{
  "ml": {
    "v": "4",
    "fs": [
      {
        "id": 0,
        "prob": 0.9940488338470459,
        "class": 2
      }
    ],
    "prob": 0.99404883,
    "class": 2,
    "oprob": 0.966739,
    "oclass": 0,
    "version": "v16.16",
    "thresholds": [
      0.9815004,
      0.99404883
    ],
    "analyzed_at": "2026-05-01T18:33:38Z"
  },
  "path": "511321",
  "raw": {
    "v": "4",
    "fs": [
      {
        "f": "K₂O₁₀(C₉Ca₅CoDy₂P₂As₈Er₄IPr₂S)H₆(Cm₃Db₂F₂Os₅Po₅Ds)Md₄(SiBi₄Pa₂)Th₅",
        "x": 702,
        "id": 0,
        "is": [
          "CreateFileA",
          "ReadFile",
          "CloseHandle",
          "WriteFile",
          "lstrlenA",
          "GlobalLock",
          "GlobalUnlock",
          "LocalFree",
          "LocalAlloc",
          "GetTickCount",
          "lstrcpyA",
          "lstrcatA",
          "GetFileAttributesA",
          "ExpandEnvironmentStringsA",
          "GetFileSize",
          "CreateFileMappingA",
          "MapViewOfFile",
          "UnmapViewOfFile",
          "LoadLibraryA",
          "GetProcAddress",
          "GetTempPathA",
          "CreateDirectoryA",
          "DeleteFileA",
          "GetCurrentProcess",
          "WideCharToMultiByte",
          "GetLastError",
          "lstrcmpA",
          "CreateToolhelp32Snapshot",
          "Process32First",
          "OpenProcess",
          "Process32Next",
          "FindFirstFileA",
          "lstrcmpiA",
          "FindNextFileA",
          "FindClose",
          "GetModuleHandleA",
          "GetVersionExA",
          "GetLocaleInfoA",
          "GetSystemInfo",
          "GetWindowsDirectoryA",
          "GetPrivateProfileStringA",
          "SetCurrentDirectoryA",
          "GetPrivateProfileSectionNamesA",
          "GetPrivateProfileIntA",
          "GetCurrentDirectoryA",
          "lstrlenW",
          "MultiByteToWideChar",
          "Sleep",
          "GetModuleFileNameA",
          "LCMapStringA",
          "ExitProcess",
          "SetUnhandledExceptionFilter",
          "RegOpenKeyExA",
          "RegQueryValueExA",
          "RegCloseKey",
          "RegOpenKeyA",
          "RegEnumKeyExA",
          "RegCreateKeyA",
          "RegSetValueExA",
          "IsTextUnicode",
          "RegOpenCurrentUser",
          "RegEnumValueA",
          "GetUserNameA",
          "CreateStreamOnHGlobal",
          "GetHGlobalFromStream",
          "CoCreateGuid",
          "CoTaskMemFree",
          "CoCreateInstance",
          "OleInitialize",
          "ShellExecuteA",
          "StrStrIA",
          "StrRChrIA",
          "StrToIntA",
          "StrStrA",
          "StrCmpNIA",
          "StrStrIW",
          "wsprintfA",
          "LoadUserProfileA",
          "UnloadUserProfile",
          "InternetCrackUrlA",
          "InternetCreateUrlA",
          "inet_addr",
          "gethostbyname",
          "socket",
          "connect",
          "closesocket",
          "send",
          "select",
          "recv",
          "setsockopt",
          "WSAStartup"
        ],
        "ms": {
          "pe": {
            "machine": 332.0,
            "checksum": 0.0,
            "subsystem": 2.0,
            "timestamp": 1442649594.0,
            "image_base": 4194304.0,
            "entry_section": ".text",
            "size_of_image": 102400.0,
            "timestamp_day": 19.0,
            "file_alignment": 512.0,
            "timestamp_year": 2015.0,
            "characteristics": 271.0,
            "entry_point_rva": 67105.0,
            "size_of_headers": 4096.0,
            "timestamp_month": 9.0,
            "checksum_missing": true,
            "checksum_present": false,
            "export_timestamp": 0.0,
            "import_dll_count": 9.0,
            "computed_checksum": 118821.0,
            "section_alignment": 4096.0,
            "number_of_sections": 3.0,
            "resource_timestamp": 0.0,
            "linker_major_version": 2.0,
            "linker_minor_version": 50.0,
            "api_hashing_indicators": 1.0,
            "export_timestamp_present": false,
            "resource_timestamp_present": false
          },
          "binary": {
            "code_size": 72704.0,
            "file_size": 92672.0,
            "entry_point": 67105.0,
            "code_entropy": 6.06,
            "data_entropy": 4.13,
            "import_count": 91.0,
            "string_count": 768.0,
            "section_count": 3.0,
            "avg_complexity": 4.97,
            "function_count": 441.0,
            "import_density": 1.28,
            "max_complexity": 107.0,
            "string_density": 10.82,
            "overall_entropy": 4.77,
            "avg_basic_blocks": 7.55,
            "avg_section_size": 30720.0,
            "dependency_count": 9.0,
            "entropy_variance": 1.27,
            "function_density": 6.21,
            "avg_function_size": 158.38,
            "avg_string_length": 14.91,
            "complexity_per_kb": 0.07,
            "max_string_length": 239.0,
            "wide_string_count": 1.0,
            "writable_sections": 1.0,
            "avg_string_entropy": 3.07,
            "code_to_data_ratio": 3.74,
            "data_to_file_ratio": 0.2,
            "entry_point_is_rva": true,
            "text_to_file_ratio": 0.78,
            "total_basic_blocks": 3329.0,
            "executable_sections": 1.0,
            "string_length_stddev": 16.07,
            "largest_section_ratio": 0.78,
            "sentence_string_count": 61.0,
            "sentence_string_ratio": 0.08,
            "behavioral_import_ratio": 0.08,
            "function_analysis_depth": 2.0,
            "high_complexity_functions": 1.0
          }
        },
        "ss": [
          [
            77,
            "!This program cannot be run in DOS mode."
          ],
          [
            376,
            ".text"
          ],
          [
            455,
            "@.data"
          ],
          [
            5521,
            "5KHA"
          ],
          [
            8312,
            "PSQRWV"
          ],
          [
            8451,
            "VWPSQR"
          ],
          [
            64539,
            "UVW3"
          ],
          [
            70713,
            "33331"
          ],
          [
            72697,
            "PPSV"
          ],
          [
            73216,
            "aPLib v1.01  -  the smaller the better :)\r\nCopyright (c) 1998-2009 by Joergen Ibsen, All Rights Reserved.\r\n\r\nMore information: h"
          ],
          [
            73220,
            "aPLib v1.01  -  the smaller the better :)"
          ],
          [
            73263,
            "Copyright (c) 1998-2009 by Joergen Ibsen, All Rights Reserved."
