{
  "ml": {
    "v": "4",
    "fs": [
      {
        "id": 0,
        "prob": 0.9995198249816895,
        "class": 2
      }
    ],
    "prob": 0.9995198,
    "class": 2,
    "models": [
      {
        "m": "az",
        "prob": 0.9995198,
        "class": 2
      },
      {
        "m": "az/native",
        "prob": 0.9993331,
        "class": 0
      },
      {
        "m": "az/pe",
        "prob": 0.9993248,
        "class": 0
      }
    ],
    "version": "v16.16",
    "thresholds": [
      0.9953178,
      0.9991311
    ],
    "analyzed_at": "2026-05-03T01:32:28Z"
  },
  "path": "10524",
  "raw": {
    "v": "4",
    "fs": [
      {
        "f": "KO₁₀(Er₁₄C₅DyAlAs₇CaI₂P₃Pr₂S)H₄(DsF₂Os₆Po₉)Md₂(Bi₅)",
        "x": 216,
        "id": 0,
        "is": [
          "ORDINAL 6374",
          "ORDINAL 4299",
          "ORDINAL 2379",
          "ORDINAL 4710",
          "ORDINAL 4287",
          "ORDINAL 4234",
          "ORDINAL 324",
          "ORDINAL 1168",
          "ORDINAL 1146",
          "ORDINAL 3597",
          "ORDINAL 4425",
          "ORDINAL 4627",
          "ORDINAL 5277",
          "ORDINAL 2124",
          "ORDINAL 2446",
          "ORDINAL 5261",
          "ORDINAL 1727",
          "ORDINAL 5065",
          "ORDINAL 3749",
          "ORDINAL 6376",
          "ORDINAL 2055",
          "ORDINAL 2648",
          "ORDINAL 4441",
          "ORDINAL 4837",
          "ORDINAL 3798",
          "ORDINAL 5280",
          "ORDINAL 4353",
          "ORDINAL 5163",
          "ORDINAL 2385",
          "ORDINAL 5241",
          "ORDINAL 4407",
          "ORDINAL 1775",
          "ORDINAL 825",
          "ORDINAL 4078",
          "ORDINAL 6052",
          "ORDINAL 4998",
          "ORDINAL 5265",
          "ORDINAL 823",
          "ORDINAL 2514",
          "ORDINAL 641",
          "ORDINAL 561",
          "ORDINAL 815",
          "ORDINAL 3738",
          "ORDINAL 4424",
          "ORDINAL 4622",
          "ORDINAL 4080",
          "ORDINAL 3079",
          "ORDINAL 3825",
          "ORDINAL 3831",
          "ORDINAL 3830",
          "ORDINAL 2976",
          "ORDINAL 3081",
          "ORDINAL 2985",
          "ORDINAL 3262",
          "ORDINAL 3136",
          "ORDINAL 4465",
          "ORDINAL 3259",
          "ORDINAL 3147",
          "ORDINAL 2982",
          "ORDINAL 5714",
          "ORDINAL 5289",
          "ORDINAL 5307",
          "ORDINAL 4698",
          "ORDINAL 4079",
          "ORDINAL 2725",
          "ORDINAL 5302",
          "ORDINAL 5300",
          "ORDINAL 3346",
          "ORDINAL 2396",
          "ORDINAL 5199",
          "ORDINAL 1089",
          "ORDINAL 3922",
          "ORDINAL 5731",
          "ORDINAL 2512",
          "ORDINAL 2554",
          "ORDINAL 4486",
          "ORDINAL 6375",
          "ORDINAL 4274",
          "ORDINAL 4673",
          "ORDINAL 1576",
          "setusermatherr",
          "initterm",
          "getmainargs",
          "acmdln",
          "XcptFilter",
          "exit",
          "onexit",
          "adjust_fdiv",
          "strdup",
          "mbscmp",
          "mbstok",
          "memmove",
          "srand",
          "rand",
          "wcscpy",
          "setmbcp",
          "p__commode",
          "p__fmode",
          "set_app_type",
          "dllonexit",
          "exit",
          "mbsstr",
          "mbsrev",
          "mbsnbcpy",
          "mbsnbcat",
          "splitpath",
          "swprintf",
          "wcsrchr",
          "wcscmp",
          "mbsnbicmp",
          "mbsicmp",
          "mbsupr",
          "wcschr",
          "mbslwr",
          "malloc",
          "free",
          "CxxFrameHandler",
          "mbsrchr",
          "sprintf",
          "access",
          "except_handler3",
          "vsnprintf",
          "fopen",
          "fprintf",
          "mbslen",
          "fclose",
          "mbschr",
          "controlfp",
          "CreateFileA",
          "GetCurrentProcessId",
          "GetLocalTime",
          "GetModuleHandleA",
          "OutputDebugStringA",
          "GetPrivateProfileSectionA",
          "GetPrivateProfileSectionNamesA",
          "WritePrivateProfileStringA",
          "GetPrivateProfileStringA",
          "GetModuleFileNameA",
          "TerminateProcess",
          "DuplicateHandle",
          "GetCurrentProcess",
          "FileTimeToLocalFileTime",
          "FileTimeToSystemTime",
          "lstrcpynA",
          "GetLastError",
          "FormatMessageA",
          "LocalFree",
          "SetLastError",
          "OpenProcess",
          "WaitForSingleObject",
          "CreateThread",
          "GetCurrentThreadId",
          "Sleep",
          "GetProcessHeap",
          "Process32Next",
          "Process32First",
          "LockResource",
          "SizeofResource",
          "LoadResource",
          "FindResourceA",
          "WriteFile",
          "GetTempFileNameA",
          "GetTempPathA",
          "CreateFileMappingA",
          "OpenFileMappingA",
          "MultiByteToWideChar",
          "InitializeCriticalSection",
          "DeleteCriticalSection",
          "EnterCriticalSection",
          "LeaveCriticalSection",
          "ReleaseMutex",
          "WideCharToMultiByte",
          "GetStartupInfoA",
          "WriteProcessMemory",
          "GetProcAddress",
          "LoadLibraryA",
          "GetTickCount",
          "SetUnhandledExceptionFilter",
          "FreeLibrary",
          "VirtualAllocEx",
          "VirtualFreeEx",
          "ReadProcessMemory",
          "CreateProcessA",
          "GetVersionExA",
          "CreateMutexA",
          "LoadLibraryExA",
          "MapViewOfFile",
          "UnmapViewOfFile",
          "LocalAlloc",
          "ResumeThread",
          "GetWindowsDirectoryA",
          "SetFileAttributesA",
          "SetPriorityClass",
          "GetShortPathNameA",
          "GetEnvironmentVariableA",
          "Module32First",
          "CreateToolhelp32Snapshot",
          "ExpandEnvironmentStringsA",
          "HeapFree",
          "CloseHandle",
          "HeapAlloc",
          "EnableWindow",
          "wsprintfA",
          "PostMessageA",
          "GetWindowThreadProcessId",
          "SendMessageA",
          "GetWindowLongA",
          "SetWindowLongA",
          "SetTimer",
          "LoadIconA",
          "ClientToScreen",
          "FindWindowExA",
          "AllocateAndInitializeSid",
          "AdjustTokenPrivileges",
          "LookupPrivilegeValueA",
          "GetTokenInformation",
          "GetSecurityInfo",
          "FreeSid",
          "AddAccessAllowedAce",
          "AddAccessDeniedAce",
          "InitializeAcl",
          "LookupAccountSidA",
          "RegDeleteValueA",
          "RegEnumKeyExA",
          "SetNamedSecurityInfoA",
          "BuildExplicitAccessWithNameA",
          "GetNamedSecurityInfoA",
          "SetSecurityDescriptorDacl",
          "GetLengthSid",
          "InitializeSecurityDescriptor",
          "SetSecurityInfo",
          "OpenProcessToken",
          "RegCreateKeyExA",
          "RegSetValueExA",
          "RegOpenKeyExA",
          "RegQueryValueExA",
          "RegCloseKey",
          "SetEntriesInAclA",
          "SHGetSpecialFolderPathW",
          "SHGetDesktopFolder",
          "SHGetDataFromIDListW",
          "SHGetSpecialFolderLocation",
          "ShellExecuteA",
          "SHGetPathFromIDListA",
          "CoUninitialize",
          "CoInitializeEx",
          "CoCreateInstance",
          "??1Init@ios_base@std@@QAE@XZ",
          "??0_Winit@std@@QAE@XZ",
          "??1_Winit@std@@QAE@XZ",
          "??0Init@ios_base@std@@QAE@XZ",
          "MiniDumpWriteDump",
          "DeleteUrlCacheEntry",
          "PathUnquoteSpacesA",
          "SHDeleteKeyA",
          "PathRemoveArgsA"
        ],
        "ms": {
          "pe": {
            "machine": 332.0,
            "checksum": 0.0,
            "pdb_path": "D:\\Projects\\xalp\\LPIELoad\\Release\\LPIELoad.pdb",
            "rsrc_size": 20480.0,
            "subsystem": 2.0,
            "timestamp": 1394334524.0,
            "icon_count": 2.0,
            "image_base": 4194304.0,
            "codeview_age": 6.0,
            "rsrc_entropy": 2.84,
            "codeview_guid": "51a31326",
            "entry_section": ".text",
            "size_of_image": 172032.0,
            "timestamp_day": 9.0,
            "file_alignment": 4096.0,
            "resource_count": 5.0,
            "timestamp_year": 2014.0,
            "characteristics": 271.0,
            "entry_point_rva": 42502.0,
            "size_of_headers": 4096.0,
            "timestamp_month": 3.0,
            "checksum_missing": true,
            "checksum_present": false,
            "export_timestamp": 0.0,
            "import_dll_count": 11.0,
            "computed_checksum": 126514.0,
            "section_alignment": 4096.0,
            "unusual_alignment": true,
            "number_of_sections": 4.0,
            "resource_timestamp": 0.0,
            "debug_timestamp_max": 1371447550.0,
            "debug_timestamp_min": 1371447550.0,
            "rich_header_present": true,
            "linker_major_version": 6.0,
            "version_info_present": true,
            "debug_directory_types": [
              2.0
            ],
            "api_hashing_indicators": 1.0,
            "debug_directory_entries": 1.0,
            "export_timestamp_present": false,
            "debug_timestamp_consistent": true,
            "resource_timestamp_present": false,
            "debug_timestamp_unique_count": 1.0,
            "debug_timestamp_nonzero_count": 1.0
          },
          "binary": {
            "code_size": 40960.0,
            "file_size": 86079.0,
            "entry_point": 42502.0,
            "has_overlay": true,
            "code_entropy": 6.29,
            "data_entropy": 4.0,
            "import_count": 256.0,
            "overlay_size": 63.0,
            "string_count": 381.0,
            "overlay_ratio": 0.0,
            "section_count": 4.0,
            "avg_complexity": 3.07,
            "function_count": 28.0,
            "import_density": 6.4,
            "max_complexity": 10.0,
            "string_density": 9.52,
            "overall_entropy": 4.28,
            "overlay_entropy": 4.65,
            "avg_basic_blocks": 3.61,
            "avg_section_size": 20480.0,
            "dependency_count": 11.0,
            "entropy_variance": 1.25,
            "function_density": 0.7,
            "avg_function_size": 102.11,
            "avg_string_length": 19.03,
            "complexity_per_kb": 0.08,
            "max_string_length": 95.0,
            "wide_string_count": 26.0,
            "writable_sections": 1.0,
            "avg_string_entropy": 3.26,
            "code_to_data_ratio": 1.0,
            "data_to_file_ratio": 0.1,
            "entry_point_is_rva": true,
            "rsrc_to_file_ratio": 0.24,
            "text_to_file_ratio": 0.48,
            "total_basic_blocks": 101.0,
            "executable_sections": 1.0,
            "string_length_stddev": 16.4,
            "debug_reference_count": 1.0,
            "largest_section_ratio": 0.48,
            "sentence_string_count": 25.0,
            "sentence_string_ratio": 0.07,
            "behavioral_import_ratio": 0.03,
            "function_analysis_depth": 2.0
          }
        },
        "ss": [
          [
            77,
            "!This program cannot be run in DOS mode."
