{
  "ml": {
    "v": "4",
    "fs": [
      {
        "id": 0,
        "prob": 0.9815003871917725,
        "class": 1
      },
      {
        "id": 1,
        "prob": 0.9233341217041016,
        "class": 0
      }
    ],
    "prob": 0.9815004,
    "class": 1,
    "oprob": 0.9594563,
    "oclass": 0,
    "version": "v16.16",
    "thresholds": [
      0.9815004,
      0.99404883
    ],
    "analyzed_at": "2026-05-02T04:05:06Z"
  },
  "path": "32702",
  "raw": {
    "v": "4",
    "fs": [
      {
        "f": "KO₆(AlAs₉Er₅C₆I₄P₂)H₆(Cm₄F₅Os₄Po₆UDs)Md₅(Bi₅HeSiPa)Th",
        "x": 373,
        "id": 0,
        "is": [
          "CreateMemoryResourceNotification",
          "UTUnRegister",
          "InterlockedExchange",
          "TrimVirtualBuffer",
          "SetConsoleCtrlHandler",
          "SetTapeParameters",
          "SizeofResource",
          "BaseInitAppcompatCacheSupport",
          "GetVolumeInformationW",
          "SetThreadPriorityBoost"
        ],
        "ms": {
          "binary": {
            "code_size": 284160.0,
            "file_size": 328192.0,
            "wx_sections": 3.0,
            "import_count": 10.0,
            "string_count": 744.0,
            "section_count": 5.0,
            "avg_complexity": 6.73,
            "function_count": 81.0,
            "import_density": 0.04,
            "max_complexity": 39.0,
            "string_density": 2.68,
            "overall_entropy": 7.69,
            "avg_basic_blocks": 13.26,
            "avg_section_size": 65433.6,
            "function_density": 0.29,
            "avg_function_size": 3517.3,
            "avg_string_length": 19.74,
            "complexity_per_kb": 0.02,
            "max_string_length": 105.0,
            "writable_sections": 5.0,
            "avg_string_entropy": 3.5,
            "code_section_ratio": 0.6,
            "code_to_data_ratio": 6.61,
            "data_to_file_ratio": 0.13,
            "text_to_file_ratio": 0.04,
            "total_basic_blocks": 1074.0,
            "embedded_file_count": 1.0,
            "executable_sections": 3.0,
            "section_name_entropy": 2.8,
            "string_length_stddev": 15.07,
            "embedded_binary_count": 1.0,
            "largest_section_ratio": 0.76,
            "sentence_string_count": 81.0,
            "sentence_string_ratio": 0.11,
            "function_analysis_depth": 2.0,
            "has_malformed_structure": true,
            "normalized_import_count": 0.02,
            "normalized_section_count": 0.27,
            "nonstandard_section_name_count": 4.0
          }
        },
        "ss": [
          [
            46,
            "xor",
            "User-Agent: Mo"
          ],
          [
            77,
            "!This program cannot be run in DOS mode."
          ],
          [
            160,
            "Rich"
          ],
          [
            424,
            ".text"
          ],
          [
            464,
            ".rdata"
          ],
          [
            504,
            ".data"
          ],
          [
            544,
            ".brdata"
          ],
          [
            1005,
            "xor",
            "User-Agent: Mozilla"
          ],
          [
            1008,
            "xor",
            "User-Agent: Mozi"
          ],
          [
            1051,
            "m6k4u"
          ],
          [
            13537,
            "w.nu"
          ],
          [
            14039,
            "FU8O"
          ],
          [
            14572,
            "KERNEL32.dll"
          ],
          [
            14588,
            "CreateMemoryResourceNotification"
          ],
          [
            14622,
            "eaUTUnRegister"
          ],
          [
            14638,
            "ObInterlockedExchange"
          ],
          [
            14661,
            "eFTrimVirtualBuffer"
          ],
          [
            14682,
            "apSetConsoleCtrlHandler"
          ],
          [
            14707,
            "reSetTapeParameters"
          ],
          [
            14728,
            "eaSizeofResource"
          ],
          [
            14748,
            "BaseInitAppcompatCacheSupport"
          ],
          [
            14779,
            "ivGetVolumeInformationW"
          ],
          [
            14804,
            "erSetThreadPriorityBoost"
          ],
          [
            14831,
            "xor",
            "User-Agent: Mozil"
          ],
          [
            14832,
            "xor",
            "User-Agent: Mozi"
          ],
          [
            16112,
            "4QKC"
          ],
          [
            27652,
            "LDW9"
          ],
          [
            28062,
            "A6CN"
          ],
          [
            29791,
            "l9od"
          ],
          [
            31238,
            "OT4W"
          ],
          [
            32190,
            "94dm"
          ],
          [
            32322,
            "6daow"
          ],
          [
            33049,
            "W7HO"
          ],
          [
            37337,
            "46nw"
          ],
          [
            38861,
            "2\u003ed`"
          ],
          [
            43853,
            "bb.a"
          ],
          [
            45593,
            "rb.3miE"
          ],
          [
            48065,
            "s4bi"
          ],
          [
            48281,
            "Nfml"
          ],
          [
            48329,
            "i4os"
          ],
          [
            58957,
            "Foxy"
          ],
          [
            59370,
            "2YFF"
          ],
          [
            62412,
            "GUZQK"
          ],
          [
            64725,
            "Oxrbf"
          ],
          [
            78685,
            "Crea"
          ],
          [
            78718,
            "Writ"
          ],
          [
            78751,
            "Clos"
          ],
          [
            78824,
            "r.ex"
          ],
          [
            79045,
            "xor",
            "User-Agent: Mo"
          ],
          [
            79047,
            "xor",
            "User-Agent: "
          ],
          [
            79228,
            "xor",
            "TteK@1,ent: Moz"
          ],
          [
            79550,
            "@.data"
          ],
          [
            79591,
            ".rsrc"
          ],
          [
            79630,
            "@.UPX0"
          ],
          [
            80003,
            "xor",
            "User-Agent: Mozilla/\\b"
          ],
          [
            80011,
            "xor",
            "User-Agent: %#"
          ],
          [
            81332,
            "Load"
          ],
          [
            81339,
            "Reso"
          ],
          [
            108032,
            "Enum"
          ],
          [
            113475,
            "ZwQuerySystemInformation"
          ],
          [
            113503,
            "ntdll.dll"
          ],
          [
            113515,
            "KeServiceDescriptorTable"
          ],
          [
            113543,
            "kernel32.dll"
          ],
          [
            113559,
            "FILE"
          ],
          [
            113567,
            "C:\\DelInfo.bin"
          ],
          [
            113583,
            "booter.exe"
          ],
          [
            113595,
            "CONFIG.exe"
          ],
          [
            113607,
            "boottemp.exe"
          ],
          [
            113637,
            "i3qs"
          ],
          [
            113943,
            "Start"
          ],
          [
            113951,
            "www.baidu.com"
          ],
          [
            113967,
            "Parameters"
          ],
          [
            113979,
            "ServiceDll"
          ],
          [
            113991,
            "sfc_os.dll"
          ],
          [
            114003,
            "%s\\system32\\%s.dll"
          ],
          [
            114023,
            "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Svchost"
          ],
          [
            114083,
            "ost.exe"
          ],
          [
            114091,
            "%SystemRoot%\\System32\\svch%s -k nets"
          ],
          [
            114139,
            "www.xunlei.com"
          ],
          [
            114155,
            "www.3-0B6F-415d-B5C7-832F0.com"
          ],
          [
            114199,
            "Wininet.dll"
          ],
          [
            114211,
            "InternetOpenA"
          ],
          [
            114227,
            "InternetOpenUrlA"
          ],
          [
            114247,
            "HttpQueryInfoA"
          ],
          [
            114263,
            "InternetReadFileExA"
          ],
          [
            114283,
            "InternetCloseHandle"
          ],
          [
            114303,
            "InternetSetStatusCallback"
          ],
          [
            114331,
            "http://%s:%d/%s"
          ],
          [
            114347,
            "winsta0"
          ],
          [
            114355,
            "default"
          ],
          [
            114363,
            "Explorer.exe"
          ],
          [
            114379,
            "%s%d.exe"
          ],
          [
            114395,
            "winsta0\\defa"
          ],
          [
            114411,
            "%s%d.nls"
          ],
          [
            114423,
            "cryptcom.dll"
          ],
          [
            114439,
            "DLFT_Shutdown"
          ],
          [
            114455,
            "DLFT_Startup"
          ],
          [
            114471,
            "DLFT_SetTrackerReportCallback"
          ],
          [
            114503,
            "c_30218.nls"
          ],
          [
            114543,
            "GET %s?%s HTTP/1.1\r\nConnection: Keep-Alive\r\nHost: %s\r\nUser-Agent: Mozilla/4.0\r\nAccept-language: cn"
          ],
          [
            114563,
            "Connection: Keep-Alive"
          ],
          [
            114597,
            "User-Agent: Mozilla/4.0"
          ],
          [
            114622,
            "Accept-language: cn"
          ],
          [
            114647,
            "address"
          ],
          [
            114655,
            "ver=%s\u0026tgid=%s\u0026%s=%s"
          ],
          [
            114683,
            "%s%s%s"
          ],
          [
            114699,
            "alexa"
          ],
          [
            114707,
            "%s\u0026flag=%s\u0026%s=0\u0026List=%s"
          ],
          [
            114735,
            "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options"
          ],
          [
            114811,
            "SYSTEM\\CurrentControlSet\\Services"
          ],
          [
            114847,
            "\\Registry\\Machine"
          ],
          [
            114867,
            "\\Internet Explorer\\iexplore.exe"
          ],
          [
            114907,
            "Forter"
          ],
          [
            114915,
            "avp.exe"
          ],
          [
            114923,
            "bdagent.exe"
          ],
          [
            114935,
            "Forter.sys"
          ],
          [
            114959,
            "MmGetSystemRoutineAddress"
          ],
          [
            114999,
            "Thunder Network"
          ],
          [
            115015,
            "Thunder"
          ],
          [
            115031,
            "WindowsUpdate"
          ],
          [
            115047,
            "Windows NT"
          ],
          [
            115059,
            "Windows Media Player"
          ],
          [
            115083,
            "Outlook Express"
          ],
          [
            115099,
            "NetMeeting"
          ],
          [
            115111,
            "MSN Gaming Zone"
          ],
          [
            115127,
            "Movie Maker"
          ],
          [
            115139,
            "microsoft frontpage"
          ],
          [
            115159,
            "Messenger"
          ],
          [
            115171,
            "Internet Explorer"
          ],
          [
            115191,
            "InstallShield Installation Information"
          ],
          [
            115231,
            "ComPlus Applications"
          ],
          [
            115255,
            "Common Files"
          ],
          [
            115271,
            "RECYCLER"
          ],
          [
            115283,
            "System Volume Information"
          ],
          [
            115311,
            "Documents and Settings"
          ],
          [
            115343,
            "WINDOWS"
          ],
          [
            115363,
            "index"
          ],
          [
            115371,
            "Default"
          ],
          [
            115379,
            "%s X -ibck \"%s\" \"%s\\\""
          ],
          [
            115407,
            "%s M -ibck -r -o+ -ep1 \"%s\" \"%s\\*\""
          ],
          [
            115422,
            "xor",
            ":XE_H1VELQI"
          ],
          [
            115479,
            "C:\\Program Files\\WinRAR\\Rar.exe"
          ],
          [
            115519,
            "explorer.exe"
          ],
          [
            115535,
            "open"
          ],
          [
            115543,
            "\\\\.\\pipe\\96DBA249-E88E-4c47-98DC-E18E6E3E3E5A"
          ],
          [
            115591,
            "127.0.0.1       localhost"
          ],
          [
            115619,
            "%s\\drivers\\etc\\hosts"
          ],
          [
            115643,
            "%s\\c_30279.nls"
          ],
          [
            115659,
            "%s%d.txt"
          ],
          [
            115671,
            "SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\Minimal"
          ],
          [
            115723,
            "SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\Network"
          ],
          [
            116439,
            "http://%s/%s"
          ],
          [
            116467,
            "\\\\%s\\pipe%s"
          ],
          [
            116487,
            "Mpr.dll"
          ],
          [
            116495,
            "%s\\desktop.txt"
          ],
          [
            116523,
            "CONFIG"
          ],
          [
            116535,
            "\\\\%s\\%s\\%s.exe"
          ],
          [
            116551,
            "at \\\\%s %d:%d C:\\%s.exe"
          ],
          [
            116575,
            "%d.%d.%d.%d"
          ],
          [
            116587,
            "%sautorun.inf"
          ],
          [
            116603,
            "recycle.{645FF040-5081-101B-9F08-00AA002F954E}"
          ],
          [
            116651,
            "Setup.exe"
          ],
          [
            116663,
            "Show"
          ],
          [
            116687,
            "Kernel32.dll"
          ],
          [
            116703,
            "Thread32First"
          ],
          [
            116719,
            "RSDSLE"
          ],
          [
            116743,
            "C:\\exe.pdb"
          ],
          [
            117761,
            "memcpy"
          ],
          [
            117771,
            "memset"
          ],
          [
            117797,
            "??3@YAXPAX@Z"
          ],
          [
            117813,
            "strrchr"
          ],
          [
            117823,
            "??2@YAPAXI@Z"
          ],
          [
            117839,
            "strlen"
          ],
          [
            117857,
            "MSVCRT.dll"
          ],
          [
            117871,
            "ZwQueryInformationThread"
          ],
          [
            117909,
            "PathFileExistsA"
          ],
          [
            117927,
            "SHDeleteKeyA"
          ],
          [
            117941,
            "SHLWAPI.dll"
          ],
          [
            117955,
            "GetModuleInformation"
          ],
          [
            117977,
            "PSAPI.DLL"
          ],
          [
            117989,
            "freeaddrinfo"
          ],
          [
            118005,
            "getaddrinfo"
          ],
          [
            118019,
            "WSAAddressToStringA"
          ],
          [
            118041,
            "WSAResetEvent"
          ],
          [
            118057,
            "WSACreateEvent"
          ],
          [
            118075,
            "WSARecvFrom"
          ],
          [
            118087,
            "WS2_32.dll"
          ],
          [
            118101,
            "GetAdaptersInfo"
          ],
          [
            118117,
            "IPHLPAPI.DLL"
          ],
          [
            118133,
            "WinVerifyTrust"
          ],
          [
            118149,
            "WINTRUST.dll"
          ],
          [
            118165,
            "WNetCancelConnection2A"
          ],
          [
            118191,
            "WNetAddConnection2A"
          ],
          [
            118213,
            "WNetCloseEnum"
          ],
          [
            118229,
            "WNetOpenEnumA"
          ],
          [
            118243,
            "MPR.dll"
          ],
          [
            118253,
            "UuidToStringA"
          ],
          [
            118269,
            "UuidFromStringA"
          ],
          [
            118285,
            "RPCRT4.dll"
          ],
          [
            118299,
            "CreateFileA"
          ],
          [
            118313,
            "FindResourceA"
          ],
          [
            118329,
            "FreeResource"
          ],
          [
            118345,
            "lstrlenA"
          ],
          [
            118357,
            "FreeLibrary"
          ],
          [
            118371,
            "Process32First"
          ],
          [
            118389,
            "GetTickCount"
          ],
          [
            118405,
            "WriteFile"
          ],
          [
            118417,
            "Sleep"
          ],
          [
            118425,
            "SizeofResource"
          ],
          [
            118443,
            "ReadFile"
          ],
          [
            118455,
            "lstrcmpiA"
          ],
          [
            118467,
            "GetProcAddress"
          ],
          [
            118485,
            "Process32Next"
          ],
          [
            118501,
            "LockResource"
          ],
          [
            118517,
            "GetModuleFileNameA"
          ],
          [
            118539,
            "GetModuleHandleA"
          ],
          [
            118559,
            "LoadLibraryExA"
          ],
          [
            118577,
            "CreateToolhelp32Snapshot"
          ],
          [
            118605,
            "CloseHandle"
          ],
          [
            118619,
            "GetSystemTime"
          ],
          [
            118635,
            "DeleteFileA"
          ],
          [
            118649,
            "lstrcpyA"
          ],
          [
            118661,
            "ExitProcess"
          ],
          [
            118675,
            "GetFileSize"
          ],
          [
            118689,
            "SetFilePointer"
          ],
          [
            118707,
            "VirtualQuery"
          ],
          [
            118723,
            "SetEndOfFile"
          ],
          [
            118739,
            "SetFileTime"
          ],
          [
            118753,
            "GetWindowsDirectoryA"
          ],
          [
            118777,
            "MultiByteToWideChar"
          ],
          [
            118799,
            "LoadLibraryA"
          ],
          [
            118815,
            "GetFileTime"
          ],
          [
            118829,
            "GetCurrentThreadId"
          ],
          [
            118851,
            "GetTempPathA"
          ],
          [
            118867,
            "WaitForSingleObject"
          ],
          [
            118889,
            "SetEvent"
          ],
          [
            118901,
            "CreateEventA"
          ],
          [
            118917,
            "GetLastError"
          ],
          [
            118933,
            "MapViewOfFile"
          ],
          [
            118949,
            "UnmapViewOfFile"
          ],
          [
            118967,
            "OpenProcess"
          ],
          [
            118981,
            "ExitThread"
          ],
          [
            119007,
            "CreateFileMappingA"
          ],
          [
            119029,
            "WinExec"
          ],
          [
            119039,
            "GetVersion"
          ],
          [
            119053,
            "CreateThread"
          ],
          [
            119069,
            "lstrcatA"
          ],
          [
            119081,
            "CreateProcessA"
          ],
          [
            119099,
            "TerminateProcess"
          ],
          [
            119119,
            "GetSystemDirectoryA"
          ],
          [
            119141,
            "DeviceIoControl"
          ],
          [
            119159,
            "lstrcpynA"
          ],
          [
            119171,
            "GetDriveTypeA"
          ],
          [
            119187,
            "GetExitCodeProcess"