          ],
          [
            73329,
            "More information: http://www.ibsensoftware.com/"
          ],
          [
            73728,
            "123456"
          ],
          [
            73735,
            "password"
          ],
          [
            73750,
            "qwerty"
          ],
          [
            73757,
            "12345"
          ],
          [
            73763,
            "jesus"
          ],
          [
            73778,
            "1234"
          ],
          [
            73783,
            "abc123"
          ],
          [
            73790,
            "letmein"
          ],
          [
            73798,
            "test"
          ],
          [
            73803,
            "love"
          ],
          [
            73812,
            "password1"
          ],
          [
            73822,
            "hello"
          ],
          [
            73828,
            "monkey"
          ],
          [
            73835,
            "dragon"
          ],
          [
            73842,
            "trustno1"
          ],
          [
            73858,
            "iloveyou"
          ],
          [
            73867,
            "1234567"
          ],
          [
            73875,
            "shadow"
          ],
          [
            73892,
            "christ"
          ],
          [
            73899,
            "sunshine"
          ],
          [
            73908,
            "master"
          ],
          [
            73915,
            "computer"
          ],
          [
            73924,
            "princess"
          ],
          [
            73933,
            "tigger"
          ],
          [
            73940,
            "football"
          ],
          [
            73949,
            "angel"
          ],
          [
            73955,
            "jesus1"
          ],
          [
            73962,
            "123123"
          ],
          [
            73969,
            "whatever"
          ],
          [
            73978,
            "freedom"
          ],
          [
            73986,
            "killer"
          ],
          [
            73998,
            "soccer"
          ],
          [
            74005,
            "superman"
          ],
          [
            74014,
            "michael"
          ],
          [
            74022,
            "cheese"
          ],
          [
            74029,
            "internet"
          ],
          [
            74038,
            "joshua"
          ],
          [
            74045,
            "fuckyou"
          ],
          [
            74053,
            "blessed"
          ],
          [
            74061,
            "baseball"
          ],
          [
            74070,
            "starwars"
          ],
          [
            74086,
            "purple"
          ],
          [
            74093,
            "jordan"
          ],
          [
            74100,
            "faith"
          ],
          [
            74106,
            "summer"
          ],
          [
            74113,
            "ashley"
          ],
          [
            74120,
            "buster"
          ],
          [
            74127,
            "heaven"
          ],
          [
            74134,
            "pepper"
          ],
          [
            74149,
            "hunter"
          ],
          [
            74156,
            "lovely"
          ],
          [
            74163,
            "andrew"
          ],
          [
            74170,
            "thomas"
          ],
          [
            74177,
            "angels"
          ],
          [
            74184,
            "charlie"
          ],
          [
            74192,
            "daniel"
          ],
          [
            74204,
            "jennifer"
          ],
          [
            74213,
            "single"
          ],
          [
            74220,
            "hannah"
          ],
          [
            74227,
            "qazwsx"
          ],
          [
            74240,
            "matrix"
          ],
          [
            74259,
            "654321"
          ],
          [
            74266,
            "amanda"
          ],
          [
            74273,
            "nothing"
          ],
          [
            74281,
            "ginger"
          ],
          [
            74288,
            "mother"
          ],
          [
            74295,
            "snoopy"
          ],
          [
            74302,
            "jessica"
          ],
          [
            74310,
            "welcome"
          ],
          [
            74318,
            "pokemon"
          ],
          [
            74326,
            "iloveyou1"
          ],
          [
            74342,
            "mustang"
          ],
          [
            74350,
            "helpme"
          ],
          [
            74357,
            "justin"
          ],
          [
            74364,
            "jasmine"
          ],
          [
            74372,
            "orange"
          ],
          [
            74379,
            "testing"
          ],
          [
            74387,
            "apple"
          ],
          [
            74393,
            "michelle"
          ],
          [
            74402,
            "peace"
          ],
          [
            74408,
            "secret"
          ],
          [
            74417,
            "grace"
          ],
          [
            74423,
            "william"
          ],
          [
            74431,
            "iloveyou2"
          ],
          [
            74441,
            "nicole"
          ],
          [
            74455,
            "muffin"
          ],
          [
            74462,
            "gateway"
          ],
          [
            74470,
            "fuckyou1"
          ],
          [
            74479,
            "asshole"
          ],
          [
            74487,
            "hahaha"
          ],
          [
            74494,
            "poop"
          ],
          [
            74499,
            "blessing"
          ],
          [
            74508,
            "blahblah"
          ],
          [
            74517,
            "myspace1"
          ],
          [
            74526,
            "matthew"
          ],
          [
            74534,
            "canada"
          ],
          [
            74541,
            "silver"
          ],
          [
            74548,
            "robert"
          ],
          [
            74555,
            "forever"
          ],
          [
            74563,
            "asdfgh"
          ],
          [
            74570,
            "rachel"
          ],
          [
            74577,
            "rainbow"
          ],
          [
            74585,
            "guitar"
          ],
          [
            74592,
            "peanut"
          ],
          [
            74599,
            "batman"
          ],
          [
            74606,
            "cookie"
          ],
          [
            74613,
            "bailey"
          ],
          [
            74620,
            "soccer1"
          ],
          [
            74628,
            "mickey"
          ],
          [
            74635,
            "biteme"
          ],
          [
            74642,
            "hello1"
          ],
          [
            74649,
            "eminem"
          ],
          [
            74656,
            "dakota"
          ],
          [
            74663,
            "samantha"
          ],
          [
            74672,
            "compaq"
          ],
          [
            74679,
            "diamond"
          ],
          [
            74687,
            "taylor"
          ],
          [
            74694,
            "forum"
          ],
          [
            74700,
            "john316"
          ],
          [
            74708,
            "richard"
          ],
          [
            74716,
            "blink182"
          ],
          [
            74725,
            "peaches"
          ],
          [
            74733,
            "cool"
          ],
          [
            74738,
            "flower"
          ],
          [
            74745,
            "scooter"
          ],
          [
            74753,
            "banana"
          ],
          [
            74760,
            "james"
          ],
          [
            74766,
            "asdfasdf"
          ],
          [
            74775,
            "victory"
          ],
          [
            74783,
            "london"
          ],
          [
            74790,
            "123qwe"
          ],
          [
            74797,
            "123321"
          ],
          [
            74804,
            "startrek"
          ],
          [
            74813,
            "george"
          ],
          [
            74820,
            "winner"
          ],
          [
            74827,
            "maggie"
          ],
          [
            74834,
            "trinity"
          ],
          [
            74842,
            "online"
          ],
          [
            74849,
            "123abc"
          ],
          [
            74856,
            "chicken"
          ],
          [
            74864,
            "junior"
          ],
          [
            74877,
            "passw0rd"
          ],
          [
            74886,
            "austin"
          ],
          [
            74893,
            "sparky"
          ],
          [
            74900,
            "admin"
          ],
          [
            74906,
            "merlin"
          ],
          [
            74913,
            "google"
          ],
          [
            74920,
            "friends"
          ],
          [
            74928,
            "hope"
          ],
          [
            74933,
            "shalom"
          ],
          [
            74940,
            "nintendo"
          ],
          [
            74949,
            "looking"
          ],
          [
            74957,
            "harley"
          ],
          [
            74964,
            "smokey"
          ],
          [
            74976,
            "joseph"
          ],
          [
            74989,
            "digital"
          ],
          [
            74999,
            "thunder"
          ],
          [
            75007,
            "spirit"
          ],
          [
            75014,
            "bandit"
          ],
          [
            75021,
            "enter"
          ],
          [
            75027,
            "anthony"
          ],
          [
            75035,
            "corvette"
          ],
          [
            75044,
            "hockey"
          ],
          [
            75051,
            "power"
          ],
          [
            75057,
            "benjamin"
          ],
          [
            75083,
            "viper"
          ],
          [
            75089,
            "genesis"
          ],
          [
            75097,
            "knight"
          ],
          [
            75104,
            "qwerty1"
          ],
          [
            75112,
            "creative"
          ],
          [
            75121,
            "foobar"
          ],
          [
            75128,
            "adidas"
          ],
          [
            75135,