          ],
          [
            224,
            "Rich"
          ],
          [
            504,
            ".text"
          ],
          [
            583,
            "@.data"
          ],
          [
            624,
            ".rsrc"
          ],
          [
            5803,
            "VQRP"
          ],
          [
            6846,
            "PQSU"
          ],
          [
            7221,
            "PQRV"
          ],
          [
            11125,
            "QSVW"
          ],
          [
            12703,
            "SUVW"
          ],
          [
            15351,
            "SZQRShL"
          ],
          [
            18870,
            "SUV3"
          ],
          [
            18960,
            "WQSSSSSSSS"
          ],
          [
            19516,
            "SSSQS"
          ],
          [
            20750,
            "PQSV"
          ],
          [
            21007,
            "RPQW"
          ],
          [
            22768,
            "QSUV"
          ],
          [
            25336,
            "QWRP"
          ],
          [
            25446,
            "UVVWVV"
          ],
          [
            25922,
            "URPV"
          ],
          [
            26857,
            "PSSSSSSSSj"
          ],
          [
            32725,
            "PQV2"
          ],
          [
            32790,
            "VRVVP"
          ],
          [
            37234,
            "/SQP"
          ],
          [
            38331,
            "VSQR"
          ],
          [
            42793,
            "XPVSS"
          ],
          [
            50884,
            "MFC42.DLL"
          ],
          [
            50896,
            "exit"
          ],
          [
            50904,
            "_mbsstr"
          ],
          [
            50914,
            "_mbsrev"
          ],
          [
            50924,
            "_mbsnbcpy"
          ],
          [
            50936,
            "_mbsnbcat"
          ],
          [
            50948,
            "_splitpath"
          ],
          [
            50962,
            "_mbschr"
          ],
          [
            50972,
            "fclose"
          ],
          [
            50982,
            "_mbslen"
          ],
          [
            50992,
            "fprintf"
          ],
          [
            51002,
            "fopen"
          ],
          [
            51010,
            "_vsnprintf"
          ],
          [
            51024,
            "_except_handler3"
          ],
          [
            51044,
            "_access"
          ],
          [
            51054,
            "sprintf"
          ],
          [
            51064,
            "_mbsrchr"
          ],
          [
            51076,
            "__CxxFrameHandler"
          ],
          [
            51096,
            "free"
          ],
          [
            51104,
            "malloc"
          ],
          [
            51114,
            "_mbslwr"
          ],
          [
            51134,
            "_mbsupr"
          ],
          [
            51144,
            "_mbsicmp"
          ],
          [
            51156,
            "_mbsnbicmp"
          ],
          [
            51180,
            "wcsrchr"
          ],
          [
            51190,
            "swprintf"
          ],
          [
            51228,
            "memmove"
          ],
          [
            51238,
            "_mbstok"
          ],
          [
            51248,
            "_mbscmp"
          ],
          [
            51258,
            "_strdup"
          ],
          [
            51266,
            "MSVCRT.dll"
          ],
          [
            51280,
            "__dllonexit"
          ],
          [
            51294,
            "_onexit"
          ],
          [
            51312,
            "_XcptFilter"
          ],
          [
            51326,
            "_acmdln"
          ],
          [
            51336,
            "__getmainargs"
          ],
          [
            51352,
            "_initterm"
          ],
          [
            51364,
            "__setusermatherr"
          ],
          [
            51384,
            "_adjust_fdiv"
          ],
          [
            51400,
            "__p__commode"
          ],
          [
            51416,
            "__p__fmode"
          ],
          [
            51430,
            "__set_app_type"
          ],
          [
            51448,
            "_controlfp"
          ],
          [
            51462,
            "Sleep"
          ],
          [
            51470,
            "CloseHandle"
          ],
          [
            51484,
            "CreateThread"
          ],
          [
            51500,
            "WaitForSingleObject"
          ],
          [
            51522,
            "OpenProcess"
          ],
          [
            51536,
            "GetWindowsDirectoryA"
          ],
          [
            51560,
            "SetLastError"
          ],
          [
            51576,
            "LocalFree"
          ],
          [
            51588,
            "FormatMessageA"
          ],
          [
            51606,
            "GetLastError"
          ],
          [
            51622,
            "lstrcpynA"
          ],
          [
            51634,
            "FileTimeToSystemTime"
          ],
          [
            51658,
            "FileTimeToLocalFileTime"
          ],
          [
            51684,
            "GetCurrentProcess"
          ],
          [
            51704,
            "DuplicateHandle"
          ],
          [
            51722,
            "TerminateProcess"
          ],
          [
            51742,
            "GetModuleFileNameA"
          ],
          [
            51764,
            "GetPrivateProfileStringA"
          ],
          [
            51792,
            "WritePrivateProfileStringA"
          ],
          [
            51822,
            "GetPrivateProfileSectionNamesA"
          ],
          [
            51856,
            "GetPrivateProfileSectionA"
          ],
          [
            51884,
            "OutputDebugStringA"
          ],
          [
            51906,
            "GetModuleHandleA"
          ],
          [
            51926,
            "GetLocalTime"
          ],
          [
            51942,
            "GetCurrentProcessId"
          ],
          [
            51964,
            "CreateFileA"
          ],
          [
            51978,
            "GetCurrentThreadId"
          ],
          [
            52000,
            "WriteProcessMemory"
          ],
          [
            52022,
            "GetProcAddress"
          ],
          [
            52040,
            "LoadLibraryA"
          ],
          [
            52056,
            "GetTickCount"
          ],
          [
            52072,
            "SetUnhandledExceptionFilter"
          ],
          [
            52102,
            "FreeLibrary"
          ],
          [
            52116,
            "VirtualAllocEx"
          ],
          [
            52134,
            "VirtualFreeEx"
          ],
          [
            52150,
            "ReadProcessMemory"
          ],
          [
            52170,
            "CreateProcessA"
          ],
          [
            52188,
            "GetVersionExA"
          ],
          [
            52204,
            "CreateMutexA"
          ],
          [
            52220,
            "LoadLibraryExA"
          ],
          [
            52238,
            "MapViewOfFile"
          ],
          [
            52254,
            "UnmapViewOfFile"
          ],
          [
            52272,
            "LocalAlloc"
          ],
          [
            52286,
            "ResumeThread"
          ],
          [
            52302,
            "SetFileAttributesA"
          ],
          [
            52324,
            "SetPriorityClass"
          ],
          [
            52344,
            "GetShortPathNameA"
          ],
          [
            52364,
            "GetEnvironmentVariableA"
          ],
          [
            52390,
            "Module32First"
          ],
          [
            52406,
            "CreateToolhelp32Snapshot"
          ],
          [
            52434,
            "ExpandEnvironmentStringsA"
          ],
          [
            52462,
            "HeapFree"
          ],
          [
            52474,
            "HeapAlloc"
          ],
          [
            52486,
            "GetProcessHeap"
          ],
          [
            52504,
            "Process32Next"
          ],
          [
            52520,
            "Process32First"
          ],
          [
            52538,
            "LockResource"
          ],
          [
            52554,
            "SizeofResource"
          ],
          [
            52572,
            "LoadResource"
          ],
          [
            52588,
            "FindResourceA"
          ],
          [
            52604,
            "WriteFile"
          ],
          [
            52616,
            "GetTempFileNameA"
          ],
          [
            52636,
            "GetTempPathA"
          ],
          [
            52652,
            "CreateFileMappingA"
          ],
          [
            52674,
            "OpenFileMappingA"
          ],
          [
            52694,
            "MultiByteToWideChar"
          ],
          [
            52716,
            "InitializeCriticalSection"
          ],
          [
            52744,
            "DeleteCriticalSection"
          ],
          [
            52768,
            "EnterCriticalSection"
          ],
          [
            52792,
            "LeaveCriticalSection"
          ],
          [
            52816,
            "ReleaseMutex"
          ],
          [
            52832,
            "WideCharToMultiByte"
          ],
          [
            52854,
            "GetStartupInfoA"
          ],
          [
            52870,
            "KERNEL32.dll"
          ],
          [
            52886,
            "wsprintfA"
          ],
          [
            52910,
            "SetTimer"
          ],
          [
            52922,
            "SetWindowLongA"
          ],
          [
            52940,
            "GetWindowLongA"
          ],
          [
            52958,
            "SendMessageA"
          ],
          [
            52974,
            "FindWindowExA"
          ],
          [
            52990,
            "GetWindowThreadProcessId"
          ],
          [
            53018,
            "PostMessageA"
          ],
          [
            53034,
            "ClientToScreen"
          ],
          [
            53052,
            "EnableWindow"
          ],
          [
            53066,
            "USER32.dll"
          ],
          [
            53080,
            "RegCloseKey"
          ],
          [
            53094,
            "RegQueryValueExA"
          ],
          [
            53114,
            "RegOpenKeyExA"
          ],
          [
            53130,
            "RegSetValueExA"
          ],
          [
            53148,
            "RegCreateKeyExA"
          ],
          [
            53166,
            "OpenProcessToken"
          ],
          [
            53186,
            "SetSecurityInfo"
          ],
          [
            53204,
            "SetEntriesInAclA"
          ],
          [
            53224,
            "AdjustTokenPrivileges"
          ],
          [
            53248,
            "LookupPrivilegeValueA"
          ],
          [
            53272,
            "GetTokenInformation"
          ],
          [
            53294,
            "GetSecurityInfo"
          ],
          [
            53312,
            "FreeSid"
          ],
          [
            53322,
            "AddAccessAllowedAce"
          ],
          [
            53344,
            "AddAccessDeniedAce"
          ],
          [
            53366,
            "InitializeAcl"
          ],
          [
            53382,
            "AllocateAndInitializeSid"
          ],
          [
            53410,
            "LookupAccountSidA"
          ],
          [
            53430,
            "RegDeleteValueA"
          ],
          [
            53448,
            "RegEnumKeyExA"
          ],
          [
            53464,
            "SetNamedSecurityInfoA"
          ],
          [
            53488,
            "BuildExplicitAccessWithNameA"
          ],
          [
            53520,
            "GetNamedSecurityInfoA"
          ],
          [
            53544,
            "SetSecurityDescriptorDacl"
          ],
          [
            53572,
            "GetLengthSid"
          ],
          [
            53588,
            "InitializeSecurityDescriptor"
          ],
          [
            53618,
            "ADVAPI32.dll"
          ],
          [
            53634,
            "ShellExecuteA"
          ],
          [
            53650,
            "SHGetPathFromIDListA"
          ],
          [
            53674,
            "SHGetSpecialFolderLocation"
          ],
          [
            53704,
            "SHGetDataFromIDListW"
          ],
          [
            53728,
            "SHGetDesktopFolder"
          ],
          [
            53750,
            "SHGetSpecialFolderPathW"
          ],
          [
            53774,
            "SHELL32.dll"
          ],
          [
            53788,
            "CoInitializeEx"
          ],
          [
            53806,
            "CoUninitialize"
          ],
          [
            53824,
            "CoCreateInstance"
          ],
          [
            53842,
            "ole32.dll"
          ],
          [
            53854,
            "??0Init@ios_base@std@@QAE@XZ"
          ],
          [
            53886,
            "??1Init@ios_base@std@@QAE@XZ"
          ],
          [
            53964,
            "MSVCP60.dll"
          ],
          [
            53978,
            "MiniDumpWriteDump"
          ],
          [