          ],
          [
            119209,
            "FindFirstFileA"
          ],
          [
            119227,
            "GetLogicalDriveStringsA"
          ]
        ],
        "sz": 328192,
        "ts": [
          {
            "a": "T1027",
            "c": 0.800000011920929,
            "d": "PE header too corrupted to parse: Malformed entity: Rich header does not contain the DanS marker",
            "e": [
              "Malformed entity: Rich header does not contain the DanS marker"
            ],
            "i": "objectives/anti-analysis/pe-tampering/corrupted-header",
            "l": 4,
            "m": "B0001"
          },
          {
            "a": "T1027.009",
            "c": 0.8999999761581421,
            "d": "Embedded PE binary at file offset 0x13497 (~262144 bytes)",
            "e": [
              "kind=Pe32 estimated_size=262144"
            ],
            "i": "binary/embedded/pe",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Detects an unspecififed malware - October 2016",
            "e": [
              "%s\\system32\\%s.dll",
              "%SystemRoot%\\System32\\svch%s -k nets",
              "\\\\.\\pipe\\96DBA249-E88E-4c47-98DC-E18E6E3E3E5A",
              "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options",
              "boottemp.exe",
              "at \\\\%s %d:%d C:\\%s.exe",
              "cryptcom.dll",
              "Wininet.dll",
              "\\\\%s\\%s\\%s.exe",
              "%s%d.exe",
              "booter.exe",
              "\\\\%s\\pipe%s",
              "C:\\DelInfo.bin"
            ],
            "i": "third_party/SigBase/Unspecified/Malware/Oct16/A",
            "l": 5
          },
          {
            "a": "T1071.001",
            "c": 0.8600000143051147,
            "d": "WinInet DLL name string",
            "e": [
              "Wininet.dll"
            ],
            "i": "micro-behaviors/communications/http/get::wininet-dll-name",
            "l": 1
          },
          {
            "c": 0.6399999856948853,
            "d": "Delete files (Windows API ANSI)",
            "e": [
              "DeleteFileA"
            ],
            "i": "micro-behaviors/fs/file/delete::deletefile-a-text",
            "l": 2
          },
          {
            "a": "T1204.002",
            "c": 0.800000011920929,
            "d": "Writes executable to drive root",
            "e": [
              "C:\\%s.exe"
            ],
            "i": "micro-behaviors/fs/path/location::path-suspicious-root-exe",
            "l": 3,
            "m": "F0013"
          },
          {
            "c": 0.800000011920929,
            "d": "Thread32First API string",
            "e": [
              "Thread32First"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::thread32-first-string",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.699999988079071,
            "d": "Code section dominates file layout",
            "e": [
              "binary.largest_section_ratio = 0.76"
            ],
            "i": "objectives/anti-static/obfuscation/string/anomaly::dominant-text-section",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1053.005",
            "c": 0.8999999761581421,
            "d": "Task Scheduler builder methods",
            "e": [
              "Connect",
              "Connect",
              "Connect",
              "Connect",
              "Connect"
            ],
            "i": "objectives/persistence/login/scheduled-task::task-scheduler-builder-methods",
            "l": 1,
            "m": "F0012"
          },
          {
            "a": "T1071.001",
            "d": "Old Mozilla 4.0 User-Agent",
            "e": [
              "…zilla/4.0(XfUser-Agent: Mozilla/4.0(XeX",
              "User-Agent: Mozilla/4.0",
              "User-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4…",
              "…zilla/4.0(XfUser-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4…",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agent: Mozilla/4.3X",
              "User-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.3%",
              "User-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0+U",
              "User-Agent: Mozilla/4.0U",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agemy",
              "…\r\nHost: %s\r\nUser-Agent: Mozilla/4.0\r\nAccept-language: cn",
              "User-Agent: Mozilla/4.0User-Agent"
            ],
            "i": "micro-behaviors/communications/http/headers::ua-mozilla-old",
            "l": 2,
            "m": "C0002"
          },
          {
            "a": "T1204.002",
            "c": 0.7599999904632568,
            "d": "Short PDB marker",
            "e": [
              "exe.pdb"
            ],
            "i": "objectives/command-and-control/dropper/execution/clickfix::short-pdb-marker",
            "l": 1,
            "m": "B0024"
          },
          {
            "a": "T1071.001",
            "c": 0.8999999761581421,
            "d": "HttpQueryInfo API name as string",
            "e": [
              "HttpQueryInfoA"
            ],
            "i": "micro-behaviors/communications/http/get::http-query-info-str",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "ServiceDll registry value marker",
            "e": [
              "servicedll"
            ],
            "i": "micro-behaviors/os/service/host::service-dll-value-name",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Tool identity claims WinRAR",
            "e": [
              "WinRAR"
            ],
            "i": "metadata/package/tooling::tool-identity-winrar",
            "l": 1
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "LoadLibraryA loader API string",
            "e": [
              "LoadLibraryA"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-loadlibrarya-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "a": "T1112",
            "c": 0.8799999952316284,
            "d": "Create registry key ANSI",
            "e": [
              "RegCreateKeyExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-create-key-ex-a",
            "l": 2
          },
          {
            "c": 0.75,
            "d": "HTTP protocol version strings",
            "e": [
              "HTTP/1.1"
            ],
            "i": "micro-behaviors/communications/http/request::http-versions",
            "l": 1
          },
          {
            "a": "T1071.001",
            "d": "HTTP/1.x version string",
            "e": [
              "GET %s?%s HTTP/1.1\r\nConnection: Keep-Aliv…"
            ],
            "i": "micro-behaviors/communications/http/request::http-version",
            "l": 2,
            "m": "C0002"
          },
          {
            "c": 1.0,
            "d": "Binary has low average string entropy",
            "e": [
              "binary.avg_string_entropy = 3.50"
            ],
            "i": "metadata/binary/metrics::avg-string-entropy-4-max",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Five section PE layout",
            "e": [
              "binary.section_count = 5.00"
            ],
            "i": "metadata/binary/section/metrics::five-section-pe",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "PE has many readable strings",
            "e": [
              "binary.string_count = 744.00"
            ],
            "i": "metadata/binary/layout::many-readable-strings",
            "l": 2
          },
          {
            "a": "T1055.012",
            "c": 0.800000011920929,
            "d": "CreateProcess API string reference",
            "e": [
              "CreateProcessAsUserA",
              "CreateProcessA"
            ],
            "i": "objectives/evasion/process/injection/hollowing::create-process-string",
            "l": 1,
            "m": "E1055.012"
          },
          {
            "a": "T1546.012",
            "c": 0.949999988079071,
            "d": "Full IFEO registry key path",
            "e": [
              "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options"
            ],
            "i": "objectives/persistence/login/ifeo/debugger::ifeo-full-path",
            "l": 1,
            "m": "F0012"
          },
          {
            "c": 0.949999988079071,
            "d": "Windows path join format string",
            "e": [
              "\\\\%s\\%s\\%s.exe"
            ],
            "i": "micro-behaviors/fs/path/construct::windows-system-path-join-format",
            "l": 1
          },
          {
            "c": 0.6600000262260437,
            "d": "Look up temp directory via GetTempPath",
            "e": [
              "GetTempPathA"
            ],
            "i": "micro-behaviors/fs/temp/directory::get-temp-path-dup",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE standard code/data section",
            "e": [
              ".text",
              ".data"
            ],
            "i": "metadata/binary/section/names::pe-code-data-standard-section",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "HTTP GET method",
            "e": [
              "GET %s?%s HTTP/1.1"
            ],
            "i": "micro-behaviors/communications/http/get::get",
            "l": 3
          },
          {
            "c": 0.7200000286102295,
            "d": "Short uppercase mutex token",
            "e": [
              "RECYCLER"
            ],
            "i": "micro-behaviors/process/sync/mutex::short-uppercase-token",
            "l": 1,
            "m": "C0042"
          },
          {
            "c": 0.8199999928474426,
            "d": "GetSystemDirectory API string",
            "e": [
              "GetSystemDirectoryA"
            ],
            "i": "micro-behaviors/os/sysinfo/directories::get-system-directory-string",
            "l": 2
          },
          {
            "a": "T1071.001",
            "d": "HTTP header syntax marker",
            "e": [
              "HTTP/1.1\r\nConnection: "
            ],
            "i": "objectives/command-and-control/channel/http/protocol::http-delimiter",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Wait for process/object",
            "e": [
              "WaitForSingleObject"
            ],
            "i": "micro-behaviors/process/create/spawn::wait-for-single-object",
            "l": 2
          },
          {
            "a": "T1562.001",
            "c": 0.8999999761581421,
            "d": "Common EDR/AV process name",
            "e": [
              "bdagent.exe"
            ],
            "i": "objectives/impact/degrade/edr::target-general-edr",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Low-entropy rdata section",
            "e": [
              ".rdata (entropy: 0.00)"
            ],
            "i": "metadata/binary/section/metrics::low-entropy-rdata-section",
            "l": 1
          },
          {
            "a": "T1057",
            "c": 0.800000011920929,
            "d": "PSAPI.dll dynamic load string",
            "e": [
              "PSAPI"
            ],
            "i": "micro-behaviors/process/enumerate/psapi::psapi-dll-string",
            "l": 1
          },
          {
            "a": "T1027.009",
            "c": 0.800000011920929,
            "d": "Size PE resource payload",
            "e": [
              "SizeofResource"
            ],
            "i": "micro-behaviors/data/embedded/payload::sizeof-resource",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "HTTP User-Agent header",
            "e": [
              "User-Agent: Mozilla/4.0U",
              "User-Agent: 碸I",
              "User-Agent: Mozil",
              "…: Keep-Alive\r\nHost: %s\r\nUser-Agent: Mozilla/4.0\r\nAccept-lan…",
              "User-Agent: Mozi",
              "User-Agent: Mozilla/4.0",
              "User-Agent: Mozilla/\\b",
              "User-Agent:",
              "User-Agent: ",
              "User-Agent: Mo",
              "User-Agent: %#",
              "User-Agent: Mozilla",
              "User-Agent: Mozilla/4.0User-Agent",
              "User-Agent: Mozill"
            ],
            "i": "micro-behaviors/communications/http/user-agent::user-agent-header-dup",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has low average complexity",
            "e": [
              "binary.avg_complexity = 6.73"
            ],
            "i": "metadata/binary/metrics::avg-complexity-15-max",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Close handle",
            "e": [
              "CloseHandle"
            ],
            "i": "micro-behaviors/process/create/spawn::close-handle-dup",
            "l": 2
          },
          {
            "a": "T1562.001",
            "c": 0.8500000238418579,
            "d": "Kaspersky AV/Internet Security specifically targeted",
            "e": [
              "avp.exe"
            ],
            "i": "objectives/impact/degrade/edr/targeting::kaspersky-target",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Binary has many functions (\u003e30)",
            "e": [
              "binary.function_count = 81.00"
            ],
            "i": "metadata/binary/metrics::many-functions",
            "l": 2
          },
          {
            "a": "T1485",
            "c": 0.8999999761581421,
            "d": "Preserves .exe .gho .bak files",
            "e": [
              ".exe"
            ],
            "i": "objectives/impact/destroy/file-deletion::exe-gho-bak-whitelist",
            "l": 1,
            "m": "C0047"
          },
          {
            "a": "T1083",
            "c": 0.8799999952316284,
            "d": "Enumerate logical drive letters",
            "e": [
              "GetLogicalDrives"
            ],
            "i": "micro-behaviors/fs/traversal/drives::get-logical-drives-text",
            "l": 3,
            "m": "E1083"
          },
          {
            "c": 0.949999988079071,
            "d": "Random low-entropy RWX cavity section",
            "e": [
              ".text (size: 13824, entropy: 0.00, perms: -rwx)",
              ".brdata (size: 20480, entropy: 0.00, perms: -rwx)"
            ],
            "i": "metadata/binary/section/metrics::random-rwx-cavity-section",
            "l": 4
          },
          {
            "c": 0.8999999761581421,
            "d": "Attach thread to desktop",
            "e": [
              "SetThreadDesktop"
            ],
            "i": "micro-behaviors/ui/window/station::set-thread-desktop-import",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "Very low code entropy, minimal code",
            "e": [
              "binary.code_entropy = 0.00"
            ],
            "i": "metadata/binary/resource::low-code-entropy",
            "l": 2
          },
          {
            "c": 0.8199999928474426,
            "d": "GetWindowsDirectory API string",
            "e": [
              "GetWindowsDirectoryA"
            ],
            "i": "micro-behaviors/os/sysinfo/directories::get-windows-directory-string",
            "l": 2
          },
          {
            "a": "T1565.001",
            "c": 0.8500000238418579,
            "d": "Windows hosts path format string",
            "e": [
              "%s\\drivers\\etc\\hosts"
            ],
            "i": "objectives/evasion/hosts-file/block-security::windows-hosts-template-path",
            "l": 4,
            "m": "F0004"
          },
          {
            "c": 0.949999988079071,
            "d": "Binary imports ADVAPI32.dll",
            "e": [
              "ADVAPI32.dll"
            ],
            "i": "metadata/binary/symbols::imports-advapi32-dll",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 50+ functions",
            "e": [
              "binary.function_count = 81.00"
            ],
            "i": "metadata/binary/metrics::many-functions-50",
            "l": 1
          },
          {
            "d": "SYSTEMROOT environment variable",
            "e": [
              "%SystemRoot%\\System32\\svch%s -k nets"
            ],
            "i": "micro-behaviors/os/env/vars/system-info::systemroot-var",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Uses Windows API for file mapping",
            "e": [
              "MapViewOfFile"
            ],
            "i": "micro-behaviors/fs/memory/mmap::win32-file-mapping",
            "l": 2
          },
          {
            "a": "T1036.005",
            "c": 0.800000011920929,
            "d": "explorer.exe process name",
            "e": [
              "explorer.exe"
            ],
            "i": "objectives/evasion/masquerade/process::explorer-name",
            "l": 1,
            "m": "F0004"
          },
          {
            "c": 0.800000011920929,
            "d": "Thread32Next API string",
            "e": [
              "Thread32Next"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::thread32-next-string",
            "l": 1
          },
          {
            "d": ".dll extension reference",
            "e": [
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll"
            ],
            "i": "micro-behaviors/fs/path/extension::dll-dup",
            "l": 2
          },
          {
            "c": 0.6200000047683716,
            "d": "Assembly Load method token",
            "e": [
              "Load"
            ],
            "i": "objectives/anti-static/obfuscation/reflection/invoke::dotnet-assembly-load-token",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE standard runtime section",
            "e": [
              ".rdata"
            ],
            "i": "metadata/binary/section/names::pe-runtime-standard-section",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Direct NT API access",
            "e": [
              "ntdll.dll"
            ],
            "i": "micro-behaviors/os/syscall/invoke::ntdll-import",
            "l": 2
          },
          {
            "c": 0.8399999737739563,
            "d": "High basic block count in sparse binary",
            "e": [
              "binary.total_basic_blocks = 1074.00"
            ],
            "i": "metadata/binary/metrics::dense-basic-blocks",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Skips Windows installation directories",
            "e": [
              "WINDOWS"
            ],
            "i": "objectives/impact/infect/binary::skip-windows-install-dir",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 3+ functions",
            "e": [
              "binary.function_count = 81.00"
            ],
            "i": "metadata/binary/metrics::few-functions-3",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "NCapture launches explorer",
            "e": [
              "explorer.exe"
            ],
            "i": "well-known/app/graphics::ncapture-explorer",
            "l": 1
          },
          {
            "a": "T1105",
            "c": 1.0,
            "d": "Binary has high overall entropy",
            "e": [
              "binary.overall_entropy = 7.69"
            ],
            "i": "objectives/command-and-control/dropper/staging::high-entropy-binary",
            "l": 1
          },
          {
            "c": 0.9599999785423279,
            "d": "Elex Internet Explorer product resource",
            "e": [
              "Internet Explorer"
            ],
            "i": "well-known/malware/trojan/elex/worm::elex-internet-explorer-product-resource",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.699999988079071,
            "d": "Encoded Mozilla user agent string",
            "e": [
              "User-Agent: Mozilla/\\b",
              "User-Agent: Mozilla/4.0User-Agent",
              "User-Agent: Mozilla/4.0U",
              "User-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4....",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agent: Mozilla/4.3X",
              "User-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.3%",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agemy",
              "User-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0+U",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0Useq ",
              "Sser-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agent: Mozilla,9",
              "User-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0(XfUser-Agent:#@",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agent: Moyd",
              "User-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0+U",
              "5ser-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0(XfUph",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0Useq ",
              "Dser-Agent: Mozilla/4.0(XfUser-Agent: Mozilla,9"
            ],
            "i": "objectives/anti-static/obfuscation/encoding::encoded-mozilla-ua",
            "l": 3
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Set registry value ANSI",
            "e": [
              "RegSetValueExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-set-value-ex-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "RECYCLER literal path marker",
            "e": [
              "RECYCLER"
            ],
            "i": "micro-behaviors/fs/path/system::recycler-literal",
            "l": 4
          },
          {
            "a": "T1082",
            "c": 0.8999999761581421,
            "d": "Query volume information",
            "e": [
              "GetVolumeInformationW"
            ],
            "i": "micro-behaviors/fs/enumerate/volume::get-volume-info",
            "l": 3
          },
          {
            "a": "T1036.005",
            "c": 0.8600000143051147,
            "d": "WindowsUpdate identity token",
            "e": [
              "WindowsUpdate"
            ],
