ],
          [
            76140,
            "CryptDestroyKey"
          ],
          [
            76156,
            "CryptReleaseContext"
          ],
          [
            76176,
            "RevertToSelf"
          ],
          [
            76189,
            "OpenProcessToken"
          ],
          [
            76206,
            "ImpersonateLoggedOnUser"
          ],
          [
            76230,
            "GetTokenInformation"
          ],
          [
            76250,
            "ConvertSidToStringSidA"
          ],
          [
            76273,
            "LogonUserA"
          ],
          [
            76284,
            "LookupPrivilegeValueA"
          ],
          [
            76306,
            "AdjustTokenPrivileges"
          ],
          [
            76329,
            "crypt32.dll"
          ],
          [
            76341,
            "CryptUnprotectData"
          ],
          [
            76360,
            "CertOpenSystemStoreA"
          ],
          [
            76381,
            "CertEnumCertificatesInStore"
          ],
          [
            76409,
            "CertCloseStore"
          ],
          [
            76424,
            "CryptAcquireCertificatePrivateKey"
          ],
          [
            76459,
            "msi.dll"
          ],
          [
            76467,
            "MsiGetComponentPathA"
          ],
          [
            76489,
            "pstorec.dll"
          ],
          [
            76501,
            "PStoreCreateInstance"
          ],
          [
            76639,
            "shell32.dll"
          ],
          [
            76651,
            "SHGetFolderPathA"
          ],
          [
            76737,
            "My Documents"
          ],
          [
            76758,
            "AppData"
          ],
          [
            76774,
            "Local AppData"
          ],
          [
            76796,
            "Cache"
          ],
          [
            76810,
            "Cookies"
          ],
          [
            76826,
            "History"
          ],
          [
            76842,
            "My Documents"
          ],
          [
            76863,
            "Common AppData"
          ],
          [
            76886,
            "My Pictures"
          ],
          [
            76906,
            "Common Documents"
          ],
          [
            76931,
            "Common Administrative Tools"
          ],
          [
            76967,
            "Administrative Tools"
          ],
          [
            76996,
            "Personal"
          ],
          [
            77005,
            "Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders"
          ],
          [
            77070,
            "explorer.exe"
          ],
          [
            77096,
            "SeImpersonatePrivilege"
          ],
          [
            77119,
            "SeTcbPrivilege"
          ],
          [
            77134,
            "SeChangeNotifyPrivilege"
          ],
          [
            77158,
            "SeCreateTokenPrivilege"
          ]
        ],
        "sz": 102400,
        "ts": [
          {
            "c": 1.0,
            "d": "Binary is not digitally signed",
            "i": "metadata/unsigned",
            "l": 3
          },
          {
            "d": "password keyword",
            "e": [
              "_FtpPassword",
              "_Password",
              "\"password\" : \"",
              "FtpPassword",
              "password",
              "PassWord",
              "Password",
              "PasswordType",
              "password1"
            ],
            "i": "micro-behaviors/data/text/keywords::password",
            "l": 1
          },
          {
            "a": "T1057",
            "d": "Browser app firefox",
            "e": [
              "Firefox",
              "Firefox"
            ],
            "i": "micro-behaviors/process/enumerate/apps::browser-apps-firefox",
            "l": 2,
            "m": "E1592"
          },
          {
            "c": 1.0,
            "d": "LoadLibrary symbol",
            "e": [
              "LoadLibraryA"
            ],
            "i": "objectives/anti-static/obfuscation/reflection/class::loadlibrary-sym",
            "l": 1
          },
          {
            "c": 0.9900000095367432,
            "d": "Exactly three sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "well-known/malware/worm/ludbaruma::metric-section-count-3",
            "l": 1
          },
          {
            "c": 0.6499999761581421,
            "d": "Get file size",
            "e": [
              "GetFileSize"
            ],
            "i": "micro-behaviors/fs/sync/fsync::get-file-size",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Exit current process",
            "e": [
              "ExitProcess"
            ],
            "i": "micro-behaviors/process/terminate/kill::exit-process",
            "l": 2
          },
          {
            "a": "T1071.001",
            "d": "User-Agent header",
            "e": [
              "User-Agent:",
              "User-Agent:",
              "User-Agent:"
            ],
            "i": "micro-behaviors/communications/http/request::user-agent-header",
            "l": 2,
            "m": "C0002"
          },
          {
            "a": "T1562.001",
            "c": 0.8999999761581421,
            "d": "Task Manager process enumeration",
            "e": [
              "Process32Next"
            ],
            "i": "micro-behaviors/process/terminate/kill::taskmgr-process-enum",
            "l": 3,
            "m": "B0001"
          },
          {
            "c": 1.0,
            "d": "PE binary has trailing overlay data",
            "e": [
              "binary.has_overlay = 1.00"
            ],
            "i": "metadata/binary/layout::has-overlay",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Tool identity claims PuTTY",
            "e": [
              "PuTTY"
            ],
            "i": "metadata/package/tooling::tool-identity-putty",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 4 or fewer sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "objectives/command-and-control/infrastructure/config::max-sections-4",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "RegOpenKeyEx API",
            "e": [
              "RegOpenKeyExA"
            ],
            "i": "objectives/anti-static/obfuscation/payload::reg-open-key",
            "l": 2,
            "m": "B0032"
          },
          {
            "a": "T1112",
            "c": 0.8500000238418579,
            "d": "Create registry key via WinAPI",
            "e": [
              "RegCreateKeyA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-create-key-a",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "HTTP User-Agent header",
            "e": [
              "User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows 98)",
              "…ntent-Encoding: binary\r\nUser-Agent: Mozilla/4.0 (compatible…",
              "…q=0\r\nConnection: close\r\nUser-Agent: Mozilla/4.0 (compatible…"
            ],
            "i": "micro-behaviors/communications/http/user-agent::user-agent-header-dup",
            "l": 2
          },
          {
            "c": 0.30000001192092896,
            "d": "secret keyword",
            "e": [
              "secret"
            ],
            "i": "micro-behaviors/data/text/keywords::secret",
            "l": 1
          },
          {
            "a": "T1071.001",
            "c": 0.7799999713897705,
            "d": "HTTP POST request line",
            "e": [
              "POST %s HTTP/1.0"
            ],
            "i": "micro-behaviors/communications/http/post::post-request-line",
            "l": 3,
            "m": "C0002"
          },
          {
            "a": "T1572",
            "c": 1.0,
            "d": "DMW custom SSH tunneling tool password string",
            "e": [
              "password",
              "password",
              "password",
              "password"
            ],
            "i": "objectives/command-and-control/channel/tunnel::dmw-tunnel-pwd",
            "l": 1
          },
          {
            "c": 0.75,