            "rotimi"
          ],
          [
            75142,
            "slayer"
          ],
          [
            75149,
            "wisdom"
          ],
          [
            75160,
            "3456"
          ],
          [
            75192,
            "http://www.funfreecasinogames.com/file/panel/gate.php"
          ],
          [
            75448,
            "http://www.funfreecasinogames.com/file/panel/shit.exe"
          ],
          [
            75705,
            "YUIPWDFILE0YUIPKDFILE0YUICRYPTED0YUI1.0"
          ],
          [
            75749,
            "68.85.1.1:19791"
          ],
          [
            75751,
            "MODU"
          ],
          [
            75765,
            "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall"
          ],
          [
            75817,
            "UninstallString"
          ],
          [
            75833,
            "DisplayName"
          ],
          [
            75855,
            ".exe"
          ],
          [
            75860,
            "Software\\WinRAR"
          ],
          [
            75876,
            "open"
          ],
          [
            75885,
            "kernel32.dll"
          ],
          [
            75898,
            "WTSGetActiveConsoleSessionId"
          ],
          [
            75927,
            "ProcessIdToSessionId"
          ],
          [
            75949,
            "netapi32.dll"
          ],
          [
            75962,
            "NetApiBufferFree"
          ],
          [
            75979,
            "NetUserEnum"
          ],
          [
            75992,
            "ole32.dll"
          ],
          [
            76002,
            "StgOpenStorage"
          ],
          [
            76018,
            "advapi32.dll"
          ],
          [
            76031,
            "AllocateAndInitializeSid"
          ],
          [
            76056,
            "CheckTokenMembership"
          ],
          [
            76077,
            "FreeSid"
          ],
          [
            76085,
            "CredEnumerateA"
          ],
          [
            76100,
            "CredFree"
          ],
          [
            76109,
            "CryptGetUserKey"
          ],
          [
            76125,
            "CryptExportKey"
          ],
          [
            76140,
            "CryptDestroyKey"
          ],
          [
            76156,
            "CryptReleaseContext"
          ],
          [
            76176,
            "RevertToSelf"
          ],
          [
            76189,
            "OpenProcessToken"
          ],
          [
            76206,
            "ImpersonateLoggedOnUser"
          ],
          [
            76230,
            "GetTokenInformation"
          ],
          [
            76250,
            "ConvertSidToStringSidA"
          ],
          [
            76273,
            "LogonUserA"
          ],
          [
            76284,
            "LookupPrivilegeValueA"
          ],
          [
            76306,
            "AdjustTokenPrivileges"
          ],
          [
            76329,
            "crypt32.dll"
          ],
          [
            76341,
            "CryptUnprotectData"
          ],
          [
            76360,
            "CertOpenSystemStoreA"
          ],
          [
            76381,
            "CertEnumCertificatesInStore"
          ],
          [
            76409,
            "CertCloseStore"
          ],
          [
            76424,
            "CryptAcquireCertificatePrivateKey"
          ],
          [
            76459,
            "msi.dll"
          ],
          [
            76467,
            "MsiGetComponentPathA"
          ],
          [
            76489,
            "pstorec.dll"
          ],
          [
            76501,
            "PStoreCreateInstance"
          ],
          [
            76639,
            "shell32.dll"
          ],
          [
            76651,
            "SHGetFolderPathA"
          ],
          [
            76737,
            "My Documents"
          ],
          [
            76758,
            "AppData"
          ],
          [
            76774,
            "Local AppData"
          ],
          [
            76796,
            "Cache"
          ],
          [
            76810,
            "Cookies"
          ],
          [
            76826,
            "History"
          ],
          [
            76863,
            "Common AppData"
          ],
          [
            76886,
            "My Pictures"
          ],
          [
            76906,
            "Common Documents"
          ],
          [
            76931,
            "Common Administrative Tools"
          ],
          [
            76967,
            "Administrative Tools"
          ],
          [
            76996,
            "Personal"
          ],
          [
            77005,
            "Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders"
          ],
          [
            77070,
            "explorer.exe"
          ],
          [
            77096,
            "SeImpersonatePrivilege"
          ],
          [
            77119,
            "SeTcbPrivilege"
          ],
          [
            77134,
            "SeChangeNotifyPrivilege"
          ],
          [
            77158,
            "SeCreateTokenPrivilege"
          ]
        ],
        "sz": 92672,
        "ts": [
          {
            "c": 1.0,
            "d": "Binary is not digitally signed",
            "i": "metadata/unsigned",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Fareit Payload",
            "e": [
              "$string1"
            ],
            "i": "third_party/CAPE/Fareit",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "d": "Pony stealer malware",
            "e": [
              "signons.sqlite",
              "signons.txt",
              "signons2.txt",
              "signons3.txt",
              "WininetCacheCredentials",
              "moz_logins",
              "encryptedPassword",
              "FlashFXP",
              "FlashFXP",
              "FlashFXP",
              "FlashFXP",
              "FlashFXP",
              "BulletProof",
              "BulletProof",
              "BulletProof",
              "BulletProof"
            ],
            "i": "third_party/BinaryAlert/Windows/Pony/Stealer",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "d": "autogenerated rule brought to you by yara-signator",
            "e": [
              "$sequence_0",
              "$sequence_1",
              "$sequence_2",
              "$sequence_3",
              "$sequence_4",
              "$sequence_5",
              "$sequence_6",
              "$sequence_7",
              "$sequence_8",
              "$sequence_9"
            ],
            "i": "third_party/Malpedia/Win/Pony/Auto",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "d": "Detects executables referencing many file transfer clients. Observed in information stealers",
            "e": [
              "FTPWare\\COREFTP\\Sites",
              "Far\\Plugins\\FTP\\",
              "Far2\\Plugins\\FTP\\",
              "Ghisler\\Total Commander",
              "LinasFTP\\Site Manager",
              "FTP Explorer\\",
              "FTP Explorer\\",
              "FTP Explorer\\",
              "Far\\SavedDialogHistory\\",
              "Far2\\SavedDialogHistory\\",
              "GlobalSCAPE\\CuteFTP ",
              "GlobalSCAPE\\CuteFTP ",
              "GlobalSCAPE\\CuteFTP ",
              "GlobalSCAPE\\CuteFTP ",
              "GlobalSCAPE\\CuteFTP ",
              "GlobalSCAPE\\CuteFTP "
            ],
            "i": "third_party/Ditekshen/INDICATOR/SUSPICIOUS/EXE/Referenfces/File/Transfer/Clients",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "e": [
              "\\Global Downloader",
              "wiseftpsrvs.bin",
              "SiteServer %d\\SFTP",
              "%s\\Keychain",
              "Connections.txt",
              "ftpshell.fsi",
              "inetcomm server passwords"
            ],
            "i": "third_party/elastic/Windows_Trojan_Pony/windows/trojan/pony",
            "l": 5
          },
          {
            "c": 0.800000011920929,
            "d": "Binary has many functions (\u003e30)",
            "e": [
              "binary.function_count = 441.00"
            ],
            "i": "metadata/binary/metrics::many-functions",
            "l": 2
          },
          {
            "a": "T1005",
            "c": 0.4000000059604645,
            "d": "Generic data extension",
            "e": [
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat",
              ".dat"
            ],
            "i": "objectives/collection/file-targeting/filter::dat-extension",
            "l": 1,
            "m": "B0024"
          },
          {
            "c": 0.8999999761581421,
            "d": "Get tick count",
            "e": [
              "GetTickCount"
            ],
            "i": "micro-behaviors/time/query::get-tick-count",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Free COM memory allocation",
            "e": [
              "CoTaskMemFree"
            ],
            "i": "micro-behaviors/os/com/invoke::co-task-mem-free",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Tool identity claims FileZilla",
            "e": [
              "filezilla",
              "FileZilla",
              "FileZilla"
            ],
            "i": "metadata/package/tooling::tool-identity-filezilla",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Small PE resource section",
            "e": [
              "pe.rsrc_size = 0.00"
            ],
            "i": "metadata/package/versioning::pe-small-rsrc",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Local memory deallocation",
            "e": [
              "LocalFree"
            ],
            "i": "micro-behaviors/mem/alloc/heap::local-free",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "PuTTY identity string",
            "e": [
              "Software\\SimonTatham\\PuTTY\\Sessions"
            ],
            "i": "objectives/supply-chain/trojanized/application/monitor::putty-identity-string",
            "l": 1
          },
          {
            "a": "T1071.001",
            "d": "User-Agent header",
            "e": [
              "User-Agent:",
              "User-Agent:",
              "User-Agent:"
            ],
            "i": "micro-behaviors/communications/http/request::user-agent-header",
            "l": 2,
            "m": "C0002"
          },
          {
            "a": "T1112",
            "c": 0.8500000238418579,
            "d": "Query registry value via import symbol",
            "e": [
              "RegQueryValueExA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-query-value-ex-a-symbol",
            "l": 2
          },
          {
            "c": 0.6499999761581421,
            "d": "Get file size",
            "e": [
              "GetFileSize"
            ],
            "i": "micro-behaviors/fs/sync/fsync::get-file-size",
            "l": 2
          },
          {
            "a": "T1555.003",
            "c": 0.699999988079071,
            "d": "Chromium Login Data database reference",
            "e": [
              "Login Data"
            ],
            "i": "objectives/credential-access/browser/chromium::logins-table",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Close handle",
