{
  "ml": {
    "v": "4",
    "fs": [
      {
        "id": 0,
        "prob": 0.9348381161689758,
        "class": 0
      }
    ],
    "prob": 0.9348381,
    "class": 0,
    "version": "v16.16",
    "thresholds": [
      0.9815004,
      0.99404883
    ],
    "analyzed_at": "2026-04-30T06:02:39Z"
  },
  "path": "X509_ACERT_get_attr.3",
  "raw": {
    "v": "4",
    "fs": [
      {
        "f": "O₂(As₂S)Md(Pa)",
        "x": 1,
        "id": 0,
        "ms": {
          "text": {
            "digit_ratio": 0.06,
            "space_count": 511.0,
            "total_lines": 113.0,
            "char_entropy": 5.33,
            "unique_chars": 82.0,
            "string_density": 0.89,
            "ascii_art_lines": 2.0,
            "avg_line_length": 32.84,
            "max_line_length": 106.0,
            "last_line_length": 46.0,
            "most_common_char": "t",
            "whitespace_ratio": 0.16,
            "most_common_ratio": 0.06,
            "identifier_density": 0.61,
            "line_length_stddev": 29.07,
            "normalized_string_count": 9.5,
            "repeated_char_sequences": 5.0,
            "suspicious_string_ratio": 0.02,
            "max_inline_whitespace_run": 32.0,
            "suspicious_identifier_ratio": 0.13,
            "normalized_unique_identifiers": 8.21
          },
          "strings": {
            "total": 101.0,
            "avg_length": 30.11,
            "max_length": 175.0,
            "avg_entropy": 3.0,
            "sql_strings": 1.0,
            "total_bytes": 3041.0,
            "entropy_stddev": 1.31,
            "high_entropy_count": 1.0,
            "shell_command_strings": 1.0
          },
          "comments": {},
          "functions": {},
          "identifiers": {
            "total": 69.0,
            "avg_length": 4.45,
            "max_length": 13.0,
            "min_length": 1.0,
            "avg_entropy": 1.69,
            "reuse_ratio": 0.81,
            "unique_count": 56.0,
            "length_stddev": 2.8,
            "sequential_names": 6.0,
            "single_char_count": 6.0,
            "single_char_ratio": 0.11,
            "all_lowercase_ratio": 0.59,
            "all_uppercase_ratio": 0.09,
            "repeated_char_names": 1.0
          }
        },
        "ss": [
          [
            218,
            " Vertical space (when we can't use .PP)"
          ],
          [
            294,
            " Begin verbatim text"
          ],
          [
            347,
            " End verbatim text"
          ],
          [
            387,
            " and \\*(C' are quotes in nroff, nothing in troff, for use with C\u003c\u003e.\n.ie n \\{\\\n.    ds C"
          ],
          [
            388,
            " and "
          ],
          [
            395,
            "(C' are quotes in nroff, nothing in troff, for use with C\u003c\u003e.\n.ie n "
          ],
          [
            466,
            ".    ds C"
          ],
          [
            489,
            " \"\"\n"
          ],
          [
            490,
            " "
          ],
          [
            517,
            "\n.    ds C'\n'br"
          ],
          [
            534,
            "\n."
          ],
          [
            538,
            "\n."
          ],
          [
            542,
            " Escape single quotes in literal strings from groff's Unicode transform.\n.ie "
          ],
          [
            621,
            "(.g .ds Aq "
          ],
          [
            634,
            "aq\n.el       .ds Aq '\n."
          ],
          [
            659,
            "\n."
          ],
          [
            663,
            " If the F register is \u003e0, we'll generate index entries on stderr for\n."
          ],
          [
            735,
            " titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index\n."
          ],
          [
            810,
            " entries marked with X\u003c\u003e in POD.  Of course, you'll have to process the\n."
          ],
          [
            885,
            " output yourself in some meaningful fashion.\n."
          ],
          [
            933,
            "\n."
          ],
          [
            937,
            " Avoid warning from groff about undefined register 'F'.\n.de IX\n..\n.nr rF 0\n.if "
          ],
          [
            1018,
            "(.g .if rF .nr rF 1\n.if ("
          ],
          [
            1045,
            "(rF:("
          ],
          [
            1052,
            "(.g==0)) "
          ],
          [
            1065,
            ".    if "
          ],
          [
            1075,
            "F "
          ],
          [
            1081,
            ".        de IX\n.        tm Index:"
          ],
          [
            1116,
            "$1"
          ],
          [
            1122,
            "n%"
          ],
          [
            1129,
            "$2\"\n..\n.        if !"
