{
  "ml": {
    "v": "4",
    "fs": [
      {
        "id": 0,
        "prob": 0.9434479475021362,
        "class": 0
      }
    ],
    "prob": 0.94344795,
    "class": 0,
    "version": "v16.16",
    "thresholds": [
      0.9815004,
      0.99404883
    ],
    "analyzed_at": "2026-04-30T08:19:25Z"
  },
  "path": "EVP_MD-RIPEMD160.7",
  "raw": {
    "v": "4",
    "fs": [
      {
        "f": "O₂(As₂S)Md(Pa)",
        "x": 1,
        "id": 0,
        "is": [
          "C.SH.IX.SH.IX.All.PP"
        ],
        "ms": {
          "text": {
            "digit_ratio": 0.04,
            "space_count": 390.0,
            "total_lines": 90.0,
            "char_entropy": 5.22,
            "unique_chars": 83.0,
            "import_density": 1.11,
            "string_density": 0.66,
            "ascii_art_lines": 2.0,
            "avg_line_length": 28.34,
            "max_line_length": 81.0,
            "last_line_length": 46.0,
            "most_common_char": "e",
            "whitespace_ratio": 0.18,
            "most_common_ratio": 0.06,
            "identifier_density": 0.86,
            "line_length_stddev": 25.61,
            "normalized_import_count": 0.11,
            "normalized_string_count": 6.22,
            "repeated_char_sequences": 4.0,
            "suspicious_string_ratio": 0.05,
            "max_inline_whitespace_run": 12.0,
            "suspicious_identifier_ratio": 0.11,
            "normalized_unique_identifiers": 9.4
          },
          "imports": {
            "total": 1.0,
            "unique_modules": 1.0,
            "third_party_count": 1.0,
            "third_party_ratio": 1.0
          },
          "strings": {
            "total": 59.0,
            "avg_length": 59.42,
            "max_length": 1674.0,
            "avg_entropy": 2.63,
            "sql_strings": 1.0,
            "total_bytes": 3506.0,
            "entropy_stddev": 1.43,
            "very_long_strings": 1.0,
            "high_entropy_count": 1.0,
            "shell_command_strings": 2.0
          },
          "comments": {},
          "functions": {},
          "identifiers": {
            "total": 77.0,
            "avg_length": 4.75,
            "max_length": 13.0,
            "min_length": 1.0,
            "avg_entropy": 1.82,
            "reuse_ratio": 0.79,
            "unique_count": 61.0,
            "length_stddev": 2.83,
            "sequential_names": 6.0,
            "single_char_count": 6.0,
            "single_char_ratio": 0.1,
            "all_lowercase_ratio": 0.59,
            "all_uppercase_ratio": 0.1,
            "repeated_char_names": 1.0
          }
        },
        "ss": [
          [
            218,
            " Vertical space (when we can't use .PP)"
          ],
          [
            294,
            " Begin verbatim text"
          ],
          [
            347,
            " End verbatim text"
          ],
          [
            387,
            " and \\*(C' are quotes in nroff, nothing in troff, for use with C\u003c\u003e.\n.ie n \\{\\\n.    ds C"
          ],
          [
            388,
            " and "
          ],
          [
            395,
            "(C' are quotes in nroff, nothing in troff, for use with C\u003c\u003e.\n.ie n "
          ],
          [
            466,
            ".    ds C"
          ],
          [
            489,
            " \"\"\n"
          ],
          [
            490,
            " "
          ],
          [
            516,
            "\n.    ds C'\n'br\\}\n.\\\"\n.\\\" Escape single quotes in literal strings from groff's Unicode transform.\n.ie \\n(.g .ds Aq \\(aq\n.el     "
          ],
          [
            517,
            "\n.    ds C'\n'br"
          ],
          [
            534,
            "\n."
          ],
          [
            538,
            "\n."
          ],
          [
            542,
            " Escape single quotes in literal strings from groff's Unicode transform.\n.ie "
          ],
          [
            621,
            "(.g .ds Aq "
          ],
          [
            634,
            "aq\n.el       .ds Aq '\n."
          ],
          [
            659,
            "\n."
          ],
          [
            663,
            " If the F register is \u003e0, we'll generate index entries on stderr for\n."
          ],
          [
            735,
            " titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index\n."
          ],
          [
            810,
            " entries marked with X\u003c\u003e in POD.  Of course, you'll have to process the\n."
          ],
          [
            885,
            " output yourself in some meaningful fashion.\n."
          ],
          [
            933,
            "\n."
          ],
          [
            937,
            " Avoid warning from groff about undefined register 'F'.\n.de IX\n..\n.nr rF 0\n.if "
          ],
          [
            1018,
            "(.g .if rF .nr rF 1\n.if ("
          ],
          [
            1045,
            "(rF:("
          ],
          [
            1052,
            "(.g==0)) "
          ],
          [
            1065,
            ".    if "
          ],
          [
            1075,
            "F "
          ],
          [
            1081,
            ".        de IX\n.        tm Index:"
          ],
          [
            1116,
            "$1"
          ],
          [
            1122,
            "n%"
          ],
          [
            1129,
            "$2\"\n..\n.        if !"