            "i": "objectives/evasion/masquerade/identity/mimicry::windowsupdate-camelcase-token",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary is not position-independent (fixed load address)",
            "e": [
              "binary.is_pie = 0.00"
            ],
            "i": "metadata/hardening::no-pie",
            "l": 2
          },
          {
            "a": "T1546.012",
            "c": 0.8999999761581421,
            "d": "IFEO registry path",
            "e": [
              "Image File Execution Options"
            ],
            "i": "objectives/persistence/login/ifeo/debugger::ifeo-registry-path",
            "l": 1,
            "m": "F0012"
          },
          {
            "c": 1.0,
            "d": "Call to GetDriveTypeA by raw bytes",
            "e": [
              "GetDriveTypeA"
            ],
            "i": "micro-behaviors/fs/traversal/drives::get-drive-type-raw",
            "l": 1
          },
          {
            "c": 0.6000000238418579,
            "d": "System32 substring reference",
            "e": [
              "%SystemRoot%\\System32\\svch%s -k nets"
            ],
            "i": "micro-behaviors/fs/path/system::system32-substr",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Get module file path (ANSI)",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/os/module/load::get-module-filename-ansi",
            "l": 2
          },
          {
            "c": 0.550000011920929,
            "d": ".NET Start method token",
            "e": [
              "Start"
            ],
            "i": "micro-behaviors/process/create/spawn::start-method-token-dotnet",
            "l": 1
          },
          {
            "c": 0.75,
            "d": "Binary exports no symbols",
            "e": [
              "binary.export_count = 0.00"
            ],
            "i": "metadata/binary/symbols::no-exports",
            "l": 1
          },
          {
            "a": "T1071.001",
            "d": "User-Agent header",
            "e": [
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:"
            ],
            "i": "micro-behaviors/communications/http/request::user-agent-header",
            "l": 2,
            "m": "C0002"
          },
          {
            "c": 0.8999999761581421,
            "d": "Valid PE/MZ binary found embedded in file",
            "e": [
              "4D 5A 90 00"
            ],
            "i": "metadata/binary/layout::pe-embedded",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.8999999761581421,
            "d": "InternetOpen API name as string",
            "e": [
              "InternetOpenA"
            ],
            "i": "micro-behaviors/communications/http/get::internet-open-str",
            "l": 1
          },
          {
            "a": "T1071.001",
            "c": 0.8999999761581421,
            "d": "InternetCloseHandle API name",
            "e": [
              "InternetCloseHandle"
            ],
            "i": "micro-behaviors/communications/http/get::internet-close-handle-str",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "File is a compiled binary",
            "e": [
              "binary.file_size = 328192.00"
            ],
            "i": "metadata/binary/framework::is-binary",
            "l": 1
          },
          {
            "a": "T1053.005",
            "c": 0.8799999952316284,
            "d": "Task action principal properties",
            "e": [
              "Path",
              "Path",
              "Path"
            ],
            "i": "objectives/persistence/login/scheduled-task::task-action-principal-properties",
            "l": 1,
            "m": "F0012"
          },
          {
            "a": "T1112",
            "c": 0.8399999737739563,
            "d": "Open registry key ANSI",
            "e": [
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-open-key-ex-a",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Multiple embedded MZ headers",
            "e": [
              "4D 5A",
              "4D 5A",
              "4D 5A",
              "4D 5A",
              "4D 5A",
              "4D 5A",
              "4D 5A"
            ],
            "i": "metadata/binary/layout::multiple-pe-embedded-loose",
            "l": 1
          },
          {
            "a": "T1055.012",
            "c": 0.9200000166893005,
            "d": "Internet Explorer hollowing target",
            "e": [
              "\\Internet Explorer\\iexplore.exe"
            ],
            "i": "objectives/evasion/process/injection/hollowing::iexplore-hollowing-target",
            "l": 1,
            "m": "E1055.012"
          },
          {
            "c": 0.7799999713897705,
            "d": "Hardcoded loopback IPv4 address",
            "e": [
              "127.0.0.1"
            ],
            "i": "micro-behaviors/communications/ip::loopback-ipv4-binary",
            "l": 3
          },
          {
            "a": "T1543.003",
            "c": 0.8500000238418579,
            "d": "Open existing service handle",
            "e": [
              "OpenServiceA"
            ],
            "i": "micro-behaviors/os/service/control::open-service",
            "l": 3
          },
          {
            "a": "T1027",
            "c": 0.8600000143051147,
            "d": "Long mixed-case identifiers cluster",
            "e": [
              "CreateMemoryResourceNotification",
              "BaseInitAppcompatCacheSupport",
              "InternetSetStatusCallback",
              "GetModuleInformation",
              "GetModuleFileNameA",
              "GetWindowsDirectoryA",
              "MultiByteToWideChar",
              "GetSystemDirectoryA",
              "GetLogicalDriveStringsA",
              "SetNamedPipeHandleState",
              "GetCurrentProcessId",
              "DisconnectNamedPipe",
              "SetProcessWindowStation"
            ],
            "i": "objectives/anti-static/obfuscation/string::long-mixedcase-identifiers",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.8500000238418579,
            "d": "PE with malformed section layout",
            "e": [
              "binary.has_malformed_structure = 1.00"
            ],
            "i": "metadata/binary/metrics::malformed-pe-structure",
            "l": 3
          },
          {
            "c": 0.949999988079071,
            "d": "Three or more writable executable sections",
            "e": [
              "binary.wx_sections = 3.00"
            ],
            "i": "metadata/hardening/memory::three-plus-wx-sections",
            "l": 3
          },
          {
            "a": "T1562.001",
            "c": 1.0,
            "d": "ntdll.dll string reference",
            "e": [
              "ntdll.dll"
            ],
            "i": "objectives/evasion/anti-av/platform::ntdll-dll-str",
            "l": 1
          },
          {
            "a": "T1027.007",
            "c": 0.8999999761581421,
            "d": "Kernel32 DLL resolution string",
            "e": [
              "kernel32.dll"
            ],
            "i": "micro-behaviors/os/api-resolution/manual::kernel32-resolver",
            "l": 1
          },
          {
            "a": "T1543.003",
            "c": 0.8500000238418579,
            "d": "Start Windows service",
            "e": [
              "StartServiceA"
            ],
            "i": "micro-behaviors/os/service/control::start-service",
            "l": 3
          },
          {
            "a": "T1027.007",
            "c": 0.800000011920929,
            "d": "DLL name strings without LoadLibrary import",
            "e": [
              "binary.import_count = 10.00"
            ],
            "i": "objectives/anti-static/obfuscation/string/runtime-decrypt::dll-names-no-loadlibrary",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "c": 0.800000011920929,
            "d": "UPX packer marker string",
            "e": [
              "UPX0"
            ],
            "i": "objectives/anti-static/pack/detect::upx-marker",
            "l": 1
          },
          {
            "c": 0.7200000286102295,
            "d": "Writable .rdata section permissions",
            "e": [
              ".rdata (perms: -rw-)"
            ],
            "i": "metadata/binary/section/names::writable-rdata",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "CreateFile API string reference",
            "e": [
              "CreateFile",
              "CreateFile"
            ],
            "i": "micro-behaviors/fs/file/open::createfile-api",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.699999988079071,
            "d": "Hardcoded loopback IP (likely test C2)",
            "e": [
              "127.0.0.1"
            ],
            "i": "objectives/command-and-control/channel/http-beacon::hardcoded-localhost-c2",
            "l": 3,
            "m": "B0030"
          },
          {
            "a": "T1559",
            "c": 0.800000011920929,
            "d": "Named pipe path prefix",
            "e": [
              "\\\\.\\pipe\\"
            ],
            "i": "micro-behaviors/communications/ipc/named-pipe::pipe-path-prefix",
            "l": 3
          },
          {
            "a": "T1027",
            "c": 0.8500000238418579,
            "d": "High overall file entropy (likely",
            "e": [
              "binary.overall_entropy = 7.69"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics::high-overall-entropy",
            "l": 3,
            "m": "B0032"
          },
          {
            "a": "T1027",
            "c": 0.9200000166893005,
            "d": "Zero-entropy executable section (carved/packed PE)",
            "e": [
              ".text (size: 13824, entropy: 0.00, perms: -rwx)",
              ".brdata (size: 20480, entropy: 0.00, perms: -rwx)",
              ".tc (size: 249856, entropy: 0.00, perms: -rwx)"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics::zero-entropy-executable-section",
            "l": 4,
            "m": "B0032"
          },
          {
            "c": 0.800000011920929,
            "d": "Binary lacks resource section entirely",
            "e": [
              "binary.rsrc_to_file_ratio = 0.00"
            ],
            "i": "metadata/binary/resource::no-resources",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.8500000238418579,
            "d": "Open service control manager",
            "e": [
              "OpenSCManagerA"
            ],
            "i": "micro-behaviors/os/service/control::open-sc-manager",
            "l": 3
          },
          {
            "a": "T1105",
            "c": 0.800000011920929,
            "d": "Compact PE import table",
            "e": [
              "binary.import_count = 10.00"
            ],
            "i": "objectives/command-and-control/dropper/delivery/download-execute::compact-import-table",
            "l": 1,
            "m": "E1105"
          },
          {
            "a": "T1134",
            "c": 1.0,
            "d": "CreateProcessAsUser API reference",
            "e": [
              "CreateProcessAsUserA"
            ],
            "i": "micro-behaviors/process/create/spawn::create-process-as-user",
            "l": 3
          },
          {
            "a": "T1071.001",
            "c": 0.949999988079071,
            "d": "InternetOpenUrl downloader API string",
            "e": [
              "InternetOpenUrlA"
            ],
            "i": "micro-behaviors/communications/http/get::dynamic-wininet-api-set",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "GUID-formatted mutex name",
            "e": [
              "{645FF040-5081-101B-9F08-00AA002F954E}"
            ],
            "i": "micro-behaviors/process/sync/mutex::guid-mutex",
            "l": 3,
            "m": "C0042"
          },
          {
            "a": "T1055.001",
            "c": 0.949999988079071,
            "d": "Dynamic LoadLibraryA resolution for remote injection",
            "e": [
              "LoadLibraryA"
            ],
            "i": "micro-behaviors/process/inject/dll::load-library-a-remote-resolution",
            "l": 3,
            "m": "F0003"
          },
          {
            "d": ".exe extension reference",
            "e": [
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe"
            ],
            "i": "micro-behaviors/fs/path/extension::exe-dup",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.699999988079071,
            "d": "Oversized data section vs code",
            "e": [
              ".rdata",
              ".data",
              ".brdata",
              ".rdata+.data+.brdata = 459.3% of text (63488 / 13824 bytes)"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::oversized-data-section",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1543.003",
            "c": 0.8500000238418579,
            "d": "Create Windows service",
            "e": [
              "CreateServiceA"
            ],
            "i": "micro-behaviors/os/service/control::create-service",
            "l": 3
          },
          {
            "c": 1.0,
            "d": "Binary is not digitally signed",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed::unsigned",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Five or more PE sections",
            "e": [
              "binary.section_count = 5.00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::five-plus-sections-pe",
            "l": 1
          },
          {
            "a": "T1574.002",
            "c": 0.8999999761581421,
            "d": "Hidden LoadLibraryA string reference",
            "e": [
              "LoadLibraryA"
            ],
            "i": "micro-behaviors/dylib/load::load-library-a-string-no-import",
            "l": 1
          },
          {
            "c": 0.8600000143051147,
            "d": "Register console control handler",
            "e": [
              "SetConsoleCtrlHandler"
            ],
            "i": "micro-behaviors/os/console/control::set-console-ctrl-handler",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.8199999928474426,
            "d": "Packed loader largest section ratio above 0.65",
            "e": [
              "binary.largest_section_ratio = 0.76"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::packed-loader-largest-section-dominates",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 1.0,
            "d": "Writable and executable section (W^X violation)",
            "e": [
              ".text (size: 13824, perms: -rwx)",
              ".brdata (size: 20480, perms: -rwx)",
              ".tc (size: 249856, perms: -rwx)"
            ],
            "i": "metadata/hardening/memory::wx-section",
            "l": 3
          },
          {
            "a": "T1057",
            "d": "Browser app iexplore",
            "e": [
              "iexplore"
            ],
            "i": "micro-behaviors/process/enumerate/apps::browser-apps-iexplore",
            "l": 3,
            "m": "E1592"
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "GetProcAddress loader API string",
            "e": [
              "GetProcAddress"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-getprocaddress-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "a": "T1027.007",
            "c": 1.0,
            "d": "ntdll.dll as wide string (runtime resolver)",
            "e": [
              "ntdll.dll"
            ],
            "i": "objectives/anti-static/obfuscation/string/runtime-decrypt::ntdll-wide-string",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "a": "T1045",
            "c": 0.949999988079071,
            "d": "Very high entropy (strongly indicates",
            "e": [
              "binary.overall_entropy = 7.69"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics::very-high-entropy",
            "l": 3,
            "m": "B0032"
          },
          {
            "c": 0.699999988079071,
            "d": "WS2_32 Winsock DLL import",
            "e": [
              "WS2_32.dll"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-32-dll-marker",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "PE executable is unsigned",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed::unsigned-pe-executable",
            "l": 3
          },
          {
            "c": 0.949999988079071,
            "d": "links KERNEL32.dll (CreateMemoryResourceNotification, UTUnRegister, InterlockedExchange, TrimVirtualBuffer, SetConsoleCtrlHandler, ... +5 more)",
            "e": [
              "KERNEL32.dll"
            ],
            "i": "metadata/dylib::kernel32/dll",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Toolhelp thread enumeration strings",
            "e": [
              "Thread32Next",
              "Thread32First"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::toolhelp-thread-enumeration-string",
            "l": 3
          },
          {
            "a": "T1027",
            "c": 0.8999999761581421,
            "d": "WinInet APIs resolved dynamically",
            "e": [
              "InternetCloseHandle",
              "InternetOpenA",
              "HttpQueryInfoA"
            ],
            "i": "micro-behaviors/communications/http/get::wininet-dynamic-load",
            "l": 4
          },
          {
            "a": "T1027.007",
            "c": 0.8500000238418579,
            "d": "Runtime API string decryption (DLL names without loader imports)",
            "e": [
              "ntdll.dll",
              "kernel32.dll",
              "binary.import_count = 10.00"
            ],
            "i": "objectives/anti-static/obfuscation/string/runtime-decrypt::runtime-api-decryption",
            "l": 4,
            "m": "B0032.014"
          },
          {
            "a": "T1112",
            "c": 0.9200000166893005,
            "d": "Registry open create and write APIs",
            "e": [
              "RegCreateKeyExA",
              "RegSetValueExA",
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::registry-write-api-chain",
            "l": 3
          },
          {
            "a": "T1036.005",
            "c": 0.8399999737739563,
            "d": "Non-Microsoft WindowsUpdate reference",
            "e": [
              "WindowsUpdate"
            ],
            "i": "objectives/evasion/masquerade/identity/mimicry::non-microsoft-windowsupdate-reference",
            "l": 4
          },
          {
            "c": 0.8999999761581421,
            "d": "Encoded payload detected: xor",
            "e": [
              "User-Agent: Mozilla/4.0User-Agent \u003cxor\u003e",
              "User-Agan2:iM#z,lla/4.0User-Age_%N \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Agent: Mo \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Agent: Mozil \u003cxor\u003e",
              "Sser-Agent: Mozilla/4.0User-Agent: Mozil \u003cxor\u003e",
              "5ser-Agent: Mozilla/4.0(XfUser-Agent: Mo \u003cxor\u003e",
              "Dser-Agent: Mozilla/4.0(XfUser-Agent: Mo \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Agenw7 \u003cxor\u003e",
              "\u0026ser-Agent: Mozilla/4.0User-Agent: Moyd \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Agent: Mozio \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Agenw7 \u003cxor\u003e",
              "\\7er-Agent: Mozilla/4.0User-Agent: Mozja \u003cxor\u003e",
              "]Ver-Agent: Mozilla/4.0(XfUser.L \u003cxor\u003e",
              "Uaer-Agent: Mozilla/4.0(XfUser-Agemy \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Agemy \u003cxor\u003e",
              "WYer-Agent: Mozilla/4.0(XfUser-Agent: Nb \u003cxor\u003e",
              "T#er-Agent: Mozilla/4.0(XfUser-Agent: Mo \u003cxor\u003e",
              "Pwer-Agent: Mozilla/4.0User-Agent: Mozil \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Bj \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Agent:#@ \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Agent9- \u003cxor\u003e",
              "user-Agent: Mozilla/4.0User-Agent: Mozil \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Agent: Mozja \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Agent:\u0026 \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Agenr \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-@m \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Agenu0 \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Agenu0 \u003cxor\u003e",
              "h|zr-Agent: Mozilla/4.0(XfUser-Ck \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Aei \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Ck \u003cxor\u003e",
              "2ser-Agent: Mozilla/4.0(XfUser-Agent: Mo \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Agent: Mozka \u003cxor\u003e",
              "Rser-Agent: Mozilla/4.0(XfUser-Agent: Mo \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Agent: Lc \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Agent;( \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Agenu2 \u003cxor\u003e",
              "Eser-Agent: Mozilla/4.0User-Agent: Mozil \u003cxor\u003e",
              "Wser-Agent: Mozilla/4.0User-Agent:! \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Agd \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-AgP@ \u003cxor\u003e",
              "51er-Agent: Mozilla/4.0(XfUser-E \u003cxor\u003e",
              "U-,r-Agent: Mozilla/4.0User-Agent: Mozil \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Agg \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Agent:+A \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Ageex \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Agenv8 \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Ce \u003cxor\u003e"