            "d": "Initialize OLE/COM subsystem",
            "e": [
              "OleInitialize"
            ],
            "i": "micro-behaviors/os/com/invoke::ole-initialize",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE standard runtime section",
            "e": [
              ".rdata"
            ],
            "i": "metadata/binary/section/names::pe-runtime-standard-section",
            "l": 1
          },
          {
            "a": "T1555",
            "c": 0.8999999761581421,
            "d": "FileZilla main config file",
            "e": [
              "\\filezilla.xml"
            ],
            "i": "objectives/credential-access/ftp/filezilla::filezilla-xml",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE standard code/data section",
            "e": [
              ".text",
              ".data"
            ],
            "i": "metadata/binary/section/names::pe-code-data-standard-section",
            "l": 1
          },
          {
            "a": "T1106",
            "c": 0.949999988079071,
            "d": "Open process handle",
            "e": [
              "OpenProcess"
            ],
            "i": "micro-behaviors/process/create/spawn::open-process",
            "l": 2
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Set registry value ANSI",
            "e": [
              "RegSetValueExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-set-value-ex-a",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "NCapture launches explorer",
            "e": [
              "explorer.exe"
            ],
            "i": "well-known/app/graphics::ncapture-explorer",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Local memory deallocation",
            "e": [
              "LocalFree"
            ],
            "i": "micro-behaviors/mem/alloc/heap::local-free",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "OpenProcess/NtOpenProcess symbol",
            "e": [
              "OpenProcess"
            ],
            "i": "objectives/evasion/fileless/memory::open-process-sym",
            "l": 1
          },
          {
            "a": "T1082",
            "c": 0.8799999952316284,
            "d": "Query locale information",
            "e": [
              "GetLocaleInfoA"
            ],
            "i": "micro-behaviors/os/sysinfo/platform::get-locale-info",
            "l": 2
          },
          {
            "a": "T1082",
            "c": 0.6499999761581421,
            "d": "Hostname in binary",
            "e": [
              "Hostname"
            ],
            "i": "micro-behaviors/os/sysinfo/hostname::hostname-string-raw",
            "l": 1,
            "m": "E1082"
          },
          {
            "c": 0.800000011920929,
            "d": "High number of imported symbols (\u003e80)",
            "e": [
              "binary.import_count = 91.00"
            ],
            "i": "metadata/binary/metrics::many-imports",
            "l": 2
          },
          {
            "a": "T1485",
            "c": 0.699999988079071,
            "d": "Windows Shell Folders registry path",
            "e": [
              "Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders"
            ],
            "i": "objectives/impact/destroy/file-deletion::shell-folders-personal-targeting",
            "l": 2,
            "m": "C0047"
          },
          {
            "c": 0.7799999713897705,
            "d": "HTTP URL prefix marker",
            "e": [
              "http://",
              "http://",
              "http://"
            ],
            "i": "well-known/malware/trojan/elex/lpadv::http-prefix",
            "l": 1
          },
          {
            "a": "T1005",
            "c": 0.550000011920929,
            "d": "Generic database extension",
            "e": [
              ".db",
              ".db",
              ".db"
            ],
            "i": "objectives/collection/file-targeting/filter::db-extension",
            "l": 1,
            "m": "B0024"
          },
          {
            "c": 1.0,
            "d": "Binary has 25+ imports",
            "e": [
              "binary.import_count = 91.00"
            ],
            "i": "metadata/binary/metrics::many-imports-25",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Get module handle ANSI",
            "e": [
              "GetModuleHandleA"
            ],
            "i": "micro-behaviors/os/module/load::get-module-handle-ansi",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Uses Windows API for file mapping",
            "e": [
              "CreateFileMappingA"
            ],
            "i": "micro-behaviors/fs/memory/mmap::win32-file-mapping",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Winsock socket creation import",
            "e": [
              "socket"
            ],
            "i": "micro-behaviors/communications/socket/init::socket-api",
            "l": 3
          },
          {
            "c": 0.7200000286102295,
            "d": "Winsock connect API string",
            "e": [
              "connect"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-connect-api-string",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has low average complexity",
            "e": [
              "binary.avg_complexity = 4.97"
            ],
            "i": "metadata/binary/metrics::avg-complexity-15-max",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Get current process handle",
            "e": [
              "GetCurrentProcess"
            ],
            "i": "micro-behaviors/os/module/load::get-current-process",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Close handle",
            "e": [
              "CloseHandle"
            ],
            "i": "micro-behaviors/process/create/spawn::close-handle-dup",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Tool identity claims WinRAR",
            "e": [
              "WinRAR"
            ],
            "i": "metadata/package/tooling::tool-identity-winrar",
            "l": 1
          },
          {
            "d": "Content-Type header string",
            "e": [
              "…%lu\r\nConnection: close\r\nContent-Type: application/octet-strea…",
              "Content-Type: application/octet-stream"
            ],
            "i": "micro-behaviors/communications/http/request::content-type-header",
            "l": 1
          },
          {
            "c": 0.6600000262260437,
            "d": "Delete files (Windows API ANSI)",
            "e": [
              "DeleteFileA"
            ],
            "i": "micro-behaviors/fs/file/delete::deletefile-a",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Delay execution",
            "e": [
              "Sleep"
            ],
            "i": "micro-behaviors/time/timing/delay::sleep-dup",
            "l": 2
          },
          {
            "c": 0.7200000286102295,
            "d": "Winsock socket API string",
            "e": [
              "socket"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-socket-api-string",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Query file attributes or existence",
            "e": [
              "GetFileAttributesA"
            ],
            "i": "micro-behaviors/fs/path/check::get-file-attributes",
            "l": 2
          },
          {
            "a": "T1555.003",
            "c": 0.949999988079071,
            "d": "Firefox PK11SDR_Decrypt function",
            "e": [
              "PK11SDR_Decrypt"
            ],
            "i": "objectives/credential-access/browser/firefox::pk11-decrypt",
            "l": 4,
            "m": "B0028"
          },
          {
            "a": "T1071.001",
            "d": "HTTP header syntax marker",
            "e": [
              "HTTP/1.0\r\nHost: "
            ],
            "i": "objectives/command-and-control/channel/http/protocol::http-delimiter",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Open registry key via import symbol",
            "e": [
              "RegOpenKeyA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-open-key-a-symbol",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Get tick count",
            "e": [
              "GetTickCount"
            ],
