{
  "ml": {
    "v": "4",
    "fs": [
      {
        "id": 0,
        "prob": 0.9815003871917725,
        "class": 1
      }
    ],
    "prob": 0.9815004,
    "class": 1,
    "oprob": 0.94225913,
    "oclass": 0,
    "version": "v16.16",
    "thresholds": [
      0.9815004,
      0.99404883
    ],
    "analyzed_at": "2026-05-01T14:42:32Z"
  },
  "path": "62225",
  "raw": {
    "v": "4",
    "fs": [
      {
        "f": "KO₆(AlAs₉Er₅C₆I₄P₂)H₆(Cm₄F₅Os₄Po₆UDs)Md₅(Bi₅HeSiPa)Th",
        "x": 373,
        "id": 0,
        "is": [
          "WriteConsoleA",
          "GlobalCompact",
          "GlobalFlags",
          "GetBinaryType",
          "OpenSemaphoreW",
          "IsBadHugeReadPtr",
          "SetFileShortNameW",
          "TlsSetValue",
          "PrivMoveFileIdentityW",
          "RegisterConsoleOS2",
          "SetConsoleCommandHistoryMode"
        ],
        "ms": {
          "binary": {
            "code_size": 284160.0,
            "file_size": 328192.0,
            "wx_sections": 3.0,
            "import_count": 11.0,
            "string_count": 746.0,
            "section_count": 5.0,
            "avg_complexity": 6.73,
            "function_count": 81.0,
            "import_density": 0.04,
            "max_complexity": 39.0,
            "string_density": 2.69,
            "overall_entropy": 7.69,
            "avg_basic_blocks": 13.26,
            "avg_section_size": 65433.6,
            "function_density": 0.29,
            "avg_function_size": 3511.25,
            "avg_string_length": 19.63,
            "complexity_per_kb": 0.02,
            "max_string_length": 105.0,
            "writable_sections": 5.0,
            "avg_string_entropy": 3.48,
            "code_section_ratio": 0.6,
            "code_to_data_ratio": 6.61,
            "data_to_file_ratio": 0.13,
            "text_to_file_ratio": 0.04,
            "total_basic_blocks": 1074.0,
            "embedded_file_count": 1.0,
            "executable_sections": 3.0,
            "section_name_entropy": 2.8,
            "string_length_stddev": 15.09,
            "embedded_binary_count": 1.0,
            "largest_section_ratio": 0.76,
            "sentence_string_count": 81.0,
            "sentence_string_ratio": 0.11,
            "function_analysis_depth": 2.0,
            "has_malformed_structure": true,
            "normalized_import_count": 0.02,
            "normalized_section_count": 0.27,
            "nonstandard_section_name_count": 4.0
          }
        },
        "ss": [
          [
            46,
            "xor",
            "User-Agent: Mo"
          ],
          [
            77,
            "!This program cannot be run in DOS mode."
          ],
          [
            160,
            "Rich"
          ],
          [
            424,
            ".text"
          ],
          [
            464,
            ".rdata"
          ],
          [
            504,
            ".data"
          ],
          [
            544,
            ".brdata"
          ],
          [
            1004,
            "xor",
            "User-Agent: Mozilla/_;ފ"
          ],
          [
            1013,
            "xor",
            "User-Agent:KX"
          ],
          [
            14456,
            "KERNEL32.dll"
          ],
          [
            14470,
            "eMWriteConsoleA"
          ],
          [
            14487,
            "nsGlobalCompact"
          ],
          [
            14504,
            "AlGlobalFlags"
          ],
          [
            14521,
            "GetBinaryType"
          ],
          [
            14536,
            "pdOpenSemaphoreW"
          ],
          [
            14554,
            "BaIsBadHugeReadPtr"
          ],
          [
            14574,
            "CoSetFileShortNameW"
          ],
          [
            14595,
            "reTlsSetValue"
          ],
          [
            14610,
            "mDPrivMoveFileIdentityW"
          ],
          [
            14635,
            "euRegisterConsoleOS2"
          ],
          [
            14657,
            "seSetConsoleCommandHistoryMode"
          ],
          [
            23800,
            "/yEz"
          ],
          [
            24359,
            "5ujf"
          ],
          [
            24906,
            "kai8s"
          ],
          [
            30864,
            "306q"
          ],
          [
            31318,
            "SO22"
          ],
          [
            31618,
            "ALT8"
          ],
          [
            32562,
            "OMP7"
          ],
          [
            32892,
            "Y.vv"
          ],
          [
            33522,
            "Yllb"
          ],
          [
            34115,
            "Kywwt"
          ],
          [
            36290,
            "ivox"
          ],
          [
            38990,
            "KS6A"
          ],
          [
            42764,
            "4tqvpi"
          ],
          [
            43261,
            "E96J"
          ],
          [
            43311,
            "2OKX"
          ],
          [
            48052,
            "e2su"
          ],
          [
            50461,
            "O1F1"
          ],
          [
            52005,
            "OI35"
          ],
          [
            52992,
            "12LZ"
          ],
          [
            53041,
            "4b0v"
          ],
          [
            56158,
            "gc7a"
          ],
          [
            58957,
            "Foxy"
          ],
          [
            59370,
            "2YFF"
          ],
          [
            62412,
            "GUZQK"
          ],
          [
            64725,
            "Oxrbf"
          ],
          [
            78685,
            "Crea"
          ],
          [
            78718,
            "Writ"
          ],
          [
            78751,
            "Clos"
          ],
          [
            78824,
            "r.ex"
          ],
          [
            79045,
            "xor",
            "User-Agent: Mo"
          ],
          [
            79047,
            "xor",
            "User-Agent: "
          ],
          [
            79228,
            "xor",
            "TteK@1,ent: Moz"
          ],
          [
            79550,
            "@.data"
          ],
          [
            79591,
            ".rsrc"
          ],
          [
            79630,
            "@.UPX0"
          ],
          [
            80003,
            "xor",
            "User-Agent: Mozilla/\\b"
          ],
          [
            80011,
            "xor",
            "User-Agent: %#"
          ],
          [
            81332,
            "Load"
          ],
          [
            81339,
            "Reso"
          ],
          [
            108032,
            "Enum"
          ],
          [
            113475,
            "ZwQuerySystemInformation"
          ],
          [
            113503,
            "ntdll.dll"
          ],
          [
            113515,
            "KeServiceDescriptorTable"
          ],
          [
            113543,
            "kernel32.dll"
          ],
          [
            113559,
            "FILE"
          ],
          [
            113567,
            "C:\\DelInfo.bin"
          ],
          [
            113583,
            "booter.exe"
          ],
          [
            113595,
            "CONFIG.exe"
          ],
          [
            113607,
            "boottemp.exe"
          ],
          [
            113637,
            "i3qs"
          ],
          [
            113943,
            "Start"
          ],
          [
            113951,
            "www.baidu.com"
          ],
          [
            113967,
            "Parameters"
          ],
          [
            113979,
            "ServiceDll"
          ],
          [
            113991,
            "sfc_os.dll"
          ],
          [
            114003,
            "%s\\system32\\%s.dll"
          ],
          [
            114023,
            "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Svchost"
          ],
          [
            114083,
            "ost.exe"
          ],
          [
            114091,