            "e": [
              "CloseHandle"
            ],
            "i": "micro-behaviors/process/create/spawn::close-handle-dup",
            "l": 2
          },
          {
            "a": "T1070.006",
            "c": 0.699999988079071,
            "d": "PE header compile timestamp predates 2025",
            "e": [
              "pe.timestamp = 1442649594.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::header-timestamp-pre-2025",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Begin directory enumeration ANSI",
            "e": [
              "FindFirstFileA"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-first-file-a",
            "l": 2
          },
          {
            "a": "T1555",
            "c": 0.8999999761581421,
            "d": "FileZilla sitemanager.xml config",
            "e": [
              "\\sitemanager.xml"
            ],
            "i": "objectives/credential-access/ftp/filezilla::sitemanager-xml",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "OpenProcess/NtOpenProcess symbol",
            "e": [
              "OpenProcess"
            ],
            "i": "objectives/evasion/fileless/memory::open-process-sym",
            "l": 1
          },
          {
            "a": "T1053.005",
            "c": 0.8999999761581421,
            "d": "Task Scheduler builder methods",
            "e": [
              "GetFolder",
              "Connect",
              "Connect",
              "Connect",
              "Connect",
              "Connect"
            ],
            "i": "objectives/persistence/login/scheduled-task::task-scheduler-builder-methods",
            "l": 1,
            "m": "F0012"
          },
          {
            "a": "T1106",
            "c": 0.949999988079071,
            "d": "Open process handle",
            "e": [
              "OpenProcess"
            ],
            "i": "micro-behaviors/process/create/spawn::open-process",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Get Windows installation directory",
            "e": [
              "GetWindowsDirectoryA",
              "sub.KERNEL32.DLL_GetWindowsDirectoryA"
            ],
            "i": "micro-behaviors/os/sysinfo/directories::get-windows-directory",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Uses internet communication API imports",
            "e": [
              "WSAStartup"
            ],
            "i": "micro-behaviors/communications/http::has-internet-communication-apis",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 40+ imports",
            "e": [
              "binary.import_count = 91.00"
            ],
            "i": "metadata/binary/metrics::many-imports-40",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Get module file path (ANSI)",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/os/module/load::get-module-filename-ansi",
            "l": 2
          },
          {
            "d": "password keyword",
            "e": [
              "\u003cPOP3_Password2",
              "password_value",
              "MS IE FTP Passwords",
              "password1",
              "FtpPassword",
              "PassWord",
              "password",
              "password 51:b:",
              "PasswordType",
              "\"password\" : \"",
              "_FtpPassword",
              "SELECT hostname, encryptedUsername, encryptedPassword FROM moz_logins",
              "FTP destination password",
              "LastPassword",
              "Password",
              "_Password"
            ],
            "i": "micro-behaviors/data/text/keywords::password",
            "l": 1
          },
          {
            "c": 1.0,
            "d": ".bat extension",
            "e": [
              ".bat"
            ],
            "i": "objectives/command-and-control/dropper/builder::bat-ext",
            "l": 1
          },
          {
            "c": 0.20000000298023224,
            "d": "command keyword",
            "e": [
              "Opera.HTML\\shell\\open\\command",
              "FTP++.Link\\shell\\open\\command"
            ],
            "i": "micro-behaviors/data/text/keywords::command-dup",
            "l": 1
          },
          {
            "a": "T1005",
            "c": 0.550000011920929,
            "d": "Generic database extension",
            "e": [
              ".db",
              ".db",
              ".db"
            ],
            "i": "objectives/collection/file-targeting/filter::db-extension",
            "l": 1,
            "m": "B0024"
          },
          {
            "c": 0.949999988079071,
            "d": "Binary imports ADVAPI32.dll",
            "e": [
              "advapi32.dll"
            ],
            "i": "metadata/binary/symbols::imports-advapi32-dll",
            "l": 1
          },
          {
            "a": "T1110.001",
            "c": 0.20000000298023224,
            "d": "admin keyword",
            "e": [
              "admin"
            ],
            "i": "micro-behaviors/data/text/keywords/username::admin-keyword",
            "l": 2,
            "m": "B0028"
          },
          {
            "a": "T1027",
            "c": 0.699999988079071,
            "d": "Code section dominates file layout",
            "e": [
              "binary.largest_section_ratio = 0.78"
            ],
            "i": "objectives/anti-static/obfuscation/string/anomaly::dominant-text-section",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1005",
            "c": 0.75,
            "d": "SQLite extension",
            "e": [
              ".sqlite",
              ".sqlite",
              ".sqlite"
            ],
            "i": "objectives/collection/file-targeting/filter::sqlite-extension",
            "l": 1,
            "m": "B0024"
          },
          {
            "c": 0.699999988079071,
            "d": "GetModuleFileName API call",
            "e": [
              "GetModuleFileNameA",
              "sub.KERNEL32.DLL_GetModuleFileNameA"
            ],
            "i": "micro-behaviors/process/info/current::get-module-filename",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary is not position-independent (fixed load address)",
            "e": [
              "binary.is_pie = 0.00"
            ],
            "i": "metadata/hardening::no-pie",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "HTTP GET method",
            "e": [
              "GET %s HTTP/1.0"
            ],
            "i": "micro-behaviors/communications/http/get::get",
            "l": 3
          },
          {
            "c": 1.0,
            "d": "Binary has low average complexity",
            "e": [
              "binary.avg_complexity = 4.97"
            ],
            "i": "metadata/binary/metrics::avg-complexity-15-max",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Directory enumeration (ANSI)",
            "e": [
              "FindNextFileA"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-next-file-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "SQLite format header",
            "e": [
              "SQLite format 3"
            ],
            "i": "micro-behaviors/data/db/conn/sqlite::sqlite-format",
            "l": 3
          },
          {
            "c": 1.0,
            "d": "Binary has low average string entropy",
            "e": [
              "binary.avg_string_entropy = 3.07"
            ],
            "i": "metadata/binary/metrics::avg-string-entropy-4-max",
            "l": 2
          },
          {
            "c": 0.75,
            "d": "HTTP protocol version strings",
            "e": [
              "HTTP/1.0",
              "HTTP/1.0"
            ],
            "i": "micro-behaviors/communications/http/request::http-versions",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "PE has few sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "metadata/binary/layout::legacy-few-sections",
            "l": 2
          },
          {
            "c": 0.6600000262260437,
            "d": "Delete files (Windows API ANSI)",
            "e": [
              "DeleteFileA"
            ],
            "i": "micro-behaviors/fs/file/delete::deletefile-a",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "NCapture launches explorer",
            "e": [
              "explorer.exe"
            ],
            "i": "well-known/app/graphics::ncapture-explorer",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Check if running under WoW64",
            "e": [
              "IsWow64Process"
            ],
            "i": "micro-behaviors/os/compat/wow64::is-wow64-process",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Get module handle ANSI",
            "e": [
              "GetModuleHandleA"
            ],
            "i": "micro-behaviors/os/module/load::get-module-handle-ansi",
            "l": 2
          },
          {
            "a": "T1555",
            "c": 0.8500000238418579,
            "d": "FileZilla application directory",
            "e": [
              "Software\\FileZilla",
              "Software\\FileZilla Client"
            ],
            "i": "objectives/credential-access/ftp/filezilla::application-path",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.8799999952316284,
            "d": "Dense short mixed-case data tokens",
            "e": [
              "Microsoft",
              "Software",
              "FreeSid",
              "CredFree",
              "Documents",
              "AppData",
              "Local",
              "Cache",
              "Cookies",
              "History",
              "Common",
              "Pictures",
              "Common",
              "Common",
              "Tools",
              "Personal"
            ],
            "i": "objectives/anti-static/obfuscation/string::dense-short-mixedcase-data-tokens",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.8999999761581421,
            "d": "Exit current process",
            "e": [
              "ExitProcess"
            ],
            "i": "micro-behaviors/process/terminate/kill::exit-process",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "High-risk token privilege name",
            "e": [
              "SeImpersonatePrivilege",
              "SeTcbPrivilege",
              "SeAssignPrimaryTokenPrivilege"
            ],
            "i": "objectives/privilege-escalation/token-manipulation::dangerous-privilege-name",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Delay execution",
            "e": [
              "Sleep"
            ],
            "i": "micro-behaviors/time/timing/delay::sleep-dup",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Create COM object instance",
            "e": [
              "CoCreateInstance"
            ],
            "i": "micro-behaviors/os/com/invoke::co-create-instance",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.7799999713897705,
            "d": "HTTP POST request line",
            "e": [
              "POST %s HTTP/1.0"
            ],
            "i": "micro-behaviors/communications/http/post::post-request-line",
            "l": 3,
            "m": "C0002"
          },
          {
            "a": "T1112",
            "c": 0.8500000238418579,
            "d": "Create registry key via WinAPI",
            "e": [
              "RegCreateKeyA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-create-key-a",