            "i": "micro-behaviors/time/query::get-tick-count",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Windows file creation/open API",
            "e": [
              "CreateFileA"
            ],
            "i": "micro-behaviors/fs/file/open::file-create-win",
            "l": 2
          },
          {
            "a": "T1555",
            "c": 0.8500000238418579,
            "d": "FileZilla application directory",
            "e": [
              "Software\\FileZilla Client",
              "Software\\FileZilla"
            ],
            "i": "objectives/credential-access/ftp/filezilla::application-path",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Low-entropy rdata section",
            "e": [
              ".rdata (entropy: 3.05)"
            ],
            "i": "metadata/binary/section/metrics::low-entropy-rdata-section",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Begin directory enumeration ANSI",
            "e": [
              "FindFirstFileA"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-first-file-a",
            "l": 2
          },
          {
            "a": "T1112",
            "c": 0.8500000238418579,
            "d": "Query registry value via import symbol",
            "e": [
              "RegQueryValueExA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-query-value-ex-a-symbol",
            "l": 2
          },
          {
            "a": "T1112",
            "c": 0.8500000238418579,
            "d": "Set registry value via WinAPI ANSI",
            "e": [
              "RegSetValueExA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-set-value-ex-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "WinExec hidden-window flag immediate",
            "e": [
              "53 4b 41 00"
            ],
            "i": "micro-behaviors/process/create/flags::winexec-sw-hide-immediate",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "PuTTY identity string",
            "e": [
              "Software\\SimonTatham\\PuTTY\\Sessions"
            ],
            "i": "objectives/supply-chain/trojanized/application/monitor::putty-identity-string",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "RegQueryValueEx API",
            "e": [
              "RegQueryValueExA"
            ],
            "i": "objectives/anti-static/obfuscation/payload::reg-query-value",
            "l": 2,
            "m": "B0032"
          },
          {
            "a": "T1112",
            "c": 0.8799999952316284,
            "d": "Enumerate registry subkeys via import",
            "e": [
              "RegEnumKeyExA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-enum-key-ex-a-symbol",
            "l": 2
          },
          {
            "a": "T1110.001",
            "c": 0.20000000298023224,
            "d": "admin keyword",
            "e": [
              "admin"
            ],
            "i": "micro-behaviors/data/text/keywords/username::admin-keyword",
            "l": 2,
            "m": "B0028"
          },
          {
            "c": 1.0,
            "d": ".bat extension",
            "e": [
              ".bat"
            ],
            "i": "objectives/command-and-control/dropper/builder::bat-ext",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 20+ imports",
            "e": [
              "binary.import_count = 91.00"
            ],
            "i": "metadata/binary/metrics::many-imports-20",
            "l": 1
          },
          {
            "c": 0.7200000286102295,
            "d": "Short uppercase mutex token",
            "e": [
              "CONSTRAINT"
            ],
            "i": "micro-behaviors/process/sync/mutex::short-uppercase-token",
            "l": 1,
            "m": "C0042"
          },
          {
            "a": "T1027",
            "c": 0.8399999737739563,
            "d": "VB6 PE with three sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "objectives/anti-static/obfuscation/payload::three-section-vb6-layout",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1071.001",
            "d": "Old Mozilla 4.0 User-Agent",
            "e": [
              "…ng: binary\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 5.0; …",
              "…ion: close\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 5.0; …",
              "User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows 98)"
            ],
            "i": "micro-behaviors/communications/http/headers::ua-mozilla-old",
            "l": 2,
            "m": "C0002"
          },
          {
            "a": "T1555",
            "c": 0.8999999761581421,
            "d": "FileZilla recentservers.xml config",
            "e": [
              "\\recentservers.xml"
            ],
            "i": "objectives/credential-access/ftp/filezilla::recentservers-xml",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Initialize Winsock library",
            "e": [
              "WSAStartup"
            ],
            "i": "micro-behaviors/communications/socket/init::wsa-startup",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "PE mapped image under 768 KiB",
            "e": [
              "pe.size_of_image = 102400.00"
            ],
            "i": "metadata/binary/layout::image-under-768kb",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 40+ imports",
            "e": [
              "binary.import_count = 91.00"
            ],
            "i": "metadata/binary/metrics::many-imports-40",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Open registry key via import symbol ANSI",
            "e": [
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-open-key-ex-a-symbol",
            "l": 2
          },
          {
            "a": "T1112",
            "c": 0.8399999737739563,
            "d": "Open registry key ANSI",
            "e": [
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-open-key-ex-a",
            "l": 2
          },
          {
            "a": "T1027.002",
            "c": 0.800000011920929,
            "d": "PEB access via FS segment (x86)",
            "e": [
              "64 a1 30 00 00 00"
            ],
            "i": "micro-behaviors/os/api-resolution/hash-based::peb-fs-access",
            "l": 2,
            "m": "F0004"
          },
          {
            "a": "T1027",
            "c": 0.699999988079071,
            "d": "Code section dominates file layout",
            "e": [
              "binary.largest_section_ratio = 0.71"
            ],
            "i": "objectives/anti-static/obfuscation/string/anomaly::dominant-text-section",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.699999988079071,
            "d": "PE has many readable strings",
            "e": [
              "binary.string_count = 841.00"
            ],
            "i": "metadata/binary/layout::many-readable-strings",
            "l": 2
          },
          {
            "a": "T1105",
            "c": 0.800000011920929,
            "d": "Numbered DAT payload filename",
            "e": [
              "ESTdb2.dat"
            ],
            "i": "objectives/command-and-control/dropper/staging::numbered-dat-payload-name",
            "l": 1,
            "m": "B0024"
          },
          {
            "c": 0.8999999761581421,
            "d": "Winsock receive import",
            "e": [
              "recv"
            ],
            "i": "micro-behaviors/communications/socket/init::recv-api",
            "l": 2
          },
          {
            "c": 0.20000000298023224,
            "d": "command keyword",
            "e": [
              "FTP++.Link\\shell\\open\\command",
              "Opera.HTML\\shell\\open\\command"
            ],
            "i": "micro-behaviors/data/text/keywords::command-dup",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Query current module path",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/fs/path/check::get-module-filename",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Tool identity claims FileZilla",
            "e": [
              "filezilla",
              "FileZilla",
              "FileZilla"
            ],
            "i": "metadata/package/tooling::tool-identity-filezilla",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.699999988079071,
            "d": "HKCU\\Software path string",
            "e": [