          ],
          [
            1151,
            "F==2 "
          ],
          [
            1160,
            ".            nr % 0\n.            nr F 2\n.        "
          ],
          [
            1211,
            "\n.    "
          ],
          [
            1219,
            "\n."
          ],
          [
            1223,
            "\n.rr rF\n."
          ],
          [
            1234,
            " ========================================================================\n."
          ],
          [
            1311,
            "\n.IX Title \"X509_ACERT_GET_ATTR 3ossl\"\n.TH X509_ACERT_GET_ATTR 3ossl 2025-09-30 3.5.4 OpenSSL\n."
          ],
          [
            1408,
            " For nroff, turn off justification.  Always turn off hyphenation; it makes\n."
          ],
          [
            1486,
            " way too many mistakes in technical documents.\n.if n .ad l\n.nh\n.SH NAME\nX509_ACERT_get_attr,\nX509_ACERT_get_attr_by_NID,\nX509_AC"
          ],
          [
            1665,
            " Retrieve attributes from an X509_ACERT structure\n.SH SYNOPSIS\n.IX Header \"SYNOPSIS\"\n.Vb 1\n"
          ],
          [
            1758,
            " #include \u003copenssl/x509_acert.h\u003e\n"
          ],
          [
            1793,
            "\n"
          ],
          [
            1796,
            " X509_ATTRIBUTE *X509_ACERT_get_attr(const X509_ACERT *x, int loc);\n"
          ],
          [
            1866,
            " int X509_ACERT_get_attr_by_NID(const X509_ACERT *x, int nid, int lastpos);\n"
          ],
          [
            1944,
            " int X509_ACERT_get_attr_by_OBJ(const X509_ACERT *x, const ASN1_OBJECT *obj,\n"
          ],
          [
            2023,
            "                                int lastpos);\n"
          ],
          [
            2071,
            " int X509_ACERT_get_attr_count(const X509_ACERT *x);\n.Ve\n.SH DESCRIPTION\n.IX Header \"DESCRIPTION\"\n"
          ],
          [
            2173,
            "BX509_ACERT_get0_attr()"
          ],
          [
            2198,
            "R retrieves the "
          ],
          [
            2216,
            "Iloc"
          ],
          [
            2222,
            "Rth "
          ],
          [
            2228,
            "BX509_ATTRIBUTE"
          ],
          [
            2245,
            "R from an\n"
          ],
          [
            2259,
            "BX509_ACERT"
          ],
          [
            2272,
            "R "
          ],
          [
            2276,
            "Ix"
          ],
          [
            2280,
            "R.  "
          ],
          [
            2286,
            "BX509_ACERT_get_attr_count()"
          ],
          [
            2316,
            "R returns the total number\nof attributes in the "
          ],
          [
            2366,
            "BX509_ACERT"
          ],
          [
            2379,
            "R.\n.PP\n"
          ],
          [
            2390,
            "BX509_ACERT_get_attr_by_NID()"
          ],
          [
            2421,
            "R and "
          ],
          [
            2429,
            "BX509_ACERT_get_attr_by_OBJ()"
          ],
          [
            2460,
            "R retrieve the next\nattribute location matching "
          ],
          [
            2510,
            "Inid"
          ],
          [
            2516,
            "R or "
          ],
          [
            2523,
            "Iobj"
          ],
          [
            2529,
            "R after "
          ],
          [
            2539,
            "Ilastpos"
          ],
          [
            2549,
            "R. "
          ],
          [
            2554,
            "Ilastpos"
          ],
          [
            2564,
            "R\nshould initially be set to "
          ],
          [
            2595,
            "1.\nIf there are no more entries "
          ],
          [
            2629,
            "1 is returned. If "
          ],
          [
            2649,
            "Inid"
          ],
          [
            2655,
            "R is invalid\n(doesn't correspond to a valid OID) then "
          ],
          [
            2711,
            "2 is returned.\n.SH \"RETURN VALUES\"\n.IX Header \"RETURN VALUES\"\n"
          ],
          [
            2777,
            "BX509_ACERT_get0_attr()"
          ],
          [
            2802,
            "R return a "
          ],
          [
            2815,
            "BX509_ATTRIBUTE"
          ],
          [
            2832,
            "R from an attribute\ncertificate, or NULL if the specified attribute is not found.\n.PP\n"
          ],
          [
            2922,
            "BX509_ACERT_get_attr_by_NID()"
          ],
          [
            2953,
            "R and "
          ],
          [
            2961,
            "BX509_ACERT_get_attr_by_OBJ()"
          ],
          [
            2992,
            "R return\nthe location of the next attribute requested or "
          ],
          [
            3051,
            "1 if not found.\n"
          ],
          [
            3071,