            "%SystemRoot%\\System32\\svch%s -k nets"
          ],
          [
            114139,
            "www.xunlei.com"
          ],
          [
            114155,
            "www.3-0B6F-415d-B5C7-832F0.com"
          ],
          [
            114199,
            "Wininet.dll"
          ],
          [
            114211,
            "InternetOpenA"
          ],
          [
            114227,
            "InternetOpenUrlA"
          ],
          [
            114247,
            "HttpQueryInfoA"
          ],
          [
            114263,
            "InternetReadFileExA"
          ],
          [
            114283,
            "InternetCloseHandle"
          ],
          [
            114303,
            "InternetSetStatusCallback"
          ],
          [
            114331,
            "http://%s:%d/%s"
          ],
          [
            114347,
            "winsta0"
          ],
          [
            114355,
            "default"
          ],
          [
            114363,
            "Explorer.exe"
          ],
          [
            114379,
            "%s%d.exe"
          ],
          [
            114395,
            "winsta0\\defa"
          ],
          [
            114411,
            "%s%d.nls"
          ],
          [
            114423,
            "cryptcom.dll"
          ],
          [
            114439,
            "DLFT_Shutdown"
          ],
          [
            114455,
            "DLFT_Startup"
          ],
          [
            114471,
            "DLFT_SetTrackerReportCallback"
          ],
          [
            114503,
            "c_30218.nls"
          ],
          [
            114543,
            "GET %s?%s HTTP/1.1\r\nConnection: Keep-Alive\r\nHost: %s\r\nUser-Agent: Mozilla/4.0\r\nAccept-language: cn"
          ],
          [
            114563,
            "Connection: Keep-Alive"
          ],
          [
            114597,
            "User-Agent: Mozilla/4.0"
          ],
          [
            114622,
            "Accept-language: cn"
          ],
          [
            114647,
            "address"
          ],
          [
            114655,
            "ver=%s\u0026tgid=%s\u0026%s=%s"
          ],
          [
            114683,
            "%s%s%s"
          ],
          [
            114699,
            "alexa"
          ],
          [
            114707,
            "%s\u0026flag=%s\u0026%s=0\u0026List=%s"
          ],
          [
            114735,
            "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options"
          ],
          [
            114811,
            "SYSTEM\\CurrentControlSet\\Services"
          ],
          [
            114847,
            "\\Registry\\Machine"
          ],
          [
            114867,
            "\\Internet Explorer\\iexplore.exe"
          ],
          [
            114907,
            "Forter"
          ],
          [
            114915,
            "avp.exe"
          ],
          [
            114923,
            "bdagent.exe"
          ],
          [
            114935,
            "Forter.sys"
          ],
          [
            114959,
            "MmGetSystemRoutineAddress"
          ],
          [
            114999,
            "Thunder Network"
          ],
          [
            115015,
            "Thunder"
          ],
          [
            115031,
            "WindowsUpdate"
          ],
          [
            115047,
            "Windows NT"
          ],
          [
            115059,
            "Windows Media Player"
          ],
          [
            115083,
            "Outlook Express"
          ],
          [
            115099,
            "NetMeeting"
          ],
          [
            115111,
            "MSN Gaming Zone"
          ],
          [
            115127,
            "Movie Maker"
          ],
          [
            115139,
            "microsoft frontpage"
          ],
          [
            115159,
            "Messenger"
          ],
          [
            115171,
            "Internet Explorer"
          ],
          [
            115191,
            "InstallShield Installation Information"
          ],
          [
            115231,
            "ComPlus Applications"
          ],
          [
            115255,
            "Common Files"
          ],
          [
            115271,
            "RECYCLER"
          ],
          [
            115283,
            "System Volume Information"
          ],
          [
            115311,
            "Documents and Settings"
          ],
          [
            115343,
            "WINDOWS"
          ],
          [
            115363,
            "index"
          ],
          [
            115371,
            "Default"
          ],
          [
            115379,
            "%s X -ibck \"%s\" \"%s\\\""
          ],
          [
            115407,
            "%s M -ibck -r -o+ -ep1 \"%s\" \"%s\\*\""
          ],
          [
            115422,
            "xor",
            ":XE_H1VELQI"
          ],
          [
            115479,
            "C:\\Program Files\\WinRAR\\Rar.exe"
          ],
          [
            115519,
            "explorer.exe"
          ],
          [
            115535,
            "open"
          ],
          [
            115543,
            "\\\\.\\pipe\\96DBA249-E88E-4c47-98DC-E18E6E3E3E5A"
          ],
          [
            115591,
            "127.0.0.1       localhost"
          ],
          [
            115619,
            "%s\\drivers\\etc\\hosts"
          ],
          [
            115643,
            "%s\\c_30279.nls"
          ],
          [
            115659,
            "%s%d.txt"
          ],
          [
            115671,
            "SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\Minimal"
          ],
          [
            115723,
            "SYSTEM\\CurrentControlSet\\Control\\SafeBoot\\Network"
          ],
          [
            116439,
            "http://%s/%s"
          ],
          [
            116467,
            "\\\\%s\\pipe%s"
          ],
          [
            116487,
            "Mpr.dll"
          ],
          [
            116495,
            "%s\\desktop.txt"
          ],
          [
            116523,
            "CONFIG"
          ],
          [
            116535,
            "\\\\%s\\%s\\%s.exe"
          ],
          [
            116551,
            "at \\\\%s %d:%d C:\\%s.exe"
          ],
          [
            116575,
            "%d.%d.%d.%d"
          ],
          [
            116587,
            "%sautorun.inf"
          ],
          [
            116603,
            "recycle.{645FF040-5081-101B-9F08-00AA002F954E}"
          ],
          [
            116651,
            "Setup.exe"
          ],
          [
            116663,
            "Show"
          ],
          [
            116687,
            "Kernel32.dll"
          ],
          [
            116703,
            "Thread32First"
          ],
          [
            116719,
            "RSDSLE"
          ],
          [
            116743,
            "C:\\exe.pdb"
          ],
          [
            117761,
            "memcpy"
          ],
          [
            117771,
            "memset"
          ],
          [
            117797,
            "??3@YAXPAX@Z"
          ],
          [
            117813,
            "strrchr"
          ],
          [
            117823,
            "??2@YAPAXI@Z"
          ],
          [
            117839,
            "strlen"
          ],
          [
            117857,
            "MSVCRT.dll"
          ],
          [
            117871,
            "ZwQueryInformationThread"
          ],
          [
            117909,
            "PathFileExistsA"
          ],
          [
            117927,
            "SHDeleteKeyA"
          ],
          [
            117941,
            "SHLWAPI.dll"
          ],
          [
            117955,
            "GetModuleInformation"
          ],
          [
            117977,
            "PSAPI.DLL"
          ],
          [
            117989,
            "freeaddrinfo"
          ],
          [
            118005,
            "getaddrinfo"
          ],