            "l": 2
          },
          {
            "a": "T1112",
            "c": 0.8399999737739563,
            "d": "Open registry key ANSI",
            "e": [
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-open-key-ex-a",
            "l": 2
          },
          {
            "a": "T1485",
            "c": 0.8999999761581421,
            "d": "Preserves .exe .gho .bak files",
            "e": [
              ".exe"
            ],
            "i": "objectives/impact/destroy/file-deletion::exe-gho-bak-whitelist",
            "l": 1,
            "m": "C0047"
          },
          {
            "c": 1.0,
            "d": "File is a compiled binary",
            "e": [
              "binary.file_size = 92672.00"
            ],
            "i": "metadata/binary/framework::is-binary",
            "l": 1
          },
          {
            "d": ".bat extension reference",
            "e": [
              ".bat"
            ],
            "i": "micro-behaviors/fs/path/extension::bat-dup",
            "l": 1
          },
          {
            "a": "T1071.001",
            "d": "HTTP/1.x version string",
            "e": [
              "POST %s HTTP/1.0\r\nHost: %s\r\nAccept: */*…",
              "GET %s HTTP/1.0\r\nHost: %s\r\nAccept: */*…"
            ],
            "i": "micro-behaviors/communications/http/request::http-version",
            "l": 2,
            "m": "C0002"
          },
          {
            "c": 0.800000011920929,
            "d": "Low-entropy rdata section",
            "e": [
              ".rdata (entropy: 3.05)"
            ],
            "i": "metadata/binary/section/metrics::low-entropy-rdata-section",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "PE has many readable strings",
            "e": [
              "binary.string_count = 768.00"
            ],
            "i": "metadata/binary/layout::many-readable-strings",
            "l": 2
          },
          {
            "a": "T1082",
            "c": 0.8999999761581421,
            "d": "Query system hardware info (CPU cores)",
            "e": [
              "GetSystemInfo"
            ],
            "i": "micro-behaviors/os/sysinfo/hardware::get-system-info",
            "l": 2
          },
          {
            "c": 0.6399999856948853,
            "d": "Delete files (Windows API ANSI)",
            "e": [
              "DeleteFileA"
            ],
            "i": "micro-behaviors/fs/file/delete::deletefile-a-text",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Uses Windows API for file mapping",
            "e": [
              "CreateFileMappingA"
            ],
            "i": "micro-behaviors/fs/memory/mmap::win32-file-mapping",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.6600000262260437,
            "d": "Accept-Encoding header",
            "e": [
              "Accept-Encoding: identity, *;q=0",
              "…\nHost: %s\r\nAccept: */*\r\nAccept-Encoding: identity, *;q=0\r\nConte…",
              "…\nHost: %s\r\nAccept: */*\r\nAccept-Encoding: identity, *;q=0\r\nConne…"
            ],
            "i": "micro-behaviors/communications/http/headers::headers-encoding",
            "l": 2,
            "m": "C0002"
          },
          {
            "c": 1.0,
            "d": "WSAStartup import",
            "e": [
              "WSAStartup"
            ],
            "i": "well-known/malware/trojan/hijack-gen::padodor-wsa-startup-import",
            "l": 1
          },
          {
            "c": 0.8199999928474426,
            "d": "GetWindowsDirectory API string",
            "e": [
              "GetWindowsDirectoryA"
            ],
            "i": "micro-behaviors/os/sysinfo/directories::get-windows-directory-string",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Binary has low overall entropy",
            "e": [
              "binary.overall_entropy = 4.77"
            ],
            "i": "metadata/binary/metrics::low-overall-entropy-binary",
            "l": 1
          },
          {
            "d": ".dll extension reference",
            "e": [
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll"
            ],
            "i": "micro-behaviors/fs/path/extension::dll-dup",
            "l": 2
          },
          {
            "a": "T1555.003",
            "c": 0.949999988079071,
            "d": "Java DPAPI unprotect call",
            "e": [
              "UnprotectData"
            ],
            "i": "objectives/credential-access/discord/token::java-crypt-unprotect-data",
            "l": 1
          },
          {
            "a": "T1071.001",
            "c": 0.8500000238418579,
            "d": "Suspicious PHP endpoint URL (gate/upload/etc)",
            "e": [
              "http://www.funfreecasinogames.com/file/panel/gate.php"
            ],
            "i": "objectives/command-and-control/infrastructure/domain::suspicious-php-filename",
            "l": 4,
            "m": "C0002"
          },
          {
            "a": "T1082",
            "c": 0.6499999761581421,
            "d": "Hostname in binary",
            "e": [
              "Hostname"
            ],
            "i": "micro-behaviors/os/sysinfo/hostname::hostname-string-raw",
            "l": 1,
            "m": "E1082"
          },
          {
            "a": "T1112",
            "c": 0.8799999952316284,
            "d": "Enumerate registry values via import",
            "e": [
              "RegEnumValueA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-enum-value-a-symbol",
            "l": 2
          },
          {
            "c": 0.6800000071525574,
            "d": "Read INI string value",
            "e": [
              "GetPrivateProfileStringA"
            ],
            "i": "micro-behaviors/fs/config/system::read-private-profile-ansi",
            "l": 2
          },
          {
            "a": "T1555",
            "c": 0.8999999761581421,
            "d": "FileZilla main config file",
            "e": [
              "\\filezilla.xml"
            ],
            "i": "objectives/credential-access/ftp/filezilla::filezilla-xml",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "High number of imported symbols (\u003e80)",
            "e": [
              "binary.import_count = 91.00"
            ],
            "i": "metadata/binary/metrics::many-imports",
            "l": 2
          },
          {
            "a": "T1112",
            "c": 0.8799999952316284,
            "d": "Enumerate registry subkeys via import",
            "e": [
              "RegEnumKeyExA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-enum-key-ex-a-symbol",
            "l": 2
          },
          {
            "c": 0.6600000262260437,
            "d": "Look up temp directory via GetTempPath",
            "e": [
              "GetTempPathA"
            ],
            "i": "micro-behaviors/fs/temp/directory::get-temp-path-dup",
            "l": 2
          },
          {
            "a": "T1555.003",
            "c": 0.949999988079071,
            "d": "Firefox PK11SDR_Decrypt function",
            "e": [
              "PK11SDR_Decrypt"
            ],
            "i": "objectives/credential-access/browser/firefox::pk11-decrypt",
            "l": 4,
            "m": "B0028"
          },
          {
            "a": "T1112",
            "c": 0.8500000238418579,
            "d": "Set registry value via WinAPI ANSI",
            "e": [
              "RegSetValueExA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-set-value-ex-a",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 25+ imports",
            "e": [
              "binary.import_count = 91.00"
            ],
            "i": "metadata/binary/metrics::many-imports-25",
            "l": 1
          },
          {
            "c": 0.9900000095367432,
            "d": "Exactly three sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "well-known/malware/worm/ludbaruma::metric-section-count-3",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 50+ imports",
            "e": [
              "binary.import_count = 91.00"
            ],
            "i": "metadata/binary/metrics::many-imports-50",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Winsock receive import",
            "e": [
              "recv"
            ],
            "i": "micro-behaviors/communications/socket/init::recv-api",
            "l": 2
          },
          {
            "c": 0.75,
            "d": "Initialize OLE/COM subsystem",
            "e": [
              "OleInitialize"
            ],
            "i": "micro-behaviors/os/com/invoke::ole-initialize",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Map a file section into memory",
            "e": [
              "MapViewOfFile"
            ],
            "i": "micro-behaviors/fs/memory/mmap::map-view-of-file",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Write data to file handle",
            "e": [
              "WriteFile"
            ],
            "i": "micro-behaviors/fs/file/write::write-file",
            "l": 2
          },
          {
            "a": "T1552.004",
            "c": 0.75,
            "d": "Remote Desktop Protocol extension",
            "e": [
              ".rdp"
            ],
            "i": "objectives/collection/file-targeting/filter::rdp-extension",
            "l": 3,
            "m": "B0024"
          },
          {
            "c": 0.8500000238418579,
            "d": "Query file attributes or existence",
            "e": [
              "GetFileAttributesA"
            ],
            "i": "micro-behaviors/fs/path/check::get-file-attributes",
            "l": 2
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Open registry key via import symbol",
            "e": [
              "RegOpenKeyA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-open-key-a-symbol",
            "l": 2
          },
          {
            "c": 0.7200000286102295,
            "d": "Winsock connect API string",
            "e": [
              "connect"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-connect-api-string",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Winsock send import",
            "e": [
              "send"
            ],
            "i": "micro-behaviors/communications/socket/init::send-api",
            "l": 2
          },
          {
            "c": 0.30000001192092896,
            "d": "secret keyword",
            "e": [
              "secret"
            ],
            "i": "micro-behaviors/data/text/keywords::secret",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Windows file creation/open API",
            "e": [
              "CreateFileA"
            ],
            "i": "micro-behaviors/fs/file/open::file-create-win",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "HTTP User-Agent header",
            "e": [
              "…q=0\r\nConnection: close\r\nUser-Agent: Mozilla/4.0 (compatible…",
              "…ntent-Encoding: binary\r\nUser-Agent: Mozilla/4.0 (compatible…",
              "User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows 98)"
            ],
            "i": "micro-behaviors/communications/http/user-agent::user-agent-header-dup",
            "l": 2
          },
          {
            "a": "T1036.005",
            "c": 0.75,
            "d": "C2 gate.php endpoint",
            "e": [
              "gate.php"
            ],