            ],
            "i": "metadata/encoded-payload/xor",
            "l": 3
          }
        ],
        "sha": "cbc68b7e24fcb97b4d83f033e18094de409cab9d82b1bcddb85c9972ff48d54f",
        "path": "/data/samples/bad/datasets/pe-machine-learning-dataset/32702",
        "type": "pe"
      },
      {
        "f": "K₂O₇(As₁₄C₆Er₉SDyP₄I₅)H₇(F₈Os₉Cm₅DbDsPo₇U)Md₄(Bi₂SiPa)",
        "x": 316,
        "dp": 1,
        "id": 1,
        "is": [
          "strstr",
          "strlen",
          "??2@YAPAXI@Z",
          "strrchr",
          "??3@YAXPAX@Z",
          "srand",
          "rand",
          "memset",
          "memcpy",
          "except_handler3",
          "ZwQueryInformationThread",
          "PathFileExistsA",
          "SHDeleteKeyA",
          "GetModuleInformation",
          "ORDINAL 4",
          "ORDINAL 52",
          "WSAResetEvent",
          "ORDINAL 23",
          "ORDINAL 11",
          "ORDINAL 19",
          "WSAAddressToStringA",
          "ORDINAL 115",
          "getaddrinfo",
          "ORDINAL 116",
          "freeaddrinfo",
          "ORDINAL 3",
          "ORDINAL 9",
          "WSACreateEvent",
          "ORDINAL 2",
          "ORDINAL 20",
          "ORDINAL 111",
          "WSARecvFrom",
          "ORDINAL 21",
          "ORDINAL 57",
          "GetAdaptersInfo",
          "WinVerifyTrust",
          "WNetOpenEnumA",
          "WNetCloseEnum",
          "WNetAddConnection2A",
          "WNetCancelConnection2A",
          "UuidToStringA",
          "UuidFromStringA",
          "GetExitCodeProcess",
          "FindFirstFileA",
          "GetLogicalDriveStringsA",
          "RemoveDirectoryA",
          "FindClose",
          "FindNextFileA",
          "MoveFileExA",
          "SetNamedPipeHandleState",
          "OpenThread",
          "CreateNamedPipeA",
          "FlushFileBuffers",
          "DisconnectNamedPipe",
          "Thread32Next",
          "ConnectNamedPipe",
          "GetCurrentProcess",
          "SetFileAttributesA",
          "CreateDirectoryA",
          "GetFileAttributesA",
          "GetLogicalDrives",
          "GetCurrentProcessId",
          "FlushViewOfFile",
          "MultiByteToWideChar",
          "GetLocalTime",
          "GlobalFree",
          "GetDriveTypeA",
          "lstrcpynA",
          "DeviceIoControl",
          "GetSystemDirectoryA",
          "TerminateProcess",
          "GlobalAlloc",
          "TransactNamedPipe",
          "GetExitCodeThread",
          "CreateFileA",
          "FindResourceA",
          "FreeResource",
          "lstrlenA",
          "FreeLibrary",
          "Process32First",
          "GetTickCount",
          "WriteFile",
          "Sleep",
          "SizeofResource",
          "ReadFile",
          "lstrcmpiA",
          "GetProcAddress",
          "Process32Next",
          "LockResource",
          "GetModuleFileNameA",
          "GetModuleHandleA",
          "LoadLibraryExA",
          "CreateToolhelp32Snapshot",
          "CloseHandle",
          "GetSystemTime",
          "DeleteFileA",
          "lstrcpyA",
          "ExitProcess",
          "GetFileSize",
          "SetFilePointer",
          "VirtualQuery",
          "SetEndOfFile",
          "SetFileTime",
          "GetWindowsDirectoryA",
          "CreateProcessA",
          "LoadLibraryA",
          "GetFileTime",
          "GetCurrentThreadId",
          "GetTempPathA",
          "WaitForSingleObject",
          "SetEvent",
          "CreateEventA",
          "GetLastError",
          "MapViewOfFile",
          "UnmapViewOfFile",
          "OpenProcess",
          "ExitThread",
          "CopyFileA",
          "CreateFileMappingA",
          "WinExec",
          "GetVersion",
          "CreateThread",
          "lstrcatA",
          "TerminateThread",
          "OpenWindowStationA",
          "SetProcessWindowStation",
          "OpenDesktopA",
          "SetThreadDesktop",
          "GetMessageA",
          "wsprintfA",
          "GetInputState",
          "PostThreadMessageA",
          "CloseServiceHandle",
          "QueryServiceStatus",
          "RegSetValueExA",
          "RegOpenKeyExA",
          "RegCloseKey",
          "OpenServiceA",
          "OpenSCManagerA",
          "RegQueryValueExA",
          "CreateServiceA",
          "StartServiceA",
          "OpenProcessToken",
          "CreateProcessAsUserA",
          "ControlService",
          "RegCreateKeyExA",
          "ShellExecuteA",
          "SHGetSpecialFolderPathA"
        ],
        "ms": {
          "pe": {
            "machine": 332.0,
            "checksum": 0.0,
            "pdb_path": "C:\\exe.pdb",
            "rsrc_size": 178688.0,
            "subsystem": 2.0,
            "timestamp": 1265659193.0,
            "icon_count": 2.0,
            "image_base": 4194304.0,
            "rsrc_entropy": 7.72,
            "entry_section": ".text",
            "size_of_image": 262144.0,
            "timestamp_day": 8.0,
            "file_alignment": 512.0,
            "resource_count": 3.0,
            "timestamp_year": 2010.0,
            "characteristics": 258.0,
            "entry_point_rva": 7023.0,
            "size_of_headers": 1024.0,
            "timestamp_month": 2.0,
            "checksum_missing": true,
            "checksum_present": false,
            "export_timestamp": 0.0,
            "import_dll_count": 13.0,
            "computed_checksum": 306688.0,
            "section_alignment": 4096.0,
            "number_of_sections": 7.0,
            "resource_timestamp": 0.0,
            "debug_timestamp_max": 1265659193.0,
            "debug_timestamp_min": 1265659193.0,
            "dll_characteristics": 33088.0,
            "rich_header_present": true,
            "linker_major_version": 9.0,
            "api_hashing_indicators": 1.0,
            "debug_directory_entries": 1.0,
            "export_timestamp_present": false,
            "debug_timestamp_consistent": true,
            "resource_timestamp_present": false,
            "debug_timestamp_unique_count": 1.0,
            "debug_timestamp_nonzero_count": 1.0
          },
          "binary": {
            "code_size": 50176.0,
            "file_size": 249193.0,
            "entry_point": 7023.0,
            "has_overlay": true,
            "code_entropy": 6.42,
            "data_entropy": 6.58,
            "import_count": 148.0,
            "overlay_size": 361.0,
            "string_count": 579.0,
            "overlay_ratio": 0.0,
            "section_count": 7.0,
            "avg_complexity": 4.81,
            "function_count": 110.0,
            "import_density": 3.02,
            "max_complexity": 28.0,
            "string_density": 11.82,
            "overall_entropy": 6.61,
            "avg_basic_blocks": 9.32,
            "avg_section_size": 35401.14,
            "dependency_count": 13.0,
            "entropy_variance": 0.92,
            "function_density": 2.24,
            "avg_function_size": 6571.55,
            "avg_string_length": 17.39,
            "complexity_per_kb": 0.1,
            "max_string_length": 102.0,
            "writable_sections": 1.0,
            "avg_string_entropy": 3.32,
            "code_to_data_ratio": 0.25,
            "data_to_file_ratio": 0.03,
            "entry_point_is_rva": true,
            "rsrc_to_file_ratio": 0.72,
            "text_to_file_ratio": 0.13,
            "total_basic_blocks": 1025.0,
            "executable_sections": 3.0,
            "high_entropy_regions": 2.0,
            "string_length_stddev": 13.73,
            "debug_reference_count": 1.0,
            "largest_section_ratio": 0.72,
            "sentence_string_count": 49.0,
            "sentence_string_ratio": 0.08,
            "behavioral_import_ratio": 0.04,
            "function_analysis_depth": 2.0,
            "nonstandard_section_name_count": 2.0
          }
        },
        "ss": [
          [
            46,
            "xor",
            "User-Agent: Mo"
          ],
          [
            77,
            "!This program cannot be run in DOS mode."
          ],
          [
            472,
            ".text"
          ],
          [
            551,
            "@.data"
          ],
          [
            592,
            ".rsrc"
          ],
          [
            631,
            "@.UPX0"
          ],
          [
            1004,
            "xor",
            "User-Agent: Mozilla/\\b"
          ],
          [
            2333,
            "Load"
          ],
          [
            2340,
            "Reso"
          ],
          [
            29033,
            "Enum"
          ],
          [
            34476,
            "ZwQuerySystemInformation"
          ],
          [
            34504,
            "ntdll.dll"
          ],
          [
            34516,
            "KeServiceDescriptorTable"
          ],
          [
            34544,
            "kernel32.dll"
          ],
          [
            34560,
            "FILE"
          ],
          [
            34568,
            "C:\\DelInfo.bin"
          ],
          [
            34584,
            "booter.exe"
          ],
          [
            34596,
            "CONFIG.exe"
          ],
          [
            34608,
            "boottemp.exe"
          ],
          [
            34638,
            "i3qs"
          ],
          [
            34944,
            "Start"
          ],
          [
            34952,
            "www.baidu.com"
          ],
          [
            34968,
            "Parameters"
          ],
          [
            34980,
            "ServiceDll"
          ],
          [
            34992,
            "sfc_os.dll"
          ],
          [
            35004,
            "%s\\system32\\%s.dll"
          ],
          [
            35024,
            "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Svchost"
          ],
          [
            35084,
            "ost.exe"
          ],
          [
            35092,
            "%SystemRoot%\\System32\\svch%s -k nets"
          ],
          [
            35140,
            "www.xunlei.com"
          ],
          [
            35156,
            "www.3-0B6F-415d-B5C7-832F0.com"
          ],
          [
            35200,
            "Wininet.dll"
          ],
          [
            35212,
            "InternetOpenA"
          ],
          [
            35228,
            "InternetOpenUrlA"
          ],
          [
            35248,
            "HttpQueryInfoA"
          ],
          [
            35264,
            "InternetReadFileExA"
          ],
          [
            35284,
            "InternetCloseHandle"
          ],
          [
            35304,
            "InternetSetStatusCallback"
          ],
          [
            35332,
            "http://%s:%d/%s"
          ],
          [
            35348,
            "winsta0"
          ],
          [
            35356,
            "default"
          ],
          [
            35364,
            "Explorer.exe"
          ],
          [
            35380,
            "%s%d.exe"
          ],
          [
            35396,
            "winsta0\\defa"
          ],
          [
            35412,
            "%s%d.nls"
          ],
          [
            35424,
            "cryptcom.dll"
          ],
          [
            35440,
            "DLFT_Shutdown"
          ],
          [
            35456,
            "DLFT_Startup"
          ],
          [
            35472,
            "DLFT_SetTrackerReportCallback"
          ],
          [
            35504,
            "c_30218.nls"
          ],
          [
            35544,
            "GET %s?%s HTTP/1.1\r\nConnection: Keep-Alive\r\nHost: %s\r\nUser-Agent: Mozilla/4.0\r\nAccept-language: cn\r\n\r\n"
          ],
          [
            35564,
            "Connection: Keep-Alive"
          ],
          [
            35598,
            "User-Agent: Mozilla/4.0"
          ],
          [
            35623,
            "Accept-language: cn"
          ],
          [
            35648,
            "address"
          ],
          [
            35656,
            "ver=%s\u0026tgid=%s\u0026%s=%s"
          ],
          [
            35684,
            "%s%s%s"
          ],
          [
            35700,
            "alexa"
          ],
          [
            35708,
            "%s\u0026flag=%s\u0026%s=0\u0026List=%s"
          ],
          [
            35736,
            "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options"
          ],
          [
            35812,
            "SYSTEM\\CurrentControlSet\\Services"
          ],
          [
            35848,
            "\\Registry\\Machine"
          ],
          [
            35868,
            "\\Internet Explorer\\iexplore.exe"
          ],
          [
            35908,
            "Forter"
          ],
          [
            35916,
            "avp.exe"
          ],
          [
            35924,
            "bdagent.exe"
          ],
          [
            35936,
            "Forter.sys"
          ],
          [
            35960,
            "MmGetSystemRoutineAddress"
          ],
          [
            36000,
            "Thunder Network"
          ],
          [
            36016,
            "Thunder"
          ],
          [
            36032,
            "WindowsUpdate"
          ],
          [
            36048,
            "Windows NT"
          ],
          [
            36060,
            "Windows Media Player"
          ],
          [
            36084,
            "Outlook Express"
          ],
          [
            36100,
            "NetMeeting"
          ],
          [
            36112,
            "MSN Gaming Zone"
          ],
          [
            36128,
            "Movie Maker"
          ],
          [
            36140,
            "microsoft frontpage"
          ],
          [
            36160,
            "Messenger"
          ],
          [
            36172,
            "Internet Explorer"
          ],
          [
            36192,
            "InstallShield Installation Information"
          ],
          [
            36232,
            "ComPlus Applications"
          ],
          [
            36256,
            "Common Files"
          ],
          [
            36272,
            "RECYCLER"
          ],
          [
            36284,
            "System Volume Information"
          ],
          [
            36312,
            "Documents and Settings"
          ],
          [
            36344,
            "WINDOWS"
          ],
          [
            36364,
            "index"
          ],
          [
            36372,
            "Default"
          ],
          [
            36380,
            "%s X -ibck \"%s\" \"%s\\\""
          ],
          [
            36408,
            "%s M -ibck -r -o+ -ep1 \"%s\" \"%s\\*\""
          ],
          [
            36423,
            "xor",
            ":XE_H1VELQI"
          ],
          [
            36480,
            "C:\\Program Files\\WinRAR\\Rar.exe"
          ],
          [
            36520,
            "explorer.exe"
          ],
          [
            36536,
            "open"
          ],
          [
            36544,
            "\\\\.\\pipe\\96DBA249-E88E-4c47-98DC-E18E6E3E3E5A"
          ],
          [
            36592,
            "127.0.0.1       localhost"
          ],
          [
            36620,
            "%s\\drivers\\etc\\hosts"
          ],
          [
            36644,
            "%s\\c_30279.nls"
          ],
          [
            36660,
            "%s%d.txt"
          ],
          [
            36672,
            "SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\Minimal"
          ],
          [
            36724,
            "SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\Network"
          ],
          [
            37125,
            "Crea"
          ],
          [
            37158,
            "Writ"
          ],
          [
            37191,
            "Clos"
          ],
          [
            37264,
            "r.ex"
          ],
          [
            37440,
            "http://%s/%s"
          ],
          [
            37468,
            "\\\\%s\\pipe%s"
          ],
          [
            37488,
            "Mpr.dll"
          ],
          [
            37496,
            "%s\\desktop.txt"
          ],
          [
            37524,
            "CONFIG"
          ],
          [
            37536,
            "\\\\%s\\%s\\%s.exe"
          ],
          [
            37552,
            "at \\\\%s %d:%d C:\\%s.exe"
          ],
          [
            37576,
            "%d.%d.%d.%d"
          ],
          [
            37588,
            "%sautorun.inf"
          ],
          [
            37604,
            "recycle.{645FF040-5081-101B-9F08-00AA002F954E}"
          ],
          [
            37652,
            "Setup.exe"
          ],
          [
            37664,
            "Show"
          ],
          [
            37688,
            "Kernel32.dll"
          ],
          [
            37704,
            "Thread32First"
          ],
          [
            37720,
            "RSDSLE"
          ],
          [
            37744,
            "C:\\exe.pdb"
          ],
          [
            38762,
            "memcpy"
          ],
          [
            38772,
            "memset"
          ],
          [
            38798,
            "??3@YAXPAX@Z"
          ],
          [
            38814,
            "strrchr"
          ],
          [
            38824,
            "??2@YAPAXI@Z"
          ],
          [
            38840,
            "strlen"
          ],
          [
            38858,
            "MSVCRT.dll"
          ],
          [
            38872,
            "ZwQueryInformationThread"
          ],
          [
            38898,
            "ntdll.dll"
          ],
          [
            38910,
            "PathFileExistsA"
          ],
          [
            38928,
            "SHDeleteKeyA"
          ],
          [
            38942,
            "SHLWAPI.dll"
          ],
          [
            38956,
            "GetModuleInformation"
          ],
          [
            38978,
            "PSAPI.DLL"
          ],
          [
            38990,
            "freeaddrinfo"
          ],
          [
            39006,
            "getaddrinfo"
          ],
          [
            39020,
            "WSAAddressToStringA"
          ],
          [
            39042,
            "WSAResetEvent"
          ],
          [
            39058,
            "WSACreateEvent"
          ],
          [
            39076,
            "WSARecvFrom"
          ],
          [
            39088,
            "WS2_32.dll"
          ],
          [
            39102,
            "GetAdaptersInfo"
          ],
          [
            39118,
            "IPHLPAPI.DLL"
          ],
          [
            39134,
            "WinVerifyTrust"
          ],
          [
            39150,
            "WINTRUST.dll"
          ],
          [
            39166,
            "WNetCancelConnection2A"
          ],
          [
            39192,
            "WNetAddConnection2A"
          ],
          [
            39214,
            "WNetCloseEnum"
          ],
          [
            39230,
            "WNetOpenEnumA"
          ],
          [
            39244,
            "MPR.dll"
          ],
          [
            39254,
            "UuidToStringA"
          ],
          [
            39270,
            "UuidFromStringA"
          ],
          [
            39286,
            "RPCRT4.dll"
          ],
          [
            39300,
            "CreateFileA"
          ],
          [
            39314,
            "FindResourceA"
          ],
          [
            39330,
            "FreeResource"
          ],
          [
            39346,
            "lstrlenA"
          ],
          [
            39358,
            "FreeLibrary"
          ],
          [
            39372,
            "Process32First"
          ],
          [
            39390,
            "GetTickCount"
          ],
          [
            39406,
            "WriteFile"
          ],
          [
            39418,
            "Sleep"
          ],
          [
            39426,
            "SizeofResource"
          ],
          [
            39444,
            "ReadFile"
          ],
          [
            39456,
            "lstrcmpiA"
          ],
          [
            39468,
            "GetProcAddress"
          ],
          [
            39486,
            "Process32Next"
          ],
          [
            39502,
            "LockResource"
          ],
          [
            39518,
            "GetModuleFileNameA"
          ],
          [
            39540,
            "GetModuleHandleA"
          ],
          [
            39560,
            "LoadLibraryExA"
          ],
          [
            39578,
            "CreateToolhelp32Snapshot"
          ],
          [
            39606,
            "CloseHandle"
          ],
          [
            39620,
            "GetSystemTime"
          ],
          [
            39636,
            "DeleteFileA"
          ],
          [
            39650,
            "lstrcpyA"
          ],
          [
            39662,
            "ExitProcess"
          ],
          [
            39676,
            "GetFileSize"
          ],
          [
            39690,
            "SetFilePointer"
          ],
          [
            39708,
            "VirtualQuery"
          ],
          [
            39724,
            "SetEndOfFile"
          ],
          [
            39740,
            "SetFileTime"
          ],
