{
  "ml": {
    "v": "4",
    "fs": [
      {
        "id": 0,
        "prob": 0.9940488338470459,
        "class": 2
      }
    ],
    "prob": 0.99404883,
    "class": 2,
    "oprob": 0.9630141,
    "oclass": 0,
    "version": "v16.16",
    "thresholds": [
      0.9815004,
      0.99404883
    ],
    "analyzed_at": "2026-05-02T07:07:44Z"
  },
  "path": "502370",
  "raw": {
    "v": "4",
    "fs": [
      {
        "f": "KO₈(Er₁₀AlC₅Pr₃DyAs₁₀PXe)H₆(Cm₉F₄Os₆Po₈Db₂Ds)Md₅(Bi₅SiPa)Th₇",
        "x": 1873,
        "id": 0,
        "is": [
          "MoveFileA",
          "FindNextFileA",
          "DeleteProcThreadAttributeList",
          "HeapAlloc",
          "UpdateProcThreadAttribute",
          "HeapFree",
          "GetProcessHeap",
          "CreateRemoteThread",
          "VirtualAlloc",
          "VirtualProtectEx",
          "VirtualAllocEx",
          "ProcessIdToSessionId",
          "VirtualProtect",
          "DuplicateHandle",
          "InitializeProcThreadAttributeList",
          "WriteProcessMemory",
          "GetThreadContext",
          "SetThreadContext",
          "FreeLibrary",
          "VirtualFree",
          "Thread32First",
          "Thread32Next",
          "SetLastError",
          "LoadLibraryA",
          "OpenThread",
          "CreateToolhelp32Snapshot",
          "SuspendThread",
          "ResumeThread",
          "PeekNamedPipe",
          "WaitNamedPipeA",
          "SetNamedPipeHandleState",
          "LocalAlloc",
          "LocalFree",
          "GetComputerNameA",
          "FindClose",
          "TerminateProcess",
          "Process32Next",
          "CopyFileA",
          "FindFirstFileA",
          "FileTimeToSystemTime",
          "GetFileAttributesA",
          "ExpandEnvironmentStringsA",
          "GetLogicalDrives",
          "SystemTimeToTzSpecificLocalTime",
          "GetFullPathNameA",
          "CreateThread",
          "GetVersionExA",
          "GetModuleHandleA",
          "CreateNamedPipeA",
          "GetProcAddress",
          "ReadFile",
          "GetCurrentThread",
          "ConnectNamedPipe",
          "GetCurrentProcess",
          "CloseHandle",
          "GetFileTime",
          "GetCurrentDirectoryA",
          "CreatePipe",
          "GetCurrentDirectoryW",
          "GetLastError",
          "GetStartupInfoA",
          "SetCurrentDirectoryA",
          "FlushFileBuffers",
          "DisconnectNamedPipe",
          "GetEnvironmentVariableA",
          "CreateProcessA",
          "OpenProcess",
          "WriteFile",
          "SetFileTime",
          "WaitForSingleObject",
          "SetEnvironmentVariableA",
          "CompareStringW",
          "CompareStringA",
          "SetEndOfFile",
          "SetEnvironmentVariableW",
          "VirtualQuery",
          "GetModuleFileNameW",
          "SetStdHandle",
          "WriteConsoleW",
          "GetConsoleOutputCP",
          "WriteConsoleA",
          "GetStringTypeW",
          "GetStringTypeA",
          "LCMapStringW",
          "LCMapStringA",
          "GetLocaleInfoA",
          "HeapSize",
          "DebugBreak",
          "RaiseException",
          "QueryPerformanceCounter",
          "GetEnvironmentStringsW",
          "FreeEnvironmentStringsW",
          "GetEnvironmentStrings",
          "FreeEnvironmentStringsA",
          "CreateFileA",
          "GetCurrentProcessId",
          "GetLocalTime",
          "Sleep",
          "Process32First",
          "GetTickCount",
          "SetFilePointer",
          "GetFileType",
          "SetHandleCount",
          "GetConsoleMode",
          "GetModuleHandleW",
          "ExitProcess",
          "MultiByteToWideChar",
          "DeleteFileA",
          "CreateDirectoryA",
          "RemoveDirectoryA",
          "GetCurrentThreadId",
          "GetCommandLineA",
          "GetSystemTimeAsFileTime",
          "UnhandledExceptionFilter",
          "SetUnhandledExceptionFilter",
          "IsDebuggerPresent",
          "HeapCreate",
          "HeapDestroy",
          "DeleteCriticalSection",
          "LeaveCriticalSection",
          "EnterCriticalSection",
          "HeapReAlloc",
          "GetStdHandle",
          "GetModuleFileNameA",
          "TlsGetValue",
          "TlsAlloc",
          "TlsSetValue",
          "TlsFree",
          "InterlockedIncrement",
          "InterlockedDecrement",
          "InitializeCriticalSectionAndSpinCount",
          "GetCPInfo",
          "GetACP",
          "GetOEMCP",
          "IsValidCodePage",
          "RtlUnwind",
          "WideCharToMultiByte",
          "GetConsoleCP",
          "GetUserNameA",
          "CloseServiceHandle",
          "OpenProcessToken",
          "CreateProcessWithLogonW",
          "DeleteService",
          "CryptReleaseContext",
          "CryptAcquireContextA",
          "CryptGenRandom",
          "LogonUserA",
          "CheckTokenMembership",
          "FreeSid",
          "RevertToSelf",
          "AllocateAndInitializeSid",
          "DuplicateTokenEx",
          "LookupAccountSidA",
          "GetTokenInformation",
          "SetSecurityDescriptorDacl",
          "InitializeSecurityDescriptor",
          "CreateProcessAsUserA",
          "AdjustTokenPrivileges",
          "ControlService",
          "QueryServiceStatusEx",
          "ImpersonateNamedPipeClient",
          "ImpersonateLoggedOnUser",
          "LookupPrivilegeValueA",
          "OpenThreadToken",
          "OpenServiceA",
          "OpenSCManagerA",
          "QueryServiceStatus",
          "CreateProcessWithTokenW",
          "StartServiceA",
          "CreateServiceA",
          "HttpQueryInfoA",
          "InternetConnectA",
          "InternetQueryDataAvailable",
          "InternetReadFile",
          "InternetSetOptionA",
          "HttpOpenRequestA",
          "HttpSendRequestA",
          "InternetCloseHandle",
          "InternetQueryOptionA",
          "InternetOpenA",
          "ORDINAL 15",
          "ORDINAL 4",
          "ORDINAL 9",
          "ORDINAL 23",
          "ORDINAL 1",
          "ORDINAL 19",
          "ORDINAL 57",
          "ORDINAL 12",
          "ORDINAL 115",
          "ORDINAL 116",
          "ORDINAL 52",
          "ORDINAL 8",
          "ORDINAL 14",
          "ORDINAL 13",
          "ORDINAL 151",
          "ORDINAL 2",
          "ORDINAL 16",
          "ORDINAL 22",