            "i": "objectives/command-and-control/beacon/network::c2-gate-php-endpoint",
            "l": 1,
            "m": "B0030"
          },
          {
            "a": "T1071.001",
            "c": 0.6000000238418579,
            "d": "HTTP Connection close header",
            "e": [
              "Connection: close"
            ],
            "i": "objectives/command-and-control/channel/http-beacon::http-connection-close-header",
            "l": 1,
            "m": "B0030"
          },
          {
            "a": "T1548.002",
            "c": 0.699999988079071,
            "d": "Shell Open command registry key",
            "e": [
              "\\shell\\open\\command"
            ],
            "i": "objectives/privilege-escalation/elevation-control/uac-bypass/hijack::shell-open-command-reg",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Query current module path",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/fs/path/check::get-module-filename",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 4 or fewer sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "objectives/command-and-control/infrastructure/config::max-sections-4",
            "l": 1
          },
          {
            "c": 0.7200000286102295,
            "d": "Short uppercase mutex token",
            "e": [
              "CONSTRAINT"
            ],
            "i": "micro-behaviors/process/sync/mutex::short-uppercase-token",
            "l": 1,
            "m": "C0042"
          },
          {
            "a": "T1036.005",
            "c": 0.800000011920929,
            "d": "explorer.exe process name",
            "e": [
              "explorer.exe"
            ],
            "i": "objectives/evasion/masquerade/process::explorer-name",
            "l": 1,
            "m": "F0004"
          },
          {
            "c": 0.75,
            "d": "Binary exports no symbols",
            "e": [
              "binary.export_count = 0.00"
            ],
            "i": "metadata/binary/symbols::no-exports",
            "l": 1
          },
          {
            "a": "T1572",
            "c": 1.0,
            "d": "DMW custom SSH tunneling tool password string",
            "e": [
              "password",
              "password",
              "password",
              "password"
            ],
            "i": "objectives/command-and-control/channel/tunnel::dmw-tunnel-pwd",
            "l": 1
          },
          {
            "a": "T1057",
            "d": "Browser app firefox",
            "e": [
              "Firefox",
              "Firefox"
            ],
            "i": "micro-behaviors/process/enumerate/apps::browser-apps-firefox",
            "l": 2,
            "m": "E1592"
          },
          {
            "c": 0.8999999761581421,
            "d": "Close directory enumeration handle",
            "e": [
              "FindClose"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-close",
            "l": 2
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "LoadLibraryA loader API string",
            "e": [
              "LoadLibraryA"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-loadlibrarya-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "c": 0.8999999761581421,
            "d": "sqlite3 string",
            "e": [
              "sqlite3"
            ],
            "i": "micro-behaviors/data/db/conn/sqlite::sqlite3-string",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Winsock socket creation import",
            "e": [
              "socket"
            ],
            "i": "micro-behaviors/communications/socket/init::socket-api",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "PE standard runtime section",
            "e": [
              ".rdata"
            ],
            "i": "metadata/binary/section/names::pe-runtime-standard-section",
            "l": 1
          },
          {
            "a": "T1027.002",
            "c": 0.800000011920929,
            "d": "PEB access via FS segment (x86)",
            "e": [
              "64 a1 30 00 00 00"
            ],
            "i": "micro-behaviors/os/api-resolution/hash-based::peb-fs-access",
            "l": 2,
            "m": "F0004"
          },
          {
            "a": "T1555.003",
            "c": 0.8999999761581421,
            "d": "Firefox logins database",
            "e": [
              "SELECT hostname, encryptedUsername, encryptedPassword FROM moz_logins"
            ],
            "i": "micro-behaviors/fs/path/sensitive/browser::firefox-logins",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "PE mapped image under 768 KiB",
            "e": [
              "pe.size_of_image = 102400.00"
            ],
            "i": "metadata/binary/layout::image-under-768kb",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Local memory allocation",
            "e": [
              "LocalAlloc"
            ],
            "i": "micro-behaviors/mem/alloc/heap::local-alloc",
            "l": 2
          },
          {
            "a": "T1082",
            "c": 0.8799999952316284,
            "d": "Query locale information",
            "e": [
              "GetLocaleInfoA"
            ],
            "i": "micro-behaviors/os/sysinfo/platform::get-locale-info",
            "l": 2
          },
          {
            "a": "T1082",
            "c": 0.8999999761581421,
            "d": "Query Windows version info",
            "e": [
              "GetVersionExA"
            ],
            "i": "micro-behaviors/os/sysinfo/platform::get-version-ex",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Padodor COM instance string",
            "e": [
              "CoCreateInstance"
            ],
            "i": "well-known/malware/trojan/shellobject/padodor::padodor-cocreateinstance-string",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Read current working directory",
            "e": [
              "GetCurrentDirectoryA"
            ],
            "i": "micro-behaviors/fs/traversal/drives::get-current-directory",
            "l": 2
          },
          {
            "a": "T1105",
            "c": 0.800000011920929,
            "d": "Numbered DAT payload filename",
            "e": [
              "ESTdb2.dat"
            ],
            "i": "objectives/command-and-control/dropper/staging::numbered-dat-payload-name",
            "l": 1,
            "m": "B0024"
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Open registry key via import symbol ANSI",
            "e": [
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/access::reg-open-key-ex-a-symbol",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Winsock outbound connect import",
            "e": [
              "connect"
            ],
            "i": "micro-behaviors/communications/socket/init::connect-api",
            "l": 3
          },
          {
            "c": 0.6600000262260437,
            "d": "Create directories (Windows API ANSI)",
            "e": [
              "CreateDirectoryA"
            ],
            "i": "micro-behaviors/fs/directory/mkdir::create-directory-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "WinExec hidden-window flag immediate",
            "e": [
              "53 4b 41 00"
            ],
            "i": "micro-behaviors/process/create/flags::winexec-sw-hide-immediate",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 50+ functions",
            "e": [
              "binary.function_count = 441.00"
            ],
            "i": "metadata/binary/metrics::many-functions-50",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Read data from file handle",
            "e": [
              "ReadFile"
            ],
            "i": "micro-behaviors/fs/file/read::read-file",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Get current process handle",
            "e": [
              "GetCurrentProcess"
            ],
            "i": "micro-behaviors/os/module/load::get-current-process",
            "l": 2
          },
          {
            "a": "T1071",
            "c": 0.6000000238418579,
            "d": "URL with .php endpoint",
            "e": [
              "http://www.funfreecasinogames.com/file/panel/gate.php"
            ],
            "i": "objectives/command-and-control/infrastructure/domain::php-endpoint-url",
            "l": 1
          },
          {
            "a": "T1059.001",
            "c": 0.75,
            "d": "Execute shell command (ShellExecuteA)",
            "e": [
              "ShellExecuteA"
            ],
            "i": "micro-behaviors/process/create/exec::shell-execute-a",
            "l": 3
          },
          {
            "c": 0.6000000238418579,
            "d": "Copyright notice",
            "e": [
              "Copyright",
              "Copyright"
            ],
            "i": "metadata/package/license::copyright-word",
            "l": 2
          },
          {
            "c": 0.7599999904632568,
            "d": "Winsock startup API string",
            "e": [
              "WSAStartup"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-startup-api-string",
            "l": 1
          },
          {
            "a": "T1195.002",
            "c": 0.550000011920929,
            "d": "Plaintext hello beacon token",
            "e": [
              "hello"
            ],
            "i": "objectives/command-and-control/backdoor/binary::plaintext-hello-beacon-token",
            "l": 1,
            "m": "B0025"
          },
          {
            "c": 1.0,
            "d": "Binary has 20+ imports",
            "e": [
              "binary.import_count = 91.00"
            ],
            "i": "metadata/binary/metrics::many-imports-20",
            "l": 1
          },
          {
            "a": "T1053.005",
            "c": 0.8799999952316284,
            "d": "Task action principal properties",
            "e": [
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path",
              "Path"
            ],
            "i": "objectives/persistence/login/scheduled-task::task-action-principal-properties",
            "l": 1,
            "m": "F0012"
          },
          {
            "a": "T1555",
            "c": 0.8999999761581421,
            "d": "FileZilla recentservers.xml config",
            "e": [
              "\\recentservers.xml"
            ],
            "i": "objectives/credential-access/ftp/filezilla::recentservers-xml",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Get system error code",
            "e": [
              "GetLastError"
            ],
            "i": "micro-behaviors/os/exception/error-handling::get-last-error",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE standard code/data section",
            "e": [
              ".text",
              ".data"
            ],
            "i": "metadata/binary/section/names::pe-code-data-standard-section",
            "l": 1
          },
          {
            "a": "T1041",
            "c": 0.6000000238418579,
            "d": "PHP gate endpoint",
            "e": [
              "http://www.funfreecasinogames.com/file/panel/gate.php"
            ],
            "i": "objectives/command-and-control/infrastructure/domain::php-gate",
            "l": 4,
            "m": "C0002"
          },
          {
            "c": 0.699999988079071,
            "d": "gethostbyname import string",
            "e": [