          ],
          [
            1151,
            "F==2 "
          ],
          [
            1160,
            ".            nr % 0\n.            nr F 2\n.        "
          ],
          [
            1211,
            "\n.    "
          ],
          [
            1219,
            "\n."
          ],
          [
            1223,
            "\n.rr rF\n."
          ],
          [
            1234,
            " ========================================================================\n."
          ],
          [
            1311,
            "\n.IX Title \"EVP_MD-RIPEMD160 7ossl\"\n.TH EVP_MD-RIPEMD160 7ossl 2025-09-30 3.5.4 OpenSSL\n."
          ],
          [
            1402,
            " For nroff, turn off justification.  Always turn off hyphenation; it makes\n."
          ],
          [
            1480,
            " way too many mistakes in technical documents.\n.if n .ad l\n.nh\n.SH NAME\nEVP_MD"
          ],
          [
            1560,
            "RIPEMD160 "
          ],
          [
            1572,
            " The RIPEMD160 EVP_MD implementation\n.SH DESCRIPTION\n.IX Header \"DESCRIPTION\"\nSupport for computing RIPEMD160 digests through th"
          ],
          [
            1704,
            "BEVP_MD"
          ],
          [
            1713,
            "R API.\n.SS Identities\n.IX Subsection \"Identities\"\nThis implementation is available in both the default and legacy providers, and"
          ],
          [
            1887,
            "160\", \"RIPEMD160\", \"RIPEMD\" and\n\"RMD160\".\n.SS \"Gettable Parameters\"\n.IX Subsection \"Gettable Parameters\"\nThis implementation sup"
          ],
          [
            2067,
            "BEVP_MD"
          ],
          [
            2076,
            "common"
          ],
          [
            2084,
            "R"
          ],
          [
            2087,
            "(7).\n.SH \"SEE ALSO\"\n.IX Header \"SEE ALSO\"\n"
          ],
          [
            2133,
            "Bprovider"
          ],
          [
            2144,
            "digest"
          ],
          [
            2152,
            "R"
          ],
          [
            2155,
            "(7), "
          ],
          [
            2162,
            "BOSSL_PROVIDER"
          ],
          [
            2178,
            "default"
          ],
          [
            2187,
            "R"
          ],
          [
            2440,
            "License"
          ],
          [
            2441,
            "License"
          ]
        ],
        "sz": 2641,
        "ts": [
          {
            "c": 0.30000001192092896,
            "d": "stderr string reference",
            "e": [
              "\n.    ds C'\n'br\\}\n.\\\"\n.\\\" Escape single quotes in literal strings from groff's Unicode transform.\n.ie \\n(.g .ds Aq \\(aq\n.el     ",
              " If the F register is \u003e0, we'll generate index entries on stderr for\n."
            ],
            "i": "micro-behaviors/process/fd/stdio::stderr-string",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Path-like string pattern",
            "e": [
              "x:\\\\$1\\t\\\\n%\\t\"\\\\$2\""
            ],
            "i": "micro-behaviors/data/text/malware::path-like-pattern",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "HISTORY documentation reference",
            "e": [
              "HISTORY"
            ],
            "i": "metadata/package/documentation::references-changelog-history",
            "l": 2
          },
          {
            "c": 0.20000000298023224,
            "d": "output keyword",
            "e": [
              "output"
            ],
            "i": "micro-behaviors/data/text/keywords::output",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.8999999761581421,
            "d": "Low string density base64 context",
            "e": [
              "text.string_density = 0.66"
            ],
            "i": "objectives/anti-static/obfuscation/code-metrics::js-base64-candidate-low-string-density",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.8999999761581421,
            "d": "File has 30 or more lines",
            "e": [
              "text.total_lines = 90.00"
            ],
            "i": "metadata/package/metrics::file-has-30-plus-lines",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Unix manual page or bundled manpage example",
            "e": [
              "EVP_MD-RIPEMD160.7"
            ],
            "i": "metadata/package/documentation::unix-manpage",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Small file under 5KB",
            "e": [
              "EVP_MD-RIPEMD160.7"
            ],
            "i": "objectives/supply-chain/metadata-anomaly/markers/npm::small-file-5k",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.6000000238418579,
            "d": "No comments in code",
            "e": [
              "comments.total = 0.00"
            ],
            "i": "objectives/anti-static/obfuscation/code-metrics/structure::no-comments",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1027",
            "c": 0.800000011920929,
            "d": "Sequential identifiers (a, b, c,",
            "e": [
              "identifiers.sequential_names = 6.00"
            ],
            "i": "objectives/anti-static/obfuscation/code-metrics/identifiers::sequential-identifiers",
            "l": 2,
            "m": "B0032"
          }
        ],
        "sha": "db0bbc73f950a60b1634f00342984004b20d9366130f8cfb11922fb9f92564e2",
        "path": "EVP_MD-RIPEMD160.7",
        "type": "javascript"
      }
    ],
    "tv": "f6eaa"
  }
}