          "ORDINAL 111",
          "ORDINAL 18",
          "ORDINAL 10",
          "ORDINAL 11",
          "ORDINAL 3",
          "DnsFree",
          "DnsQuery_A",
          "GetIfEntry",
          "GetIpAddrTable",
          "LsaCallAuthenticationPackage",
          "LsaConnectUntrusted",
          "LsaLookupAuthenticationPackage"
        ],
        "ms": {
          "pe": {
            "machine": 332.0,
            "checksum": 232751.0,
            "rsrc_size": 512.0,
            "subsystem": 2.0,
            "timestamp": 1495488078.0,
            "image_base": 268435456.0,
            "rsrc_entropy": 5.1,
            "entry_section": ".text",
            "size_of_image": 274432.0,
            "timestamp_day": 22.0,
            "file_alignment": 512.0,
            "resource_count": 1.0,
            "timestamp_year": 2017.0,
            "characteristics": 41218.0,
            "entry_point_rva": 94033.0,
            "size_of_headers": 1024.0,
            "timestamp_month": 5.0,
            "checksum_present": true,
            "export_timestamp": 1495488077.0,
            "import_dll_count": 7.0,
            "manifest_present": true,
            "checksum_mismatch": true,
            "computed_checksum": 245640.0,
            "section_alignment": 4096.0,
            "number_of_sections": 5.0,
            "resource_timestamp": 0.0,
            "dll_characteristics": 320.0,
            "rich_header_present": true,
            "export_timestamp_day": 22.0,
            "linker_major_version": 9.0,
            "export_timestamp_year": 2017.0,
            "api_hashing_indicators": 1.0,
            "export_timestamp_month": 5.0,
            "suspicious_import_combo": true,
            "export_timestamp_present": true,
            "resource_timestamp_present": false
          },
          "binary": {
            "code_size": 147968.0,
            "file_size": 206848.0,
            "entry_point": 94033.0,
            "code_entropy": 6.64,
            "data_entropy": 4.8,
            "export_count": 1.0,
            "import_count": 210.0,
            "string_count": 554.0,
            "section_count": 5.0,
            "avg_complexity": 8.48,
            "function_count": 637.0,
            "import_density": 1.45,
            "max_complexity": 384.0,
            "string_density": 3.83,
            "overall_entropy": 5.37,
            "avg_basic_blocks": 13.2,
            "avg_section_size": 41164.8,
            "dependency_count": 7.0,
            "entropy_variance": 1.33,
            "function_density": 4.41,
            "avg_function_size": 531.05,
            "avg_string_length": 25.3,
            "complexity_per_kb": 0.06,
            "max_string_length": 314.0,
            "wide_string_count": 6.0,
            "writable_sections": 1.0,
            "avg_string_entropy": 3.15,
            "code_to_data_ratio": 2.56,
            "data_to_file_ratio": 0.04,
            "entry_point_is_rva": true,
            "rsrc_to_file_ratio": 0.0,
            "text_to_file_ratio": 0.72,
            "total_basic_blocks": 8410.0,
            "executable_sections": 1.0,
            "high_entropy_strings": 3.0,
            "string_length_stddev": 32.52,
            "largest_section_ratio": 0.72,
            "sentence_string_count": 119.0,
            "sentence_string_ratio": 0.21,
            "behavioral_import_ratio": 0.06,
            "function_analysis_depth": 2.0,
            "high_complexity_functions": 11.0
          }
        },
        "ss": [
          [
            77,
            "!This program cannot be run in DOS mode."
          ],
          [
            488,
            ".text"
          ],
          [
            567,
            "@.data"
          ],
          [
            608,
            ".rsrc"
          ],
          [
            647,
            "@.reloc"
          ],
          [
            1024,
            "QVHW"
          ],
          [
            1993,
            "xor",
            "xiyKxiy'xiy"
          ],
          [
            2005,
            "xor",
            "ziyGxiyQxiy3xiy"
          ],
          [
            5065,
            "SVW3"
          ],
          [
            10622,
            "QQSVW3"
          ],
          [
            12621,
            "SVWjD_W"
          ],
          [
            14433,
            "LSVW"
          ],
          [
            19985,
            "PWV3"
          ],
          [
            24799,
            "QQSV"
          ],
          [
            28669,
            "QQS3"
          ],
          [
            29133,
            "QSVW"
          ],
          [
            37756,
            "PSSSSSSh"
          ],
          [
            38343,
            "YYSSPhr"
          ],
          [
            47529,
            "VPSW"
          ],
          [
            57421,
            "QQSVW"
          ],
          [
            57831,
            "BW9S"
          ],
          [
            65813,
            "QPQP"
          ],
          [
            87897,
            "t79u"
          ],
          [
            87902,
            "t29u"
          ],
          [
            104731,
            "HHtXHHt"
          ],
          [
            106008,
            "RPSW"
          ],
          [
            111611,
            "HHtYHHt"
          ],
          [
            118534,
            "UVWS"
          ],
          [
            135734,
            "8VVVVV"
          ],
          [
            137197,
            "UQPXY]Y["
          ],
          [
            141211,
            "WWWWV"
          ],
          [
            141577,
            "u99u"
          ],
          [
            143086,
            "QQSV3"
          ],
          [
            145655,
            "QQV3"
          ],
          [
            146010,
            "tq9u"
          ],
          [
            146066,
            "t09u"
          ],
          [
            149920,
            "rijndael"
          ],
          [
            150564,
            "D\u003c\u003cx"
          ],
          [
            151151,
            ",cccc||||wwww{{{{"
          ],
          [
            151172,
            "kkkkoooo"
          ],
          [
            151236,
            "YYYYGGGG"
          ],
          [
            151292,
            "\u0026\u0026\u0026\u00266666????"