          [
            118019,
            "WSAAddressToStringA"
          ],
          [
            118041,
            "WSAResetEvent"
          ],
          [
            118057,
            "WSACreateEvent"
          ],
          [
            118075,
            "WSARecvFrom"
          ],
          [
            118087,
            "WS2_32.dll"
          ],
          [
            118101,
            "GetAdaptersInfo"
          ],
          [
            118117,
            "IPHLPAPI.DLL"
          ],
          [
            118133,
            "WinVerifyTrust"
          ],
          [
            118149,
            "WINTRUST.dll"
          ],
          [
            118165,
            "WNetCancelConnection2A"
          ],
          [
            118191,
            "WNetAddConnection2A"
          ],
          [
            118213,
            "WNetCloseEnum"
          ],
          [
            118229,
            "WNetOpenEnumA"
          ],
          [
            118243,
            "MPR.dll"
          ],
          [
            118253,
            "UuidToStringA"
          ],
          [
            118269,
            "UuidFromStringA"
          ],
          [
            118285,
            "RPCRT4.dll"
          ],
          [
            118299,
            "CreateFileA"
          ],
          [
            118313,
            "FindResourceA"
          ],
          [
            118329,
            "FreeResource"
          ],
          [
            118345,
            "lstrlenA"
          ],
          [
            118357,
            "FreeLibrary"
          ],
          [
            118371,
            "Process32First"
          ],
          [
            118389,
            "GetTickCount"
          ],
          [
            118405,
            "WriteFile"
          ],
          [
            118417,
            "Sleep"
          ],
          [
            118425,
            "SizeofResource"
          ],
          [
            118443,
            "ReadFile"
          ],
          [
            118455,
            "lstrcmpiA"
          ],
          [
            118467,
            "GetProcAddress"
          ],
          [
            118485,
            "Process32Next"
          ],
          [
            118501,
            "LockResource"
          ],
          [
            118517,
            "GetModuleFileNameA"
          ],
          [
            118539,
            "GetModuleHandleA"
          ],
          [
            118559,
            "LoadLibraryExA"
          ],
          [
            118577,
            "CreateToolhelp32Snapshot"
          ],
          [
            118605,
            "CloseHandle"
          ],
          [
            118619,
            "GetSystemTime"
          ],
          [
            118635,
            "DeleteFileA"
          ],
          [
            118649,
            "lstrcpyA"
          ],
          [
            118661,
            "ExitProcess"
          ],
          [
            118675,
            "GetFileSize"
          ],
          [
            118689,
            "SetFilePointer"
          ],
          [
            118707,
            "VirtualQuery"
          ],
          [
            118723,
            "SetEndOfFile"
          ],
          [
            118739,
            "SetFileTime"
          ],
          [
            118753,
            "GetWindowsDirectoryA"
          ],
          [
            118777,
            "MultiByteToWideChar"
          ],
          [
            118799,
            "LoadLibraryA"
          ],
          [
            118815,
            "GetFileTime"
          ],
          [
            118829,
            "GetCurrentThreadId"
          ],
          [
            118851,
            "GetTempPathA"
          ],
          [
            118867,
            "WaitForSingleObject"
          ],
          [
            118889,
            "SetEvent"
          ],
          [
            118901,
            "CreateEventA"
          ],
          [
            118917,
            "GetLastError"
          ],
          [
            118933,
            "MapViewOfFile"
          ],
          [
            118949,
            "UnmapViewOfFile"
          ],
          [
            118967,
            "OpenProcess"
          ],
          [
            118981,
            "ExitThread"
          ],
          [
            119007,
            "CreateFileMappingA"
          ],
          [
            119029,
            "WinExec"
          ],
          [
            119039,
            "GetVersion"
          ],
          [
            119053,
            "CreateThread"
          ],
          [
            119069,
            "lstrcatA"
          ],
          [
            119081,
            "CreateProcessA"
          ],
          [
            119099,
            "TerminateProcess"
          ],
          [
            119119,
            "GetSystemDirectoryA"
          ],
          [
            119141,
            "DeviceIoControl"
          ],
          [
            119159,
            "lstrcpynA"
          ],
          [
            119171,
            "GetDriveTypeA"
          ],
          [
            119187,
            "GetExitCodeProcess"
          ]
        ],
        "sz": 328192,
        "ts": [
          {
            "a": "T1027",
            "c": 0.800000011920929,
            "d": "PE header too corrupted to parse: Malformed entity: Rich header does not contain the DanS marker",
            "e": [
              "Malformed entity: Rich header does not contain the DanS marker"
            ],
            "i": "objectives/anti-analysis/pe-tampering/corrupted-header",
            "l": 4,
            "m": "B0001"
          },
          {
            "a": "T1027.009",
            "c": 0.8999999761581421,
            "d": "Embedded PE binary at file offset 0x13497 (~262144 bytes)",
            "e": [
              "kind=Pe32 estimated_size=262144"
            ],
            "i": "binary/embedded/pe",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Detects an unspecififed malware - October 2016",
            "e": [
              "%s\\system32\\%s.dll",
              "%SystemRoot%\\System32\\svch%s -k nets",
              "\\\\.\\pipe\\96DBA249-E88E-4c47-98DC-E18E6E3E3E5A",
              "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options",
              "boottemp.exe",
              "at \\\\%s %d:%d C:\\%s.exe",
              "cryptcom.dll",
              "Wininet.dll",
              "\\\\%s\\%s\\%s.exe",
              "%s%d.exe",
              "booter.exe",
              "\\\\%s\\pipe%s",
              "C:\\DelInfo.bin"
            ],
            "i": "third_party/SigBase/Unspecified/Malware/Oct16/A",
            "l": 5
          },
          {
            "d": ".dll extension reference",
            "e": [
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll"
            ],
            "i": "micro-behaviors/fs/path/extension::dll-dup",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Attach thread to desktop",
            "e": [
              "SetThreadDesktop"
            ],
            "i": "micro-behaviors/ui/window/station::set-thread-desktop-import",
            "l": 3
          },
          {
            "a": "T1204.002",
            "c": 0.800000011920929,
            "d": "Writes executable to drive root",
            "e": [
              "C:\\%s.exe"
            ],
            "i": "micro-behaviors/fs/path/location::path-suspicious-root-exe",
            "l": 3,
            "m": "F0013"
          },
          {
            "c": 0.75,
            "d": "HTTP protocol version strings",
            "e": [
              "HTTP/1.1"
            ],
            "i": "micro-behaviors/communications/http/request::http-versions",
            "l": 1
          },
          {
            "c": 0.6000000238418579,
            "d": "System32 substring reference",
            "e": [
              "%SystemRoot%\\System32\\svch%s -k nets"
            ],
            "i": "micro-behaviors/fs/path/system::system32-substr",
            "l": 2
          },
          {
            "a": "T1105",