              "gethostbyname"
            ],
            "i": "micro-behaviors/communications/ip/resolve::resolve-gethostbyname-import",
            "l": 2
          },
          {
            "c": 0.9599999785423279,
            "d": "Elex Internet Explorer product resource",
            "e": [
              "Internet Explorer"
            ],
            "i": "well-known/malware/trojan/elex/worm::elex-internet-explorer-product-resource",
            "l": 2
          },
          {
            "c": 0.7799999713897705,
            "d": "HTTP URL prefix marker",
            "e": [
              "http://"
            ],
            "i": "well-known/malware/trojan/elex/lpadv::http-prefix",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "LoadLibrary symbol",
            "e": [
              "LoadLibraryA"
            ],
            "i": "objectives/anti-static/obfuscation/reflection/class::loadlibrary-sym",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Set registry value ANSI",
            "e": [
              "RegSetValueExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-set-value-ex-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Initialize Winsock library",
            "e": [
              "WSAStartup"
            ],
            "i": "micro-behaviors/communications/socket/init::wsa-startup",
            "l": 3
          },
          {
            "a": "T1485",
            "c": 0.699999988079071,
            "d": "Windows Shell Folders registry path",
            "e": [
              "Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders"
            ],
            "i": "objectives/impact/destroy/file-deletion::shell-folders-personal-targeting",
            "l": 2,
            "m": "C0047"
          },
          {
            "c": 1.0,
            "d": "Binary has 3+ functions",
            "e": [
              "binary.function_count = 441.00"
            ],
            "i": "metadata/binary/metrics::few-functions-3",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Tool identity claims WinRAR",
            "e": [
              "WinRAR"
            ],
            "i": "metadata/package/tooling::tool-identity-winrar",
            "l": 1
          },
          {
            "a": "T1071.001",
            "d": "HTTP header syntax marker",
            "e": [
              "HTTP/1.0\r\nHost: "
            ],
            "i": "objectives/command-and-control/channel/http/protocol::http-delimiter",
            "l": 1
          },
          {
            "c": 0.75,
            "d": "INI extension marker",
            "e": [
              ".ini"
            ],
            "i": "well-known/malware/trojan/elex/lpadv::ini-extension",
            "l": 1
          },
          {
            "c": 0.8399999737739563,
            "d": "High basic block count in sparse binary",
            "e": [
              "binary.total_basic_blocks = 3329.00"
            ],
            "i": "metadata/binary/metrics::dense-basic-blocks",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 30+ imports",
            "e": [
              "binary.import_count = 91.00"
            ],
            "i": "metadata/binary/metrics::many-imports-30",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Close registry key",
            "e": [
              "RegCloseKey"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-close-key",
            "l": 2
          },
          {
            "a": "T1562.001",
            "c": 0.8999999761581421,
            "d": "Task Manager process enumeration",
            "e": [
              "Process32Next"
            ],
            "i": "micro-behaviors/process/terminate/kill::taskmgr-process-enum",
            "l": 3,
            "m": "B0001"
          },
          {
            "c": 0.6000000238418579,
            "d": "SELECT SQL keyword in query",
            "e": [
              "SELECT hostname, encryptedUsername, encryptedPassword FROM"
            ],
            "i": "micro-behaviors/data/db/conn/sql::sql-select",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.8399999737739563,
            "d": "VB6 PE with three sections",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "objectives/anti-static/obfuscation/payload::three-section-vb6-layout",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.8999999761581421,
            "d": "Tool identity claims PuTTY",
            "e": [
              "PuTTY"
            ],
            "i": "metadata/package/tooling::tool-identity-putty",
            "l": 1
          },
          {
            "a": "T1071.001",
            "d": "Old Mozilla 4.0 User-Agent",
            "e": [
              "…ng: binary\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 5.0; …",
              "User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows 98)",
              "…ion: close\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 5.0; …"
            ],
            "i": "micro-behaviors/communications/http/headers::ua-mozilla-old",
            "l": 2,
            "m": "C0002"
          },
          {
            "c": 0.699999988079071,
            "d": "PE has low overall entropy",
            "e": [
              "binary.overall_entropy = 4.77"
            ],
            "i": "metadata/binary/layout::low-overall-entropy",
            "l": 2
          },
          {
            "c": 0.8600000143051147,
            "d": "Register unhandled exception filter",
            "e": [
              "SetUnhandledExceptionFilter"
            ],
            "i": "micro-behaviors/os/exception/error-handling::set-unhandled-exception-filter-import",
            "l": 2
          },
          {
            "d": "Content-Type header string",
            "e": [
              "…%lu\r\nConnection: close\r\nContent-Type: application/octet-strea…",
              "Content-Type: application/octet-stream"
            ],
            "i": "micro-behaviors/communications/http/request::content-type-header",
            "l": 1
          },
          {
            "c": 0.7200000286102295,
            "d": "Winsock socket API string",
            "e": [
              "socket"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-socket-api-string",
            "l": 1
          },
          {
            "a": "T1027.007",
            "c": 0.8500000238418579,
            "d": "PEB Ldr access for module enumeration",
            "e": [
              "64 A1 30 00 00 00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::peb-ldr-access",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "a": "T1070.006",
            "c": 0.8999999761581421,
            "d": "Export timestamp is absent",
            "e": [
              "pe.export_timestamp_present = 0.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::export-timestamp-absent",
            "l": 2
          },
          {
            "a": "T1055",
            "c": 0.949999988079071,
            "d": "Huge null run in executable (128+ bytes)",
            "e": [
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00",
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00",
              "00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00"
            ],
            "i": "objectives/anti-static/obfuscation/binary-structure::huge-null-run-text",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary is not digitally signed",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed::unsigned",
            "l": 2
          },
          {
            "a": "T1027.007",
            "c": 0.8600000143051147,
            "d": "PE API hashing indicator present",
            "e": [
              "pe.api_hashing_indicators = 1.00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::pe-api-hashing-indicator-single",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "a": "T1071",
            "c": 0.75,
            "d": "PHP URL endpoint (often used for C2)",
            "e": [
              "http://www.funfreecasinogames.com/file/panel/gate.php"
            ],
            "i": "objectives/command-and-control/infrastructure/domain::php-url",
            "l": 3,
            "m": "C0002"
          },
          {
            "c": 0.6000000238418579,
            "d": "Very few sections (merged/stripped)",
            "e": [
              "binary.section_count = 3.00"
            ],
            "i": "metadata/binary/metrics::few-sections",
            "l": 2
          },
          {
            "a": "T1546.015",
            "c": 0.8199999928474426,
            "d": "InprocServer32 registry write",
            "e": [
              "CLSID\\{11C1D741-A95B-11d2-8A80-0080ADB32FF4}\\InProcServer32"
            ],
            "i": "objectives/persistence/system/registry/com-hijack::inprocserver32-write",
            "l": 3
          },
          {
            "a": "T1552.004",
            "c": 0.800000011920929,
            "d": "PuTTY sessions registry reference",
            "e": [
              "Software\\SimonTatham\\PuTTY\\Sessions"
            ],
            "i": "objectives/credential-access/ssh/key::putty-sessions",
            "l": 4
          },
          {
            "a": "T1555.003",
            "c": 0.949999988079071,
            "d": "Firefox moz_logins SQL query",
            "e": [
              "SELECT hostname, encryptedUsername, encryptedPassword FROM moz_logins"
            ],
            "i": "objectives/credential-access/browser/firefox::moz-logins-sql",
            "l": 4,
            "m": "B0028"
          },
          {
            "c": 0.800000011920929,
            "d": "GUID-formatted mutex name",
            "e": [
              "{CB1F2C0F-8094-4AAC-BCF5-41A64E27F777}",
              "{9EA55529-E122-4757-BC79-E4825F80732C}",
              "{11C1D741-A95B-11d2-8A80-0080ADB32FF4}",
              "{F9043C88-F6F2-101A-A3C9-08002B2F49FB}",
              "{74FF1730-B1F2-4D88-926B-1568FAE61DB7}"
            ],
            "i": "micro-behaviors/process/sync/mutex::guid-mutex",
            "l": 2,
            "m": "C0042"
          },
          {
            "a": "T1082",
            "c": 0.699999988079071,
            "d": "hwid string",
            "e": [
              "HWID"
            ],
            "i": "objectives/discovery/system/fingerprint/machine-id::hwid-string",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "High function count over 200",
            "e": [
              "binary.function_count = 441.00"
            ],
            "i": "metadata/binary/metrics::high-function-count-200",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Binary lacks resource section entirely",
            "e": [
              "binary.rsrc_to_file_ratio = 0.00"
            ],
            "i": "metadata/binary/resource::no-resources",
            "l": 2
          },
          {
            "a": "T1027.007",
            "c": 0.8999999761581421,
            "d": "Kernel32 DLL resolution string",
            "e": [
              "kernel32.dll"
            ],
            "i": "micro-behaviors/os/api-resolution/manual::kernel32-resolver",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "PE executable is unsigned",
            "i": "metadata/signed::unsigned-pe-executable",
            "l": 3
          },
          {
            "d": ".exe extension reference",
            "e": [
              ".exe",
              ".exe",
              ".exe",
              ".exe"
            ],