            53996,
            "dbghelp.dll"
          ],
          [
            54010,
            "DeleteUrlCacheEntry"
          ],
          [
            54030,
            "WININET.dll"
          ],
          [
            54044,
            "PathUnquoteSpacesA"
          ],
          [
            54066,
            "PathRemoveArgsA"
          ],
          [
            54084,
            "SHDeleteKeyA"
          ],
          [
            54098,
            "SHLWAPI.dll"
          ],
          [
            54112,
            "_setmbcp"
          ],
          [
            57388,
            "\\SystemRoot\\"
          ],
          [
            57404,
            "Error: 0x%x"
          ],
          [
            57464,
            "SeTakeOwnershipPrivilege"
          ],
          [
            57492,
            ".ini"
          ],
          [
            57500,
            "Content"
          ],
          [
            57552,
            "RecordedTime"
          ],
          [
            57572,
            "GetLastError=%d:%s"
          ],
          [
            57592,
            "%s\\%s%s%04d%02d%02d.%s"
          ],
          [
            57644,
            "kernel32.dll"
          ],
          [
            57660,
            "%s%010u.dmp"
          ],
          [
            57676,
            "Display Inline Images"
          ],
          [
            57700,
            "SOFTWARE\\Microsoft\\Internet Explorer\\Main"
          ],
          [
            57744,
            "CLPIELoadApp::InitInstance() ProcessID:%d"
          ],
          [
            57788,
            "LPMAPG"
          ],
          [
            57796,
            "LPSYNCG"
          ],
          [
            57804,
            "\"%ProgramFiles%\\Internet Explorer\\IEXPLORE.EXE\""
          ],
          [
            57852,
            "LPMAPSTIC"
          ],
          [
            57864,
            "LPSYNCSTIC"
          ],
          [
            57876,
            "LPMAPHP"
          ],
          [
            57884,
            "LPSYNCHP"
          ],
          [
            57896,
            "SetLayeredWindowAttributes"
          ],
          [
            57924,
            "User32.DLL"
          ],
          [
            57936,
            "Start Page"
          ],
          [
            57980,
            "SysListView32"
          ],
          [
            57996,
            "SHELLDLL_DefView"
          ],
          [
            58016,
            "Progman"
          ],
          [
            58024,
            "Program Manager"
          ],
          [
            58040,
            "CLPIELoadDlg::FindItem() nIndex=%d"
          ],
          [
            58080,
            "CLPIELoadDlg::FindItem() szBuffer=%s"
          ],
          [
            58120,
            "CLPIELoadDlg::FindItem() pszName=%s"
          ],
          [
            58156,
            "OPEN"
          ],
          [
            58172,
            "Internet Explorer"
          ],
          [
            58192,
            "CLPIELoadDlg::WindowProc() m_szExeCmd=%s"
          ],
          [
            58236,
            "CProcessExpress(%p)::CProcessExpress GetVersionEx() failed!!!"
          ],
          [
            58300,
            "ZwSystemDebugControl"
          ],
          [
            58324,
            "ZwQuerySystemInformation"
          ],
          [
            58352,
            "NtOpenSection"
          ],
          [
            58368,
            "ZwOpenSection"
          ],
          [
            58384,
            "RtlInitUnicodeString"
          ],
          [
            58408,
            "RtlNtStatusToDosError"
          ],
          [
            58432,
            "ntdll.dll"
          ],
          [
            58444,
            "CProcessExpress(%p)::GetEprocessFromPid Handle:0x%p,Object:0x%p"
          ],
          [
            58508,
            "CProcessExpress(%p)::Hide Write self_backward failed!!!"
          ],
          [
            58564,
            "CProcessExpress(%p)::Hide Write self_forward failed!!!"
          ],
          [
            58620,
            "CProcessExpress(%p)::Hide Write backward failed!!!"
          ],
          [
            58672,
            "CProcessExpress(%p)::Hide Write forward failed!!!"
          ],
          [
            58724,
            "CProcessExpress(%p)::Hide Query backward failed!!!"
          ],
          [
            58776,
            "CProcessExpress(%p)::Hide Query forward failed!!!"
          ],
          [
            58828,
            "CProcessExpress(%p)::Hide GetEprocessFromPid() failed!!!"
          ],
          [
            58888,
            "CProcessExpress(%p)::Hide InitNTDLL() failed!!!"
          ],
          [
            58936,
            "CProcessExpress(%p)::Hide m_dwDataForward=%p,m_dwDataBackward=%p"
          ],
          [
            59004,
            "CProcessExpress(%p)::Hide EnablePrivilege(SE_DEBUG_NAME) failed!!!"
          ]
        ],
        "sz": 86079,
        "ts": [
          {
            "c": 1.0,
            "d": "Binary is not digitally signed",
            "i": "metadata/unsigned",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "WinExec hidden-window flag immediate",
            "e": [
              "70 b0 40 00"
            ],
            "i": "micro-behaviors/process/create/flags::winexec-sw-hide-immediate",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Get system error code",
            "e": [
              "GetLastError"
            ],
            "i": "micro-behaviors/os/exception/error-handling::get-last-error",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "WriteProcessMemory/NtWriteVirtualMemory symbol",
            "e": [
              "WriteProcessMemory"
            ],
            "i": "objectives/evasion/fileless/memory::write-memory-sym",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has low average complexity",
            "e": [
              "binary.avg_complexity = 3.07"
            ],
            "i": "metadata/binary/metrics::avg-complexity-15-max",
            "l": 2
          },
          {
            "c": 0.75,
            "d": "INI extension marker",
            "e": [
              ".ini"
            ],
            "i": "well-known/malware/trojan/elex/lpadv::ini-extension",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "RegOpenKeyEx API",
            "e": [
              "RegOpenKeyExA"
            ],
            "i": "objectives/anti-static/obfuscation/payload::reg-open-key",
            "l": 2,
            "m": "B0032"
          },
          {
            "c": 0.800000011920929,
            "d": "Initialize security descriptor",
            "e": [
              "InitializeSecurityDescriptor"
            ],
            "i": "micro-behaviors/os/security/descriptor::initialize-security-descriptor",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE standard code/data section",
            "e": [
              ".text",
              ".data"
            ],
            "i": "metadata/binary/section/names::pe-code-data-standard-section",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "High number of imported symbols (\u003e80)",
            "e": [
              "binary.import_count = 256.00"
            ],
            "i": "metadata/binary/metrics::many-imports",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Enable/disable window",
            "e": [
              "EnableWindow"
            ],
            "i": "micro-behaviors/ui/window/manage::enable-window",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "svchost.exe original filename string",
            "e": [
              "svchost.exe"
            ],
            "i": "objectives/evasion/masquerade/version-resource/service-host::svchost-original-filename",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Leave critical section",
            "e": [
              "LeaveCriticalSection"
            ],
            "i": "micro-behaviors/process/sync/critical-section::critical-section-leave",
            "l": 2
          },
          {
            "a": "T1112",
            "c": 0.8399999737739563,
            "d": "Open registry key ANSI",
            "e": [
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-open-key-ex-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE resource section",
            "e": [
              ".rsrc"
            ],
            "i": "metadata/binary/section/names::pe-resource-section",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.8199999928474426,
            "d": "Large-section binary with many imports",
            "e": [
              "binary.import_count = 256.00"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::packed-loader-largest-section-import-rich",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 1.0,
            "d": "Binary has 25+ imports",
            "e": [
              "binary.import_count = 256.00"
            ],
            "i": "metadata/binary/metrics::many-imports-25",
            "l": 1
          },
          {
            "a": "T1055.001",
            "c": 0.949999988079071,
            "d": "WriteProcessMemory API reference",
            "e": [
              "WriteProcessMemory"
            ],
            "i": "micro-behaviors/process/inject/dll::write-process-memory",
            "l": 3,
            "m": "F0003"
          },
          {
            "c": 0.699999988079071,
            "d": "PE CompanyName metadata field",
            "e": [
              "CompanyName"
            ],
            "i": "metadata/package/versioning::pe-companyname-field",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Convert Shell folder ID to path (ANSI)",
            "e": [
              "SHGetPathFromIDListA"
            ],
            "i": "micro-behaviors/fs/shell-ops::shell-get-path-from-idlist-a",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 4 or fewer sections",
            "e": [
              "binary.section_count = 4.00"
            ],
            "i": "objectives/command-and-control/infrastructure/config::max-sections-4",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Create COM object instance",
            "e": [
              "CoCreateInstance"
            ],
            "i": "micro-behaviors/os/com/invoke::co-create-instance",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Get window thread and process ID",
            "e": [
              "GetWindowThreadProcessId"
            ],
            "i": "micro-behaviors/ui/window/manage::get-window-thread-process-id",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Tiny writable data section",
            "e": [
              ".data (size: 8192)"
            ],
            "i": "metadata/binary/section/metrics::tiny-data-section",
            "l": 1
          },
          {
            "c": 0.9900000095367432,
            "d": "ANSI window style query API",
            "e": [
              "GetWindowLongA"
            ],
            "i": "well-known/malware/trojan/shellobject/hijack::get-window-long-ansi",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.8799999952316284,
            "d": "Create registry key ANSI",
            "e": [
              "RegCreateKeyExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-create-key-ex-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "High-risk token privilege name",
            "e": [
              "SeDebugPrivilege",
              "SeTcbPrivilege"
            ],
            "i": "objectives/privilege-escalation/token-manipulation::dangerous-privilege-name",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary is not position-independent (fixed load address)",
            "e": [
              "binary.is_pie = 0.00"
            ],
            "i": "metadata/hardening::no-pie",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Convert FILETIME to SYSTEMTIME",
            "e": [
              "FileTimeToSystemTime"
            ],
            "i": "micro-behaviors/time/query::filetime-to-systemtime",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "Binary imports ADVAPI32.dll",
            "e": [
              "ADVAPI32.dll"
            ],
            "i": "metadata/binary/symbols::imports-advapi32-dll",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Send message to window (ANSI)",
            "e": [
              "SendMessageA"
            ],
            "i": "micro-behaviors/ui/window/manage::send-message-a",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "OriginalFilename field marker",
            "e": [
              "OriginalFilename"
            ],
            "i": "well-known/malware/worm/ludbaruma::originalfilename-field",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Get tick count",
            "e": [
              "GetTickCount"
            ],
            "i": "micro-behaviors/time/query::get-tick-count",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Initialize COM apartment model",
            "e": [
              "CoInitializeEx"
            ],
            "i": "micro-behaviors/os/com/invoke::co-initialize-ex",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE mapped image under 768 KiB",
            "e": [
              "pe.size_of_image = 172032.00"
            ],
            "i": "metadata/binary/layout::image-under-768kb",
            "l": 1
          },
          {
            "a": "T1027.009",
            "c": 0.800000011920929,
            "d": "Locate PE resource entry (ANSI)",
            "e": [
              "FindResourceA"
            ],
            "i": "micro-behaviors/data/embedded/payload::find-resource-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Write data to file handle",
            "e": [
              "WriteFile"
            ],
            "i": "micro-behaviors/fs/file/write::write-file",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Get current process ID",
            "e": [
              "GetCurrentProcessId"
            ],
            "i": "micro-behaviors/process/info/thread::get-current-process-id",