            "c": 1.0,
            "d": "Binary has high overall entropy",
            "e": [
              "binary.overall_entropy = 7.69"
            ],
            "i": "objectives/command-and-control/dropper/staging::high-entropy-binary",
            "l": 1
          },
          {
            "a": "T1071.001",
            "c": 0.699999988079071,
            "d": "Encoded Mozilla user agent string",
            "e": [
              "User-Agent: Mozilla/_;ފ",
              "User-Agent: Mozilla/\\b",
              "User-Agent: Mozilla/4.0User-Agent",
              "User-Agent: Mozilla/4.0U",
              "User-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4....",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agent: Mozilla/4.3X",
              "User-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.3%",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agemy",
              "User-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0+U",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0Useq ",
              "Sser-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agent: Mozilla,9",
              "User-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0(XfUser-Agent:#@",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agent: Moyd",
              "User-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0+U",
              "5ser-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0(XfUph",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0Useq "
            ],
            "i": "objectives/anti-static/obfuscation/encoding::encoded-mozilla-ua",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "PE standard code/data section",
            "e": [
              ".text",
              ".data"
            ],
            "i": "metadata/binary/section/names::pe-code-data-standard-section",
            "l": 1
          },
          {
            "a": "T1071.001",
            "d": "HTTP header syntax marker",
            "e": [
              "HTTP/1.1\r\nConnection: "
            ],
            "i": "objectives/command-and-control/channel/http/protocol::http-delimiter",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.8799999952316284,
            "d": "Create registry key ANSI",
            "e": [
              "RegCreateKeyExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-create-key-ex-a",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has low average string entropy",
            "e": [
              "binary.avg_string_entropy = 3.48"
            ],
            "i": "metadata/binary/metrics::avg-string-entropy-4-max",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "Binary imports ADVAPI32.dll",
            "e": [
              "ADVAPI32.dll"
            ],
            "i": "metadata/binary/symbols::imports-advapi32-dll",
            "l": 1
          },
          {
            "a": "T1036.005",
            "c": 0.8600000143051147,
            "d": "WindowsUpdate identity token",
            "e": [
              "WindowsUpdate"
            ],
            "i": "objectives/evasion/masquerade/identity/mimicry::windowsupdate-camelcase-token",
            "l": 1
          },
          {
            "a": "T1546.012",
            "c": 0.949999988079071,
            "d": "Full IFEO registry key path",
            "e": [
              "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options"
            ],
            "i": "objectives/persistence/login/ifeo/debugger::ifeo-full-path",
            "l": 1,
            "m": "F0012"
          },
          {
            "c": 0.800000011920929,
            "d": "Multiple embedded MZ headers",
            "e": [
              "4D 5A",
              "4D 5A",
              "4D 5A",
              "4D 5A",
              "4D 5A",
              "4D 5A",
              "4D 5A"
            ],
            "i": "metadata/binary/layout::multiple-pe-embedded-loose",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "Windows path join format string",
            "e": [
              "\\\\%s\\%s\\%s.exe"
            ],
            "i": "micro-behaviors/fs/path/construct::windows-system-path-join-format",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "NCapture launches explorer",
            "e": [
              "explorer.exe"
            ],
            "i": "well-known/app/graphics::ncapture-explorer",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Set registry value ANSI",
            "e": [
              "RegSetValueExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-set-value-ex-a",
            "l": 2
          },
          {
            "a": "T1083",
            "c": 0.8799999952316284,
            "d": "Enumerate logical drive letters",
            "e": [
              "GetLogicalDrives"
            ],
            "i": "micro-behaviors/fs/traversal/drives::get-logical-drives-text",
            "l": 3,
            "m": "E1083"
          },
          {
            "a": "T1112",
            "c": 0.8399999737739563,
            "d": "Open registry key ANSI",
            "e": [
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-open-key-ex-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Valid PE/MZ binary found embedded in file",
            "e": [
              "4D 5A 90 00"
            ],
            "i": "metadata/binary/layout::pe-embedded",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Thread32Next API string",
            "e": [
              "Thread32Next"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::thread32-next-string",
            "l": 1
          },
          {
            "a": "T1565.001",
            "c": 0.8500000238418579,
            "d": "Windows hosts path format string",
            "e": [
              "%s\\drivers\\etc\\hosts"
            ],
            "i": "objectives/evasion/hosts-file/block-security::windows-hosts-template-path",
            "l": 4,
            "m": "F0004"
          },
          {
            "c": 1.0,
            "d": "Binary has low average complexity",
            "e": [
              "binary.avg_complexity = 6.73"
            ],
            "i": "metadata/binary/metrics::avg-complexity-15-max",
            "l": 2
          },
          {
            "a": "T1036.005",
            "c": 0.800000011920929,
            "d": "explorer.exe process name",
            "e": [
              "explorer.exe"
            ],
            "i": "objectives/evasion/masquerade/process::explorer-name",
            "l": 1,
            "m": "F0004"
          },
          {
            "c": 0.8500000238418579,
            "d": "Direct NT API access",
            "e": [
              "ntdll.dll"
            ],
            "i": "micro-behaviors/os/syscall/invoke::ntdll-import",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Uses Windows API for file mapping",
            "e": [
              "MapViewOfFile"
            ],
            "i": "micro-behaviors/fs/memory/mmap::win32-file-mapping",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.699999988079071,
            "d": "Code section dominates file layout",
            "e": [
              "binary.largest_section_ratio = 0.76"
            ],
            "i": "objectives/anti-static/obfuscation/string/anomaly::dominant-text-section",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1485",
            "c": 0.8999999761581421,
            "d": "Preserves .exe .gho .bak files",
            "e": [
              ".exe"
            ],
            "i": "objectives/impact/destroy/file-deletion::exe-gho-bak-whitelist",
            "l": 1,
            "m": "C0047"
          },
          {
            "c": 0.8999999761581421,
            "d": "Thread-local storage assignment",
            "e": [
              "TlsSetValue"
            ],
            "i": "micro-behaviors/process/tls/fiber::tls-set-value",
            "l": 2
          },
          {
            "c": 0.550000011920929,
            "d": ".NET Start method token",
            "e": [
              "Start"
            ],
            "i": "micro-behaviors/process/create/spawn::start-method-token-dotnet",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "Random low-entropy RWX cavity section",