            "BX509_ACERT_get_attr_by_NID()"
          ],
          [
            3102,
            "R can also return "
          ],
          [
            3122,
            "2 if the supplied NID is invalid.\n.PP\n"
          ],
          [
            3164,
            "BX509_ACERT_get_attr_count()"
          ],
          [
            3194,
            "R returns the number of attributes in the given\nattribute certificate.\n.SH HISTORY\n.IX Header \"HISTORY\"\n"
          ],
          [
            3302,
            "BX509_ACERT_get0_attr()"
          ],
          [
            3327,
            "R, "
          ],
          [
            3332,
            "BX509_ACERT_get_attr_by_NID()"
          ],
          [
            3363,
            "R, "
          ],
          [
            3368,
            "BX509_ACERT_get_attr_by_OBJ()"
          ],
          [
            3399,
            "R and\n"
          ],
          [
            3409,
            "BX509_ACERT_get_attr_count()"
          ],
          [
            3439,
            "R were added in OpenSSL 3.4.\n.SH COPYRIGHT\n.IX Header \"COPYRIGHT\"\nCopyright 2023"
          ]
        ],
        "sz": 3824,
        "ts": [
          {
            "c": 0.699999988079071,
            "d": "X509_ function prefix",
            "e": [
              "X509_"
            ],
            "i": "micro-behaviors/crypto/certificate/operations::x509-prefix",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "ES6 const/let declarations",
            "e": [
              "const X",
              "const X",
              "const X",
              "const X"
            ],
            "i": "metadata/lang/javascript-features::const-let",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.8999999761581421,
            "d": "Low string density base64 context",
            "e": [
              "text.string_density = 0.89"
            ],
            "i": "objectives/anti-static/obfuscation/code-metrics::js-base64-candidate-low-string-density",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.8999999761581421,
            "d": "Unix manual page or bundled manpage example",
            "e": [
              "X509_ACERT_get_attr.3"
            ],
            "i": "metadata/package/documentation::unix-manpage",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "HISTORY documentation reference",
            "e": [
              "HISTORY"
            ],
            "i": "metadata/package/documentation::references-changelog-history",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Path-like string pattern",
            "e": [
              "x:\\\\$1\\t\\\\n%\\t\"\\\\$2\""
            ],
            "i": "micro-behaviors/data/text/malware::path-like-pattern",
            "l": 2
          },
          {
            "c": 0.20000000298023224,
            "d": "output keyword",
            "e": [
              "output"
            ],
            "i": "micro-behaviors/data/text/keywords::output",
            "l": 1
          },
          {
            "d": "certificate string reference",
            "e": [
              "certificate"
            ],
            "i": "micro-behaviors/crypto/certificate/operations::certificate-ref",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "File has 30 or more lines",
            "e": [
              "text.total_lines = 113.00"
            ],
            "i": "metadata/package/metrics::file-has-30-plus-lines",
            "l": 1
          },
          {
            "c": 0.30000001192092896,
            "d": "stderr string reference",
            "e": [
              " If the F register is \u003e0, we'll generate index entries on stderr for\n."
            ],
            "i": "micro-behaviors/process/fd/stdio::stderr-string",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.6000000238418579,
            "d": "No comments in code",
            "e": [
              "comments.total = 0.00"
            ],
            "i": "objectives/anti-static/obfuscation/code-metrics/structure::no-comments",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1027",
            "c": 0.800000011920929,
            "d": "Sequential identifiers (a, b, c,",
            "e": [
              "identifiers.sequential_names = 6.00"
            ],
            "i": "objectives/anti-static/obfuscation/code-metrics/identifiers::sequential-identifiers",
            "l": 2,
            "m": "B0032"
          },
          {
            "c": 0.699999988079071,
            "d": "Small file under 5KB",
            "e": [
              "X509_ACERT_get_attr.3"
            ],
            "i": "objectives/supply-chain/metadata-anomaly/markers/npm::small-file-5k",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "X.509 certificate handling (legitimate)",
            "e": [
              "certificate",
              "X509_"
            ],
            "i": "micro-behaviors/crypto/certificate/operations::certificate-handling",
            "l": 2
          }
        ],
        "sha": "e21eada1f5bb27e4f050e13f433db7cf4cc357640cdee3f6e2e178157df01b6a",
        "path": "X509_ACERT_get_attr.3",
        "type": "javascript"
      }
    ],
    "tv": "f6eaa"
  }
}