              "Software\\W",
              "Software\\M",
              "Software\\F",
              "Software\\F",
              "Software\\F",
              "Software\\F",
              "Software\\F",
              "Software\\F",
              "Software\\G",
              "Software\\G",
              "Software\\G",
              "Software\\G",
              "Software\\G",
              "Software\\G",
              "Software\\G",
              "Software\\G"
            ],
            "i": "objectives/anti-static/obfuscation/payload::hkcu-software-text",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 1.0,
            "d": "Binary has 50+ functions",
            "e": [
              "binary.function_count = 441.00"
            ],
            "i": "metadata/binary/metrics::many-functions-50",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Padodor COM instance string",
            "e": [
              "CoCreateInstance"
            ],
            "i": "well-known/malware/trojan/shellobject/padodor::padodor-cocreateinstance-string",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Binary has low overall entropy",
            "e": [
              "binary.overall_entropy = 4.77"
            ],
            "i": "metadata/binary/metrics::low-overall-entropy-binary",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Check if running under WoW64",
            "e": [
              "IsWow64Process"
            ],
            "i": "micro-behaviors/os/compat/wow64::is-wow64-process",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Get module file path (ANSI)",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/os/module/load::get-module-filename-ansi",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "GetModuleFileName API call",
            "e": [
              "GetModuleFileNameA",
              "sub.KERNEL32.DLL_GetModuleFileNameA"
            ],
            "i": "micro-behaviors/process/info/current::get-module-filename",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "sqlite3 string",
            "e": [
              "sqlite3"
            ],
            "i": "micro-behaviors/data/db/conn/sqlite::sqlite3-string",
            "l": 2
          },
          {
            "a": "T1005",
            "c": 0.75,
            "d": "SQLite extension",
            "e": [
              ".sqlite",
              ".sqlite",
              ".sqlite"
            ],
            "i": "objectives/collection/file-targeting/filter::sqlite-extension",
            "l": 1,
            "m": "B0024"
          },
          {
            "c": 0.6000000238418579,
            "d": "Copyright notice",
            "e": [
              "Copyright",
              "Copyright"
            ],
            "i": "metadata/package/license::copyright-word",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "File is a compiled binary",
            "e": [
              "binary.file_size = 102400.00"
            ],
            "i": "metadata/binary/framework::is-binary",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.8799999952316284,
            "d": "Dense short mixed-case data tokens",
            "e": [
              "Microsoft",
              "Software",
              "FreeSid",
              "CredFree",
              "Documents",
              "AppData",
              "Local",
              "Cache",
              "Cookies",
              "History",
              "Documents",
              "Common",
              "Pictures",
              "Common",
              "Common",
              "Tools"
            ],
            "i": "objectives/anti-static/obfuscation/string::dense-short-mixedcase-data-tokens",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1071.001",
            "c": 0.6000000238418579,
            "d": "HTTP Connection close header",
            "e": [
              "Connection: close"
            ],
            "i": "objectives/command-and-control/channel/http-beacon::http-connection-close-header",
            "l": 1,
            "m": "B0030"
          },
          {
            "a": "T1036.005",
            "c": 0.75,
            "d": "C2 gate.php endpoint",
            "e": [
              "gate.php"
            ],
            "i": "objectives/command-and-control/beacon/network::c2-gate-php-endpoint",
            "l": 1,
            "m": "B0030"
          },
          {
            "c": 0.8399999737739563,
            "d": "High basic block count in sparse binary",
            "e": [
              "binary.total_basic_blocks = 3329.00"
            ],
            "i": "metadata/binary/metrics::dense-basic-blocks",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Read current working directory",
            "e": [
              "GetCurrentDirectoryA"
            ],
            "i": "micro-behaviors/fs/traversal/drives::get-current-directory",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Small PE resource section",
            "e": [
              "pe.rsrc_size = 0.00"
            ],
            "i": "metadata/package/versioning::pe-small-rsrc",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "Binary imports ADVAPI32.dll",
            "e": [
              "advapi32.dll"
            ],
            "i": "metadata/binary/symbols::imports-advapi32-dll",
            "l": 1
          },
          {
            "a": "T1552.004",
            "c": 0.75,
            "d": "Remote Desktop Protocol extension",
            "e": [
              ".rdp"
            ],
            "i": "objectives/collection/file-targeting/filter::rdp-extension",
            "l": 3,
            "m": "B0024"
          },
          {
            "a": "T1555.003",
            "c": 0.8999999761581421,
            "d": "Firefox logins database",
            "e": [
              "SELECT hostname, encryptedUsername, encryptedPassword FROM moz_logins"
            ],
            "i": "micro-behaviors/fs/path/sensitive/browser::firefox-logins",
            "l": 3
          },
          {
            "a": "T1059.001",
            "c": 0.75,
            "d": "Execute shell command (ShellExecuteA)",
            "e": [
              "ShellExecuteA"
            ],
            "i": "micro-behaviors/process/create/exec::shell-execute-a",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "Map a file section into memory",
            "e": [
              "MapViewOfFile"
            ],
            "i": "micro-behaviors/fs/memory/mmap::map-view-of-file",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "High-risk token privilege name",
            "e": [
              "SeImpersonatePrivilege",
              "SeTcbPrivilege",
              "SeAssignPrimaryTokenPrivilege"
            ],
            "i": "objectives/privilege-escalation/token-manipulation::dangerous-privilege-name",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary is not position-independent (fixed load address)",
            "e": [
              "binary.is_pie = 0.00"
            ],
            "i": "metadata/hardening::no-pie",
            "l": 2
          },
          {
            "c": 0.6399999856948853,
            "d": "Delete files (Windows API ANSI)",
            "e": [
              "DeleteFileA"
            ],
            "i": "micro-behaviors/fs/file/delete::deletefile-a-text",
            "l": 2
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "LoadLibraryA loader API string",
            "e": [
              "LoadLibraryA"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-loadlibrarya-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "c": 1.0,
            "d": "Binary has 3+ functions",
            "e": [
              "binary.function_count = 441.00"
            ],
            "i": "metadata/binary/metrics::few-functions-3",
            "l": 1
          },
          {
            "a": "T1195.002",
            "c": 0.550000011920929,
            "d": "Plaintext hello beacon token",
            "e": [
              "hello"
            ],
            "i": "objectives/command-and-control/backdoor/binary::plaintext-hello-beacon-token",
            "l": 1,
            "m": "B0025"
          },
          {
            "c": 1.0,
            "d": "WSAStartup import",
            "e": [
              "WSAStartup"
            ],