            "e": [
              ".text (size: 13824, entropy: 0.00, perms: -rwx)",
              ".brdata (size: 20480, entropy: 0.00, perms: -rwx)"
            ],
            "i": "metadata/binary/section/metrics::random-rwx-cavity-section",
            "l": 4
          },
          {
            "a": "T1204.002",
            "c": 0.7599999904632568,
            "d": "Short PDB marker",
            "e": [
              "exe.pdb"
            ],
            "i": "objectives/command-and-control/dropper/execution/clickfix::short-pdb-marker",
            "l": 1,
            "m": "B0024"
          },
          {
            "c": 0.6399999856948853,
            "d": "Delete files (Windows API ANSI)",
            "e": [
              "DeleteFileA"
            ],
            "i": "micro-behaviors/fs/file/delete::deletefile-a-text",
            "l": 2
          },
          {
            "a": "T1053.005",
            "c": 0.8999999761581421,
            "d": "Task Scheduler builder methods",
            "e": [
              "Connect",
              "Connect",
              "Connect",
              "Connect",
              "Connect"
            ],
            "i": "objectives/persistence/login/scheduled-task::task-scheduler-builder-methods",
            "l": 1,
            "m": "F0012"
          },
          {
            "c": 0.6600000262260437,
            "d": "Look up temp directory via GetTempPath",
            "e": [
              "GetTempPathA"
            ],
            "i": "micro-behaviors/fs/temp/directory::get-temp-path-dup",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Five section PE layout",
            "e": [
              "binary.section_count = 5.00"
            ],
            "i": "metadata/binary/section/metrics::five-section-pe",
            "l": 1
          },
          {
            "c": 0.9599999785423279,
            "d": "Elex Internet Explorer product resource",
            "e": [
              "Internet Explorer"
            ],
            "i": "well-known/malware/trojan/elex/worm::elex-internet-explorer-product-resource",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.8999999761581421,
            "d": "HttpQueryInfo API name as string",
            "e": [
              "HttpQueryInfoA"
            ],
            "i": "micro-behaviors/communications/http/get::http-query-info-str",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Very low code entropy, minimal code",
            "e": [
              "binary.code_entropy = 0.00"
            ],
            "i": "metadata/binary/resource::low-code-entropy",
            "l": 2
          },
          {
            "a": "T1071.001",
            "d": "HTTP/1.x version string",
            "e": [
              "GET %s?%s HTTP/1.1\r\nConnection: Keep-Aliv…"
            ],
            "i": "micro-behaviors/communications/http/request::http-version",
            "l": 2,
            "m": "C0002"
          },
          {
            "a": "T1071.001",
            "d": "User-Agent header",
            "e": [
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:",
              "User-Agent:"
            ],
            "i": "micro-behaviors/communications/http/request::user-agent-header",
            "l": 2,
            "m": "C0002"
          },
          {
            "c": 0.8399999737739563,
            "d": "High basic block count in sparse binary",
            "e": [
              "binary.total_basic_blocks = 1074.00"
            ],
            "i": "metadata/binary/metrics::dense-basic-blocks",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "HTTP User-Agent header",
            "e": [
              "User-Agent: 碸I",
              "…: Keep-Alive\r\nHost: %s\r\nUser-Agent: Mozilla/4.0\r\nAccept-lan…",
              "User-Agent: Mozilla/_;ފ",
              "User-Agent: Mozilla/4.0",
              "User-Agent: ",
              "User-Agent: Mo",
              "User-Agent: Mozill",
              "User-Agent: Mozilla/4.0U",
              "User-Agent: %#",
              "User-Agent: Mozilla/4.0(XfUser-Agen…",
              "User-Agent:",
              "User-Agent: Mozilla/4.0User-Agent",
              "User-Agent:KX",
              "User-Agent: Mozilla/\\b",
              "…er-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0(XfUser-Agen…"
            ],
            "i": "micro-behaviors/communications/http/user-agent::user-agent-header-dup",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Tool identity claims WinRAR",
            "e": [
              "WinRAR"
            ],
            "i": "metadata/package/tooling::tool-identity-winrar",
            "l": 1
          },
          {
            "d": "SYSTEMROOT environment variable",
            "e": [
              "%SystemRoot%\\System32\\svch%s -k nets"
            ],
            "i": "micro-behaviors/os/env/vars/system-info::systemroot-var",
            "l": 2
          },
          {
            "c": 0.6200000047683716,
            "d": "Assembly Load method token",
            "e": [
              "Load"
            ],
            "i": "objectives/anti-static/obfuscation/reflection/invoke::dotnet-assembly-load-token",
            "l": 1
          },
          {
            "a": "T1071.001",
            "c": 0.8600000143051147,
            "d": "WinInet DLL name string",
            "e": [
              "Wininet.dll"
            ],
            "i": "micro-behaviors/communications/http/get::wininet-dll-name",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE standard runtime section",
            "e": [
              ".rdata"
            ],
            "i": "metadata/binary/section/names::pe-runtime-standard-section",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Thread32First API string",
            "e": [
              "Thread32First"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::thread32-first-string",
            "l": 1
          },
          {
            "c": 0.7200000286102295,
            "d": "Short uppercase mutex token",
            "e": [
              "RECYCLER"
            ],
            "i": "micro-behaviors/process/sync/mutex::short-uppercase-token",
            "l": 1,
            "m": "C0042"
          },
          {
            "c": 0.949999988079071,
            "d": "ANSI console output",
            "e": [
              "WriteConsoleA"
            ],
            "i": "micro-behaviors/hardware/display/screen::write-console-a",
            "l": 2
          },
          {
            "a": "T1071.001",
            "d": "Old Mozilla 4.0 User-Agent",
            "e": [
              "…\r\nHost: %s\r\nUser-Agent: Mozilla/4.0\r\nAccept-language: cn",
              "User-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.3%",
              "User-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4…",
              "…zilla/4.0(XfUser-Agent: Mozilla/4.0(XeX",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agent: Mozilla/4.3X",
              "User-Agent: Mozilla/4.0User-Agent: Mozilla/4.0User-Agemy",
              "User-Agent: Mozilla/4.0",
              "…zilla/4.0(XfUser-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4…",
              "User-Agent: Mozilla/4.0User-Agent",
              "User-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0(XfUser-Agent: Mozilla/4.0+U",
              "User-Agent: Mozilla/4.0U"
            ],
            "i": "micro-behaviors/communications/http/headers::ua-mozilla-old",
            "l": 2,
            "m": "C0002"
          },
          {
            "c": 0.8199999928474426,
            "d": "GetSystemDirectory API string",
            "e": [
              "GetSystemDirectoryA"
            ],
            "i": "micro-behaviors/os/sysinfo/directories::get-system-directory-string",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "File is a compiled binary",
            "e": [
              "binary.file_size = 328192.00"
            ],
            "i": "metadata/binary/framework::is-binary",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Skips Windows installation directories",
            "e": [
              "WINDOWS"