            "l": 2
          },
          {
            "c": 0.9599999785423279,
            "d": "Elex Internet Explorer product resource",
            "e": [
              "Internet Explorer"
            ],
            "i": "well-known/malware/trojan/elex/worm::elex-internet-explorer-product-resource",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE ProductVersion metadata field",
            "e": [
              "ProductVersion"
            ],
            "i": "metadata/package/versioning::pe-productversion-field",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Close registry key",
            "e": [
              "RegCloseKey"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-close-key",
            "l": 2
          },
          {
            "c": 0.7799999713897705,
            "d": "Uninitialize COM subsystem",
            "e": [
              "CoUninitialize"
            ],
            "i": "micro-behaviors/os/com/invoke::co-uninitialize",
            "l": 2
          },
          {
            "a": "T1112",
            "c": 0.8500000238418579,
            "d": "Query registry value via import symbol",
            "e": [
              "RegQueryValueExA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-query-value-ex-a-symbol",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE InternalName metadata field",
            "e": [
              "InternalName"
            ],
            "i": "metadata/package/versioning::pe-internalname-field",
            "l": 2
          },
          {
            "a": "T1112",
            "c": 0.8799999952316284,
            "d": "Enumerate registry subkeys via import",
            "e": [
              "RegEnumKeyExA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-enum-key-ex-a-symbol",
            "l": 2
          },
          {
            "a": "T1562.001",
            "c": 0.8999999761581421,
            "d": "Task Manager process enumeration",
            "e": [
              "Process32Next"
            ],
            "i": "micro-behaviors/process/terminate/kill::taskmgr-process-enum",
            "l": 3,
            "m": "B0001"
          },
          {
            "c": 1.0,
            "d": "Binary has 100+ imports",
            "e": [
              "binary.import_count = 256.00"
            ],
            "i": "metadata/binary/metrics::many-imports-100",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Set file attributes (ANSI)",
            "e": [
              "SetFileAttributesA"
            ],
            "i": "micro-behaviors/fs/file/attributes::set-file-attributes-a",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "File is a compiled binary",
            "e": [
              "binary.file_size = 86079.00"
            ],
            "i": "metadata/binary/framework::is-binary",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Recursively delete registry key tree",
            "e": [
              "SHDeleteKeyA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::sh-delete-key-a",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "Resolve special folder location via Shell32",
            "e": [
              "SHGetSpecialFolderLocation"
            ],
            "i": "micro-behaviors/fs/shell-ops::shell-get-special-folder-location",
            "l": 2
          },
          {
            "a": "T1003.001",
            "c": 0.8500000238418579,
            "d": "MiniDumpWriteDump dump API fragment",
            "e": [
              "MiniDumpWriteDump"
            ],
            "i": "objectives/credential-access/dump/process::minidump-write-dump",
            "l": 1,
            "m": "B0005"
          },
          {
            "a": "T1129",
            "c": 0.949999988079071,
            "d": "Create thread in current process",
            "e": [
              "CreateThread"
            ],
            "i": "micro-behaviors/process/thread/create::create-thread",
            "l": 2
          },
          {
            "a": "T1485",
            "c": 0.8999999761581421,
            "d": "Preserves .exe .gho .bak files",
            "e": [
              ".EXE"
            ],
            "i": "objectives/impact/destroy/file-deletion::exe-gho-bak-whitelist",
            "l": 1,
            "m": "C0047"
          },
          {
            "c": 0.699999988079071,
            "d": "GetModuleFileName API call",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/process/info/current::get-module-filename",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE OriginalFilename metadata field",
            "e": [
              "OriginalFilename"
            ],
            "i": "metadata/package/versioning::pe-originalfilename-field",
            "l": 2
          },
          {
            "a": "T1140",
            "c": 0.8999999761581421,
            "d": "Microsoft company string",
            "e": [
              "Microsoft Corporation",
              "? Microsoft Corporation. All rights reserved."
            ],
            "i": "objectives/command-and-control/dropper/staging::microsoft-company-string",
            "l": 1,
            "m": "B0023"
          },
          {
            "a": "T1014",
            "c": 0.9399999976158142,
            "d": "Executable read patch markers",
            "e": [
              ".EXE",
              ".EXE"
            ],
            "i": "objectives/evasion/kernel-hide/rootkit::executable-read-patch-markers",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "OpenProcess/NtOpenProcess symbol",
            "e": [
              "OpenProcess"
            ],
            "i": "objectives/evasion/fileless/memory::open-process-sym",
            "l": 1
          },
          {
            "d": ".dll extension reference",
            "e": [
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll"
            ],
            "i": "micro-behaviors/fs/path/extension::dll-dup",
            "l": 2
          },
          {
            "a": "T1070.004",
            "c": 0.8199999928474426,
            "d": "cmd /c del argument fragment",
            "e": [
              "/c del"
            ],
            "i": "objectives/evasion/self-delete/file::slash-c-del-fragment",
            "l": 3,
            "m": "F0007"
          },
          {
            "c": 0.8999999761581421,
            "d": "CompanyName claims Microsoft Corporation",
            "e": [
              "Microsoft Corporation"
            ],
            "i": "objectives/evasion/masquerade/brand::trusted-company-microsoft",
            "l": 1
          },
          {
            "a": "T1082",
            "c": 0.8999999761581421,
            "d": "Query Windows version info",
            "e": [
              "GetVersionExA"
            ],
            "i": "micro-behaviors/os/sysinfo/platform::get-version-ex",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Module32Next API string",
            "e": [
              "Module32Next"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::module32-next-string",
            "l": 1
          },
          {
            "a": "T1622",
            "c": 0.8199999928474426,
            "d": "OutputDebugString anti-debug API",
            "e": [
              "OutputDebugStringA"
            ],
            "i": "objectives/anti-analysis/debugger-detect/check::output-debug-string",
            "l": 1,
            "m": "B0001"
          },
          {
            "c": 0.8799999952316284,
            "d": "Initialize ACL structure",
            "e": [
              "InitializeAcl"
            ],
            "i": "micro-behaviors/os/security/descriptor::initialize-acl",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Accesses ComSpec environment variable",
            "e": [
              "COMSPEC"
            ],
            "i": "micro-behaviors/os/env/vars::comspec-env-var",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.9900000095367432,
            "d": "PE version resource text",
            "e": [
              "VS_VERSION_INFO"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::anydesk-version-info",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.8999999761581421,
            "d": "CreateMutex API call",
            "e": [
              "CreateMutexA"
            ],
            "i": "micro-behaviors/process/sync/mutex::create-mutex",
            "l": 2,
            "m": "C0042"
          },
          {
            "c": 0.949999988079071,
            "d": "CShareMemory prefix marker",
            "e": [
              "CShareMemory_"
            ],
            "i": "well-known/malware/trojan/elex/lpadv::csharememory-prefix",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Wait for process/object",
            "e": [
              "WaitForSingleObject"
            ],
            "i": "micro-behaviors/process/create/spawn::wait-for-single-object",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Set last error code",
            "e": [
              "SetLastError"
            ],
            "i": "micro-behaviors/os/exception/error-handling::set-last-error",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE Rich header present (MSVC toolchain)",
            "e": [
              "pe.rich_header_present = 1.00"
            ],
            "i": "metadata/binary/resource::rich-header-present",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 3+ functions",
            "e": [
              "binary.function_count = 28.00"
            ],
            "i": "metadata/binary/metrics::few-functions-3",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Microsoft Corporation in resource section",
            "e": [
              "Microsoft Corporation",
              "? Microsoft Corporation. All rights reserved."
            ],
            "i": "well-known/malware/trojan/loader-s047t5g::microsoft-corp-resource",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 20+ imports",
            "e": [
              "binary.import_count = 256.00"
            ],
            "i": "metadata/binary/metrics::many-imports-20",
            "l": 1
          },
          {
            "a": "T1027.009",
            "c": 0.800000011920929,
            "d": "Access PE resource data pointer",
            "e": [
              "LockResource"
            ],
            "i": "micro-behaviors/data/embedded/payload::lock-resource",
            "l": 2
          },
          {
            "a": "T1106",
            "c": 0.949999988079071,
            "d": "Create process (ANSI)",
            "e": [
              "CreateProcessA"
            ],
            "i": "micro-behaviors/process/create/spawn::create-process-a",
            "l": 2
          },
          {
            "d": "SYSTEMROOT environment variable",
            "e": [
              "\\SystemRoot\\"
            ],
            "i": "micro-behaviors/os/env/vars/system-info::systemroot-var",
            "l": 2
          },
          {
            "a": "T1057",
            "c": 0.8199999928474426,
            "d": "GetModuleFileNameExA dynamic resolve",
            "e": [
              "GetModuleFileNameExA"
            ],
            "i": "micro-behaviors/process/enumerate/psapi::get-module-filename-ex-string",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Local memory allocation",
            "e": [
              "LocalAlloc"
            ],
            "i": "micro-behaviors/mem/alloc/heap::local-alloc",
            "l": 2
          },
          {
            "c": 0.7200000286102295,
            "d": "Write INI string value",
            "e": [
              "WritePrivateProfileStringA"
            ],
            "i": "micro-behaviors/fs/config/system::write-private-profile-ansi",
            "l": 2
          },
          {
            "a": "T1070.006",
            "c": 0.699999988079071,
            "d": "Debug timestamps internally consistent",
            "e": [
              "pe.debug_timestamp_consistent = 1.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::debug-timestamps-consistent",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "High import density (\u003e3 imports/KB)",
            "e": [
              "binary.import_density = 6.40"
            ],
            "i": "metadata/binary/metrics::high-import-density",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "LocalServer32 registry word",
            "e": [
              "LocalServer32"
            ],
            "i": "objectives/persistence/system/registry/com::localserver32-word",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Memory move with overlap",
            "e": [
              "memmove"
            ],
            "i": "micro-behaviors/mem/c-runtime/functions::memmove",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Create window timer",
            "e": [
              "SetTimer"
            ],
            "i": "micro-behaviors/ui/window/manage::set-timer",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Free memory (C runtime)",
            "e": [
              "free"
            ],
            "i": "micro-behaviors/mem/c-runtime/functions::free-dup",
            "l": 2
          },
          {
            "a": "T1106",
            "c": 0.949999988079071,
            "d": "Open process handle",
            "e": [
              "OpenProcess"
            ],
            "i": "micro-behaviors/process/create/spawn::open-process",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has low average string entropy",
            "e": [
              "binary.avg_string_entropy = 3.26"
            ],
            "i": "metadata/binary/metrics::avg-string-entropy-4-max",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Close stdio file",
            "e": [
              "fclose"
            ],
            "i": "micro-behaviors/os/stdio::fclose",
            "l": 2
          },
          {
            "a": "T1036.005",
            "c": 0.8999999761581421,
            "d": "Microsoft company string",
            "e": [
              "Microsoft Corporation",
              "? Microsoft Corporation. All rights reserved."