            "i": "micro-behaviors/fs/path/extension::exe-dup",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "CreateFile API string reference",
            "e": [
              "CreateFile",
              "CreateFile"
            ],
            "i": "micro-behaviors/fs/file/open::createfile-api",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "NetUserEnum remote user enumeration",
            "e": [
              "NetUserEnum"
            ],
            "i": "micro-behaviors/os/service/remote::net-user-enum-source",
            "l": 3
          },
          {
            "a": "T1033",
            "c": 0.8999999761581421,
            "d": "Query current username",
            "e": [
              "GetUserNameA"
            ],
            "i": "micro-behaviors/os/sysinfo/hostname::get-user-name",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Resolve exports with GetProcAddress",
            "e": [
              "GetProcAddress"
            ],
            "i": "micro-behaviors/os/module/load::get-proc-address-import",
            "l": 2
          },
          {
            "c": 0.8799999952316284,
            "d": "CLSID registry path manipulation",
            "e": [
              "CLSID\\{11C1D741-A95B-11d2-8A80-0080ADB32FF4}"
            ],
            "i": "objectives/persistence/system/registry/com-hijack::clsid-registry-path",
            "l": 3
          },
          {
            "a": "T1027",
            "c": 0.800000011920929,
            "d": "Few PE resource entries (no DIALOG/MENU/STRINGTABLE)",
            "e": [
              "pe.resource_count = 0.00"
            ],
            "i": "objectives/evasion/anti-av/heuristic::minimal-pe-resources",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.8199999928474426,
            "d": "Packed loader largest section ratio above 0.65",
            "e": [
              "binary.largest_section_ratio = 0.78"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::packed-loader-largest-section-dominates",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1055.001",
            "c": 0.949999988079071,
            "d": "Dynamic LoadLibraryA resolution for remote injection",
            "e": [
              "LoadLibraryA"
            ],
            "i": "micro-behaviors/process/inject/dll::load-library-a-remote-resolution",
            "l": 3,
            "m": "F0003"
          },
          {
            "c": 0.8999999761581421,
            "d": "Switch current working directory",
            "e": [
              "SetCurrentDirectoryA"
            ],
            "i": "micro-behaviors/fs/traversal/drives::set-current-directory",
            "l": 3
          },
          {
            "a": "T1574.002",
            "c": 0.8999999761581421,
            "d": "Hidden LoadLibraryA string reference",
            "e": [
              "LoadLibraryA"
            ],
            "i": "micro-behaviors/dylib/load::load-library-a-string-no-import",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Android Pictures folder",
            "e": [
              "My Pictures"
            ],
            "i": "objectives/impact/wipe/disk/mass-delete::android-pictures",
            "l": 1
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "GetProcAddress loader API string",
            "e": [
              "GetProcAddress"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-getprocaddress-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "a": "T1027",
            "c": 0.8600000143051147,
            "d": "Long mixed-case identifiers cluster",
            "e": [
              "ProcessIdToSessionId",
              "AllocateAndInitializeSid",
              "CheckTokenMembership",
              "ImpersonateLoggedOnUser",
              "ConvertSidToStringSidA",
              "AdjustTokenPrivileges",
              "CryptAcquireCertificatePrivateKey",
              "GetNativeSystemInfo",
              "WininetCacheCredentials",
              "WideCharToMultiByte",
              "GetWindowsDirectoryA",
              "GetPrivateProfileStringA",
              "SetCurrentDirectoryA",
              "GetPrivateProfileSectionNamesA",
              "GetPrivateProfileIntA",
              "GetCurrentDirectoryA"
            ],
            "i": "objectives/anti-static/obfuscation/string::long-mixedcase-identifiers",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1057",
            "c": 0.8999999761581421,
            "d": "Create process or module snapshot",
            "e": [
              "CreateToolhelp32Snapshot"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::create-toolhelp32-snapshot",
            "l": 3,
            "m": "E1057"
          },
          {
            "c": 0.949999988079071,
            "d": "links shell32.dll (ShellExecuteA)",
            "e": [
              "shell32.dll"
            ],
            "i": "metadata/dylib::shell32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links user32.dll (wsprintfA)",
            "e": [
              "user32.dll"
            ],
            "i": "metadata/dylib::user32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links wsock32.dll (inet_addr, gethostbyname, socket, connect, closesocket, ... +5 more)",
            "e": [
              "wsock32.dll"
            ],
            "i": "metadata/dylib::wsock32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links KERNEL32.DLL (CreateFileA, ReadFile, CloseHandle, WriteFile, lstrlenA, ... +47 more)",
            "e": [
              "KERNEL32.DLL"
            ],
            "i": "metadata/dylib::kernel32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links wininet.dll (InternetCrackUrlA, InternetCreateUrlA)",
            "e": [
              "wininet.dll"
            ],
            "i": "metadata/dylib::wininet/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links userenv.dll (LoadUserProfileA, UnloadUserProfile)",
            "e": [
              "userenv.dll"
            ],
            "i": "metadata/dylib::userenv/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links advapi32.dll (RegOpenKeyExA, RegQueryValueExA, RegCloseKey, RegOpenKeyA, RegEnumKeyExA, ... +6 more)",
            "e": [
              "advapi32.dll"
            ],
            "i": "metadata/dylib::advapi32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links ole32.dll (CreateStreamOnHGlobal, GetHGlobalFromStream, CoCreateGuid, CoTaskMemFree, CoCreateInstance, ... +1 more)",
            "e": [
              "ole32.dll"
            ],
            "i": "metadata/dylib::ole32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links shlwapi.dll (StrStrIA, StrRChrIA, StrToIntA, StrStrA, StrCmpNIA, ... +1 more)",
            "e": [
              "shlwapi.dll"
            ],
            "i": "metadata/dylib::shlwapi/dll",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Drop and execute file from Temp directory",
            "e": [
              "GetTempPathA",
              "WriteFile",
              "ShellExecuteA"
            ],
            "i": "objectives/command-and-control/dropper/staging::temp-file-execution",
            "l": 2
          },
          {
            "a": "T1555",
            "c": 0.949999988079071,
            "d": "FileZilla credential stealer detected",
            "e": [
              "Software\\FileZilla Client",
              "\\sitemanager.xml",
              "\\recentservers.xml",
              "Software\\FileZilla",
              "\\filezilla.xml"
            ],
            "i": "objectives/credential-access/ftp/filezilla::filezilla-stealer",
            "l": 4
          },
          {
            "c": 0.9200000166893005,
            "d": "Directory walker using Win32 find APIs",
            "e": [
              "FindNextFileA",
              "FindFirstFileA",
              "FindClose"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-file-walker",
            "l": 2
          },
          {
            "c": 0.9200000166893005,
            "d": "Dynamically resolve own modules and exports",
            "e": [
              "GetModuleHandleA",
              "GetProcAddress"
            ],
            "i": "micro-behaviors/os/module/load::dynamic-self-resolution-imports",
            "l": 2
          },
          {
            "c": 0.9200000166893005,
            "d": "Winsock client symbol lifecycle",
            "e": [
              "connect",
              "recv",
              "send",
              "socket"
            ],
            "i": "micro-behaviors/communications/socket/init::winsock-client-symbol-lifecycle",
            "l": 3
          },
          {
            "a": "T1027.009",
            "c": 0.800000011920929,
            "d": "File self-reading import chain",
            "e": [
              "ReadFile",
              "CreateFileA",
              "GetFileSize",
              "GetModuleFileNameA"
            ],
            "i": "objectives/anti-static/obfuscation/payload/self-read::self-read-file-import-chain",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Registry key open and query chain",
            "e": [
              "RegOpenKeyExA",
              "RegOpenKeyA",
              "RegQueryValueExA"
            ],
            "i": "micro-behaviors/os/registry/access::registry-read-api-chain",
            "l": 2
          },
          {
            "a": "T1070.004",
            "c": 0.8199999928474426,
            "d": "Resolve own path then delete file",
            "e": [
              "sub.KERNEL32.DLL_GetModuleFileNameA",
              "GetModuleFileNameA",
              "DeleteFileA",
              "DeleteFileA"
            ],
            "i": "objectives/evasion/self-delete/file::module-path-delete",
            "l": 1,
            "m": "F0007"
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Registry key and value write chain",
            "e": [
              "RegCreateKeyA",
              "RegSetValueExA",
              "RegOpenKeyA",
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/access::registry-write-api-chain",
            "l": 2
          },
          {
            "a": "T1057",
            "c": 0.8999999761581421,
            "d": "ToolHelp snapshot enumeration with process access",
            "e": [
              "OpenProcess",
              "CreateToolhelp32Snapshot"
            ],
            "i": "objectives/discovery/process/targeting::toolhelp-enumeration-with-access",
            "l": 3,
            "m": "E1057"
          },
          {
            "a": "T1112",
            "c": 0.8999999761581421,
            "d": "Registry key enumeration API chain",
            "e": [
              "RegEnumValueA",
              "RegOpenKeyExA",
              "RegEnumKeyExA",
              "RegOpenKeyA"
            ],
            "i": "micro-behaviors/os/registry/access::registry-enumeration-api-chain",
            "l": 3
          },
          {
            "a": "T1112",
            "c": 0.9200000166893005,
            "d": "Registry open create and write APIs",
            "e": [
              "RegOpenKeyExA",
              "RegOpenKeyExA",
              "RegOpenKeyA",
              "RegSetValueExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::registry-write-api-chain",
            "l": 3
          }
        ],
        "sha": "eef383ab273ad64f3a9ac927b1ac01b9b204b1a8ac456a005b59af32e7502be4",
        "path": "511321",
        "type": "pe"
      }
    ],
    "tv": "feb13"
  }
}