            ],
            "i": "objectives/impact/infect/binary::skip-windows-install-dir",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary is not position-independent (fixed load address)",
            "e": [
              "binary.is_pie = 0.00"
            ],
            "i": "metadata/hardening::no-pie",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Close handle",
            "e": [
              "CloseHandle"
            ],
            "i": "micro-behaviors/process/create/spawn::close-handle-dup",
            "l": 2
          },
          {
            "a": "T1562.001",
            "c": 0.8999999761581421,
            "d": "Common EDR/AV process name",
            "e": [
              "bdagent.exe"
            ],
            "i": "objectives/impact/degrade/edr::target-general-edr",
            "l": 1
          },
          {
            "a": "T1071.001",
            "c": 0.8999999761581421,
            "d": "InternetCloseHandle API name",
            "e": [
              "InternetCloseHandle"
            ],
            "i": "micro-behaviors/communications/http/get::internet-close-handle-str",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "HTTP GET method",
            "e": [
              "GET %s?%s HTTP/1.1"
            ],
            "i": "micro-behaviors/communications/http/get::get",
            "l": 3
          },
          {
            "c": 0.699999988079071,
            "d": "Get module file path (ANSI)",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/os/module/load::get-module-filename-ansi",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Call to GetDriveTypeA by raw bytes",
            "e": [
              "GetDriveTypeA"
            ],
            "i": "micro-behaviors/fs/traversal/drives::get-drive-type-raw",
            "l": 1
          },
          {
            "a": "T1562.001",
            "c": 0.8500000238418579,
            "d": "Kaspersky AV/Internet Security specifically targeted",
            "e": [
              "avp.exe"
            ],
            "i": "objectives/impact/degrade/edr/targeting::kaspersky-target",
            "l": 1
          },
          {
            "a": "T1546.012",
            "c": 0.8999999761581421,
            "d": "IFEO registry path",
            "e": [
              "Image File Execution Options"
            ],
            "i": "objectives/persistence/login/ifeo/debugger::ifeo-registry-path",
            "l": 1,
            "m": "F0012"
          },
          {
            "c": 0.699999988079071,
            "d": "PE has many readable strings",
            "e": [
              "binary.string_count = 746.00"
            ],
            "i": "metadata/binary/layout::many-readable-strings",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 3+ functions",
            "e": [
              "binary.function_count = 81.00"
            ],
            "i": "metadata/binary/metrics::few-functions-3",
            "l": 1
          },
          {
            "a": "T1055.012",
            "c": 0.800000011920929,
            "d": "CreateProcess API string reference",
            "e": [
              "CreateProcessAsUserA",
              "CreateProcessA"
            ],
            "i": "objectives/evasion/process/injection/hollowing::create-process-string",
            "l": 1,
            "m": "E1055.012"
          },
          {
            "c": 0.800000011920929,
            "d": "Binary has many functions (\u003e30)",
            "e": [
              "binary.function_count = 81.00"
            ],
            "i": "metadata/binary/metrics::many-functions",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Rewrite a file's 8.3 short name",
            "e": [
              "SetFileShortNameW"
            ],
            "i": "micro-behaviors/fs/file/rename::set-file-short-name-w",
            "l": 3
          },
          {
            "a": "T1057",
            "c": 0.800000011920929,
            "d": "PSAPI.dll dynamic load string",
            "e": [
              "PSAPI"
            ],
            "i": "micro-behaviors/process/enumerate/psapi::psapi-dll-string",
            "l": 1
          },
          {
            "a": "T1071.001",
            "c": 0.8999999761581421,
            "d": "InternetOpen API name as string",
            "e": [
              "InternetOpenA"
            ],
            "i": "micro-behaviors/communications/http/get::internet-open-str",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "RECYCLER literal path marker",
            "e": [
              "RECYCLER"
            ],
            "i": "micro-behaviors/fs/path/system::recycler-literal",
            "l": 4
          },
          {
            "c": 0.75,
            "d": "Binary exports no symbols",
            "e": [
              "binary.export_count = 0.00"
            ],
            "i": "metadata/binary/symbols::no-exports",
            "l": 1
          },
          {
            "a": "T1055.012",
            "c": 0.9200000166893005,
            "d": "Internet Explorer hollowing target",
            "e": [
              "\\Internet Explorer\\iexplore.exe"
            ],
            "i": "objectives/evasion/process/injection/hollowing::iexplore-hollowing-target",
            "l": 1,
            "m": "E1055.012"
          },
          {
            "a": "T1053.005",
            "c": 0.8799999952316284,
            "d": "Task action principal properties",
            "e": [
              "Path",
              "Path",
              "Path"
            ],
            "i": "objectives/persistence/login/scheduled-task::task-action-principal-properties",
            "l": 1,
            "m": "F0012"
          },
          {
            "c": 0.8999999761581421,
            "d": "ServiceDll registry value marker",
            "e": [
              "servicedll"
            ],
            "i": "micro-behaviors/os/service/host::service-dll-value-name",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "Low-entropy rdata section",
            "e": [
              ".rdata (entropy: 0.00)"
            ],
            "i": "metadata/binary/section/metrics::low-entropy-rdata-section",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Wait for process/object",
            "e": [
              "WaitForSingleObject"
            ],
            "i": "micro-behaviors/process/create/spawn::wait-for-single-object",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 50+ functions",
            "e": [
              "binary.function_count = 81.00"
            ],
            "i": "metadata/binary/metrics::many-functions-50",
            "l": 1
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "LoadLibraryA loader API string",
            "e": [
              "LoadLibraryA"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-loadlibrarya-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "c": 0.8199999928474426,
            "d": "GetWindowsDirectory API string",
            "e": [
              "GetWindowsDirectoryA"
            ],
            "i": "micro-behaviors/os/sysinfo/directories::get-windows-directory-string",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Open named semaphore object",
            "e": [
              "OpenSemaphoreW"
            ],
            "i": "micro-behaviors/process/sync/semaphore::open-semaphore",
            "l": 2,
            "m": "C0042"
          },
          {
            "a": "T1027.007",
            "c": 0.800000011920929,
            "d": "DLL name strings without LoadLibrary import",
            "e": [
              "binary.import_count = 11.00"
            ],
            "i": "objectives/anti-static/obfuscation/string/runtime-decrypt::dll-names-no-loadlibrary",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "a": "T1543.003",
            "c": 0.8500000238418579,
            "d": "Open service control manager",
            "e": [
              "OpenSCManagerA"
            ],
            "i": "micro-behaviors/os/service/control::open-sc-manager",
            "l": 3
          },
          {
            "a": "T1027",
            "c": 0.9200000166893005,
            "d": "Zero-entropy executable section (carved/packed PE)",