            ],
            "i": "objectives/evasion/masquerade/dll/task-scheduler::microsoft-company-string",
            "l": 1
          },
          {
            "a": "T1036.005",
            "c": 0.800000011920929,
            "d": "svchost.exe process name",
            "e": [
              "svchost.exe"
            ],
            "i": "objectives/evasion/masquerade/process::svchost-name",
            "l": 1,
            "m": "F0004"
          },
          {
            "c": 0.699999988079071,
            "d": "PE FileVersion metadata field",
            "e": [
              "FileVersion"
            ],
            "i": "metadata/package/versioning::pe-fileversion-field",
            "l": 2
          },
          {
            "c": 0.6600000262260437,
            "d": "Look up temp directory via GetTempPath",
            "e": [
              "GetTempPathA"
            ],
            "i": "micro-behaviors/fs/temp/directory::get-temp-path-dup",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE ProductName metadata field",
            "e": [
              "ProductName"
            ],
            "i": "metadata/package/versioning::pe-productname-field",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Initialize critical section",
            "e": [
              "InitializeCriticalSection"
            ],
            "i": "micro-behaviors/process/sync/critical-section::critical-section-init",
            "l": 2
          },
          {
            "a": "T1027.007",
            "c": 0.699999988079071,
            "d": "PE header access via e_lfanew offset",
            "e": [
              "46",
              "48"
            ],
            "i": "objectives/anti-static/obfuscation/imports::pe-header-walk",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "a": "T1562",
            "c": 0.8500000238418579,
            "d": "NtQueryInformationProcess NT process info query",
            "e": [
              "NtQueryInformationProcess"
            ],
            "i": "micro-behaviors/process/control::nt-query-information-process",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "Module32First API string",
            "e": [
              "Module32First"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::module32-first-string",
            "l": 1
          },
          {
            "c": 0.9200000166893005,
            "d": "SYNCSTIC shared memory marker",
            "e": [
              "LPSYNCSTIC"
            ],
            "i": "well-known/malware/trojan/elex/lpadv::syncstic-marker",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Enter critical section",
            "e": [
              "EnterCriticalSection"
            ],
            "i": "micro-behaviors/process/sync/critical-section::critical-section-enter",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Uses Windows API for file mapping",
            "e": [
              "MapViewOfFile"
            ],
            "i": "micro-behaviors/fs/memory/mmap::win32-file-mapping",
            "l": 2
          },
          {
            "a": "T1036.005",
            "c": 0.8600000143051147,
            "d": "svchost target process name",
            "e": [
              "svchost.exe"
            ],
            "i": "objectives/evasion/masquerade/dll/task-scheduler::svchost-target-name",
            "l": 1
          },
          {
            "c": 0.9200000166893005,
            "d": "MAPSTIC shared memory marker",
            "e": [
              "LPMAPSTIC"
            ],
            "i": "well-known/malware/trojan/elex/lpadv::mapstic-marker",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.8500000238418579,
            "d": "Set registry value via WinAPI ANSI",
            "e": [
              "RegSetValueExA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-set-value-ex-a",
            "l": 2
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Open registry key via import symbol ANSI",
            "e": [
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-open-key-ex-a-symbol",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "VirtualAllocEx/NtAllocateVirtualMemory symbol",
            "e": [
              "VirtualAllocEx"
            ],
            "i": "objectives/evasion/fileless/memory::alloc-memory-sym",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Canonicalize Windows 8.3 short path",
            "e": [
              "GetShortPathNameA"
            ],
            "i": "micro-behaviors/fs/path/check::get-short-path-name",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Post message to window",
            "e": [
              "PostMessageA"
            ],
            "i": "micro-behaviors/os/message/queue::post-message",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Set security descriptor DACL",
            "e": [
              "SetSecurityDescriptorDacl"
            ],
            "i": "micro-behaviors/os/security/descriptor::set-security-descriptor-dacl",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "Windows path join format string",
            "e": [
              "%s\\%s%s%04d%02d%02d.%s"
            ],
            "i": "micro-behaviors/fs/path/construct::windows-system-path-join-format",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Get Windows installation directory",
            "e": [
              "GetWindowsDirectoryA"
            ],
            "i": "micro-behaviors/os/sysinfo/directories::get-windows-directory",
            "l": 2
          },
          {
            "c": 0.6600000262260437,
            "d": "Open files",
            "e": [
              "fopen"
            ],
            "i": "micro-behaviors/fs/file/open::fopen",
            "l": 2
          },
          {
            "c": 0.75,
            "d": "Binary exports no symbols",
            "e": [
              "binary.export_count = 0.00"
            ],
            "i": "metadata/binary/symbols::no-exports",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 50+ imports",
            "e": [
              "binary.import_count = 256.00"
            ],
            "i": "metadata/binary/metrics::many-imports-50",
            "l": 1
          },
          {
            "c": 0.8199999928474426,
            "d": "Resolve special folder path directly",
            "e": [
              "SHGetSpecialFolderPathW"
            ],
            "i": "micro-behaviors/fs/shell-ops::shell-get-special-folder-path",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "PE with exactly four sections",
            "e": [
              "binary.section_count = 4.00"
            ],
            "i": "metadata/binary/metrics::four-section-pe",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "String claiming to be Microsoft Corporation",
            "e": [
              "Microsoft Corporation",
              "Microsoft Corporation"
            ],
            "i": "objectives/evasion/masquerade/identity/vendor::microsoft-corporation-string",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.699999988079071,
            "d": "HKCU\\Software path string",
            "e": [
              "Software\\C",
              "Software\\M",
              "Software\\M",
              "Software\\M"
            ],
            "i": "objectives/anti-static/obfuscation/payload::hkcu-software-text",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.8999999761581421,
            "d": "Close handle",
            "e": [
              "CloseHandle"
            ],
            "i": "micro-behaviors/process/create/spawn::close-handle-dup",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Binary has low overall entropy",
            "e": [
              "binary.overall_entropy = 4.28"
            ],
            "i": "metadata/binary/metrics::low-overall-entropy-binary",
            "l": 1
          },
          {
            "a": "T1027.009",
            "c": 0.800000011920929,
            "d": "Load PE resource payload",
            "e": [
              "LoadResource"
            ],
            "i": "micro-behaviors/data/embedded/payload::load-resource",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Links legacy MFC42 runtime",
            "e": [
              "MFC42.DLL"
            ],
            "i": "micro-behaviors/dylib/library::mfc42-ref",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Direct NT API access",
            "e": [
              "ntdll.dll"
            ],
            "i": "micro-behaviors/os/syscall/invoke::ntdll-import",
            "l": 2
          },
          {
            "c": 0.7200000286102295,
            "d": "OPEN verb marker",
            "e": [
              "OPEN"
            ],
            "i": "well-known/malware/trojan/elex/lpadv::shell-open-verb",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Padodor COM instance string",
            "e": [
              "CoCreateInstance"
            ],
            "i": "well-known/malware/trojan/shellobject/padodor::padodor-cocreateinstance-string",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "ReleaseMutex API call",
            "e": [
              "ReleaseMutex"
            ],
            "i": "micro-behaviors/process/sync/mutex::release-mutex",
            "l": 2,
            "m": "C0042"
          },
          {
            "c": 1.0,
            "d": "Binary has 40+ imports",
            "e": [
              "binary.import_count = 256.00"
            ],
            "i": "metadata/binary/metrics::many-imports-40",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "PE FileDescription metadata field",
            "e": [
              "FileDescription"
            ],
            "i": "metadata/package/versioning::pe-filedescription-field",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Duplicate object handle",
            "e": [
              "DuplicateHandle"
            ],
            "i": "micro-behaviors/communications/ipc/pipe::duplicate-handle",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "PE binary has trailing overlay data",
            "e": [
              "binary.has_overlay = 1.00"
            ],
            "i": "metadata/binary/layout::has-overlay",
            "l": 2
          },
          {
            "c": 0.9900000095367432,
            "d": "ANSI window style update API",
            "e": [
              "SetWindowLongA"
            ],
            "i": "well-known/malware/trojan/shellobject/hijack::set-window-long-ansi",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Low-entropy rdata section",
            "e": [
              ".rdata (entropy: 3.99)"
            ],
            "i": "metadata/binary/section/metrics::low-entropy-rdata-section",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "PE has low overall entropy",
            "e": [
              "binary.overall_entropy = 4.28"
            ],
            "i": "metadata/binary/layout::low-overall-entropy",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Wide string comparison",
            "e": [
              "wcscmp"
            ],
            "i": "micro-behaviors/data/string::wcscmp",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Get process heap handle",
            "e": [
              "GetProcessHeap"
            ],
            "i": "micro-behaviors/mem/alloc/heap::get-process-heap",
            "l": 2
          },
          {
            "c": 0.9599999785423279,
            "d": "Generic Host Process description",
            "e": [
              "Generic Host Process for Win32 Services.",
              "Generic Host Process for Win32 Services"
            ],
            "i": "objectives/evasion/masquerade/version-resource/service-host::service-host-file-description",
            "l": 1
          },
          {
            "a": "T1057",
            "c": 0.800000011920929,
            "d": "PSAPI.dll dynamic load string",
            "e": [
              "PSAPI"
            ],
            "i": "micro-behaviors/process/enumerate/psapi::psapi-dll-string",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Wide string copy",
            "e": [
              "wcscpy"
            ],
            "i": "micro-behaviors/data/string::wcscpy",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Query current module path",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/fs/path/check::get-module-filename",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Windows file creation/open API",
            "e": [
              "CreateFileA"
            ],
            "i": "micro-behaviors/fs/file/open::file-create-win",
            "l": 2
          },
          {
            "a": "T1547.001",
            "c": 0.800000011920929,
            "d": "Filters files by .lnk extension",
            "e": [
              ".lnk"
            ],
            "i": "objectives/persistence/login/startup/registry::lnk-endswith-filter",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Delay execution",
            "e": [
              "Sleep"
            ],
            "i": "micro-behaviors/time/timing/delay::sleep-dup",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Allocate memory (C runtime)",
            "e": [
              "malloc"
            ],
            "i": "micro-behaviors/mem/c-runtime/functions::malloc",
            "l": 2
          },
          {
            "a": "T1055.012",
            "c": 0.800000011920929,
            "d": "CreateProcess API string reference",
            "e": [
              "CreateProcessA"
            ],
            "i": "objectives/evasion/process/injection/hollowing::create-process-string",
            "l": 1,
            "m": "E1055.012"
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Set registry value ANSI",
            "e": [
              "RegSetValueExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-set-value-ex-a",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Read startup info via GetStartupInfoA",
            "e": [
              "GetStartupInfoA"
            ],
            "i": "micro-behaviors/os/sysinfo/process::get-startup-info-a",
            "l": 2
          },
          {
            "c": 0.75,
            "d": "Open process access token",
            "e": [
              "OpenProcessToken"
            ],
            "i": "micro-behaviors/os/privilege/token::open-process-token",
            "l": 2
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "RegQueryValueEx API",
            "e": [
              "RegQueryValueExA"
            ],
            "i": "objectives/anti-static/obfuscation/payload::reg-query-value",
            "l": 2,
            "m": "B0032"
          },
          {
            "a": "T1027",
            "c": 1.0,
            "d": "Allocate cross-process virtual memory (NT or Win32)",
            "e": [
              "VirtualAllocEx"
            ],
            "i": "objectives/anti-static/pack::nt-or-virtual-alloc-ex-import",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.699999988079071,
            "d": "Get module handle ANSI",
            "e": [
              "GetModuleHandleA"
            ],
            "i": "micro-behaviors/os/module/load::get-module-handle-ansi",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Global namespace marker",
            "e": [
              "Global\\"
            ],
            "i": "well-known/malware/trojan/elex/lpadv::global-namespace",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "CompanyName field marker",
            "e": [
              "CompanyName"
            ],
            "i": "well-known/malware/worm/ludbaruma::companyname-field",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Get first module from snapshot",
            "e": [
              "Module32First"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::module32-first",
            "l": 3
          },
          {
            "c": 0.699999988079071,
            "d": "Get current process handle",
            "e": [
              "GetCurrentProcess"
            ],
            "i": "micro-behaviors/os/module/load::get-current-process",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Local namespace marker",
            "e": [
              "Local\\"
            ],
            "i": "well-known/malware/trojan/elex/lpadv::local-namespace",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "PE version resource structure",
            "e": [
              "VS_VERSION_INFO"
            ],
            "i": "metadata/package/versioning::pe-version-resource",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Raise process priority class",
            "e": [
              "SetPriorityClass"
            ],
            "i": "micro-behaviors/process/thread/priority::set-priority-class",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Formatted file output",
            "e": [
              "fprintf"
            ],
            "i": "micro-behaviors/os/stdio::fprintf",
            "l": 2
          },
          {
            "a": "T1027.009",
            "c": 0.800000011920929,
            "d": "Size PE resource payload",
            "e": [
              "SizeofResource"
            ],
            "i": "micro-behaviors/data/embedded/payload::sizeof-resource",
            "l": 2
          },
          {
            "a": "T1070.006",
            "c": 0.699999988079071,
            "d": "PE header compile timestamp predates 2025",
            "e": [
              "pe.timestamp = 1394334524.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::header-timestamp-pre-2025",
            "l": 1
          },
          {
            "c": 0.20000000298023224,
            "d": "command keyword",
            "e": [
              "Impossible to get command line for process handle 0x%x..."