            "i": "well-known/malware/trojan/hijack-gen::padodor-wsa-startup-import",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 30+ imports",
            "e": [
              "binary.import_count = 91.00"
            ],
            "i": "metadata/binary/metrics::many-imports-30",
            "l": 1
          },
          {
            "c": 0.8199999928474426,
            "d": "GetWindowsDirectory API string",
            "e": [
              "GetWindowsDirectoryA"
            ],
            "i": "micro-behaviors/os/sysinfo/directories::get-windows-directory-string",
            "l": 2
          },
          {
            "a": "T1112",
            "c": 0.8799999952316284,
            "d": "Enumerate registry values via import",
            "e": [
              "RegEnumValueA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-enum-value-a-symbol",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE has low overall entropy",
            "e": [
              "binary.overall_entropy = 4.77"
            ],
            "i": "metadata/binary/layout::low-overall-entropy",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.8500000238418579,
            "d": "Suspicious PHP endpoint URL (gate/upload/etc)",
            "e": [
              "http://don.service-master.eu/gate.php"
            ],
            "i": "objectives/command-and-control/infrastructure/domain::suspicious-php-filename",
            "l": 4,
            "m": "C0002"
          },
          {
            "a": "T1071.001",
            "d": "HTTP/1.x version string",
            "e": [
              "GET %s HTTP/1.0\r\nHost: %s\r\nAccept: */*…",
              "POST %s HTTP/1.0\r\nHost: %s\r\nAccept: */*…"
            ],
            "i": "micro-behaviors/communications/http/request::http-version",
            "l": 2,
            "m": "C0002"
          },
          {
            "c": 0.75,
            "d": "HTTP protocol version strings",
            "e": [
              "HTTP/1.0",
              "HTTP/1.0"
            ],
            "i": "micro-behaviors/communications/http/request::http-versions",
            "l": 1
          },
          {
            "c": 0.75,
            "d": "INI extension marker",
            "e": [
              ".ini",
              ".ini"
            ],
            "i": "well-known/malware/trojan/elex/lpadv::ini-extension",
            "l": 1
          },
          {
            "a": "T1485",
            "c": 0.8999999761581421,
            "d": "Preserves .exe .gho .bak files",
            "e": [
              ".exe"
            ],
            "i": "objectives/impact/destroy/file-deletion::exe-gho-bak-whitelist",
            "l": 1,
            "m": "C0047"
          },
          {
            "a": "T1005",
            "c": 0.4000000059604645,
            "d": "Generic data extension",
            "e": [
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat"
            ],
            "i": "objectives/collection/file-targeting/filter::dat-extension",
            "l": 1,
            "m": "B0024"
          },
          {
            "c": 1.0,
            "d": "Binary has low average string entropy",
            "e": [
              "binary.avg_string_entropy = 3.03"
            ],
            "i": "metadata/binary/metrics::avg-string-entropy-4-max",
            "l": 2
          },
          {
            "a": "T1053.005",
            "c": 0.8799999952316284,
            "d": "Task action principal properties",
            "e": [
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path"
            ],
            "i": "objectives/persistence/login/scheduled-task::task-action-principal-properties",
            "l": 1,
            "m": "F0012"
          },
          {
            "c": 0.7599999904632568,
            "d": "Winsock startup API string",
            "e": [
              "WSAStartup"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-startup-api-string",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Get system error code",
            "e": [
              "GetLastError"
            ],
            "i": "micro-behaviors/os/exception/error-handling::get-last-error",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Binary has many functions (\u003e30)",
            "e": [
              "binary.function_count = 441.00"
            ],
            "i": "metadata/binary/metrics::many-functions",
            "l": 2
          },
          {
            "c": 0.9599999785423279,
            "d": "Elex Internet Explorer product resource",
            "e": [
              "Internet Explorer"
            ],
            "i": "well-known/malware/trojan/elex/worm::elex-internet-explorer-product-resource",
            "l": 2
          },
          {
            "a": "T1555.003",
            "c": 0.699999988079071,
            "d": "Chromium Login Data database reference",
            "e": [
              "Login Data"
            ],
            "i": "objectives/credential-access/browser/chromium::logins-table",
            "l": 3
          },
          {
            "c": 0.8500000238418579,
            "d": "PE linked with binutils 2.x (MinGW/GCC)",
            "e": [
              "pe.linker_major_version = 2.00"
            ],
            "i": "metadata/lang/compiler/native::linker-binutils-2x",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "Uses internet communication API imports",
            "e": [
              "WSAStartup"
            ],
            "i": "micro-behaviors/communications/http::has-internet-communication-apis",
            "l": 2
          },
          {
            "a": "T1555",
            "c": 0.8999999761581421,
            "d": "FileZilla sitemanager.xml config",
            "e": [
              "\\sitemanager.xml"
            ],
            "i": "objectives/credential-access/ftp/filezilla::sitemanager-xml",
            "l": 1
          },
          {
            "c": 0.6800000071525574,
            "d": "Read INI string value",
            "e": [
              "GetPrivateProfileStringA"
            ],
            "i": "micro-behaviors/fs/config/system::read-private-profile-ansi",
            "l": 2
          },
          {
            "a": "T1555.003",
            "c": 0.949999988079071,
            "d": "Java DPAPI unprotect call",
            "e": [
              "UnprotectData"
            ],
            "i": "objectives/credential-access/discord/token::java-crypt-unprotect-data",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Directory enumeration (ANSI)",
            "e": [
              "FindNextFileA"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-next-file-a",
            "l": 2
          },
          {
            "a": "T1082",
            "c": 0.8999999761581421,
            "d": "Query Windows version info",
            "e": [
              "GetVersionExA"
            ],
            "i": "micro-behaviors/os/sysinfo/platform::get-version-ex",
            "l": 2
          },
          {
            "c": 0.8600000143051147,
            "d": "Register unhandled exception filter",
            "e": [
              "SetUnhandledExceptionFilter"
            ],
            "i": "micro-behaviors/os/exception/error-handling::set-unhandled-exception-filter-import",
            "l": 2
          },
          {
            "c": 0.6600000262260437,
            "d": "Create directories (Windows API ANSI)",
            "e": [
              "CreateDirectoryA"
            ],
            "i": "micro-behaviors/fs/directory/mkdir::create-directory-a",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Create COM object instance",
            "e": [
              "CoCreateInstance"
            ],
            "i": "micro-behaviors/os/com/invoke::co-create-instance",
            "l": 2
          },
          {
            "a": "T1071",
            "c": 0.6000000238418579,
            "d": "URL with .php endpoint",
            "e": [
              "http://don.service-master.eu/gate.php"
            ],
            "i": "objectives/command-and-control/infrastructure/domain::php-endpoint-url",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "gethostbyname import string",
            "e": [
              "gethostbyname"
            ],
            "i": "micro-behaviors/communications/ip/resolve::resolve-gethostbyname-import",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Write data to file handle",