            "e": [
              ".text (size: 13824, entropy: 0.00, perms: -rwx)",
              ".brdata (size: 20480, entropy: 0.00, perms: -rwx)",
              ".tc (size: 249856, entropy: 0.00, perms: -rwx)"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics::zero-entropy-executable-section",
            "l": 4,
            "m": "B0032"
          },
          {
            "c": 0.8999999761581421,
            "d": "CreateFile API string reference",
            "e": [
              "CreateFile",
              "CreateFile"
            ],
            "i": "micro-behaviors/fs/file/open::createfile-api",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.699999988079071,
            "d": "Hardcoded loopback IP (likely test C2)",
            "e": [
              "127.0.0.1"
            ],
            "i": "objectives/command-and-control/channel/http-beacon::hardcoded-localhost-c2",
            "l": 3,
            "m": "B0030"
          },
          {
            "c": 0.800000011920929,
            "d": "Five or more PE sections",
            "e": [
              "binary.section_count = 5.00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::five-plus-sections-pe",
            "l": 1
          },
          {
            "c": 0.7799999713897705,
            "d": "Hardcoded loopback IPv4 address",
            "e": [
              "127.0.0.1"
            ],
            "i": "micro-behaviors/communications/ip::loopback-ipv4-binary",
            "l": 3
          },
          {
            "a": "T1574.002",
            "c": 0.8999999761581421,
            "d": "Hidden LoadLibraryA string reference",
            "e": [
              "LoadLibraryA"
            ],
            "i": "micro-behaviors/dylib/load::load-library-a-string-no-import",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary is not digitally signed",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed::unsigned",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "GUID-formatted mutex name",
            "e": [
              "{645FF040-5081-101B-9F08-00AA002F954E}"
            ],
            "i": "micro-behaviors/process/sync/mutex::guid-mutex",
            "l": 3,
            "m": "C0042"
          },
          {
            "a": "T1027",
            "c": 0.699999988079071,
            "d": "Oversized data section vs code",
            "e": [
              ".rdata",
              ".data",
              ".brdata",
              ".rdata+.data+.brdata = 459.3% of text (63488 / 13824 bytes)"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::oversized-data-section",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.8500000238418579,
            "d": "PE with malformed section layout",
            "e": [
              "binary.has_malformed_structure = 1.00"
            ],
            "i": "metadata/binary/metrics::malformed-pe-structure",
            "l": 3
          },
          {
            "a": "T1559",
            "c": 0.800000011920929,
            "d": "Named pipe path prefix",
            "e": [
              "\\\\.\\pipe\\"
            ],
            "i": "micro-behaviors/communications/ipc/named-pipe::pipe-path-prefix",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "UPX packer marker string",
            "e": [
              "UPX0"
            ],
            "i": "objectives/anti-static/pack/detect::upx-marker",
            "l": 1
          },
          {
            "c": 0.7200000286102295,
            "d": "Writable .rdata section permissions",
            "e": [
              ".rdata (perms: -rw-)"
            ],
            "i": "metadata/binary/section/names::writable-rdata",
            "l": 3
          },
          {
            "c": 0.949999988079071,
            "d": "Three or more writable executable sections",
            "e": [
              "binary.wx_sections = 3.00"
            ],
            "i": "metadata/hardening/memory::three-plus-wx-sections",
            "l": 3
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "GetProcAddress loader API string",
            "e": [
              "GetProcAddress"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-getprocaddress-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "a": "T1027",
            "c": 0.8199999928474426,
            "d": "Packed loader largest section ratio above 0.65",
            "e": [
              "binary.largest_section_ratio = 0.76"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::packed-loader-largest-section-dominates",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1071.001",
            "c": 0.949999988079071,
            "d": "InternetOpenUrl downloader API string",
            "e": [
              "InternetOpenUrlA"
            ],
            "i": "micro-behaviors/communications/http/get::dynamic-wininet-api-set",
            "l": 3
          },
          {
            "a": "T1027.007",
            "c": 1.0,
            "d": "ntdll.dll as wide string (runtime resolver)",
            "e": [
              "ntdll.dll"
            ],
            "i": "objectives/anti-static/obfuscation/string/runtime-decrypt::ntdll-wide-string",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "a": "T1057",
            "d": "Browser app iexplore",
            "e": [
              "iexplore"
            ],
            "i": "micro-behaviors/process/enumerate/apps::browser-apps-iexplore",
            "l": 3,
            "m": "E1592"
          },
          {
            "a": "T1134",
            "c": 1.0,
            "d": "CreateProcessAsUser API reference",
            "e": [
              "CreateProcessAsUserA"
            ],
            "i": "micro-behaviors/process/create/spawn::create-process-as-user",
            "l": 3
          },
          {
            "a": "T1055.001",
            "c": 0.949999988079071,
            "d": "Dynamic LoadLibraryA resolution for remote injection",
            "e": [
              "LoadLibraryA"
            ],
            "i": "micro-behaviors/process/inject/dll::load-library-a-remote-resolution",
            "l": 3,
            "m": "F0003"
          },
          {
            "d": ".exe extension reference",
            "e": [
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe",
              ".exe"
            ],
            "i": "micro-behaviors/fs/path/extension::exe-dup",
            "l": 2
          },
          {
            "a": "T1562.001",
            "c": 1.0,
            "d": "ntdll.dll string reference",
            "e": [
              "ntdll.dll"
            ],
            "i": "objectives/evasion/anti-av/platform::ntdll-dll-str",
            "l": 1
          },
          {
            "a": "T1045",
            "c": 0.949999988079071,
            "d": "Very high entropy (strongly indicates",
            "e": [
              "binary.overall_entropy = 7.69"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics::very-high-entropy",
            "l": 3,
            "m": "B0032"
          },
          {
            "c": 0.800000011920929,
            "d": "Binary lacks resource section entirely",
            "e": [
              "binary.rsrc_to_file_ratio = 0.00"
            ],
            "i": "metadata/binary/resource::no-resources",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.8500000238418579,
            "d": "Create Windows service",
            "e": [
              "CreateServiceA"
            ],
            "i": "micro-behaviors/os/service/control::create-service",
            "l": 3
          },
          {
            "a": "T1543.003",
            "c": 0.8500000238418579,
            "d": "Open existing service handle",
            "e": [
              "OpenServiceA"
            ],
            "i": "micro-behaviors/os/service/control::open-service",
            "l": 3
          },
          {
            "c": 1.0,
            "d": "Writable and executable section (W^X violation)",
            "e": [
              ".text (size: 13824, perms: -rwx)",
              ".brdata (size: 20480, perms: -rwx)",
              ".tc (size: 249856, perms: -rwx)"
            ],
            "i": "metadata/hardening/memory::wx-section",
            "l": 3