          [
            39754,
            "GetWindowsDirectoryA"
          ],
          [
            39778,
            "MultiByteToWideChar"
          ],
          [
            39800,
            "LoadLibraryA"
          ],
          [
            39816,
            "GetFileTime"
          ],
          [
            39830,
            "GetCurrentThreadId"
          ],
          [
            39852,
            "GetTempPathA"
          ],
          [
            39868,
            "WaitForSingleObject"
          ],
          [
            39890,
            "SetEvent"
          ],
          [
            39902,
            "CreateEventA"
          ],
          [
            39918,
            "GetLastError"
          ],
          [
            39934,
            "MapViewOfFile"
          ],
          [
            39950,
            "UnmapViewOfFile"
          ],
          [
            39968,
            "OpenProcess"
          ],
          [
            39982,
            "ExitThread"
          ],
          [
            40008,
            "CreateFileMappingA"
          ],
          [
            40030,
            "WinExec"
          ],
          [
            40040,
            "GetVersion"
          ],
          [
            40054,
            "CreateThread"
          ],
          [
            40070,
            "lstrcatA"
          ],
          [
            40082,
            "CreateProcessA"
          ],
          [
            40100,
            "TerminateProcess"
          ],
          [
            40120,
            "GetSystemDirectoryA"
          ],
          [
            40142,
            "DeviceIoControl"
          ],
          [
            40160,
            "lstrcpynA"
          ],
          [
            40172,
            "GetDriveTypeA"
          ],
          [
            40188,
            "GetExitCodeProcess"
          ],
          [
            40210,
            "FindFirstFileA"
          ],
          [
            40228,
            "GetLogicalDriveStringsA"
          ],
          [
            40254,
            "RemoveDirectoryA"
          ],
          [
            40274,
            "FindClose"
          ],
          [
            40286,
            "FindNextFileA"
          ],
          [
            40316,
            "SetNamedPipeHandleState"
          ],
          [
            40342,
            "FlushViewOfFile"
          ],
          [
            40360,
            "TerminateThread"
          ],
          [
            40378,
            "GetExitCodeThread"
          ],
          [
            40398,
            "TransactNamedPipe"
          ],
          [
            40418,
            "GlobalAlloc"
          ],
          [
            40432,
            "GlobalFree"
          ],
          [
            40446,
            "GetLocalTime"
          ],
          [
            40462,
            "GetCurrentProcessId"
          ],
          [
            40484,
            "GetLogicalDrives"
          ],
          [
            40504,
            "GetFileAttributesA"
          ],
          [
            40526,
            "CreateDirectoryA"
          ],
          [
            40546,
            "SetFileAttributesA"
          ],
          [
            40568,
            "GetCurrentProcess"
          ],
          [
            40588,
            "ConnectNamedPipe"
          ],
          [
            40608,
            "Thread32Next"
          ],
          [
            40624,
            "DisconnectNamedPipe"
          ],
          [
            40646,
            "FlushFileBuffers"
          ],
          [
            40666,
            "CreateNamedPipeA"
          ],
          [
            40686,
            "OpenThread"
          ],
          [
            40698,
            "KERNEL32.dll"
          ],
          [
            40714,
            "wsprintfA"
          ],
          [
            40726,
            "GetInputState"
          ],
          [
            40742,
            "PostThreadMessageA"
          ],
          [
            40764,
            "GetMessageA"
          ],
          [
            40778,
            "SetThreadDesktop"
          ],
          [
            40798,
            "OpenWindowStationA"
          ],
          [
            40820,
            "OpenDesktopA"
          ],
          [
            40836,
            "SetProcessWindowStation"
          ],
          [
            40860,
            "USER32.dll"
          ],
          [
            40874,
            "RegSetValueExA"
          ],
          [
            40892,
            "RegOpenKeyExA"
          ],
          [
            40908,
            "RegCloseKey"
          ],
          [
            40922,
            "OpenServiceA"
          ],
          [
            40938,
            "CloseServiceHandle"
          ],
          [
            40960,
            "RegQueryValueExA"
          ],
          [
            40980,
            "CreateServiceA"
          ],
          [
            40998,
            "StartServiceA"
          ],
          [
            41014,
            "RegCreateKeyExA"
          ],
          [
            41032,
            "QueryServiceStatus"
          ],
          [
            41054,
            "OpenSCManagerA"
          ]
        ],
        "sz": 249193,
        "ts": [
          {
            "c": 1.0,
            "d": "Binary is not digitally signed",
            "i": "metadata/unsigned",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Close directory enumeration handle",
            "e": [
              "FindClose"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-close",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.8600000143051147,
            "d": "WinInet DLL name string",
            "e": [
              "Wininet.dll"
            ],
            "i": "micro-behaviors/communications/http/get::wininet-dll-name",
            "l": 1
          },
          {
            "c": 0.6399999856948853,
            "d": "Delete files (Windows API ANSI)",
            "e": [
              "DeleteFileA"
            ],
            "i": "micro-behaviors/fs/file/delete::deletefile-a-text",
            "l": 2
          },
          {
            "a": "T1204.002",
            "c": 0.800000011920929,
            "d": "Writes executable to drive root",
            "e": [
              "C:\\%s.exe"
            ],
            "i": "micro-behaviors/fs/path/location::path-suspicious-root-exe",
            "l": 3,
            "m": "F0013"
          },
          {
            "c": 1.0,
            "d": "OpenProcess/NtOpenProcess symbol",
            "e": [
              "OpenProcess"
            ],
            "i": "objectives/evasion/fileless/memory::open-process-sym",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Thread32First API string",
            "e": [
              "Thread32First"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::thread32-first-string",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Truncate file via SetEndOfFile",
            "e": [
              "SetEndOfFile"
            ],
            "i": "micro-behaviors/fs/file/truncate::set-end-of-file-win",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 25+ imports",
            "e": [
              "binary.import_count = 148.00"
            ],
            "i": "metadata/binary/metrics::many-imports-25",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 20+ imports",
            "e": [
              "binary.import_count = 148.00"
            ],
            "i": "metadata/binary/metrics::many-imports-20",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.699999988079071,
            "d": "Code section dominates file layout",
            "e": [
              "binary.largest_section_ratio = 0.72"
            ],
            "i": "objectives/anti-static/obfuscation/string/anomaly::dominant-text-section",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1027.009",
            "c": 0.800000011920929,
            "d": "Access PE resource data pointer",
            "e": [
              "LockResource"
            ],
            "i": "micro-behaviors/data/embedded/payload::lock-resource",
            "l": 2
          },
          {
            "a": "T1053.005",
            "c": 0.8999999761581421,
            "d": "Task Scheduler builder methods",
            "e": [
              "Connect",
              "Connect",
              "Connect",
              "Connect",
              "Connect"
            ],
            "i": "objectives/persistence/login/scheduled-task::task-scheduler-builder-methods",
            "l": 1,
            "m": "F0012"
          },
          {
            "c": 1.0,
            "d": "Uses named pipe IPC APIs",
            "e": [
              "SetNamedPipeHandleState",
              "CreateNamedPipeA",
              "DisconnectNamedPipe",
              "ConnectNamedPipe",
              "TransactNamedPipe"
            ],
            "i": "micro-behaviors/communications/ipc/named-pipe::named-pipe-api-usage",
            "l": 2
          },
          {
            "a": "T1083",
            "c": 0.8999999761581421,
            "d": "Enumerate logical drive letters",
            "e": [
              "GetLogicalDrives"
            ],
            "i": "micro-behaviors/fs/traversal/drives::get-logical-drives",
            "l": 3,
            "m": "E1083"
          },
          {
            "c": 0.8999999761581421,
            "d": "Read data from file handle",
            "e": [
              "ReadFile"
            ],
            "i": "micro-behaviors/fs/file/read::read-file",
            "l": 2
          },
          {
            "a": "T1071.001",
            "d": "Old Mozilla 4.0 User-Agent",
            "e": [
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agemy",
              "…\r\nHost: %s\r\nUser-Agent: Mozilla/4.0\r\nAccept-language: cn\r\n\r…",
              "User-Agent: Mozilla/4.0U",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agent: Mozilla/4.3X",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0Useq ",
              "Sser-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agent: Mozilla,9",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agent: Moyd",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0Useq ",
              "User-Agent: Mozilla/4.0",
              "User-Agent: Mozilla/4.0User-Agent"
            ],
            "i": "micro-behaviors/communications/http/headers::ua-mozilla-old",
            "l": 2,
            "m": "C0002"
          },
          {
            "c": 1.0,
            "d": "Binary has 30+ imports",
            "e": [
              "binary.import_count = 148.00"
            ],
            "i": "metadata/binary/metrics::many-imports-30",
            "l": 1
          },
          {
            "c": 0.8199999928474426,
            "d": "Short BIN sidecar reference",
            "e": [
              "DelInfo.bin"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::short-bin-sidecar-reference",
            "l": 1
          },
          {
            "a": "T1071",
            "c": 0.7799999713897705,
            "d": "Winsock library string marker",
            "e": [
              "WS2_32.dll"
            ],
            "i": "objectives/command-and-control/backdoor/binary::winsock-library-reference",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Unload dynamic library",
            "e": [
              "FreeLibrary"
            ],
            "i": "micro-behaviors/os/module/load::free-library",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Tiny writable data section",
            "e": [
              ".data (size: 8704)"
            ],
            "i": "metadata/binary/section/metrics::tiny-data-section",
            "l": 1
          },
          {
            "c": 0.6600000262260437,
            "d": "Copy files (Windows API ANSI)",
            "e": [
              "CopyFileA"
            ],
            "i": "micro-behaviors/fs/file/copy::copyfile-a",
            "l": 3
          },
          {
            "a": "T1204.002",
            "c": 0.7599999904632568,
            "d": "Short PDB marker",
            "e": [
              "exe.pdb"
            ],
            "i": "objectives/command-and-control/dropper/execution/clickfix::short-pdb-marker",
            "l": 1,
            "m": "B0024"
          },
          {
            "c": 0.8999999761581421,
            "d": "Directory enumeration (ANSI)",
            "e": [
              "FindNextFileA"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-next-file-a",
            "l": 2
          },
          {
            "c": 0.6600000262260437,
            "d": "Create directories (Windows API ANSI)",
            "e": [
              "CreateDirectoryA"
            ],
            "i": "micro-behaviors/fs/directory/mkdir::create-directory-a",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.8999999761581421,
            "d": "HttpQueryInfo API name as string",
            "e": [
              "HttpQueryInfoA"
            ],
            "i": "micro-behaviors/communications/http/get::http-query-info-str",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Exit current process",
            "e": [
              "ExitProcess"
            ],
            "i": "micro-behaviors/process/terminate/kill::exit-process",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE mapped image under 768 KiB",
            "e": [
              "pe.size_of_image = 262144.00"
            ],
            "i": "metadata/binary/layout::image-under-768kb",
            "l": 1
          },
          {
            "a": "T1106",
            "c": 0.949999988079071,
            "d": "Create process (ANSI)",
            "e": [
              "CreateProcessA"
            ],
            "i": "micro-behaviors/process/create/spawn::create-process-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Get local time",
            "e": [
              "GetLocalTime"
            ],
            "i": "micro-behaviors/time/query::get-local-time",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.949999988079071,
            "d": "Create service import",
            "e": [
              "CreateServiceA"
            ],
            "i": "micro-behaviors/os/service/control::create-service-import",
            "l": 1
          },
          {
            "a": "T1083",
            "c": 0.8999999761581421,
            "d": "Query drive type by symbol",
            "e": [
              "GetDriveTypeA"
            ],
            "i": "micro-behaviors/fs/traversal/drives::get-drive-type",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.9300000071525574,
            "d": "Open service import",
            "e": [
              "OpenServiceA"
            ],
            "i": "micro-behaviors/os/service/control::open-service-import",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Get module handle ANSI",
            "e": [
              "GetModuleHandleA"
            ],
            "i": "micro-behaviors/os/module/load::get-module-handle-ansi",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "ServiceDll registry value marker",
            "e": [
              "servicedll"
            ],
            "i": "micro-behaviors/os/service/host::service-dll-value-name",
            "l": 3
          },
          {
            "a": "T1083",
            "c": 0.8999999761581421,
            "d": "Enumerate logical drive strings",
            "e": [
              "GetLogicalDriveStringsA"
            ],
            "i": "micro-behaviors/fs/traversal/drives::get-logical-drive-strings",
            "l": 3,
            "m": "E1083"
          },
          {
            "c": 0.8999999761581421,
            "d": "PE .reloc section presence",
            "e": [
              ".reloc"
            ],
            "i": "metadata/binary/section/names::reloc-section-presence",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Get process exit code",
            "e": [
              "GetExitCodeProcess"
            ],
            "i": "micro-behaviors/process/create/spawn::get-exit-code-process",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Tool identity claims WinRAR",
            "e": [
              "WinRAR"
            ],
            "i": "metadata/package/tooling::tool-identity-winrar",
            "l": 1
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "LoadLibraryA loader API string",
            "e": [
              "LoadLibraryA"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-loadlibrarya-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "a": "T1112",
            "c": 0.8799999952316284,
            "d": "Create registry key ANSI",
            "e": [
              "RegCreateKeyExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-create-key-ex-a",
            "l": 2
          },
          {
            "a": "T1059.001",
            "c": 0.75,
            "d": "Execute shell command (ShellExecuteA)",
            "e": [
              "ShellExecuteA"
            ],
            "i": "micro-behaviors/process/create/exec::shell-execute-a",
            "l": 3
          },
          {
            "c": 0.75,
            "d": "HTTP protocol version strings",
            "e": [
              "HTTP/1.1"
            ],
            "i": "micro-behaviors/communications/http/request::http-versions",
            "l": 1
          },
          {
            "a": "T1071.001",
            "d": "HTTP/1.x version string",
            "e": [
              "GET %s?%s HTTP/1.1\r\nConnection: Keep-Aliv…"
            ],
            "i": "micro-behaviors/communications/http/request::http-version",
            "l": 2,
            "m": "C0002"
          },
          {
            "c": 0.8799999952316284,
            "d": "High entropy resource section (encrypted payload)",
            "e": [
              "pe.rsrc_entropy = 7.72"
            ],
            "i": "well-known/malware/trojan/shellobject::xll-high-rsrc-entropy",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has low average string entropy",
            "e": [
              "binary.avg_string_entropy = 3.32"
            ],
            "i": "metadata/binary/metrics::avg-string-entropy-4-max",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Network share disconnect API import",
            "e": [
              "WNetCancelConnection2A"
            ],
            "i": "micro-behaviors/os/network/share::wnet-cancel-connection",
            "l": 3
          },
          {
            "c": 0.699999988079071,
            "d": "GetModuleFileName API call",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/process/info/current::get-module-filename",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE has many readable strings",
            "e": [
              "binary.string_count = 579.00"
            ],
            "i": "metadata/binary/layout::many-readable-strings",
            "l": 2
          },
          {
            "a": "T1055.012",
            "c": 0.800000011920929,
            "d": "CreateProcess API string reference",
            "e": [
              "CreateProcessAsUserA",
              "CreateProcessA"
            ],
            "i": "objectives/evasion/process/injection/hollowing::create-process-string",
            "l": 1,
            "m": "E1055.012"
          },
          {
            "c": 0.8500000238418579,
            "d": "Oversized resource section for a DLL",
            "e": [
              "pe.rsrc_size = 178688.00"
            ],
            "i": "well-known/malware/trojan/shellobject::xll-large-rsrc-section",
            "l": 1
          },
          {
            "a": "T1546.012",
            "c": 0.949999988079071,
            "d": "Full IFEO registry key path",
            "e": [
              "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options"
            ],
            "i": "objectives/persistence/login/ifeo/debugger::ifeo-full-path",
            "l": 1,
            "m": "F0012"
          },
          {
            "c": 0.949999988079071,
            "d": "Windows path join format string",
            "e": [
              "\\\\%s\\%s\\%s.exe"
            ],
            "i": "micro-behaviors/fs/path/construct::windows-system-path-join-format",
            "l": 1
          },
          {
            "a": "T1106",
            "c": 0.949999988079071,
            "d": "Open process handle",
            "e": [
              "OpenProcess"
            ],
            "i": "micro-behaviors/process/create/spawn::open-process",
            "l": 2
          },
          {
            "c": 0.6600000262260437,
            "d": "Look up temp directory via GetTempPath",
            "e": [
              "GetTempPathA"
            ],
            "i": "micro-behaviors/fs/temp/directory::get-temp-path-dup",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "High import density (\u003e3 imports/KB)",
            "e": [
              "binary.import_density = 3.02"
            ],
            "i": "metadata/binary/metrics::high-import-density",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Set file position",
            "e": [
              "SetFilePointer"
            ],
            "i": "micro-behaviors/fs/file/operations::set-file-pointer",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE standard code/data section",
            "e": [
              ".text",
              ".data"
            ],
            "i": "metadata/binary/section/names::pe-code-data-standard-section",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "HTTP GET method",
            "e": [
              "GET %s?%s HTTP/1.1"