          ],
          [
            151428,
            "nnnnZZZZ"
          ],
          [
            151516,
            "9999JJJJLLLLXXXX"
          ],
          [
            151552,
            "CCCCMMMM3333"
          ],
          [
            151584,
            "PPPP\u003c\u003c\u003c\u003c"
          ],
          [
            151888,
            "llllVVVV"
          ],
          [
            151904,
            "eeeezzzz"
          ],
          [
            151924,
            "xxxx%%%%...."
          ],
          [
            151996,
            "ffffHHHH"
          ],
          [
            152016,
            "aaaa5555WWWW"
          ],
          [
            152136,
            "BBBBhhhhAAAA"
          ],
          [
            153304,
            "CCCCDDDD"
          ],
          [
            153436,
            "IIIImmmm"
          ],
          [
            153452,
            "%%%%rrrr"
          ],
          [
            153520,
            "llllppppHHHHPPPP"
          ],
          [
            153560,
            "FFFFWWWW"
          ],
          [
            153724,
            "AAAAOOOOgggg"
          ],
          [
            153836,
            "nnnnGGGG"
          ],
          [
            153908,
            "VVVV\u003e\u003e\u003e\u003eKKKK"
          ],
          [
            154028,
            "____````QQQQ"
          ],
          [
            154204,
            "ccccUUUU!!!!"
          ],
          [
            154660,
            "\u003c\u003cxD"
          ],
          [
            156706,
            "PPxD\u003c\u003c%"
          ],
          [
            157138,
            "aaj_55"
          ],
          [
            163438,
            "BWQP"
          ],
          [
            168804,
            "CorExitProcess"
          ],
          [
            168820,
            "wide",
            "mscoree.dll"
          ],
          [
            168856,
            "runtime error"
          ],
          [
            168876,
            "TLOSS error"
          ],
          [
            168892,
            "SING error"
          ],
          [
            168908,
            "DOMAIN error"
          ],
          [
            168928,
            "R6034\r\nAn application has made an attempt to load the C runtime library incorrectly.\nPlease contact the application's support te"
          ],
          [
            168935,
            "An application has made an attempt to load the C runtime library incorrectly."
          ],
          [
            169013,
            "Please contact the application's support team for more information."
          ],
          [
            169088,
            "R6033\r\n- Attempt to use MSIL code from this assembly during native code initialization\nThis indicates a bug in your application."
          ],
          [
            169095,
            "- Attempt to use MSIL code from this assembly during native code initialization"
          ],
          [
            169175,
            "This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native"
          ],
          [
            169336,
            "R6032\r\n- not enough space for locale information"
          ],
          [
            169343,
            "- not enough space for locale information"
          ],
          [
            169392,
            "R6031\r\n- Attempt to initialize the CRT more than once.\nThis indicates a bug in your application."
          ],
          [
            169399,
            "- Attempt to initialize the CRT more than once."
          ],
          [
            169447,
            "This indicates a bug in your application."
          ],
          [
            169492,
            "R6030\r\n- CRT not initialized"
          ],
          [
            169499,
            "- CRT not initialized"
          ],
          [
            169524,
            "R6028\r\n- unable to initialize heap"
          ],
          [
            169531,
            "- unable to initialize heap"
          ],
          [
            169564,
            "R6027\r\n- not enough space for lowio initialization"
          ],
          [
            169571,
            "- not enough space for lowio initialization"
          ],
          [
            169620,
            "R6026\r\n- not enough space for stdio initialization"
          ],
          [
            169627,
            "- not enough space for stdio initialization"
          ],
          [
            169676,
            "R6025\r\n- pure virtual function call"
          ],
          [
            169683,
            "- pure virtual function call"
          ],
          [
            169716,
            "R6024\r\n- not enough space for _onexit/atexit table"
          ],
          [
            169723,
            "- not enough space for _onexit/atexit table"
          ],
          [
            169772,
            "R6019\r\n- unable to open console device"
          ],
          [
            169779,
            "- unable to open console device"
          ],
          [
            169816,
            "R6018\r\n- unexpected heap error"
          ],
          [
            169823,
            "- unexpected heap error"
          ],
          [
            169852,
            "R6017\r\n- unexpected multithread lock error"
          ],
          [
            169859,
            "- unexpected multithread lock error"
          ],
          [
            169900,
            "R6016\r\n- not enough space for thread data"
          ],
          [
            169907,
            "- not enough space for thread data"
          ],
          [
            169944,
            "This application has requested the Runtime to terminate it in an unusual way.\nPlease contact the application's support team for "
          ],
          [
            169946,
            "This application has requested the Runtime to terminate it in an unusual way."