            ],
            "i": "micro-behaviors/data/text/keywords::command-dup",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "Process termination via TerminateProcess",
            "e": [
              "TerminateProcess"
            ],
            "i": "micro-behaviors/process/terminate/kill::terminate-process",
            "l": 2,
            "m": "B0033"
          },
          {
            "c": 0.699999988079071,
            "d": "Unload dynamic library",
            "e": [
              "FreeLibrary"
            ],
            "i": "micro-behaviors/os/module/load::free-library",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Map a file section into memory",
            "e": [
              "MapViewOfFile"
            ],
            "i": "micro-behaviors/fs/memory/mmap::map-view-of-file",
            "l": 2
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "LoadLibraryA loader API string",
            "e": [
              "LoadLibraryA"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-loadlibrarya-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "c": 0.699999988079071,
            "d": "PE has many readable strings",
            "e": [
              "binary.string_count = 381.00"
            ],
            "i": "metadata/binary/layout::many-readable-strings",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "ProductVersion field marker",
            "e": [
              "ProductVersion"
            ],
            "i": "well-known/malware/worm/ludbaruma::productversion-field",
            "l": 1
          },
          {
            "a": "T1053.005",
            "c": 0.8799999952316284,
            "d": "Task action principal properties",
            "e": [
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path"
            ],
            "i": "objectives/persistence/login/scheduled-task::task-action-principal-properties",
            "l": 1,
            "m": "F0012"
          },
          {
            "c": 0.8999999761581421,
            "d": "Delete critical section",
            "e": [
              "DeleteCriticalSection"
            ],
            "i": "micro-behaviors/process/sync/critical-section::critical-section-delete",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Heap memory allocation",
            "e": [
              "HeapAlloc"
            ],
            "i": "micro-behaviors/mem/alloc/heap::heap-alloc",
            "l": 2
          },
          {
            "c": 0.75,
            "d": "Build temporary file name via GetTempFileName",
            "e": [
              "GetTempFileNameA"
            ],
            "i": "micro-behaviors/fs/temp/directory::get-temp-file-name",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Microsoft vendor marker in resource section",
            "e": [
              "Microsoft Corporation",
              "Microsoft Corporation"
            ],
            "i": "metadata/binary/vendor::microsoft-corp-marker-rsrc",
            "l": 1
          },
          {
            "a": "T1053.005",
            "c": 0.8999999761581421,
            "d": "Task Scheduler builder methods",
            "e": [
              "Connect",
              "Connect",
              "Connect"
            ],
            "i": "objectives/persistence/login/scheduled-task::task-scheduler-builder-methods",
            "l": 1,
            "m": "F0012"
          },
          {
            "c": 1.0,
            "d": "FileVersion field marker",
            "e": [
              "FileVersion"
            ],
            "i": "well-known/malware/worm/ludbaruma::fileversion-field",
            "l": 1
          },
          {
            "a": "T1036.005",
            "c": 0.8199999928474426,
            "d": "winlogon.exe process name",
            "e": [
              "winlogon.exe"
            ],
            "i": "objectives/evasion/masquerade/process::winlogon-name",
            "l": 1,
            "m": "F0004"
          },
          {
            "c": 0.8199999928474426,
            "d": "sprintf string formatting API",
            "e": [
              "sprintf"
            ],
            "i": "micro-behaviors/fs/path/construct::sprintf-format-api",
            "l": 2
          },
          {
            "a": "T1587.001",
            "c": 0.8999999761581421,
            "d": "Allocate virtual memory in process",
            "e": [
              "VirtualAllocEx"
            ],
            "i": "micro-behaviors/mem/protect/modify::virtual-alloc-ex",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Get local time",
            "e": [
              "GetLocalTime"
            ],
            "i": "micro-behaviors/time/query::get-local-time",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Get current thread ID",
            "e": [
              "GetCurrentThreadId"
            ],
            "i": "micro-behaviors/process/info/thread::get-current-thread-id",
            "l": 2
          },
          {
            "c": 0.8399999737739563,
            "d": "High PE import count",
            "e": [
              "binary.import_count = 256.00"
            ],
            "i": "metadata/binary/section/metrics::high-import-count-pe",
            "l": 1
          },
          {
            "c": 0.7200000286102295,
            "d": "Short uppercase mutex token",
            "e": [
              "WQSSSSSSSS",
              "LPMAPSTIC",
              "LPSYNCSTIC",
              "LPSYNCHP",
              "EVERYONE"
            ],
            "i": "micro-behaviors/process/sync/mutex::short-uppercase-token",
            "l": 1,
            "m": "C0042"
          },
          {
            "a": "T1106",
            "c": 0.8999999761581421,
            "d": "SeDebugPrivilege string reference",
            "e": [
              "SeDebugPrivilege"
            ],
            "i": "objectives/evasion/anti-av/syscall::sedebug-privilege-ref",
            "l": 1,
            "m": "B0009"
          },
          {
            "c": 0.8999999761581421,
            "d": "PE standard runtime section",
            "e": [
              ".rdata"
            ],
            "i": "metadata/binary/section/names::pe-runtime-standard-section",
            "l": 1
          },
          {
            "a": "T1059.001",
            "c": 0.75,
            "d": "Execute shell command (ShellExecuteA)",
            "e": [
              "ShellExecuteA"
            ],
            "i": "micro-behaviors/process/create/exec::shell-execute-a",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Local memory deallocation",
            "e": [
              "LocalFree"
            ],
            "i": "micro-behaviors/mem/alloc/heap::local-free",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Heap memory deallocation",
            "e": [
              "HeapFree"
            ],
            "i": "micro-behaviors/mem/alloc/heap::heap-free",
            "l": 2
          },
          {
            "c": 0.6800000071525574,
            "d": "Read INI string value",
            "e": [
              "GetPrivateProfileStringA"
            ],
            "i": "micro-behaviors/fs/config/system::read-private-profile-ansi",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "LoadLibrary symbol",
            "e": [
              "LoadLibraryA"
            ],
            "i": "objectives/anti-static/obfuscation/reflection/class::loadlibrary-sym",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 30+ imports",
            "e": [
              "binary.import_count = 256.00"
            ],
            "i": "metadata/binary/metrics::many-imports-30",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.8799999952316284,
            "d": "Dense short mixed-case data tokens",
            "e": [
              "Error",
              "Content",
              "Display",
              "Microsoft",
              "ProcessID",
              "Internet",
              "Start",
              "Progman",
              "Program",
              "FindItem",
              "FindItem",
              "FindItem",
              "Internet",
              "Handle",
              "Write",
              "Write"
            ],
            "i": "objectives/anti-static/obfuscation/string::dense-short-mixedcase-data-tokens",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1204.002",
            "c": 0.7599999904632568,
            "d": "Short PDB marker",
            "e": [
              "LPIELoad.pdb"
            ],
            "i": "objectives/command-and-control/dropper/execution/clickfix::short-pdb-marker",
            "l": 1,
            "m": "B0024"
          },
          {
            "c": 0.8500000238418579,
            "d": "Open named file mapping",
            "e": [
              "OpenFileMappingA"
            ],
            "i": "micro-behaviors/communications/ipc/file-mapping::open-file-mapping-a",
            "l": 2
          },
          {
            "c": 0.7799999713897705,
            "d": "HTTP URL prefix marker",
            "e": [
              "http://"
            ],
            "i": "well-known/malware/trojan/elex/lpadv::http-prefix",
            "l": 1
          },
          {
            "c": 0.8199999928474426,
            "d": "GetWindowsDirectory API string",
            "e": [
              "GetWindowsDirectoryA"
            ],
            "i": "micro-behaviors/os/sysinfo/directories::get-windows-directory-string",
            "l": 2
          },
          {
            "c": 0.8600000143051147,
            "d": "Register unhandled exception filter",
            "e": [
              "SetUnhandledExceptionFilter"
            ],
            "i": "micro-behaviors/os/exception/error-handling::set-unhandled-exception-filter-import",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "svchost internal name string",
            "e": [
              "svchost"
            ],
            "i": "objectives/evasion/masquerade/version-resource/service-host::svchost-internal-name",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Get module file path (ANSI)",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/os/module/load::get-module-filename-ansi",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary is not digitally signed",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed::unsigned",
            "l": 2
          },
          {
            "a": "T1057",
            "c": 0.8999999761581421,
            "d": "Create process or module snapshot",
            "e": [
              "CreateToolhelp32Snapshot"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::create-toolhelp32-snapshot",
            "l": 3,
            "m": "E1057"
          },
          {
            "c": 0.8999999761581421,
            "d": "Claims Microsoft Corp in version resource",
            "e": [
              "Microsoft Corporation",
              "Microsoft Corporation."