            ],
            "i": "micro-behaviors/communications/http/get::get",
            "l": 3
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Recursively delete registry key tree",
            "e": [
              "SHDeleteKeyA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::sh-delete-key-a",
            "l": 3
          },
          {
            "c": 0.7200000286102295,
            "d": "Short uppercase mutex token",
            "e": [
              "RECYCLER"
            ],
            "i": "micro-behaviors/process/sync/mutex::short-uppercase-token",
            "l": 1,
            "m": "C0042"
          },
          {
            "c": 0.8199999928474426,
            "d": "GetSystemDirectory API string",
            "e": [
              "GetSystemDirectoryA"
            ],
            "i": "micro-behaviors/os/sysinfo/directories::get-system-directory-string",
            "l": 2
          },
          {
            "a": "T1071.001",
            "d": "HTTP header syntax marker",
            "e": [
              "HTTP/1.1\r\nConnection: "
            ],
            "i": "objectives/command-and-control/channel/http/protocol::http-delimiter",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Low entropy overlay payload",
            "e": [
              "binary.overlay_entropy = 0.00"
            ],
            "i": "metadata/binary/layout::low-overlay-entropy",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Memory copy operation",
            "e": [
              "memcpy"
            ],
            "i": "micro-behaviors/mem/c-runtime/functions::memcpy",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "LoadLibrary symbol",
            "e": [
              "LoadLibraryA"
            ],
            "i": "objectives/anti-static/obfuscation/reflection/class::loadlibrary-sym",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Wait for process/object",
            "e": [
              "WaitForSingleObject"
            ],
            "i": "micro-behaviors/process/create/spawn::wait-for-single-object",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 50+ imports",
            "e": [
              "binary.import_count = 148.00"
            ],
            "i": "metadata/binary/metrics::many-imports-50",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "ws2_32 ordinal 4 (connect)",
            "e": [
              "ORDINAL 4"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-32-ordinal-4",
            "l": 1
          },
          {
            "a": "T1562.001",
            "c": 0.8999999761581421,
            "d": "Common EDR/AV process name",
            "e": [
              "bdagent.exe"
            ],
            "i": "objectives/impact/degrade/edr::target-general-edr",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "ws2_32 ordinal 11 (inet_addr)",
            "e": [
              "ORDINAL 11"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-32-ordinal-11",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Close registry key",
            "e": [
              "RegCloseKey"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-close-key",
            "l": 2
          },
          {
            "a": "T1553.002",
            "c": 0.949999988079071,
            "d": "Verify Authenticode trust chain",
            "e": [
              "WinVerifyTrust"
            ],
            "i": "micro-behaviors/os/security/auth/verify::winverifytrust-symbol",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Network share connection API import",
            "e": [
              "WNetAddConnection2A"
            ],
            "i": "micro-behaviors/os/network/share::wnet-add-connection",
            "l": 3
          },
          {
            "a": "T1057",
            "c": 0.800000011920929,
            "d": "PSAPI.dll dynamic load string",
            "e": [
              "PSAPI"
            ],
            "i": "micro-behaviors/process/enumerate/psapi::psapi-dll-string",
            "l": 1
          },
          {
            "a": "T1027.009",
            "c": 0.800000011920929,
            "d": "Size PE resource payload",
            "e": [
              "SizeofResource"
            ],
            "i": "micro-behaviors/data/embedded/payload::sizeof-resource",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "HTTP User-Agent header",
            "e": [
              "User-Agent:",
              "User-Agent: Mo",
              "User-Agent: Mozilla/4.0User-Agent",
              "User-Agent: Mozilla/4.0",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0Useq ",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agent: Mozilla/4.3X",
              "User-Agent: Mozilla/\\b",
              "User-Agent: Mozilla/4.0U",
              "User-Agent: 碸I",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agemy",
              "…: Keep-Alive\r\nHost: %s\r\nUser-Agent: Mozilla/4.0\r\nAccept-lan…"
            ],
            "i": "micro-behaviors/communications/http/user-agent::user-agent-header-dup",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Large PE resource section (\u003e150KB)",
            "e": [
              ".rsrc (size: 178688)"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics::large-pe-resource-section",
            "l": 1
          },
          {
            "a": "T1055",
            "c": 0.699999988079071,
            "d": "Query virtual memory info (VirtualQuery)",
            "e": [
              "VirtualQuery"
            ],
            "i": "micro-behaviors/mem/query/info::virtualquery",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Windows file creation/open API",
            "e": [
              "CreateFileA"
            ],
            "i": "micro-behaviors/fs/file/open::file-create-win",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has low average complexity",
            "e": [
              "binary.avg_complexity = 4.81"
            ],
            "i": "metadata/binary/metrics::avg-complexity-15-max",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "High number of imported symbols (\u003e80)",
            "e": [
              "binary.import_count = 148.00"
            ],
            "i": "metadata/binary/metrics::many-imports",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.949999988079071,
            "d": "Open service control manager import",
            "e": [
              "OpenSCManagerA"
            ],
            "i": "micro-behaviors/os/service/control::open-sc-manager-import",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Close handle",
            "e": [
              "CloseHandle"
            ],
            "i": "micro-behaviors/process/create/spawn::close-handle-dup",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Modify file creation/access/write times",
            "e": [
              "SetFileTime"
            ],
            "i": "micro-behaviors/fs/sync/fsync::set-file-time",
            "l": 3
          },
          {
            "a": "T1071",
            "c": 0.8999999761581421,
            "d": "Create Winsock event handle",
            "e": [
              "WSACreateEvent"
            ],
            "i": "micro-behaviors/communications/socket/multiplex::wsa-create-event",
            "l": 3,
            "m": "C0001"
          },
          {
            "c": 0.699999988079071,
            "d": "ws2_32 ordinal 19 (send)",
            "e": [
              "ORDINAL 19"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-32-ordinal-19",
            "l": 1
          },
          {
            "a": "T1562.001",
            "c": 0.8500000238418579,
            "d": "Kaspersky AV/Internet Security specifically targeted",
            "e": [
              "avp.exe"
            ],
            "i": "objectives/impact/degrade/edr/targeting::kaspersky-target",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Exit thread execution",
            "e": [
              "ExitThread"
            ],
            "i": "micro-behaviors/process/thread/create::exit-thread",
            "l": 2
          },
          {
            "a": "T1106",
            "c": 0.8999999761581421,
            "d": "WinExec command execution API",
            "e": [
              "WinExec"
            ],
            "i": "micro-behaviors/process/create/exec::winexec",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "Binary has many functions (\u003e30)",
            "e": [
              "binary.function_count = 110.00"
            ],
            "i": "metadata/binary/metrics::many-functions",
            "l": 2
          },
          {
            "a": "T1485",
            "c": 0.8999999761581421,
            "d": "Preserves .exe .gho .bak files",
            "e": [
              ".exe"
            ],
            "i": "objectives/impact/destroy/file-deletion::exe-gho-bak-whitelist",
            "l": 1,
            "m": "C0047"
          },
          {
            "a": "T1562.001",
            "c": 0.8999999761581421,
            "d": "Task Manager process enumeration",
            "e": [
              "Process32Next"
            ],
            "i": "micro-behaviors/process/terminate/kill::taskmgr-process-enum",
            "l": 3,
            "m": "B0001"
          },
          {
            "a": "T1083",
            "c": 0.8799999952316284,
            "d": "Enumerate logical drive letters",
            "e": [
              "GetLogicalDrives"
            ],
            "i": "micro-behaviors/fs/traversal/drives::get-logical-drives-text",
            "l": 3,
            "m": "E1083"
          },
          {
            "c": 0.8500000238418579,
            "d": "Query file attributes or existence",
            "e": [
              "GetFileAttributesA"
            ],
            "i": "micro-behaviors/fs/path/check::get-file-attributes",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "ws2_32 ordinal 116 (WSACleanup)",
            "e": [
              "ORDINAL 116"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-32-ordinal-116",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Attach thread to desktop",
            "e": [
              "SetThreadDesktop"
            ],
            "i": "micro-behaviors/ui/window/station::set-thread-desktop-import",
            "l": 3
          },
          {
            "c": 0.8199999928474426,
            "d": "GetWindowsDirectory API string",
            "e": [
              "GetWindowsDirectoryA"
            ],
            "i": "micro-behaviors/os/sysinfo/directories::get-windows-directory-string",
            "l": 2
          },
          {
            "a": "T1565.001",
            "c": 0.8500000238418579,
            "d": "Windows hosts path format string",
            "e": [
              "%s\\drivers\\etc\\hosts"
            ],
            "i": "objectives/evasion/hosts-file/block-security::windows-hosts-template-path",
            "l": 4,
            "m": "F0004"
          },
          {
            "c": 0.949999988079071,
            "d": "Binary imports ADVAPI32.dll",
            "e": [
              "ADVAPI32.dll"
            ],
            "i": "metadata/binary/symbols::imports-advapi32-dll",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Get current process ID",
            "e": [
              "GetCurrentProcessId"
            ],
            "i": "micro-behaviors/process/info/thread::get-current-process-id",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 50+ functions",
            "e": [
              "binary.function_count = 110.00"
            ],
            "i": "metadata/binary/metrics::many-functions-50",
            "l": 1
          },
          {
            "d": "SYSTEMROOT environment variable",
            "e": [
              "%SystemRoot%\\System32\\svch%s -k nets"
            ],
            "i": "micro-behaviors/os/env/vars/system-info::systemroot-var",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Get message (ANSI)",
            "e": [
              "GetMessageA"
            ],
            "i": "micro-behaviors/os/message/queue::get-message-a",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Delay execution",
            "e": [
              "Sleep"
            ],
            "i": "micro-behaviors/time/timing/delay::sleep-dup",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "ws2_32 ordinal 23 (socket)",
            "e": [
              "ORDINAL 23"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-32-ordinal-23",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 100+ imports",
            "e": [
              "binary.import_count = 148.00"
            ],
            "i": "metadata/binary/metrics::many-imports-100",
            "l": 1
          },
          {
            "c": 0.8199999928474426,
            "d": "Resolve special folder path ANSI",
            "e": [
              "SHGetSpecialFolderPathA"
            ],
            "i": "micro-behaviors/fs/shell-ops/commands::shell-get-special-folder-path-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Begin directory enumeration ANSI",
            "e": [
              "FindFirstFileA"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-first-file-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Get tick count",
            "e": [
              "GetTickCount"
            ],
            "i": "micro-behaviors/time/query::get-tick-count",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "ws2_32 ordinal 115 (WSAStartup)",
            "e": [
              "ORDINAL 115"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-32-ordinal-115",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE resource section",
            "e": [
              ".rsrc"
            ],
            "i": "metadata/binary/section/names::pe-resource-section",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Set file attributes (ANSI)",
            "e": [
              "SetFileAttributesA"
            ],
            "i": "micro-behaviors/fs/file/attributes::set-file-attributes-a",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Get system error code",
            "e": [
              "GetLastError"
            ],
            "i": "micro-behaviors/os/exception/error-handling::get-last-error",
            "l": 2
          },
          {
            "c": 0.75,
            "d": "Open process access token",
            "e": [
              "OpenProcessToken"
            ],
            "i": "micro-behaviors/os/privilege/token::open-process-token",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Uses Windows API for file mapping",
            "e": [
              "MapViewOfFile"
            ],
            "i": "micro-behaviors/fs/memory/mmap::win32-file-mapping",
            "l": 2
          },
          {
            "a": "T1036.005",
            "c": 0.800000011920929,
            "d": "explorer.exe process name",
            "e": [
              "explorer.exe"
            ],
            "i": "objectives/evasion/masquerade/process::explorer-name",
            "l": 1,
            "m": "F0004"
          },
          {
            "c": 0.800000011920929,
            "d": "Thread32Next API string",
            "e": [
              "Thread32Next"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::thread32-next-string",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "PE binary has trailing overlay data",
            "e": [
              "binary.has_overlay = 1.00"
            ],
            "i": "metadata/binary/layout::has-overlay",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Create named event object",
            "e": [
              "CreateEventA"
            ],
            "i": "micro-behaviors/process/sync/event::create-event",
            "l": 2,
            "m": "C0039"
          },
          {
            "d": ".dll extension reference",
            "e": [
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll"
            ],
            "i": "micro-behaviors/fs/path/extension::dll-dup",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "Process termination via TerminateProcess",
            "e": [
              "TerminateProcess"
            ],
            "i": "micro-behaviors/process/terminate/kill::terminate-process",
            "l": 2,
            "m": "B0033"
          },
          {
            "c": 0.6200000047683716,
            "d": "Assembly Load method token",
            "e": [
              "Load"
            ],
            "i": "objectives/anti-static/obfuscation/reflection/invoke::dotnet-assembly-load-token",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE standard runtime section",
            "e": [
              ".rdata",
              ".reloc"
            ],
            "i": "metadata/binary/section/names::pe-runtime-standard-section",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "ws2_32 ordinal 9 (htons)",
            "e": [
              "ORDINAL 9"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-32-ordinal-9",
            "l": 1
          },
          {
            "c": 0.6499999761581421,
            "d": "Get file size",
            "e": [
              "GetFileSize"
            ],
            "i": "micro-behaviors/fs/sync/fsync::get-file-size",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Direct NT API access",
            "e": [
              "ntdll.dll"
            ],
            "i": "micro-behaviors/os/syscall/invoke::ntdll-import",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Creates a new service (ANSI)",
            "e": [
              "CreateServiceA"
            ],
            "i": "micro-behaviors/os/service::create-service-a",
            "l": 3
          },
          {
            "c": 0.8399999737739563,
            "d": "High basic block count in sparse binary",
            "e": [
              "binary.total_basic_blocks = 1025.00"
            ],
            "i": "metadata/binary/metrics::dense-basic-blocks",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Skips Windows installation directories",
            "e": [
              "WINDOWS"
            ],
            "i": "objectives/impact/infect/binary::skip-windows-install-dir",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 3+ functions",
            "e": [
              "binary.function_count = 110.00"
            ],
            "i": "metadata/binary/metrics::few-functions-3",
            "l": 1
          },
          {
            "a": "T1070.006",
            "c": 0.699999988079071,
            "d": "Debug timestamps internally consistent",
            "e": [
              "pe.debug_timestamp_consistent = 1.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::debug-timestamps-consistent",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Open registry key via import symbol ANSI",
            "e": [
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-open-key-ex-a-symbol",
            "l": 2
          },
          {
            "a": "T1105",
            "c": 1.0,
            "d": "Binary contains high-entropy data regions",
            "e": [
              "binary.high_entropy_regions = 2.00"
            ],
            "i": "objectives/command-and-control/dropper/staging::has-high-entropy-regions",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Get system time",
            "e": [
              "GetSystemTime"
            ],
            "i": "micro-behaviors/time/query::get-system-time",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "NCapture launches explorer",
            "e": [
              "explorer.exe"
            ],
            "i": "well-known/app/graphics::ncapture-explorer",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Large PE resource section",
            "e": [
              "pe.rsrc_size = 178688.00"
            ],
            "i": "metadata/binary/framework::large-rsrc-section",
            "l": 2
          },
          {
            "a": "T1105",
            "c": 1.0,
            "d": "Binary has high overall entropy",
            "e": [
              "binary.overall_entropy = 6.61"
            ],
            "i": "objectives/command-and-control/dropper/staging::high-entropy-binary",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.8500000238418579,
            "d": "Set registry value via WinAPI ANSI",
            "e": [
              "RegSetValueExA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-set-value-ex-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Get Windows installation directory",
            "e": [
              "GetWindowsDirectoryA"
            ],
            "i": "micro-behaviors/os/sysinfo/directories::get-windows-directory",
            "l": 2
          },
          {
            "c": 0.9599999785423279,
            "d": "Elex Internet Explorer product resource",
            "e": [
              "Internet Explorer"
            ],
            "i": "well-known/malware/trojan/elex/worm::elex-internet-explorer-product-resource",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.699999988079071,
            "d": "Encoded Mozilla user agent string",
            "e": [
              "User-Agent: Mozilla/\\b",
              "User-Agent: Mozilla/4.0User-Agent",
              "User-Agent: Mozilla/4.0U",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agent: Mozilla/4.3X",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agemy",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0Useq ",
              "Sser-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agent: Mozilla,9",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agent: Moyd",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0Useq ",
              "Dser-Agent: Mozilla/4.0User-Agent: Mozilla/4.3X",