          ],
          [
            170096,
            "R6009\r\n- not enough space for environment"
          ],
          [
            170103,
            "- not enough space for environment"
          ],
          [
            170137,
            "xor",
            "dci;_YYQdcDI"
          ],
          [
            170140,
            "R6008\r\n- not enough space for arguments"
          ],
          [
            170147,
            "- not enough space for arguments"
          ],
          [
            170184,
            "R6002\r\n- floating point support not loaded"
          ],
          [
            170191,
            "- floating point support not loaded"
          ],
          [
            170232,
            "Microsoft Visual C++ Runtime Library"
          ],
          [
            170280,
            "\u003cprogram name unknown\u003e"
          ],
          [
            170304,
            "Runtime Error!\n\nProgram:"
          ],
          [
            170332,
            "wide",
            "(null)"
          ],
          [
            170348,
            "(null)"
          ],
          [
            170401,
            "700WP"
          ],
          [
            170417,
            "`h````"
          ],
          [
            170452,
            "EncodePointer"
          ],
          [
            170468,
            "wide",
            "KERNEL32.DLL"
          ],
          [
            170496,
            "DecodePointer"
          ],
          [
            170512,
            "FlsFree"
          ],
          [
            170520,
            "FlsSetValue"
          ],
          [
            170532,
            "FlsGetValue"
          ],
          [
            170544,
            "FlsAlloc"
          ],
          [
            170680,
            "ADVAPI32.DLL"
          ],
          [
            170742,
            "700PP"
          ],
          [
            170823,
            "!\"#$%\u0026'()*+,-./0123456789:;\u003c=\u003e?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~"
          ],
          [
            170932,
            "UTF-16LE"
          ],
          [
            170944,
            "UNICODE"
          ],
          [
            170952,
            "Unknown Runtime Check Error"
          ],
          [
            170984,
            "Stack memory around _alloca was corrupted"
          ],
          [
            171028,
            "A local variable was used before it was initialized"
          ],
          [
            171084,
            "Stack memory was corrupted"
          ],
          [
            171120,
            "A cast to a smaller data type has caused a loss of data.  If this was intentional, you should mask the source of the cast with t"
          ],
          [
            171289,
            "char c = (i \u0026 0xFF);"
          ],
          [
            171312,
            "Changing the code in this way will not affect the quality of the resulting optimized code."
          ],
          [
            171408,
            "The value of ESP was not properly saved across a function call.  This is usually a result of calling a function declared with on"
          ],
          [
            171680,
            "Stack around the variable '"
          ],
          [
            171708,
            "' was corrupted."
          ],
          [
            171728,
            "The variable '"
          ],
          [
            171744,
            "' is being used without being initialized."
          ],
          [
            171788,
            "Run-Time Check Failure #%d - %s"
          ],
          [
            171820,
            "Unknown Module Name"
          ],
          [
            171840,
            "Unknown Filename"
          ],
          [
            171864,
            "wide",
            "Run-Time Check Failure #%d - %s"
          ],
          [
            171928,
            "wide",
            "Runtime Check Error.\n\r Unable to display RTC Message."
          ],
          [
            172036,
            "Stack corrupted near unknown variable"
          ],
          [
            172076,
            "Stack around _alloca corrupted"
          ],
          [
            172108,
            "Local variable used before initialization"
          ],
          [
            172152,
            "Stack memory corruption"
          ],
          [
            172176,
            "Cast to smaller type causing loss of data"
          ],
          [
            172220,
            "Stack pointer corruption"
          ],
          [
            172268,
            "GetProcessWindowStation"
          ],
          [
            172292,
            "GetUserObjectInformationA"
          ],
          [
            172320,
            "GetLastActivePopup"
          ],
          [
            172340,
            "GetActiveWindow"
          ],
          [
            172356,
            "MessageBoxA"
          ],
          [
            172368,
            "USER32.DLL"
          ],
          [
            173154,
            "wide",
            "h((((                  H"
          ],
          [
            173832,
            "!\"#$%\u0026'()*+,-./0123456789:;\u003c=\u003e?@abcdefghijklmnopqrstuvwxyz[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~"
          ],
          [
            174216,
            "!\"#$%\u0026'()*+,-./0123456789:;\u003c=\u003e?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~"
          ],
          [
            174452,
            "dddd, MMMM dd, yyyy"
          ],
          [
            174472,
            "MM/dd/yy"
          ],
          [
            174492,
            "December"
          ],
          [
            174504,
            "November"
          ],
          [
            174516,
            "October"
          ],
          [
            174524,
            "September"
          ],
          [
            174536,
            "August"
          ],
          [
            174544,
            "July"
          ],
          [
            174552,
            "June"
          ],
          [
            174560,
            "April"
          ],
          [
            174568,
            "March"
          ],
          [
            174576,
            "February"
          ],
          [
            174588,
            "January"
          ],
          [
            174644,
            "Saturday"
          ],
          [
            174656,
            "Friday"
          ],
          [
            174664,
            "Thursday"
          ],
          [
            174676,
            "Wednesday"
          ],
          [
            174688,
            "Tuesday"
          ],
          [
            174696,
            "Monday"
          ],
          [
            174704,
            "Sunday"
          ],
          [
            174740,
            "MSPDB80.DLL"
          ],
          [
            174752,
            "EnvironmentDirectory"
          ],
          [
            174776,
            "SOFTWARE\\Microsoft\\VisualStudio\\9.0\\Setup\\VS"
          ],
          [
            174824,
            "RegCloseKey"
          ],
          [
            174836,
            "RegQueryValueExA"
          ],
          [
            174856,
            "RegOpenKeyExA"
          ],
          [
            174876,
            "PDBOpenValidate5"
          ],
          [
            174896,
            "SunMonTueWedThuFriSat"
          ],
          [
            174920,
            "JanFebMarAprMayJunJulAugSepOctNovDec"
          ],
          [
            175020,
            "cdn.%x%x.%s"
          ],
          [
            175032,
            "www6.%x%x.%s"
          ],
          [
            175048,
            "%s.1%x.%x%x.%s"
          ],
          [
            175064,
            "%s.4%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x%08x%08x.%x%x.%s"
          ],
          [
            175184,
            "%s.3%08x%08x%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x%08x%08x.%x%x.%s"
          ],
          [
            175288,
            "%s.2%08x%08x%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x%08x%08x.%x%x.%s"
          ],
          [
            175360,
            "%s.2%08x%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x%08x.%x%x.%s"
          ],
          [
            175424,
            "%s.2%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x.%x%x.%s"
          ],
          [
            175480,
            "%s.1%08x%08x%08x%08x%08x%08x%08x.%x%x.%s"
          ],
          [
            175524,
            "%s.1%08x%08x%08x%08x%08x%08x.%x%x.%s"
          ],
          [
            175564,
            "%s.1%08x%08x%08x%08x%08x.%x%x.%s"
          ],
          [
            175600,
            "%s.1%08x%08x%08x%08x.%x%x.%s"
          ],
          [
            175632,
            "%s.1%08x%08x%08x.%x%x.%s"
          ],
          [
            175660,
            "%s.1%08x%08x.%x%x.%s"
          ],
          [
            175684,
            "%s.1%08x.%x%x.%s"
          ],
          [
            175704,
            "api.%x%x.%s"
          ],
          [
            175716,
            "unknown"
          ],
          [
            175728,
            "could not run command (w/ token) because of its length of %d bytes!"