          },
          {
            "a": "T1027.007",
            "c": 0.8999999761581421,
            "d": "Kernel32 DLL resolution string",
            "e": [
              "kernel32.dll"
            ],
            "i": "micro-behaviors/os/api-resolution/manual::kernel32-resolver",
            "l": 1
          },
          {
            "a": "T1105",
            "c": 0.800000011920929,
            "d": "Compact PE import table",
            "e": [
              "binary.import_count = 11.00"
            ],
            "i": "objectives/command-and-control/dropper/delivery/download-execute::compact-import-table",
            "l": 1,
            "m": "E1105"
          },
          {
            "c": 0.699999988079071,
            "d": "WS2_32 Winsock DLL import",
            "e": [
              "WS2_32.dll"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-32-dll-marker",
            "l": 3
          },
          {
            "a": "T1543.003",
            "c": 0.8500000238418579,
            "d": "Start Windows service",
            "e": [
              "StartServiceA"
            ],
            "i": "micro-behaviors/os/service/control::start-service",
            "l": 3
          },
          {
            "a": "T1027",
            "c": 0.8500000238418579,
            "d": "High overall file entropy (likely",
            "e": [
              "binary.overall_entropy = 7.69"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics::high-overall-entropy",
            "l": 3,
            "m": "B0032"
          },
          {
            "a": "T1027",
            "c": 0.8600000143051147,
            "d": "Long mixed-case identifiers cluster",
            "e": [
              "InternetSetStatusCallback",
              "GetModuleInformation",
              "GetModuleFileNameA",
              "GetWindowsDirectoryA",
              "MultiByteToWideChar",
              "GetSystemDirectoryA",
              "GetLogicalDriveStringsA",
              "SetNamedPipeHandleState",
              "GetCurrentProcessId",
              "DisconnectNamedPipe",
              "SetProcessWindowStation"
            ],
            "i": "objectives/anti-static/obfuscation/string::long-mixedcase-identifiers",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.800000011920929,
            "d": "PE executable is unsigned",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed::unsigned-pe-executable",
            "l": 3
          },
          {
            "c": 0.949999988079071,
            "d": "links KERNEL32.dll (WriteConsoleA, GlobalCompact, GlobalFlags, GetBinaryType, OpenSemaphoreW, ... +6 more)",
            "e": [
              "KERNEL32.dll"
            ],
            "i": "metadata/dylib::kernel32/dll",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.8999999761581421,
            "d": "WinInet APIs resolved dynamically",
            "e": [
              "InternetOpenA",
              "HttpQueryInfoA",
              "InternetCloseHandle"
            ],
            "i": "micro-behaviors/communications/http/get::wininet-dynamic-load",
            "l": 4
          },
          {
            "c": 0.8999999761581421,
            "d": "Toolhelp thread enumeration strings",
            "e": [
              "Thread32First",
              "Thread32Next"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::toolhelp-thread-enumeration-string",
            "l": 3
          },
          {
            "a": "T1036.005",
            "c": 0.8399999737739563,
            "d": "Non-Microsoft WindowsUpdate reference",
            "e": [
              "WindowsUpdate"
            ],
            "i": "objectives/evasion/masquerade/identity/mimicry::non-microsoft-windowsupdate-reference",
            "l": 4
          },
          {
            "a": "T1027.007",
            "c": 0.8500000238418579,
            "d": "Runtime API string decryption (DLL names without loader imports)",
            "e": [
              "binary.import_count = 11.00",
              "kernel32.dll",
              "ntdll.dll"
            ],
            "i": "objectives/anti-static/obfuscation/string/runtime-decrypt::runtime-api-decryption",
            "l": 4,
            "m": "B0032.014"
          },
          {
            "a": "T1112",
            "c": 0.9200000166893005,
            "d": "Registry open create and write APIs",
            "e": [
              "RegOpenKeyExA",
              "RegCreateKeyExA",
              "RegSetValueExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::registry-write-api-chain",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Encoded payload detected: xor",
            "e": [
              "User-Agent: Mozilla/4.0User-Agent \u003cxor\u003e",
              "User-Agan2:iM#z,lla/4.0User-Age_%N \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Agent: Mo \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Agent: Mozil \u003cxor\u003e",
              "Sser-Agent: Mozilla/4.0User-Agent: Mozil \u003cxor\u003e",
              "5ser-Agent: Mozilla/4.0(XfUser-Agent: Mo \u003cxor\u003e",
              "Dser-Agent: Mozilla/4.0User-Agent: Mozil \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Agenw7 \u003cxor\u003e",
              "\u0026ser-Agent: Mozilla/4.0User-Agent: Moyd \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Agent: Mozio \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Agenw7 \u003cxor\u003e",
              "\\7er-Agent: Mozilla/4.0User-Agent: Mozja \u003cxor\u003e",
              "]Ver-Agent: Mozilla/4.0(XfUser.L \u003cxor\u003e",
              "Uaer-Agent: Mozilla/4.0(XfUser-Agemy \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Agemy \u003cxor\u003e",
              "WYer-Agent: Mozilla/4.0(XfUser-Agent: Nb \u003cxor\u003e",
              "T#er-Agent: Mozilla/4.0(XfUser-Agent: Mo \u003cxor\u003e",
              "Pwer-Agent: Mozilla/4.0User-Agent: Mozil \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Bj \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Agent:#@ \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Agent9- \u003cxor\u003e",
              "user-Agent: Mozilla/4.0User-Agent: Mozil \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Agent: Mozja \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Agent:\u0026 \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Agenr \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-@m \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Agenu0 \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Agenu0 \u003cxor\u003e",
              "h|zr-Agent: Mozilla/4.0User-Agelx \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Aei \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Ck \u003cxor\u003e",
              "2ser-Agent: Mozilla/4.0(XfUser-Agent: Mo \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Agent: Mozka \u003cxor\u003e",
              "Rser-Agent: Mozilla/4.0(XfUser-Agent: Mo \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Agent: Lc \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Agent;( \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Agenu2 \u003cxor\u003e",
              "Eser-Agent: Mozilla/4.0User-Agent: Mozil \u003cxor\u003e",
              "Wser-Agent: Mozilla/4.0User-Agent:! \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Agd \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-AgP@ \u003cxor\u003e",
              "51er-Agent: Mozilla/4.0(XfUser-E \u003cxor\u003e",
              "U-,r-Agent: Mozilla/4.0User-Agent: Mozil \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Agg \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Agent:+A \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Ageex \u003cxor\u003e",
              "User-Agent: Mozilla/4.0User-Agenv8 \u003cxor\u003e",
              "User-Agent: Mozilla/4.0(XfUser-Ce \u003cxor\u003e"
            ],
            "i": "metadata/encoded-payload/xor",
            "l": 3
          }
        ],
        "sha": "e4efeffde6b370833daf07c9aeb2b3116fdb7ba9c213d1fb58fbca89ea833ecb",
        "path": "/data/samples/bad/datasets/pe-machine-learning-dataset/62225",
        "type": "pe"
      }
    ],
    "tv": "feb13"
  }
}