            "e": [
              "WriteFile"
            ],
            "i": "micro-behaviors/fs/file/write::write-file",
            "l": 2
          },
          {
            "a": "T1036.005",
            "c": 0.800000011920929,
            "d": "explorer.exe process name",
            "e": [
              "explorer.exe"
            ],
            "i": "objectives/evasion/masquerade/process::explorer-name",
            "l": 1,
            "m": "F0004"
          },
          {
            "c": 0.8999999761581421,
            "d": "Winsock outbound connect import",
            "e": [
              "connect"
            ],
            "i": "micro-behaviors/communications/socket/init::connect-api",
            "l": 3
          },
          {
            "c": 0.6600000262260437,
            "d": "Look up temp directory via GetTempPath",
            "e": [
              "GetTempPathA"
            ],
            "i": "micro-behaviors/fs/temp/directory::get-temp-path-dup",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE has few sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "metadata/binary/layout::legacy-few-sections",
            "l": 2
          },
          {
            "a": "T1053.005",
            "c": 0.8999999761581421,
            "d": "Task Scheduler builder methods",
            "e": [
              "GetFolder",
              "Connect",
              "Connect",
              "Connect",
              "Connect",
              "Connect"
            ],
            "i": "objectives/persistence/login/scheduled-task::task-scheduler-builder-methods",
            "l": 1,
            "m": "F0012"
          },
          {
            "c": 0.8999999761581421,
            "d": "Close registry key",
            "e": [
              "RegCloseKey"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-close-key",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Close directory enumeration handle",
            "e": [
              "FindClose"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-close",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Winsock send import",
            "e": [
              "send"
            ],
            "i": "micro-behaviors/communications/socket/init::send-api",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Get Windows installation directory",
            "e": [
              "GetWindowsDirectoryA",
              "sub.KERNEL32.DLL_GetWindowsDirectoryA"
            ],
            "i": "micro-behaviors/os/sysinfo/directories::get-windows-directory",
            "l": 2
          },
          {
            "a": "T1027.007",
            "c": 0.8500000238418579,
            "d": "PEB Ldr access for module enumeration",
            "e": [
              "64 A1 30 00 00 00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::peb-ldr-access",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "c": 0.8999999761581421,
            "d": "Local memory allocation",
            "e": [
              "LocalAlloc"
            ],
            "i": "micro-behaviors/mem/alloc/heap::local-alloc",
            "l": 2
          },
          {
            "a": "T1082",
            "c": 0.8999999761581421,
            "d": "Query system hardware info (CPU cores)",
            "e": [
              "GetSystemInfo"
            ],
            "i": "micro-behaviors/os/sysinfo/hardware::get-system-info",
            "l": 2
          },
          {
            "a": "T1548.002",
            "c": 0.699999988079071,
            "d": "Shell Open command registry key",
            "e": [
              "\\shell\\open\\command"
            ],
            "i": "objectives/privilege-escalation/elevation-control/uac-bypass/hijack::shell-open-command-reg",
            "l": 1
          },
          {
            "a": "T1071.001",
            "c": 0.6600000262260437,
            "d": "Accept-Encoding header",
            "e": [
              "Accept-Encoding: identity, *;q=0",
              "…\nHost: %s\r\nAccept: */*\r\nAccept-Encoding: identity, *;q=0\r\nConne…",
              "…\nHost: %s\r\nAccept: */*\r\nAccept-Encoding: identity, *;q=0\r\nConte…"
            ],
            "i": "micro-behaviors/communications/http/headers::headers-encoding",
            "l": 2,
            "m": "C0002"
          },
          {
            "c": 0.8999999761581421,
            "d": "SQLite format header",
            "e": [
              "SQLite format 3"
            ],
            "i": "micro-behaviors/data/db/conn/sqlite::sqlite-format",
            "l": 3
          },
          {
            "c": 0.699999988079071,
            "d": "HTTP GET method",
            "e": [
              "GET %s HTTP/1.0"
            ],
            "i": "micro-behaviors/communications/http/get::get",
            "l": 3
          },
          {
            "c": 0.75,
            "d": "Binary exports no symbols",
            "e": [
              "binary.export_count = 0.00"
            ],
            "i": "metadata/binary/symbols::no-exports",
            "l": 1
          },
          {
            "d": ".bat extension reference",
            "e": [
              ".bat"
            ],
            "i": "micro-behaviors/fs/path/extension::bat-dup",
            "l": 1
          },
          {
            "a": "T1070.006",
            "c": 0.699999988079071,
            "d": "PE header compile timestamp predates 2025",
            "e": [
              "pe.timestamp = 1442649594.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::header-timestamp-pre-2025",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Read data from file handle",
            "e": [
              "ReadFile"
            ],
            "i": "micro-behaviors/fs/file/read::read-file",
            "l": 2
          },
          {
            "c": 0.6000000238418579,
            "d": "SELECT SQL keyword in query",
            "e": [
              "SELECT hostname, encryptedUsername, encryptedPassword FROM"
            ],
            "i": "micro-behaviors/data/db/conn/sql::sql-select",
            "l": 2
          },
          {
            "a": "T1499",
            "c": 0.8999999761581421,
            "d": "Shutdown prank markers",
            "e": [
              "Shutdown"
            ],
            "i": "objectives/impact/ui/manipulation::shutdown-prank-markers",
            "l": 3
          },
          {
            "a": "T1041",
            "c": 0.6000000238418579,
            "d": "PHP gate endpoint",
            "e": [
              "http://don.service-master.eu/gate.php"
            ],
            "i": "objectives/command-and-control/infrastructure/domain::php-gate",
            "l": 4,
            "m": "C0002"
          },
          {
            "d": ".dll extension reference",
            "e": [
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll"
            ],
            "i": "micro-behaviors/fs/path/extension::dll-dup",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 50+ imports",
            "e": [
              "binary.import_count = 91.00"
            ],
            "i": "metadata/binary/metrics::many-imports-50",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Free COM memory allocation",
            "e": [
              "CoTaskMemFree"
            ],
            "i": "micro-behaviors/os/com/invoke::co-task-mem-free",
            "l": 2
          },
          {
            "a": "T1057",
            "c": 0.8999999761581421,
            "d": "Create process or module snapshot",
            "e": [
              "CreateToolhelp32Snapshot"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::create-toolhelp32-snapshot",
            "l": 3,
            "m": "E1057"
          },
          {
            "a": "T1055",
            "c": 0.949999988079071,
            "d": "Huge null run in executable (128+ bytes)",
            "e": [
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00",
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00",
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00"
            ],
            "i": "objectives/anti-static/obfuscation/binary-structure::huge-null-run-text",
            "l": 1
          },
          {
            "a": "T1082",