          ],
          [
            175796,
            "could not spawn %s (token): %d"
          ],
          [
            175828,
            "could not spawn %s: %d"
          ],
          [
            175852,
            "Could not open process token: %d (%u)"
          ],
          [
            175892,
            "could not run %s as %s\\%s: %d"
          ],
          [
            175924,
            "COMSPEC"
          ],
          [
            175940,
            "could not upload file: %d"
          ],
          [
            175968,
            "could not open %s: %d"
          ],
          [
            175992,
            "could not get file time: %d"
          ],
          [
            176020,
            "could not set file time: %d"
          ],
          [
            176060,
            "Could not connect to pipe (%s): %d"
          ],
          [
            176096,
            "Could not open service control manager on %s: %d"
          ],
          [
            176148,
            "Could not create service %s on %s: %d"
          ],
          [
            176188,
            "Could not start service %s on %s: %d"
          ],
          [
            176228,
            "Started service %s on %s"
          ],
          [
            176256,
            "Could not query service %s on %s: %d"
          ],
          [
            176296,
            "Could not delete service %s on %s: %d"
          ],
          [
            176336,
            "SeDebugPrivilege"
          ],
          [
            176356,
            "SeTcbPrivilege"
          ],
          [
            176372,
            "SeCreateTokenPrivilege"
          ],
          [
            176396,
            "SeAssignPrimaryTokenPrivilege"
          ],
          [
            176428,
            "SeLockMemoryPrivilege"
          ],
          [
            176452,
            "SeIncreaseQuotaPrivilege"
          ],
          [
            176480,
            "SeUnsolicitedInputPrivilege"
          ],
          [
            176508,
            "SeMachineAccountPrivilege"
          ],
          [
            176536,
            "SeSecurityPrivilege"
          ],
          [
            176556,
            "SeTakeOwnershipPrivilege"
          ],
          [
            176584,
            "SeLoadDriverPrivilege"
          ],
          [
            176608,
            "SeSystemProfilePrivilege"
          ],
          [
            176636,
            "SeSystemtimePrivilege"
          ],
          [
            176660,
            "SeProfileSingleProcessPrivilege"
          ],
          [
            176692,
            "SeIncreaseBasePriorityPrivilege"
          ],
          [
            176724,
            "SeCreatePagefilePrivilege"
          ],
          [
            176752,
            "SeCreatePermanentPrivilege"
          ],
          [
            176780,
            "SeBackupPrivilege"
          ],
          [
            176800,
            "SeRestorePrivilege"
          ],
          [
            176820,
            "SeShutdownPrivilege"
          ],
          [
            176840,
            "SeAuditPrivilege"
          ],
          [
            176860,
            "SeSystemEnvironmentPrivilege"
          ],
          [
            176892,
            "SeChangeNotifyPrivilege"
          ],
          [
            176916,
            "SeRemoteShutdownPrivilege"
          ],
          [
            176944,
            "SeUndockPrivilege"
          ],
          [
            176964,
            "SeSyncAgentPrivilege"
          ],
          [
            176988,
            "SeEnableDelegationPrivilege"
          ],
          [
            177016,
            "SeManageVolumePrivilege"
          ],
          [
            177040,
            "Could not create service: %d"
          ],
          [
            177072,
            "Could not start service: %d"
          ]
        ],
        "sz": 206848,
        "ts": [
          {
            "c": 1.0,
            "d": "Binary is not digitally signed",
            "i": "metadata/unsigned",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Cobalt Strike's resources/beacon.dll Versions 3.8",
            "e": [
              "$version_sig",
              "$decoder"
            ],
            "i": "third_party/GCTI/Cobaltstrike/Resources/Beacon/Dll/V3",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "d": "autogenerated rule brought to you by yara-signator",
            "e": [
              "$sequence_0",
              "$sequence_1",
              "$sequence_3",
              "$sequence_4",
              "$sequence_5",
              "$sequence_6",
              "$sequence_7",
              "$sequence_8",
              "$sequence_10",
              "$sequence_11",
              "$sequence_11",
              "$sequence_16"
            ],
            "i": "third_party/Malpedia/Win/Cobalt/Strike/Auto",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "d": "Rule to detect CobaltStrike beacon",
            "e": [
              "$pattern_0",
              "$pattern_1",
              "$pattern_2",
              "$pattern_2",
              "$pattern_3",
              "$pattern_4",
              "$pattern_5",
              "$pattern_6",
              "$pattern_7",
              "$pattern_8",
              "$pattern_9"
            ],
            "i": "third_party/Trellix/ARC/MALW/Cobaltrike",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "d": "The CobaltStrike malware family, variant D.",
            "e": [
              "%s (admin)",
              "$s2",
              "%02d/%02d/%02d %02d:%02d:%02d",
              "%02d/%02d/%02d %02d:%02d:%02d",
              "%s as %s\\%s: %d",
              "%s\u0026%s=%s",
              "rijndael",
              "(null)"
            ],
            "i": "third_party/Volexity/Win/Cobaltstrike/D",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "d": "Detects Reflective DLL injection artifacts",
            "e": [
              "_ReflectiveLoader@",
              "ReflectiveLoader@"
            ],
            "i": "third_party/Ditekshen/INDICATOR/SUSPICIOUS/Reflectiveloader",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "d": "CobaltStrike payload",