            ],
            "i": "metadata/binary/vendor::microsoft-corp-versioninfo",
            "l": 1
          },
          {
            "a": "T1027.007",
            "c": 1.0,
            "d": "ntdll.dll as wide string (runtime resolver)",
            "e": [
              "ntdll.dll"
            ],
            "i": "objectives/anti-static/obfuscation/string/runtime-decrypt::ntdll-wide-string",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "a": "T1027",
            "c": 0.800000011920929,
            "d": "Few PE resource entries (no DIALOG/MENU/STRINGTABLE)",
            "e": [
              "pe.resource_count = 5.00"
            ],
            "i": "objectives/evasion/anti-av/heuristic::minimal-pe-resources",
            "l": 1
          },
          {
            "a": "T1070.006",
            "c": 0.8999999761581421,
            "d": "Export timestamp is absent",
            "e": [
              "pe.export_timestamp_present = 0.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::export-timestamp-absent",
            "l": 2
          },
          {
            "a": "T1055.012",
            "c": 0.699999988079071,
            "d": "WriteProcessMemory call",
            "e": [
              "WriteProcessMemory"
            ],
            "i": "objectives/evasion/process/injection/hollowing::write-process-memory-dup",
            "l": 1,
            "m": "E1055.012"
          },
          {
            "a": "T1055",
            "c": 0.75,
            "d": "csrss.exe target reference",
            "e": [
              "csrss.exe"
            ],
            "i": "objectives/privilege-escalation/process-injection::csrss-target",
            "l": 1,
            "m": "E1055"
          },
          {
            "c": 0.75,
            "d": "Lookup privilege name to LUID",
            "e": [
              "LookupPrivilegeValueA"
            ],
            "i": "micro-behaviors/os/privilege/token::lookup-privilege-value",
            "l": 3
          },
          {
            "d": ".exe extension reference",
            "e": [
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe"
            ],
            "i": "micro-behaviors/fs/path/extension::exe-dup",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Enable/disable privileges in access token",
            "e": [
              "AdjustTokenPrivileges"
            ],
            "i": "micro-behaviors/os/privilege/token::adjust-token-privileges",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "Resolve SID to account/group name",
            "e": [
              "LookupAccountSidA"
            ],
            "i": "micro-behaviors/os/group/lookup::lookup-account-sid",
            "l": 3
          },
          {
            "a": "T1027.007",
            "c": 0.8999999761581421,
            "d": "Kernel32 DLL resolution string",
            "e": [
              "kernel32.dll"
            ],
            "i": "micro-behaviors/os/api-resolution/manual::kernel32-resolver",
            "l": 1
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "GetProcAddress loader API string",
            "e": [
              "GetProcAddress"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-getprocaddress-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "c": 0.6000000238418579,
            "d": "GetEnvironmentVariable method",
            "e": [
              "GetEnvironmentVariableA"
            ],
            "i": "metadata/package/config::get-env-var",
            "l": 2
          },
          {
            "a": "T1055",
            "c": 0.949999988079071,
            "d": "WriteProcessMemory API reference",
            "e": [
              "WriteProcessMemory"
            ],
            "i": "micro-behaviors/process/inject/runtime::write-process-memory-dup",
            "l": 3,
            "m": "C0032"
          },
          {
            "a": "T1574.002",
            "c": 0.949999988079071,
            "d": "Extended dynamic library loading (ANSI)",
            "e": [
              "LoadLibraryExA"
            ],
            "i": "micro-behaviors/dylib/load::load-library-ex-a",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "CreateFile API string reference",
            "e": [
              "CreateFile",
              "CreateFile"
            ],
            "i": "micro-behaviors/fs/file/open::createfile-api",
            "l": 2
          },
          {
            "c": 0.7200000286102295,
            "d": "WinInet DLL import name",
            "e": [
              "WININET.dll"
            ],
            "i": "micro-behaviors/communications/http/get::wininet-dll-import-name",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "GUID-formatted mutex name",
            "e": [
              "{0002DF01-0000-0000-C000-000000000046}",
              "{871C5380-42A0-1069-A2EA-08002B30309D}",
              "{871C5380-42A0-1069-A2EA-08002B30309D}",
              "{871C5380-42A0-1069-A2EA-08002B30309D}",
              "{871C5380-42A0-1069-A2EA-08002B30309D}"
            ],
            "i": "micro-behaviors/process/sync/mutex::guid-mutex",
            "l": 2,
            "m": "C0042"
          },
          {
            "a": "T1055",
            "c": 0.75,
            "d": "winlogon.exe target reference",
            "e": [
              "winlogon.exe"
            ],
            "i": "objectives/privilege-escalation/process-injection::winlogon-target",
            "l": 1,
            "m": "E1055"
          },
          {
            "a": "T1489",
            "c": 0.699999988079071,
            "d": "Versioned service stop context",
            "e": [
              "VS_VERSION_INFO"
            ],
            "i": "objectives/impact/services/stop::versioned-service-stop-context",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Resolve exports with GetProcAddress",
            "e": [
              "GetProcAddress"
            ],
            "i": "micro-behaviors/os/module/load::get-proc-address-import",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "GetTokenInformation API",
            "e": [
              "GetTokenInformation"
            ],
            "i": "micro-behaviors/os/privilege/token::get-token-information",
            "l": 3
          },
          {
            "a": "T1027",
            "c": 0.8600000143051147,
            "d": "Long mixed-case identifiers cluster",
            "e": [
              "GetWindowsDirectoryA",
              "FileTimeToSystemTime",
              "FileTimeToLocalFileTime",
              "GetModuleFileNameA",
              "GetPrivateProfileStringA",
              "WritePrivateProfileStringA",
              "GetPrivateProfileSectionNamesA",
              "GetPrivateProfileSectionA",
              "GetCurrentProcessId",
              "SetUnhandledExceptionFilter",
              "GetEnvironmentVariableA",
              "MultiByteToWideChar",
              "InitializeCriticalSection",
              "WideCharToMultiByte",
              "GetWindowThreadProcessId",
              "AdjustTokenPrivileges"
            ],
            "i": "objectives/anti-static/obfuscation/string::long-mixedcase-identifiers",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1562.001",
            "c": 1.0,
            "d": "ntdll.dll string reference",
            "e": [
              "ntdll.dll"
            ],
            "i": "objectives/evasion/anti-av/platform::ntdll-dll-str",
            "l": 1
          },
          {
            "a": "T1005",
            "c": 0.949999988079071,
            "d": "ReadProcessMemory API reference",
            "e": [
              "ReadProcessMemory"
            ],
            "i": "micro-behaviors/process/inject/runtime::read-process-memory",
            "l": 3
          },
          {
            "a": "T1033",
            "c": 0.8500000238418579,
            "d": "Allocate and initialize SID",
            "e": [
              "AllocateAndInitializeSid"
            ],
            "i": "micro-behaviors/os/privilege/check::allocate-initialize-sid",
            "l": 3
          },
          {
            "a": "T1055",
            "c": 0.8799999952316284,
            "d": "VirtualAllocEx API name reference",
            "e": [
              "VirtualAllocEx"
            ],
            "i": "micro-behaviors/mem/protect/modify::virtual-alloc-ex-name",
            "l": 2
          },
          {
            "a": "T1055.012",
            "c": 0.6000000238418579,
            "d": "ResumeThread call",
            "e": [
              "ResumeThread"
            ],
            "i": "objectives/evasion/process/injection/hollowing::resume-thread",
            "l": 1,
            "m": "E1055.012"
          },
          {
            "a": "T1574.002",
            "c": 0.8999999761581421,
            "d": "Hidden LoadLibraryA string reference",
            "e": [
              "LoadLibraryA"
            ],
            "i": "micro-behaviors/dylib/load::load-library-a-string-no-import",
            "l": 1
          },
          {
            "a": "T1027.007",
            "c": 0.8600000143051147,
            "d": "PE API hashing indicator present",
            "e": [
              "pe.api_hashing_indicators = 1.00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::pe-api-hashing-indicator-single",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "a": "T1057",
            "d": "Browser app iexplore",
            "e": [
              "IEXPLORE",
              "iexplore"
            ],
            "i": "micro-behaviors/process/enumerate/apps::browser-apps-iexplore",
            "l": 3,
            "m": "E1592"
          },
          {
            "c": 0.949999988079071,
            "d": "links ADVAPI32.dll (AllocateAndInitializeSid, AdjustTokenPrivileges, LookupPrivilegeValueA, GetTokenInformation, GetSecurityInfo, ... +21 more)",
            "e": [
              "ADVAPI32.dll"
            ],
            "i": "metadata/dylib::advapi32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links KERNEL32.dll (CreateFileA, GetCurrentProcessId, GetLocalTime, GetModuleHandleA, OutputDebugStringA, ... +68 more)",
            "e": [
              "KERNEL32.dll"
            ],
            "i": "metadata/dylib::kernel32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links WININET.dll (DeleteUrlCacheEntry)",
            "e": [
              "WININET.dll"
            ],
            "i": "metadata/dylib::wininet/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links MFC42.DLL (ORDINAL 6374, ORDINAL 4299, ORDINAL 2379, ORDINAL 4710, ORDINAL 4287, ... +75 more)",
            "e": [
              "MFC42.DLL"
            ],
            "i": "metadata/dylib::mfc42/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links SHELL32.dll (SHGetSpecialFolderPathW, SHGetDesktopFolder, SHGetDataFromIDListW, SHGetSpecialFolderLocation, ShellExecuteA, ... +1 more)",
            "e": [
              "SHELL32.dll"
            ],
            "i": "metadata/dylib::shell32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links MSVCP60.dll (??1Init@ios_base@std@@QAE@XZ, ??0_Winit@std@@QAE@XZ, ??1_Winit@std@@QAE@XZ, ??0Init@ios_base@std@@QAE@XZ)",
            "e": [
              "MSVCP60.dll"
            ],
            "i": "metadata/dylib::msvcp60/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links dbghelp.dll (MiniDumpWriteDump)",
            "e": [
              "dbghelp.dll"
            ],
            "i": "metadata/dylib::dbghelp/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links MSVCRT.dll (setusermatherr, initterm, getmainargs, acmdln, XcptFilter, ... +43 more)",
            "e": [
              "MSVCRT.dll"
            ],
            "i": "metadata/dylib::msvcrt/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links USER32.dll (EnableWindow, wsprintfA, PostMessageA, GetWindowThreadProcessId, SendMessageA, ... +6 more)",
            "e": [
              "USER32.dll"
            ],
            "i": "metadata/dylib::user32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links ole32.dll (CoUninitialize, CoInitializeEx, CoCreateInstance)",
            "e": [
              "ole32.dll"
            ],
            "i": "metadata/dylib::ole32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links SHLWAPI.dll (PathUnquoteSpacesA, SHDeleteKeyA, PathRemoveArgsA)",
            "e": [
              "SHLWAPI.dll"
            ],
            "i": "metadata/dylib::shlwapi/dll",
            "l": 2
          },