              "User-Agent: Mozilla/4.0User-Agent: Mozilol",
              "\u0026ser-Agent: Mozilla/4.0User-Agent: Moyd",
              "User-Agent: Mozilla/4.0User.L",
              "User-Agent: Mozilla/4.0V~",
              "Xþr-Agent: Mozilla/4.0User.L",
              "User-Agent: Mozilla/4.0V~"
            ],
            "i": "objectives/anti-static/obfuscation/encoding::encoded-mozilla-ua",
            "l": 3
          },
          {
            "a": "T1016",
            "c": 0.8999999761581421,
            "d": "Enumerate local adapters via GetAdaptersInfo",
            "e": [
              "GetAdaptersInfo"
            ],
            "i": "micro-behaviors/os/network/interface::get-adapters-info",
            "l": 3
          },
          {
            "a": "T1112",
            "c": 0.8500000238418579,
            "d": "Query registry value via import symbol",
            "e": [
              "RegQueryValueExA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-query-value-ex-a-symbol",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Query current module path",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/fs/path/check::get-module-filename",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Check file existence via SHLWAPI",
            "e": [
              "PathFileExistsA"
            ],
            "i": "micro-behaviors/fs/path/check::path-file-exists",
            "l": 2
          },
          {
            "c": 0.6600000262260437,
            "d": "Delete files (Windows API ANSI)",
            "e": [
              "DeleteFileA"
            ],
            "i": "micro-behaviors/fs/file/delete::deletefile-a",
            "l": 2
          },
          {
            "a": "T1129",
            "c": 0.949999988079071,
            "d": "Create thread in current process",
            "e": [
              "CreateThread"
            ],
            "i": "micro-behaviors/process/thread/create::create-thread",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.9300000071525574,
            "d": "Start service import",
            "e": [
              "StartServiceA"
            ],
            "i": "micro-behaviors/os/service/control::start-service-import",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Set event object state",
            "e": [
              "SetEvent"
            ],
            "i": "micro-behaviors/process/sync/event::set-event",
            "l": 2,
            "m": "C0039"
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Set registry value ANSI",
            "e": [
              "RegSetValueExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-set-value-ex-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "RECYCLER literal path marker",
            "e": [
              "RECYCLER"
            ],
            "i": "micro-behaviors/fs/path/system::recycler-literal",
            "l": 4
          },
          {
            "a": "T1036.005",
            "c": 0.8600000143051147,
            "d": "WindowsUpdate identity token",
            "e": [
              "WindowsUpdate"
            ],
            "i": "objectives/evasion/masquerade/identity/mimicry::windowsupdate-camelcase-token",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Dominant text section ratio",
            "e": [
              "binary.largest_section_ratio = 0.72"
            ],
            "i": "well-known/malware/trojan/elex-technoinox::runner-dominant-text-ratio",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary is not position-independent (fixed load address)",
            "e": [
              "binary.is_pie = 0.00"
            ],
            "i": "metadata/hardening::no-pie",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Move or rename file with options",
            "e": [
              "MoveFileExA"
            ],
            "i": "micro-behaviors/fs/file/move::move-file-ex",
            "l": 2
          },
          {
            "a": "T1071",
            "c": 1.0,
            "d": "oleaut32 ordinal 2",
            "e": [
              "ORDINAL 2"
            ],
            "i": "objectives/command-and-control/backdoor/binary::oleaut-ordinal-2",
            "l": 1,
            "m": "B0025"
          },
          {
            "c": 0.8999999761581421,
            "d": "Memory fill operation",
            "e": [
              "memset"
            ],
            "i": "micro-behaviors/mem/c-runtime/functions::memset",
            "l": 2
          },
          {
            "a": "T1546.012",
            "c": 0.8999999761581421,
            "d": "IFEO registry path",
            "e": [
              "Image File Execution Options"
            ],
            "i": "objectives/persistence/login/ifeo/debugger::ifeo-registry-path",
            "l": 1,
            "m": "F0012"
          },
          {
            "c": 1.0,
            "d": "Call to GetDriveTypeA by raw bytes",
            "e": [
              "GetDriveTypeA"
            ],
            "i": "micro-behaviors/fs/traversal/drives::get-drive-type-raw",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE Rich header present (MSVC toolchain)",
            "e": [
              "pe.rich_header_present = 1.00"
            ],
            "i": "metadata/binary/resource::rich-header-present",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 40+ imports",
            "e": [
              "binary.import_count = 148.00"
            ],
            "i": "metadata/binary/metrics::many-imports-40",
            "l": 1
          },
          {
            "c": 0.6000000238418579,
            "d": "System32 substring reference",
            "e": [
              "%SystemRoot%\\System32\\svch%s -k nets"
            ],
            "i": "micro-behaviors/fs/path/system::system32-substr",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Write data to file handle",
            "e": [
              "WriteFile"
            ],
            "i": "micro-behaviors/fs/file/write::write-file",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Find substring",
            "e": [
              "strstr"
            ],
            "i": "micro-behaviors/data/string/operations::strstr",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Get module file path (ANSI)",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/os/module/load::get-module-filename-ansi",
            "l": 2
          },
          {
            "c": 0.550000011920929,
            "d": ".NET Start method token",
            "e": [
              "Start"
            ],
            "i": "micro-behaviors/process/create/spawn::start-method-token-dotnet",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Get current process handle",
            "e": [
              "GetCurrentProcess"
            ],
            "i": "micro-behaviors/os/module/load::get-current-process",
            "l": 2
          },
          {
            "c": 0.7200000286102295,
            "d": "Embedded absolute PDB path",
            "e": [
              "C:\\exe.pdb"
            ],
            "i": "metadata/binary/debug::pdb-absolute-path",
            "l": 2
          },
          {
            "c": 0.75,
            "d": "Binary exports no symbols",
            "e": [
              "binary.export_count = 0.00"
            ],
            "i": "metadata/binary/symbols::no-exports",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "String length",
            "e": [
              "strlen"
            ],
            "i": "micro-behaviors/data/string/operations::strlen",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Remove directory (ANSI)",
            "e": [
              "RemoveDirectoryA"
            ],
            "i": "micro-behaviors/fs/directory/rmdir::remove-directory-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Flush file buffer to disk",
            "e": [
              "FlushFileBuffers"
            ],
            "i": "micro-behaviors/fs/file/operations::flush-file-buffers",
            "l": 2
          },
          {
            "a": "T1071.001",
            "d": "User-Agent header",
            "e": [
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:"
            ],
            "i": "micro-behaviors/communications/http/request::user-agent-header",
            "l": 2,
            "m": "C0002"
          },
          {
            "a": "T1071.001",
            "c": 0.8999999761581421,
            "d": "InternetOpen API name as string",
            "e": [
              "InternetOpenA"
            ],
            "i": "micro-behaviors/communications/http/get::internet-open-str",
            "l": 1
          },
          {
            "a": "T1071.001",
            "c": 0.8999999761581421,
            "d": "InternetCloseHandle API name",
            "e": [
              "InternetCloseHandle"
            ],
            "i": "micro-behaviors/communications/http/get::internet-close-handle-str",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Post message to thread (ANSI)",
            "e": [
              "PostThreadMessageA"
            ],
            "i": "micro-behaviors/os/message/queue::post-thread-message-a",
            "l": 2
          },
          {
            "c": 0.75,
            "d": "Large .data section in PE binary",
            "e": [
              ".data (size: 8704, entropy: 7.47)"
            ],
            "i": "micro-behaviors/data/embedded/payload::large-data-section",
            "l": 3
          },
          {
            "a": "T1027.009",
            "c": 0.800000011920929,
            "d": "Locate PE resource entry (ANSI)",
            "e": [
              "FindResourceA"
            ],
            "i": "micro-behaviors/data/embedded/payload::find-resource-a",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "File is a compiled binary",
            "e": [
              "binary.file_size = 249193.00"
            ],
            "i": "metadata/binary/framework::is-binary",
            "l": 1
          },
          {
            "a": "T1053.005",
            "c": 0.8799999952316284,
            "d": "Task action principal properties",
            "e": [
              "Path",
              "Path",
              "Path"
            ],
            "i": "objectives/persistence/login/scheduled-task::task-action-principal-properties",
            "l": 1,
            "m": "F0012"
          },
          {
            "a": "T1070.006",
            "c": 0.699999988079071,
            "d": "PE header compile timestamp predates 2025",
            "e": [
              "pe.timestamp = 1265659193.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::header-timestamp-pre-2025",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.8399999737739563,
            "d": "Open registry key ANSI",
            "e": [
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-open-key-ex-a",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Map a file section into memory",
            "e": [
              "MapViewOfFile"
            ],
            "i": "micro-behaviors/fs/memory/mmap::map-view-of-file",
            "l": 2
          },
          {
            "a": "T1027.003",
            "c": 0.8600000143051147,
            "d": "Encoded PE resource section",
            "e": [
              ".rsrc (size: 178688, entropy: 7.72)"
            ],
            "i": "objectives/anti-static/obfuscation/payload/container::moderately-encoded-rsrc",
            "l": 1,
            "m": "F0001.006"
          },
          {
            "c": 0.800000011920929,
            "d": "Multiple embedded MZ headers",
            "e": [
              "4D 5A",
              "4D 5A",
              "4D 5A",
              "4D 5A"
            ],
            "i": "metadata/binary/layout::multiple-pe-embedded-loose",
            "l": 1
          },
          {
            "a": "T1055.012",
            "c": 0.9200000166893005,
            "d": "Internet Explorer hollowing target",
            "e": [
              "\\Internet Explorer\\iexplore.exe"
            ],
            "i": "objectives/evasion/process/injection/hollowing::iexplore-hollowing-target",
            "l": 1,
            "m": "E1055.012"
          },
          {
            "c": 0.8999999761581421,
            "d": "Get current thread ID",
            "e": [
              "GetCurrentThreadId"
            ],
            "i": "micro-behaviors/process/info/thread::get-current-thread-id",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Get Windows system directory path",
            "e": [
              "GetSystemDirectoryA"
            ],
            "i": "micro-behaviors/os/sysinfo/directories::get-system-directory",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.8399999737739563,
            "d": "High entropy .data section",
            "e": [
              ".data (size: 8704, entropy: 7.47)"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::high-entropy-dot-data-section",
            "l": 3,
            "m": "B0032"
          },
          {
            "c": 0.7799999713897705,
            "d": "Hardcoded loopback IPv4 address",
            "e": [
              "127.0.0.1"
            ],
            "i": "micro-behaviors/communications/ip::loopback-ipv4-binary",
            "l": 3
          },
          {
            "a": "T1543.003",
            "c": 0.8500000238418579,
            "d": "Open existing service handle",
            "e": [
              "OpenServiceA"
            ],
            "i": "micro-behaviors/os/service/control::open-service",
            "l": 3
          },
          {
            "a": "T1027",
            "c": 0.8600000143051147,
            "d": "Long mixed-case identifiers cluster",
            "e": [
              "InternetSetStatusCallback",
              "GetModuleInformation",
              "GetModuleFileNameA",
              "GetWindowsDirectoryA",
              "MultiByteToWideChar",
              "GetSystemDirectoryA",
              "GetLogicalDriveStringsA",
              "SetNamedPipeHandleState",
              "GetCurrentProcessId",
              "DisconnectNamedPipe",
              "SetProcessWindowStation"
            ],
            "i": "objectives/anti-static/obfuscation/string::long-mixedcase-identifiers",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.8199999928474426,
            "d": "High entropy in writable data section",
            "e": [
              ".data (entropy: 7.47, perms: rw-)"
            ],
            "i": "objectives/anti-static/pack/entropy::high-entropy-data-section",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Small DLL, high-entropy resource",
            "e": [
              ".rsrc (entropy: 7.72)"
            ],
            "i": "metadata/binary/section/metrics::high-entropy-resource-small-dll",
            "l": 3
          },
          {
            "a": "T1562.001",
            "c": 1.0,
            "d": "ntdll.dll string reference",
            "e": [
              "ntdll.dll"
            ],
            "i": "objectives/evasion/anti-av/platform::ntdll-dll-str",
            "l": 1
          },
          {
            "a": "T1027.007",
            "c": 0.8999999761581421,
            "d": "Kernel32 DLL resolution string",
            "e": [
              "kernel32.dll"
            ],
            "i": "micro-behaviors/os/api-resolution/manual::kernel32-resolver",
            "l": 1
          },
          {
            "a": "T1543.003",
            "c": 0.8500000238418579,
            "d": "Start Windows service",
            "e": [
              "StartServiceA"
            ],
            "i": "micro-behaviors/os/service/control::start-service",
            "l": 3
          },
          {
            "c": 0.8600000143051147,
            "d": "Query Windows system directory",
            "e": [
              "GetSystemDirectoryA"
            ],
            "i": "micro-behaviors/fs/path/system::get-system-directory-import",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "UPX packer marker string",
            "e": [
              "UPX0"
            ],
            "i": "objectives/anti-static/pack/detect::upx-marker",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "CreateFile API string reference",
            "e": [
              "CreateFile",
              "CreateFile"
            ],
            "i": "micro-behaviors/fs/file/open::createfile-api",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.699999988079071,
            "d": "Hardcoded loopback IP (likely test C2)",
            "e": [
              "127.0.0.1"
            ],
            "i": "objectives/command-and-control/channel/http-beacon::hardcoded-localhost-c2",
            "l": 3,
            "m": "B0030"
          },
          {
            "a": "T1027",
            "c": 0.8999999761581421,
            "d": "Packed loader code-to-data ratio below 0.4",
            "e": [
              "binary.code_to_data_ratio = 0.25"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::packed-loader-low-code-to-data-ratio",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1559",
            "c": 0.800000011920929,
            "d": "Named pipe path prefix",
            "e": [
              "\\\\.\\pipe\\"
            ],
            "i": "micro-behaviors/communications/ipc/named-pipe::pipe-path-prefix",
            "l": 3
          },
          {
            "a": "T1543.003",
            "c": 0.8600000143051147,
            "d": "Send service control code",
            "e": [
              "ControlService"
            ],
            "i": "micro-behaviors/os/service/control::control-service",
            "l": 3
          },
          {
            "a": "T1543.003",
            "c": 0.8500000238418579,
            "d": "Open service control manager",
            "e": [
              "OpenSCManagerA"
            ],
            "i": "micro-behaviors/os/service/control::open-sc-manager",
            "l": 3
          },
          {
            "a": "T1027.002",
            "c": 0.8500000238418579,
            "d": "High entropy PE resource section",
            "e": [
              ".rsrc (size: 178688, entropy: 7.72)"
            ],
            "i": "objectives/anti-static/pack/entropy::high-entropy-rsrc",
            "l": 4
          },
          {
            "a": "T1134",
            "c": 1.0,
            "d": "CreateProcessAsUser API reference",
            "e": [
              "CreateProcessAsUserA"
            ],
            "i": "micro-behaviors/process/create/spawn::create-process-as-user",
            "l": 3
          },
          {
            "a": "T1071.001",
            "c": 0.949999988079071,
            "d": "InternetOpenUrl downloader API string",
            "e": [
              "InternetOpenUrlA"
            ],
            "i": "micro-behaviors/communications/http/get::dynamic-wininet-api-set",
            "l": 3
          },
          {
            "a": "T1574.002",
            "c": 0.949999988079071,
            "d": "Extended dynamic library loading (ANSI)",
            "e": [
              "LoadLibraryExA"
            ],
            "i": "micro-behaviors/dylib/load::load-library-ex-a",
            "l": 3
          },
          {
            "a": "T1559",
            "c": 0.6499999761581421,
            "d": "ConnectNamedPipe API call",
            "e": [
              "ConnectNamedPipe"
            ],
            "i": "micro-behaviors/communications/ipc/named-pipe::connect-named-pipe",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "PE executable is unsigned",
            "i": "metadata/signed::unsigned-pe-executable",
            "l": 3
          },
          {
            "c": 0.8500000238418579,
            "d": "Repeated GetTickCount with small-constant comparisons",
            "e": [
              "18 91 40 00",
              "f0 91 40 00",
              "60 dc 40 00",
              "3c 92 40 00",
              "3c 91 40 00",
              "a4 90 40 00",
              "5c 91 40 00",
              "ec 90 40 00",
              "d0 90 40 00",
              "60 92 40 00",
              "64 92 40 00",
              "f0 91 40 00"
            ],
            "i": "objectives/anti-static/obfuscation/instruction/junk::gettickcount-junk-branches",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "GUID-formatted mutex name",
            "e": [
              "{645FF040-5081-101B-9F08-00AA002F954E}"
            ],
            "i": "micro-behaviors/process/sync/mutex::guid-mutex",
            "l": 2,
            "m": "C0042"
          },
          {
            "a": "T1055.001",
            "c": 0.949999988079071,
            "d": "Dynamic LoadLibraryA resolution for remote injection",
            "e": [
              "LoadLibraryA"
            ],
            "i": "micro-behaviors/process/inject/dll::load-library-a-remote-resolution",
            "l": 3,
            "m": "F0003"
          },
          {
            "c": 1.0,
            "d": "Compatibility alias",
            "e": [
              "GetAdaptersInfo"
            ],
            "i": "micro-behaviors/os/sysinfo/network::get-adapters-info",
            "l": 1
          },
          {
            "d": ".exe extension reference",
            "e": [
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe"
            ],
            "i": "micro-behaviors/fs/path/extension::exe-dup",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "DeviceIoControl API usage",
            "e": [
              "DeviceIoControl"
            ],
            "i": "micro-behaviors/fs/file/operations::device-io-control-win",
            "l": 3
          },
          {
            "a": "T1559",
            "c": 0.699999988079071,
            "d": "CreateNamedPipe API call",