            "e": [
              "%%IMPORT%%",
              "www6.%x%x.%s",
              "cdn.%x%x.%s",
              "api.%x%x.%s",
              "%s (admin)",
              "could not spawn %s: %d",
              "Could not kill %d: %d",
              "Could not connect to pipe (%s): %d",
              "%s.1%x.%x%x.%s",
              "\u003c119 bytes\u003e",
              "%s.3%08x%08x%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x%08x%08x.%x%x.%s",
              "%s.2%08x%08x%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x%08x%08x.%x%x.%s",
              "%s.2%08x%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x%08x.%x%x.%s",
              "%s.2%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x.%x%x.%s",
              "%s.1%08x%08x%08x%08x%08x%08x%08x.%x%x.%s",
              "%s.1%08x%08x%08x%08x%08x%08x.%x%x.%s"
            ],
            "i": "third_party/Ditekshen/Win/Cobaltstrike",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "d": "Detects CobaltStrike C2 encoded profile configuration",
            "e": [
              "$s105"
            ],
            "i": "third_party/SigBase/Cobaltstrike/C2/Encoded/XOR/Config/Indicator",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "d": "Detects unmodified CobaltStrike beacon DLL",
            "e": [
              "ReflectiveLoader",
              "beacon.dll"
            ],
            "i": "third_party/SigBase/Cobaltstrike/Unmodifed/Beacon",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "d": "Detects a unspecified hack tool, crack or malware using a reflective loader - no hard match - further investigation recommended",
            "e": [
              "ReflectiveLoader"
            ],
            "i": "third_party/SigBase/Reflectiveloader",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "d": "Detects Meterpreter in-memory",
            "e": [
              "WS2_32.dll",
              "ReflectiveLoader"
            ],
            "i": "third_party/SigBase/HKTL/Meterpreter/Inmemory",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "d": "Detects reflective loader (Cobalt Strike) used in Operation Wilted Tulip",
            "e": [
              "powershell -nop -exec bypass -EncodedCommand \"%s\"",
              "%d is an x86 process (can't inject x64 content)",
              "IEX (New-Object Net.Webclient).DownloadString('http://127.0.0.1:%u/'); %s",
              "Failed to impersonate token from %d (%u)",
              "Failed to impersonate logged on user %d (%u)",
              "\u003c119 bytes\u003e"
            ],
            "i": "third_party/SigBase/Wiltedtulip/Reflectiveloader",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "d": "VT Research QA uploaded malware - file vqgk.dll",
            "e": [
              "%d is an x86 process (can't inject x64 content)",
              "%d is an x64 process (can't inject x86 content)",
              "powershell -nop -exec bypass -EncodedCommand \"%s\"",
              "Could not open process token: %d (%u)",
              "Failed to impersonate logged on user %d (%u)",
              "IEX (New-Object Net.Webclient).DownloadString('http://127.0.0.1:%u/'); %s",
              "could not write to process memory: %d",
              "beacon.dll",
              "Failed to impersonate token from %d (%u)"
            ],
            "i": "third_party/SigBase/QA/Vqgk",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "d": "Identifies strings used in Cobalt Strike Beacon DLL",
            "e": [
              "%02d/%02d/%02d %02d:%02d:%02d",
              "%02d/%02d/%02d %02d:%02d:%02d",
              "Started service %s on %s",
              "%s as %s\\%s: %d"
            ],
            "i": "third_party/SigBase/HKTL/Cobaltstrike/Beacon/Strings",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "d": "The CobaltStrike malware family.",
            "e": [
              "%s (admin)",
              "$s2",
              "%02d/%02d/%02d %02d:%02d:%02d",
              "%02d/%02d/%02d %02d:%02d:%02d",
              "%s as %s\\%s: %d",
              "%s\u0026%s=%s",
              "rijndael",
              "(null)"
            ],
            "i": "third_party/SigBase/HKTL/Win/Cobaltstrike",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "d": "Detects Cobalt Strike sample from Leviathan report",
            "e": [
              "%d is an x64 process (can't inject x86 content)",
              "Failed to impersonate logged on user %d (%u)",
              "powershell -nop -exec bypass -EncodedCommand \"%s\"",
              "IEX (New-Object Net.Webclient).DownloadString('http://127.0.0.1:%u/'); %s",
              "could not run command (w/ token) because of its length of %d bytes!",
              "could not write to process memory: %d",
              "\u003c119 bytes\u003e",
              "Could not connect to pipe (%s): %d"
            ],
            "i": "third_party/SigBase/Leviathan/Cobaltstrike/Sample",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "d": "Attempts to detect Cobalt Strike based on strings found in BEACON",
            "e": [
              "\u003c119 bytes\u003e",
              "%s.3%08x%08x%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x%08x%08x.%x%x.%s",
              "ppid %d is in a different desktop session (spawned jobs may fail). Use 'ppid' to reset.",
              "IEX (New-Object Net.Webclient).DownloadString('http://127.0.0.1:%u/'); %s",
              "IEX (New-Object Net.Webclient).DownloadString('http://127.0.0.1:%u/')",
              "IEX (New-Object Net.Webclient).DownloadString('http://127.0.0.1:%u/')",
              "%s.2%08x%08x%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x%08x%08x.%x%x.%s",
              "could not run command (w/ token) because of its length of %d bytes!",
              "%s.2%08x%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x%08x.%x%x.%s",
              "%s.2%08x%08x%08x%08x%08x.%08x%08x%08x%08x%08x.%x%x.%s",
              "powershell -nop -exec bypass -EncodedCommand \"%s\"",
              "Could not open service control manager on %s: %d",