            "c": 0.699999988079071,
            "d": "hwid string",
            "e": [
              "HWID"
            ],
            "i": "objectives/discovery/system/fingerprint/machine-id::hwid-string",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "GUID-formatted mutex name",
            "e": [
              "{CB1F2C0F-8094-4AAC-BCF5-41A64E27F777}",
              "{9EA55529-E122-4757-BC79-E4825F80732C}",
              "{11C1D741-A95B-11d2-8A80-0080ADB32FF4}",
              "{F9043C88-F6F2-101A-A3C9-08002B2F49FB}",
              "{74FF1730-B1F2-4D88-926B-1568FAE61DB7}"
            ],
            "i": "micro-behaviors/process/sync/mutex::guid-mutex",
            "l": 2,
            "m": "C0042"
          },
          {
            "d": ".exe extension reference",
            "e": [
              ".exe",
              ".exe",
              ".exe",
              ".exe"
            ],
            "i": "micro-behaviors/fs/path/extension::exe-dup",
            "l": 2
          },
          {
            "a": "T1027.007",
            "c": 0.8600000143051147,
            "d": "PE API hashing indicator present",
            "e": [
              "pe.api_hashing_indicators = 1.00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::pe-api-hashing-indicator-single",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "a": "T1027",
            "c": 0.8199999928474426,
            "d": "Packed loader largest section ratio above 0.65",
            "e": [
              "binary.largest_section_ratio = 0.71"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::packed-loader-largest-section-dominates",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1033",
            "c": 0.8999999761581421,
            "d": "Query current username",
            "e": [
              "GetUserNameA"
            ],
            "i": "micro-behaviors/os/sysinfo/hostname::get-user-name",
            "l": 3
          },
          {
            "a": "T1574.002",
            "c": 0.8999999761581421,
            "d": "Hidden LoadLibraryA string reference",
            "e": [
              "LoadLibraryA"
            ],
            "i": "micro-behaviors/dylib/load::load-library-a-string-no-import",
            "l": 1
          },
          {
            "c": 0.6000000238418579,
            "d": "Very few sections (merged/stripped)",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "metadata/binary/metrics::few-sections",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.800000011920929,
            "d": "Few PE resource entries (no DIALOG/MENU/STRINGTABLE)",
            "e": [
              "pe.resource_count = 0.00"
            ],
            "i": "objectives/evasion/anti-av/heuristic::minimal-pe-resources",
            "l": 1
          },
          {
            "a": "T1555.003",
            "c": 0.949999988079071,
            "d": "Firefox moz_logins SQL query",
            "e": [
              "SELECT hostname, encryptedUsername, encryptedPassword FROM moz_logins"
            ],
            "i": "objectives/credential-access/browser/firefox::moz-logins-sql",
            "l": 4,
            "m": "B0028"
          },
          {
            "c": 0.8999999761581421,
            "d": "Resolve exports with GetProcAddress",
            "e": [
              "GetProcAddress"
            ],
            "i": "micro-behaviors/os/module/load::get-proc-address-import",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "CreateFile API string reference",
            "e": [
              "CreateFile",
              "CreateFile"
            ],
            "i": "micro-behaviors/fs/file/open::createfile-api",
            "l": 2
          },
          {
            "a": "T1546.015",
            "c": 0.8199999928474426,
            "d": "InprocServer32 registry write",
            "e": [
              "CLSID\\{11C1D741-A95B-11d2-8A80-0080ADB32FF4}\\InProcServer32"
            ],
            "i": "objectives/persistence/system/registry/com-hijack::inprocserver32-write",
            "l": 3
          },
          {
            "c": 0.8799999952316284,
            "d": "CLSID registry path manipulation",
            "e": [
              "CLSID\\{11C1D741-A95B-11d2-8A80-0080ADB32FF4}"
            ],
            "i": "objectives/persistence/system/registry/com-hijack::clsid-registry-path",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "Binary lacks resource section entirely",
            "e": [
              "binary.rsrc_to_file_ratio = 0.00"
            ],
            "i": "metadata/binary/resource::no-resources",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "PE executable is unsigned",
            "i": "metadata/signed::unsigned-pe-executable",
            "l": 3
          },
          {
            "a": "T1071",
            "c": 0.75,
            "d": "PHP URL endpoint (often used for C2)",
            "e": [
              "http://don.service-master.eu/gate.php"
            ],
            "i": "objectives/command-and-control/infrastructure/domain::php-url",
            "l": 3,
            "m": "C0002"
          },
          {
            "a": "T1027.007",
            "c": 0.8999999761581421,
            "d": "Kernel32 DLL resolution string",
            "e": [
              "kernel32.dll"
            ],
            "i": "micro-behaviors/os/api-resolution/manual::kernel32-resolver",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary is not digitally signed",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed::unsigned",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Android Pictures folder",
            "e": [
              "My Pictures"
            ],
            "i": "objectives/impact/wipe/disk/mass-delete::android-pictures",
            "l": 1
          },
          {
            "a": "T1070.006",
            "c": 0.8999999761581421,
            "d": "Export timestamp is absent",
            "e": [
              "pe.export_timestamp_present = 0.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::export-timestamp-absent",
            "l": 2
          },
          {
            "a": "T1055.001",
            "c": 0.949999988079071,
            "d": "Dynamic LoadLibraryA resolution for remote injection",
            "e": [
              "LoadLibraryA"
            ],
            "i": "micro-behaviors/process/inject/dll::load-library-a-remote-resolution",
            "l": 3,
            "m": "F0003"
          },
          {
            "a": "T1552.004",
            "c": 0.800000011920929,
            "d": "PuTTY sessions registry reference",
            "e": [
              "Software\\SimonTatham\\PuTTY\\Sessions"
            ],
            "i": "objectives/credential-access/ssh/key::putty-sessions",
            "l": 4
          },
          {
            "c": 0.8999999761581421,
            "d": "NetUserEnum remote user enumeration",
            "e": [
              "NetUserEnum"
            ],
            "i": "micro-behaviors/os/service/remote::net-user-enum-source",
            "l": 3
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "GetProcAddress loader API string",
            "e": [
              "GetProcAddress"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-getprocaddress-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "c": 0.699999988079071,
            "d": "High function count over 200",
            "e": [
              "binary.function_count = 441.00"
            ],
            "i": "metadata/binary/metrics::high-function-count-200",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.8600000143051147,
            "d": "Long mixed-case identifiers cluster",
            "e": [
              "ProcessIdToSessionId",
              "AllocateAndInitializeSid",
              "CheckTokenMembership",
              "ImpersonateLoggedOnUser",
              "ConvertSidToStringSidA",
              "AdjustTokenPrivileges",
              "CryptAcquireCertificatePrivateKey",
              "GetNativeSystemInfo",
              "WininetCacheCredentials",
              "WideCharToMultiByte",
              "GetWindowsDirectoryA",
              "GetPrivateProfileStringA",
              "SetCurrentDirectoryA",
              "GetPrivateProfileSectionNamesA",
              "GetPrivateProfileIntA",
              "GetCurrentDirectoryA"