            "e": [
              "CreateNamedPipeA"
            ],
            "i": "micro-behaviors/communications/ipc/named-pipe::create-named-pipe",
            "l": 3
          },
          {
            "a": "T1070.006",
            "c": 0.8999999761581421,
            "d": "Export timestamp is absent",
            "e": [
              "pe.export_timestamp_present = 0.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::export-timestamp-absent",
            "l": 2
          },
          {
            "a": "T1057",
            "c": 0.8999999761581421,
            "d": "Create process or module snapshot",
            "e": [
              "CreateToolhelp32Snapshot"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::create-toolhelp32-snapshot",
            "l": 3,
            "m": "E1057"
          },
          {
            "a": "T1543.003",
            "c": 0.8500000238418579,
            "d": "Create Windows service",
            "e": [
              "CreateServiceA"
            ],
            "i": "micro-behaviors/os/service/control::create-service",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Resolve exports with GetProcAddress",
            "e": [
              "GetProcAddress"
            ],
            "i": "micro-behaviors/os/module/load::get-proc-address-import",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary is not digitally signed",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed::unsigned",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Five or more PE sections",
            "e": [
              "binary.section_count = 7.00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::five-plus-sections-pe",
            "l": 1
          },
          {
            "a": "T1574.002",
            "c": 0.8999999761581421,
            "d": "Hidden LoadLibraryA string reference",
            "e": [
              "LoadLibraryA"
            ],
            "i": "micro-behaviors/dylib/load::load-library-a-string-no-import",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.800000011920929,
            "d": "Few PE resource entries (no DIALOG/MENU/STRINGTABLE)",
            "e": [
              "pe.resource_count = 3.00"
            ],
            "i": "objectives/evasion/anti-av/heuristic::minimal-pe-resources",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "UPX packed section name",
            "e": [
              ".UPX0",
              ".UPX1"
            ],
            "i": "metadata/binary/section/names::upx-section",
            "l": 2,
            "m": "F0001.008"
          },
          {
            "a": "T1027.007",
            "c": 0.8600000143051147,
            "d": "PE API hashing indicator present",
            "e": [
              "pe.api_hashing_indicators = 1.00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::pe-api-hashing-indicator-single",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "a": "T1057",
            "d": "Browser app iexplore",
            "e": [
              "iexplore"
            ],
            "i": "micro-behaviors/process/enumerate/apps::browser-apps-iexplore",
            "l": 3,
            "m": "E1592"
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "GetProcAddress loader API string",
            "e": [
              "GetProcAddress"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-getprocaddress-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "a": "T1027.007",
            "c": 1.0,
            "d": "ntdll.dll as wide string (runtime resolver)",
            "e": [
              "ntdll.dll"
            ],
            "i": "objectives/anti-static/obfuscation/string/runtime-decrypt::ntdll-wide-string",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "c": 0.699999988079071,
            "d": "WS2_32 Winsock DLL import",
            "e": [
              "WS2_32.dll"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-32-dll-marker",
            "l": 3
          },
          {
            "a": "T1543.003",
            "c": 0.8199999928474426,
            "d": "Query service runtime status",
            "e": [
              "QueryServiceStatus"
            ],
            "i": "micro-behaviors/os/service/control::query-service-status",
            "l": 3
          },
          {
            "a": "T1027",
            "c": 0.6000000238418579,
            "d": "High entropy in .rsrc section",
            "e": [
              ".rsrc (entropy: 7.72)"
            ],
            "i": "objectives/anti-static/obfuscation/payload/encrypted::high-entropy-rsrc",
            "l": 2,
            "m": "C0027"
          },
          {
            "c": 0.949999988079071,
            "d": "links SHLWAPI.dll (PathFileExistsA, SHDeleteKeyA)",
            "e": [
              "SHLWAPI.dll"
            ],
            "i": "metadata/dylib::shlwapi/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links WINTRUST.dll (WinVerifyTrust)",
            "e": [
              "WINTRUST.dll"
            ],
            "i": "metadata/dylib::wintrust/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links ADVAPI32.dll (CloseServiceHandle, QueryServiceStatus, RegSetValueExA, RegOpenKeyExA, RegCloseKey, ... +9 more)",
            "e": [
              "ADVAPI32.dll"
            ],
            "i": "metadata/dylib::advapi32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links MPR.dll (WNetOpenEnumA, WNetCloseEnum, WNetAddConnection2A, WNetCancelConnection2A)",
            "e": [
              "MPR.dll"
            ],
            "i": "metadata/dylib::mpr/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links MSVCRT.dll (strstr, strlen, ??2@YAPAXI@Z, strrchr, ??3@YAXPAX@Z, ... +5 more)",
            "e": [
              "MSVCRT.dll"
            ],
            "i": "metadata/dylib::msvcrt/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links SHELL32.dll (ShellExecuteA, SHGetSpecialFolderPathA)",
            "e": [
              "SHELL32.dll"
            ],
            "i": "metadata/dylib::shell32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links RPCRT4.dll (UuidToStringA, UuidFromStringA)",
            "e": [
              "RPCRT4.dll"
            ],
            "i": "metadata/dylib::rpcrt4/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links USER32.dll (OpenWindowStationA, SetProcessWindowStation, OpenDesktopA, SetThreadDesktop, GetMessageA, ... +3 more)",
            "e": [
              "USER32.dll"
            ],
            "i": "metadata/dylib::user32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links WS2_32.dll (ORDINAL 4, ORDINAL 52, WSAResetEvent, ORDINAL 23, ORDINAL 11, ... +15 more)",
            "e": [
              "WS2_32.dll"
            ],
            "i": "metadata/dylib::ws2_32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links KERNEL32.dll (GetExitCodeProcess, FindFirstFileA, GetLogicalDriveStringsA, RemoveDirectoryA, FindClose, ... +77 more)",
            "e": [
              "KERNEL32.dll"
            ],
            "i": "metadata/dylib::kernel32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links IPHLPAPI.DLL (GetAdaptersInfo)",
            "e": [
              "IPHLPAPI.DLL"
            ],
            "i": "metadata/dylib::iphlpapi/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links PSAPI.DLL (GetModuleInformation)",
            "e": [
              "PSAPI.DLL"
            ],
            "i": "metadata/dylib::psapi/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links ntdll.dll (ZwQueryInformationThread)",
            "e": [
              "ntdll.dll"
            ],
            "i": "metadata/dylib::ntdll/dll",
            "l": 2
          },
          {
            "c": 0.9200000166893005,
            "d": "Directory walker using Win32 find APIs",
            "e": [
              "FindNextFileA",
              "FindClose",
              "FindFirstFileA"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-file-walker",
            "l": 2
          },
          {
            "c": 0.8600000143051147,
            "d": "Initialize Winsock library",
            "e": [
              "WS2_32.dll",
              "ORDINAL 115"
            ],
            "i": "micro-behaviors/communications/socket/init::winsock-startup-ordinal",
            "l": 3
          },
          {
            "a": "T1027.009",
            "c": 0.800000011920929,
            "d": "File self-reading import chain",
            "e": [
              "GetFileSize",
              "GetModuleFileNameA",
              "ReadFile",
              "CreateFileA"
            ],
            "i": "objectives/anti-static/obfuscation/payload/self-read::self-read-file-import-chain",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.8600000143051147,
            "d": "Winsock send import",
            "e": [
              "ORDINAL 19",
              "WS2_32.dll"
            ],
            "i": "micro-behaviors/communications/socket/init::send-api-ordinal",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Temp directory staging primitives",
            "e": [
              "MoveFileExA",
              "GetTempPathA"
            ],
            "i": "micro-behaviors/fs/temp/directory::temp-file-staging-primitives",
            "l": 3
          },
          {
            "c": 0.9200000166893005,
            "d": "Network share connect and disconnect cycle",
            "e": [
              "WNetAddConnection2A",
              "WNetCancelConnection2A"
            ],
            "i": "micro-behaviors/os/network/share::wnet-share-connect-cycle",
            "l": 4
          },
          {
            "a": "T1071",
            "c": 0.9200000166893005,
            "d": "UPX packed PE with networking and shell execution",
            "e": [
              ".UPX0",
              ".UPX1",
              "SHDeleteKeyA",
              "WS2_32.dll",
              "ShellExecuteA"
            ],
            "i": "objectives/command-and-control/backdoor::upx-packed-network-shell-trojan",
            "l": 4
          },
          {
            "c": 0.8799999952316284,
            "d": "Winsock outbound connect import",
            "e": [
              "ORDINAL 4",
              "WS2_32.dll"
            ],
            "i": "micro-behaviors/communications/socket/init::connect-api-ordinal",
            "l": 3
          },
          {
            "c": 0.949999988079071,
            "d": "Standard MSVC CRT linkage (rich header + many imports)",
            "e": [
              "binary.import_count = 148.00",
              "pe.rich_header_present = 1.00"
            ],
            "i": "objectives/evasion/process/injection::msvc-crt-full-linkage",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Toolhelp thread enumeration strings",
            "e": [
              "Thread32Next",
              "Thread32First"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::toolhelp-thread-enumeration-string",
            "l": 3
          },
          {
            "a": "T1543.003",
            "c": 0.949999988079071,
            "d": "Windows service admin import cluster",
            "e": [
              "OpenServiceA",
              "OpenSCManagerA",
              "CreateServiceA",
              "StartServiceA"
            ],
            "i": "micro-behaviors/os/service/control::service-admin-import-cluster",
            "l": 3
          },
          {
            "a": "T1485",
            "c": 0.8799999952316284,
            "d": "Raw disk I/O helper API set",
            "e": [
              "CreateFileA",
              "ReadFile",
              "DeviceIoControl"
            ],
            "i": "objectives/impact/system/directory::windows-raw-disk-io-api-set",
            "l": 1
          },
          {
            "c": 0.8399999737739563,
            "d": "Network byte order conversion",
            "e": [
              "ORDINAL 9",
              "WS2_32.dll"
            ],
            "i": "micro-behaviors/communications/socket/init::htons-api-ordinal",
            "l": 2
          },
          {
            "c": 0.8399999737739563,
            "d": "IPv4 string conversion import",
            "e": [
              "WS2_32.dll",
              "ORDINAL 11"
            ],
            "i": "micro-behaviors/communications/socket/init::inet-addr-api-ordinal",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.9200000166893005,
            "d": "Service stop or delete chain",
            "e": [
              "OpenSCManagerA",
              "OpenServiceA",
              "ControlService",
              "QueryServiceStatus"
            ],
            "i": "micro-behaviors/os/service/control::service-stop-control",
            "l": 3
          },
          {
            "c": 0.8399999737739563,
            "d": "Cleanup Winsock library",
            "e": [
              "WS2_32.dll",
              "ORDINAL 116"
            ],
            "i": "micro-behaviors/communications/socket/init::winsock-cleanup-ordinal",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.8799999952316284,
            "d": "Timing API junk branches in minimal stub",
            "e": [
              "5c 91 40 00",
              "18 91 40 00",
              "ec 90 40 00",
              "60 92 40 00",
              "64 92 40 00",
              "3c 92 40 00",
              "3c 91 40 00",
              "f0 91 40 00",
              "60 dc 40 00",
              "d0 90 40 00",
              "a4 90 40 00",
              "GetTickCount"
            ],
            "i": "objectives/anti-static/obfuscation/instruction/junk::timing-junk-code-stub",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Drop and execute file from Temp directory",
            "e": [
              "CreateProcessA",
              "GetTempPathA",
              "WriteFile",
              "ShellExecuteA"
            ],
            "i": "objectives/command-and-control/dropper/staging::temp-file-execution",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.8999999761581421,
            "d": "WinInet APIs resolved dynamically",
            "e": [
              "HttpQueryInfoA",
              "InternetOpenA",
              "InternetCloseHandle"
            ],
            "i": "micro-behaviors/communications/http/get::wininet-dynamic-load",
            "l": 2
          },
          {
            "c": 0.9200000166893005,
            "d": "Dynamically resolve own modules and exports",
            "e": [
              "GetModuleHandleA",
              "GetProcAddress"
            ],
            "i": "micro-behaviors/os/module/load::dynamic-self-resolution-imports",
            "l": 2
          },
          {
            "c": 0.8799999952316284,
            "d": "Winsock socket creation import",
            "e": [
              "WS2_32.dll",
              "ORDINAL 23"
            ],
            "i": "micro-behaviors/communications/socket/init::socket-api-ordinal",
            "l": 3
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Registry key and value write chain",
            "e": [
              "RegOpenKeyExA",
              "RegSetValueExA",
              "RegCreateKeyExA"
            ],
            "i": "micro-behaviors/os/registry/access::registry-write-api-chain",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.9399999976158142,
            "d": "Installs and starts Windows service",
            "e": [
              "GetFileSize",
              "CreateServiceA",
              "StartServiceA",
              "GetModuleFileNameA",
              "CreateFileA",
              "OpenSCManagerA",
              "ReadFile"
            ],
            "i": "objectives/persistence/system/service/install::service-install-and-start",
            "l": 3,
            "m": "B0011.003"
          },
          {
            "a": "T1070.004",
            "c": 0.8199999928474426,
            "d": "Resolve own path then delete file",
            "e": [
              "GetModuleFileNameA",
              "DeleteFileA",
              "DeleteFileA"
            ],
            "i": "objectives/evasion/self-delete/file::module-path-delete",
            "l": 1,
            "m": "F0007"
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Registry key open and query chain",
            "e": [
              "RegQueryValueExA",
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/access::registry-read-api-chain",
            "l": 2
          },
          {
            "c": 0.9200000166893005,
            "d": "Dynamic Toolhelp enumeration suite",
            "e": [
              "Thread32Next",
              "Thread32First",
              "GetProcAddress"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::dynamic-toolhelp-enumerator",
            "l": 3
          },
          {
            "a": "T1543.003",
            "c": 0.949999988079071,
            "d": "Copies binary then installs service",
            "e": [
              "CreateFileA",
              "CopyFileA",
              "ReadFile",
              "StartServiceA",
              "GetModuleFileNameA",
              "GetFileSize",
              "OpenSCManagerA",
              "GetModuleFileNameA",
              "CreateDirectoryA",
              "CreateServiceA"
            ],
            "i": "objectives/persistence/system/service/install::service-self-copy-install",
            "l": 3,
            "m": "B0011.003"
          },
          {
            "c": 0.8999999761581421,
            "d": "High-trust tool delivered via low-integrity packaging",
            "e": [
              "binary.has_overlay = 1.00"
            ],
            "i": "objectives/supply-chain/trojanized/application/monitor::low-integrity-installer-packaging",
            "l": 1
          },
          {
            "a": "T1105",
            "c": 0.949999988079071,
            "d": "Temp staged file copy with shell handoff",
            "e": [
              "ShellExecuteA",
              "GetTempPathA",
              "GetModuleFileNameA",
              "MoveFileExA",
              "CopyFileA"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::temp-copy-shell-handoff",
            "l": 4,
            "m": "B0024"
          },
          {
            "a": "T1547.001",
            "c": 0.9200000166893005,
            "d": "Drop into Windows directory and WinExec",
            "e": [
              "WinExec",
              "CopyFileA",
              "GetWindowsDirectoryA",
              "DeleteFileA",
              "WriteFile",
              "CreateFileA"
            ],
            "i": "objectives/persistence/login/self-install/copy::windir-copy-winexec-dropper",
            "l": 2
          },
          {
            "a": "T1565.001",
            "c": 0.8999999761581421,
            "d": "Hosts tamper with file APIs",
            "e": [
              "%s\\drivers\\etc\\hosts",
              "DeleteFileA",
              "SetFileAttributesA",
              "CopyFileA"
            ],
            "i": "objectives/evasion/hosts-file/block-security::windows-hosts-tamper-api",
            "l": 4,
            "m": "F0004"
          },
          {
            "a": "T1057",
            "c": 0.8999999761581421,
            "d": "ToolHelp snapshot enumeration with process access",
            "e": [
              "OpenProcess",
              "CreateToolhelp32Snapshot"
            ],
            "i": "objectives/discovery/process/targeting::toolhelp-enumeration-with-access",
            "l": 3,
            "m": "E1057"
          },
          {
            "a": "T1559",
            "c": 0.800000011920929,
            "d": "Named pipe server creation",
            "e": [
              "CreateNamedPipeA",
              "ConnectNamedPipe"
            ],
            "i": "micro-behaviors/communications/ipc/named-pipe::named-pipe-server",
            "l": 3
          },
          {
            "a": "T1112",
            "c": 0.9200000166893005,
            "d": "Registry open create and write APIs",
            "e": [
              "RegSetValueExA",
              "RegOpenKeyExA",
              "RegCreateKeyExA",
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::registry-write-api-chain",
            "l": 3
          },
          {
            "a": "T1036.005",
            "c": 0.8399999737739563,
            "d": "Non-Microsoft WindowsUpdate reference",
            "e": [
              "WindowsUpdate"
            ],
            "i": "objectives/evasion/masquerade/identity/mimicry::non-microsoft-windowsupdate-reference",
            "l": 4
          },
          {
            "c": 0.8999999761581421,
            "d": "Trojanized system utility or hardware monitor dropper",
            "e": [
              "WinRAR",
              "binary.has_overlay = 1.00"
            ],
            "i": "objectives/supply-chain/trojanized/application/monitor::trojanized-system-utility-dropper",
            "l": 4
          },
          {
            "a": "T1547.001",
            "c": 0.949999988079071,
            "d": "Windows-directory dropper with registry persistence",
            "e": [
              "RegOpenKeyExA",
              "RegCreateKeyExA",
              "CreateFileA",
              "CopyFileA",
              "GetWindowsDirectoryA",
              "RegSetValueExA",
              "RegOpenKeyExA",
              "WriteFile",
              "WinExec",
              "DeleteFileA"
            ],
            "i": "objectives/persistence/login/self-install/copy::windir-dropper-registry-persist",
            "l": 3
          }
        ],
        "sha": "637876eb1f8c192dbc77afdbab9b3c0f7b8ed5af884875790df070047fbe9047",
        "path": "32702!!embedded:pe@0x13497",
        "type": "pe"
      }
    ],
    "tv": "2a0fe"
  }
}