              "%d is an x64 process (can't inject x86 content)",
              "%d is an x86 process (can't inject x64 content)",
              "Failed to impersonate logged on user %d (%u)",
              "could not create remote thread in %d: %d"
            ],
            "i": "third_party/elastic/Windows_Trojan_CobaltStrike/windows/trojan/cobaltstrike",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "d": "Identifies the API address lookup function used by metasploit. Also used by other tools (like beacon).",
            "e": [
              "$a1"
            ],
            "i": "third_party/elastic/Windows_Trojan_Metasploit/windows/trojan/metasploit",
            "l": 5
          },
          {
            "c": 0.8999999761581421,
            "d": "Detects PowerShell invocation with suspicious parameters",
            "e": [
              " -EncodedCommand ",
              " -nop ",
              " -exec bypass ",
              " -exec bypass "
            ],
            "i": "third_party/SigBase/Powershell/Susp/Parameter/Combo",
            "l": 5
          },
          {
            "d": "COMPUTERNAME environment variable",
            "e": [
              "GetComputerNameA"
            ],
            "i": "micro-behaviors/os/env/vars/system-info::computername-var",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Get local time",
            "e": [
              "GetLocalTime"
            ],
            "i": "micro-behaviors/time/query::get-local-time",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.949999988079071,
            "d": "HttpSendRequest WinInet API",
            "e": [
              "HttpSendRequestA"
            ],
            "i": "micro-behaviors/communications/http/post::http-send-request",
            "l": 3,
            "m": "C0002"
          },
          {
            "c": 0.800000011920929,
            "d": "Release wide environment block",
            "e": [
              "FreeEnvironmentStringsW"
            ],
            "i": "micro-behaviors/os/env/access::free-environment-strings-wide",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Uses named pipe IPC APIs",
            "e": [
              "PeekNamedPipe",
              "WaitNamedPipeA",
              "SetNamedPipeHandleState",
              "CreateNamedPipeA",
              "ConnectNamedPipe",
              "DisconnectNamedPipe",
              "ImpersonateNamedPipeClient"
            ],
            "i": "micro-behaviors/communications/ipc/named-pipe::named-pipe-api-usage",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "PE has many readable strings",
            "e": [
              "binary.string_count = 554.00"
            ],
            "i": "metadata/binary/layout::many-readable-strings",
            "l": 2
          },
          {
            "c": 0.6399999856948853,
            "d": "Delete files (Windows API ANSI)",
            "e": [
              "DeleteFileA"
            ],
            "i": "micro-behaviors/fs/file/delete::deletefile-a-text",
            "l": 2
          },
          {
            "c": 0.75,
            "d": "Printable ASCII substitution table",
            "e": [
              "!\"#$%\u0026'()*+,-./0123456789:;\u003c=\u003e?@abcdefghijklmnopqrstuvwxyz[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~"
            ],
            "i": "micro-behaviors/data/encode/charset::printable-ascii-substitution-table",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Binary has many functions (\u003e30)",
            "e": [
              "binary.function_count = 637.00"
            ],
            "i": "metadata/binary/metrics::many-functions",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Local memory deallocation",
            "e": [
              "LocalFree"
            ],
            "i": "micro-behaviors/mem/alloc/heap::local-free",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Exit current process",
            "e": [
              "ExitProcess"
            ],
            "i": "micro-behaviors/process/terminate/kill::exit-process",
            "l": 2
          },
          {
            "a": "T1486",
            "c": 0.8999999761581421,
            "d": "Acquire cryptographic service provider context",
            "e": [
              "CryptAcquireContextA"
            ],
            "i": "micro-behaviors/crypto/library::crypt-acquire-context",
            "l": 2,
            "m": "C0027"
          },
          {
            "c": 0.8999999761581421,
            "d": "Release cryptographic context",
            "e": [
              "CryptReleaseContext"
            ],
            "i": "micro-behaviors/crypto/library::crypt-release-context",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "ws2_32 ordinal 23 (socket)",
            "e": [
              "ORDINAL 23"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-32-ordinal-23",
            "l": 1
          },
          {
            "a": "T1105, T1204.002",
            "c": 0.8999999761581421,
            "d": "Italian staged download status",
            "e": [
              "Download",
              "Download",
              "download",
              "download",
              "download"
            ],
            "i": "objectives/command-and-control/dropper/delivery/download-execute::italian-download-status-burst",
            "l": 1,
            "m": "E1105"
          },
          {
            "c": 0.8999999761581421,
            "d": "Convert FILETIME to SYSTEMTIME",
            "e": [
              "FileTimeToSystemTime"
            ],
            "i": "micro-behaviors/time/query::filetime-to-systemtime",
            "l": 2
          },
          {
            "a": "T1105",
            "c": 0.9200000166893005,
            "d": "Embedded stage remote thread API",
            "e": [
              "CreateRemoteThread"
            ],
            "i": "objectives/command-and-control/dropper/staging/signed-bundle::embedded-remote-thread-stage",
            "l": 1,
            "m": "B0024"
          },
          {
            "c": 0.20000000298023224,
            "d": "command keyword",
            "e": [
              "could not run command (w/ token) because of its length of %d bytes!"