            ],
            "i": "objectives/anti-static/obfuscation/string::long-mixedcase-identifiers",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.8999999761581421,
            "d": "Switch current working directory",
            "e": [
              "SetCurrentDirectoryA"
            ],
            "i": "micro-behaviors/fs/traversal/drives::set-current-directory",
            "l": 3
          },
          {
            "c": 0.949999988079071,
            "d": "links shlwapi.dll (StrStrIA, StrRChrIA, StrToIntA, StrStrA, StrCmpNIA, ... +1 more)",
            "e": [
              "shlwapi.dll"
            ],
            "i": "metadata/dylib::shlwapi/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links user32.dll (wsprintfA)",
            "e": [
              "user32.dll"
            ],
            "i": "metadata/dylib::user32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links userenv.dll (LoadUserProfileA, UnloadUserProfile)",
            "e": [
              "userenv.dll"
            ],
            "i": "metadata/dylib::userenv/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links KERNEL32.DLL (CreateFileA, ReadFile, CloseHandle, WriteFile, lstrlenA, ... +47 more)",
            "e": [
              "KERNEL32.DLL"
            ],
            "i": "metadata/dylib::kernel32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links ole32.dll (CreateStreamOnHGlobal, GetHGlobalFromStream, CoCreateGuid, CoTaskMemFree, CoCreateInstance, ... +1 more)",
            "e": [
              "ole32.dll"
            ],
            "i": "metadata/dylib::ole32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links advapi32.dll (RegOpenKeyExA, RegQueryValueExA, RegCloseKey, RegOpenKeyA, RegEnumKeyExA, ... +6 more)",
            "e": [
              "advapi32.dll"
            ],
            "i": "metadata/dylib::advapi32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links wininet.dll (InternetCrackUrlA, InternetCreateUrlA)",
            "e": [
              "wininet.dll"
            ],
            "i": "metadata/dylib::wininet/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links wsock32.dll (inet_addr, gethostbyname, socket, connect, closesocket, ... +5 more)",
            "e": [
              "wsock32.dll"
            ],
            "i": "metadata/dylib::wsock32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links shell32.dll (ShellExecuteA)",
            "e": [
              "shell32.dll"
            ],
            "i": "metadata/dylib::shell32/dll",
            "l": 2
          },
          {
            "a": "T1027.009",
            "c": 0.800000011920929,
            "d": "File self-reading import chain",
            "e": [
              "CreateFileA",
              "GetFileSize",
              "GetModuleFileNameA",
              "ReadFile"
            ],
            "i": "objectives/anti-static/obfuscation/payload/self-read::self-read-file-import-chain",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.8500000238418579,
            "d": "Drop and execute file from Temp directory",
            "e": [
              "WriteFile",
              "ShellExecuteA",
              "GetTempPathA"
            ],
            "i": "objectives/command-and-control/dropper/staging::temp-file-execution",
            "l": 2
          },
          {
            "c": 0.9200000166893005,
            "d": "Directory walker using Win32 find APIs",
            "e": [
              "FindClose",
              "FindNextFileA",
              "FindFirstFileA"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-file-walker",
            "l": 2
          },
          {
            "c": 0.9200000166893005,
            "d": "Winsock client symbol lifecycle",
            "e": [
              "send",
              "socket",
              "connect",
              "recv"
            ],
            "i": "micro-behaviors/communications/socket/init::winsock-client-symbol-lifecycle",
            "l": 3
          },
          {
            "c": 0.9200000166893005,
            "d": "Dynamically resolve own modules and exports",
            "e": [
              "GetProcAddress",
              "GetModuleHandleA"
            ],
            "i": "micro-behaviors/os/module/load::dynamic-self-resolution-imports",
            "l": 2
          },
          {
            "a": "T1555",
            "c": 0.949999988079071,
            "d": "FileZilla credential stealer detected",
            "e": [
              "Software\\FileZilla",
              "Software\\FileZilla Client",
              "\\recentservers.xml",
              "\\filezilla.xml",
              "\\sitemanager.xml"
            ],
            "i": "objectives/credential-access/ftp/filezilla::filezilla-stealer",
            "l": 4
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Registry key and value write chain",
            "e": [
              "RegOpenKeyExA",
              "RegOpenKeyA",
              "RegCreateKeyA",
              "RegSetValueExA"
            ],
            "i": "micro-behaviors/os/registry/access::registry-write-api-chain",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.9200000166893005,
            "d": "MinGW PE with anti-analysis features",
            "e": [
              "pe.linker_major_version = 2.00",
              "pe.api_hashing_indicators = 1.00"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics/cross-compiled::mingw-with-anti-analysis",
            "l": 4,
            "m": "B0032"
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Registry key open and query chain",
            "e": [
              "RegQueryValueExA",
              "RegOpenKeyExA",
              "RegOpenKeyA"
            ],
            "i": "micro-behaviors/os/registry/access::registry-read-api-chain",
            "l": 2
          },
          {
            "a": "T1070.004",
            "c": 0.8199999928474426,
            "d": "Resolve own path then delete file",
            "e": [
              "DeleteFileA",
              "sub.KERNEL32.DLL_GetModuleFileNameA",
              "DeleteFileA",
              "GetModuleFileNameA"
            ],
            "i": "objectives/evasion/self-delete/file::module-path-delete",
            "l": 1,
            "m": "F0007"
          },
          {
            "a": "T1057",
            "c": 0.8999999761581421,
            "d": "ToolHelp snapshot enumeration with process access",
            "e": [
              "OpenProcess",
              "CreateToolhelp32Snapshot"
            ],
            "i": "objectives/discovery/process/targeting::toolhelp-enumeration-with-access",
            "l": 3,
            "m": "E1057"
          },
          {
            "c": 0.8999999761581421,
            "d": "High-trust tool delivered via low-integrity packaging",
            "e": [
              "binary.has_overlay = 1.00"
            ],
            "i": "objectives/supply-chain/trojanized/application/monitor::low-integrity-installer-packaging",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.9200000166893005,
            "d": "Registry open create and write APIs",
            "e": [
              "RegOpenKeyExA",
              "RegOpenKeyA",
              "RegSetValueExA",
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::registry-write-api-chain",
            "l": 3
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Registry key enumeration API chain",
            "e": [
              "RegOpenKeyA",
              "RegEnumKeyExA",
              "RegOpenKeyExA",
              "RegEnumValueA"
            ],
            "i": "micro-behaviors/os/registry/access::registry-enumeration-api-chain",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Trojanized system utility or hardware monitor dropper",
            "e": [
              "PuTTY",
              "FileZilla",
              "WinRAR",
              "binary.has_overlay = 1.00",
              "filezilla"
            ],
            "i": "objectives/supply-chain/trojanized/application/monitor::trojanized-system-utility-dropper",
            "l": 4
          }
        ],
        "sha": "dc49b33c246924ab631eea4173522a3a82b601c14e2f38a2408aa063cfb86fd6",
        "path": "479505!!embedded:pe@0x23c61e",
        "type": "pe"
      }
    ],
    "tv": "b2c18"
  }
}