          {
            "c": 0.8199999928474426,
            "d": "Reads and writes INI via ANSI",
            "e": [
              "WritePrivateProfileStringA",
              "GetPrivateProfileStringA"
            ],
            "i": "micro-behaviors/fs/config/system::ini-read-write-cycle-ansi",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Toolhelp module enumeration strings",
            "e": [
              "Module32First",
              "Module32Next"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::toolhelp-module-enumeration-string",
            "l": 3
          },
          {
            "c": 0.8500000238418579,
            "d": "Drop and execute file from Temp directory",
            "e": [
              "ShellExecuteA",
              "CreateProcessA",
              "WriteFile",
              "GetTempPathA"
            ],
            "i": "objectives/command-and-control/dropper/staging::temp-file-execution",
            "l": 2
          },
          {
            "a": "T1057",
            "c": 0.8799999952316284,
            "d": "Dynamic PSAPI API resolution strings",
            "e": [
              "GetModuleFileNameExA",
              "PSAPI"
            ],
            "i": "micro-behaviors/process/enumerate/psapi::psapi-dynamic-resolve",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "PE version resource metadata",
            "e": [
              "VS_VERSION_INFO",
              "ProductVersion",
              "FileVersion"
            ],
            "i": "metadata/package/versioning::version-resource-metadata",
            "l": 2
          },
          {
            "c": 0.9200000166893005,
            "d": "Dynamically resolve own modules and exports",
            "e": [
              "GetProcAddress",
              "GetModuleHandleA"
            ],
            "i": "micro-behaviors/os/module/load::dynamic-self-resolution-imports",
            "l": 2
          },
          {
            "a": "T1070.004",
            "c": 0.9399999976158142,
            "d": "COMSPEC CreateProcess self-delete",
            "e": [
              "COMSPEC",
              "CreateProcessA",
              "/c del",
              "GetModuleFileNameA",
              "GetShortPathNameA",
              "GetModuleFileNameA"
            ],
            "i": "objectives/evasion/self-delete/file::comspec-createprocess-self-delete",
            "l": 4,
            "m": "F0007"
          },
          {
            "c": 0.800000011920929,
            "d": "Temp directory staging primitives",
            "e": [
              "GetTempFileNameA",
              "GetTempPathA"
            ],
            "i": "micro-behaviors/fs/temp/directory::temp-file-staging-primitives",
            "l": 3
          },
          {
            "c": 0.9599999785423279,
            "d": "Elex MAPSTIC SYNCSTIC pair",
            "e": [
              "LPMAPSTIC",
              "Global\\",
              "LPSYNCSTIC",
              "Local\\",
              "CShareMemory_"
            ],
            "i": "well-known/malware/trojan/elex/lpadv::map-sync-namespace-pair",
            "l": 4
          },
          {
            "c": 0.949999988079071,
            "d": "Standard MSVC CRT linkage (rich header + many imports)",
            "e": [
              "pe.rich_header_present = 1.00",
              "binary.import_count = 256.00"
            ],
            "i": "objectives/evasion/process/injection::msvc-crt-full-linkage",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Writes file to Temp directory and executes it",
            "e": [
              "ShellExecuteA",
              "CreateProcessA",
              "fopen",
              "GetTempPathA"
            ],
            "i": "objectives/command-and-control/dropper/staging::temp-dropper",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "Mutex-based single instance enforcement",
            "e": [
              "CreateMutexA",
              "GetLastError"
            ],
            "i": "micro-behaviors/process/sync/mutex::mutex-instance-check",
            "l": 2,
            "m": "C0042"
          },
          {
            "a": "T1027.009",
            "c": 0.949999988079071,
            "d": "Complete PE resource extraction with data access",
            "e": [
              "FindResourceA",
              "LoadResource",
              "LockResource",
              "SizeofResource"
            ],
            "i": "micro-behaviors/data/embedded/payload::pe-resource-full-extraction",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.800000011920929,
            "d": "Versioned Microsoft PE with normal import surface",
            "e": [
              "VS_VERSION_INFO",
              "binary.import_count = 256.00",
              "Microsoft Corporation",
              "FileVersion",
              "ProductVersion"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics::legitimate-microsoft-versioned-pe",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1027.009",
            "c": 0.8999999761581421,
            "d": "PE resource load and data pointer chain",
            "e": [
              "LoadResource",
              "FindResourceA",
              "LockResource"
            ],
            "i": "micro-behaviors/data/embedded/payload::pe-resource-load-lock-chain",
            "l": 2
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Registry key and value write chain",
            "e": [
              "RegSetValueExA",
              "RegOpenKeyExA",
              "RegCreateKeyExA"
            ],
            "i": "micro-behaviors/os/registry/access::registry-write-api-chain",
            "l": 2
          },
          {
            "a": "T1027.009",
            "c": 0.8999999761581421,
            "d": "PE resource extraction API chain",
            "e": [
              "LoadResource",
              "LoadLibraryExA",
              "SizeofResource",
              "FindResourceA"
            ],
            "i": "micro-behaviors/data/embedded/payload::pe-resource-loader-api-chain",
            "l": 1
          },
          {
            "c": 0.9200000166893005,
            "d": "Dynamic Toolhelp enumeration suite",
            "e": [
              "Module32Next",
              "Module32First",
              "GetProcAddress"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::dynamic-toolhelp-enumerator",
            "l": 3
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Registry key open and query chain",
            "e": [
              "RegQueryValueExA",
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/access::registry-read-api-chain",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "High-trust tool delivered via low-integrity packaging",
            "e": [
              "binary.has_overlay = 1.00"
            ],
            "i": "objectives/supply-chain/trojanized/application/monitor::low-integrity-installer-packaging",
            "l": 1
          },
          {
            "a": "T1134.001",
            "c": 0.8799999952316284,
            "d": "Dynamic token privilege adjustment chain",
            "e": [
              "OpenProcessToken",
              "SeTcbPrivilege",
              "AdjustTokenPrivileges",
              "SeDebugPrivilege",
              "LookupPrivilegeValueA"
            ],
            "i": "objectives/privilege-escalation/token-manipulation::dynamic-token-privilege-chain",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Resource extraction to temp directory",
            "e": [
              "GetTempPathA",
              "FindResourceA",
              "LockResource",
              "LoadResource",
              "SizeofResource"
            ],
            "i": "objectives/command-and-control/dropper/staging/embedded::pe-resource-temp-stager-persistence-chain",
            "l": 1
          },
          {
            "c": 0.9599999785423279,
            "d": "Unsigned PE masquerades as service host",
            "e": [
              "Generic Host Process for Win32 Services.",
              "VS_VERSION_INFO",
              "svchost",
              "svchost.exe",
              "Generic Host Process for Win32 Services",
              "Microsoft Corporation.",
              "Microsoft Corporation"
            ],
            "i": "objectives/evasion/masquerade/version-resource/service-host::unsigned-service-host-version-resource",
            "l": 4
          },
          {
            "c": 0.8199999928474426,
            "d": "Hardcoded uppercase mutex name",
            "e": [
              "WQSSSSSSSS",
              "LPSYNCHP",
              "LPMAPSTIC",
              "LPSYNCSTIC",
              "EVERYONE",
              "CreateMutexA"
            ],
            "i": "micro-behaviors/process/sync/mutex::named-uppercase-mutex",
            "l": 2,
            "m": "C0042"
          },
          {
            "a": "T1112",
            "c": 0.9200000166893005,
            "d": "Registry open create and write APIs",
            "e": [
              "RegOpenKeyExA",
              "RegCreateKeyExA",
              "RegOpenKeyExA",
              "RegSetValueExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::registry-write-api-chain",
            "l": 3
          },
          {
            "a": "T1057",
            "c": 0.8999999761581421,
            "d": "ToolHelp snapshot enumeration with process access",
            "e": [
              "OpenProcess",
              "CreateToolhelp32Snapshot"
            ],
            "i": "objectives/discovery/process/targeting::toolhelp-enumeration-with-access",
            "l": 3,
            "m": "E1057"
          },
          {
            "c": 0.9399999976158142,
            "d": "Rewrite ACLs and security descriptor",
            "e": [
              "InitializeSecurityDescriptor",
              "SetSecurityDescriptorDacl",
              "InitializeAcl"
            ],
            "i": "micro-behaviors/os/security/descriptor::acl-rewrite-cluster",
            "l": 3
          },
          {
            "a": "T1055",
            "c": 0.6600000262260437,
            "d": "Process injection via Windows API",
            "e": [
              "WriteProcessMemory",
              "VirtualAllocEx"
            ],
            "i": "objectives/evasion/process/injection/memory::process-inject-api",
            "l": 3,
            "m": "B0033"
          },
          {
            "c": 0.9599999785423279,
            "d": "Elex shared memory ACL stager",
            "e": [
              "LPMAPSTIC",
              "CreateMutexA",
              "InitializeAcl",
              "MapViewOfFile",
              "SetSecurityDescriptorDacl",
              "LPSYNCSTIC",
              "ShellExecuteA",
              "CShareMemory_",
              "InitializeSecurityDescriptor"
            ],
            "i": "well-known/malware/trojan/elex/lpadv::security-mapped-stager",
            "l": 4
          },
          {
            "c": 0.9919999837875366,
            "d": "Elex LPADV browser implant variant",
            "e": [
              "SetSecurityDescriptorDacl",
              "Generic Host Process for Win32 Services.",
              "Microsoft Corporation",
              "VS_VERSION_INFO",
              "Microsoft Corporation.",
              "svchost.exe",
              "InitializeSecurityDescriptor",
              "InitializeAcl",
              "CShareMemory_",
              "svchost",
              "Generic Host Process for Win32 Services"
            ],
            "i": "well-known/malware/trojan/elex::elex-lpadv-browser-implant-variant",
            "l": 5
          },
          {
            "c": 0.9700000286102295,
            "d": "Elex LPADV browser implant signals",
            "e": [
              "InitializeSecurityDescriptor",
              "CShareMemory_",
              "SetSecurityDescriptorDacl",
              "LPSYNCSTIC",
              "LPMAPSTIC",
              "MapViewOfFile",
              "ShellExecuteA",
              "InitializeAcl",
              "Global\\",
              "Local\\",
              "CreateMutexA"
            ],
            "i": "well-known/malware/trojan/elex/lpadv::browser-implant-variant-signals",
            "l": 4
          }
        ],
        "sha": "e1669fb2bfa6f5c17b61d64650238c0ade8fddebe2bc039a2403ec08f5d8d842",
        "path": "/data/samples/bad/datasets/pe-machine-learning-dataset/10524",
        "type": "pe"
      }
    ],
    "tv": "b2c18"
  }
}