            ],
            "i": "micro-behaviors/data/text/keywords::command-dup",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Write data to file handle",
            "e": [
              "WriteFile"
            ],
            "i": "micro-behaviors/fs/file/write::write-file",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Binary has many sentence-like strings",
            "e": [
              "binary.sentence_string_ratio = 0.21"
            ],
            "i": "metadata/binary/metrics::rich-sentence-strings-20pct",
            "l": 1
          },
          {
            "c": 0.8500000238418579,
            "d": "Query current module path",
            "e": [
              "GetModuleFileNameW",
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/fs/path/check::get-module-filename",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Set last error code",
            "e": [
              "SetLastError"
            ],
            "i": "micro-behaviors/os/exception/error-handling::set-last-error",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "Windows path join format string",
            "e": [
              "could not run %s as %s\\%s: %d"
            ],
            "i": "micro-behaviors/fs/path/construct::windows-system-path-join-format",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Close handle",
            "e": [
              "CloseHandle"
            ],
            "i": "micro-behaviors/process/create/spawn::close-handle-dup",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "WriteProcessMemory/NtWriteVirtualMemory symbol",
            "e": [
              "WriteProcessMemory"
            ],
            "i": "objectives/evasion/fileless/memory::write-memory-sym",
            "l": 1
          },
          {
            "c": 0.8399999737739563,
            "d": "High PE import count",
            "e": [
              "binary.import_count = 210.00"
            ],
            "i": "metadata/binary/section/metrics::high-import-count-pe",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Unload dynamic library",
            "e": [
              "FreeLibrary"
            ],
            "i": "micro-behaviors/os/module/load::free-library",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.550000011920929,
            "d": "Content-Length printf template",
            "e": [
              "Content-Length: %d"
            ],
            "i": "micro-behaviors/communications/http/headers::content-length-template",
            "l": 2,
            "m": "C0002"
          },
          {
            "c": 0.800000011920929,
            "d": "Duplicate object handle",
            "e": [
              "DuplicateHandle"
            ],
            "i": "micro-behaviors/communications/ipc/pipe::duplicate-handle",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.8999999761581421,
            "d": "HttpOpenRequest API name as string",
            "e": [
              "HttpOpenRequestA"
            ],
            "i": "micro-behaviors/communications/http/get::http-open-request-str",
            "l": 1
          },
          {
            "a": "T1559",
            "c": 0.699999988079071,
            "d": "Wait for named pipe server",
            "e": [
              "WaitNamedPipeA"
            ],
            "i": "micro-behaviors/communications/ipc/named-pipe::wait-named-pipe",
            "l": 3
          },
          {
            "a": "T1071.001",
            "c": 0.8999999761581421,
            "d": "InternetReadFile API name as string",
            "e": [
              "InternetReadFile"
            ],
            "i": "micro-behaviors/communications/http/get::internet-read-file-str",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 40+ imports",
            "e": [
              "binary.import_count = 210.00"
            ],
            "i": "metadata/binary/metrics::many-imports-40",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "ws2_32 ordinal 11 (inet_addr)",
            "e": [
              "ORDINAL 11"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-32-ordinal-11",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Query process window station",
            "e": [
              "GetProcessWindowStation"
            ],
            "i": "micro-behaviors/ui/window/station::get-process-window-station",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.8999999761581421,
            "d": "InternetConnect API name as string",
            "e": [
              "InternetConnectA"
            ],
            "i": "micro-behaviors/communications/http/get::internet-connect-str",
            "l": 1
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "VirtualProtect loader API string",
            "e": [
              "VirtualProtect"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-virtualprotect-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "a": "T1071",
            "c": 1.0,
            "d": "oleaut32 ordinal 2",
            "e": [
              "ORDINAL 2"
            ],
            "i": "objectives/command-and-control/backdoor/binary::oleaut-ordinal-2",
            "l": 1,
            "m": "B0025"
          },
          {
            "a": "T1027.007",
            "c": 0.8500000238418579,
            "d": "MZ header validation in code",
            "e": [
              "B8 4D 5A 00 00",
              "B8 4D 5A 00 00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::mz-magic-check",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "a": "T1106",
            "c": 0.8999999761581421,
            "d": "SeDebugPrivilege string reference",
            "e": [
              "SeDebugPrivilege"
            ],
            "i": "objectives/evasion/anti-av/syscall::sedebug-privilege-ref",
            "l": 1,
            "m": "B0009"
          },
          {
            "c": 0.949999988079071,
            "d": "Binary imports ADVAPI32.dll",
            "e": [
              "ADVAPI32.DLL",
              "ADVAPI32.dll"
            ],
            "i": "metadata/binary/symbols::imports-advapi32-dll",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "Connect to HTTP/FTP server via WinInet",
            "e": [
              "InternetConnectA"
            ],
            "i": "micro-behaviors/communications/http/get::internet-connect",
            "l": 3
          },
          {
            "a": "T1055.001",
            "c": 0.949999988079071,
            "d": "WriteProcessMemory API reference",
            "e": [
              "WriteProcessMemory"
            ],
            "i": "micro-behaviors/process/inject/dll::write-process-memory",
            "l": 3,
            "m": "F0003"
          },
          {
            "c": 0.8600000143051147,
            "d": "VirtualAlloc then VirtualProtect strings",
            "e": [
              "VirtualAlloc[\u0004VirtualProtect"
            ],
            "i": "micro-behaviors/mem/protect/modify::virtualalloc-virtualprotect-pair",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Small PE resource section",
            "e": [
              "pe.rsrc_size = 512.00"
            ],
            "i": "metadata/package/versioning::pe-small-rsrc",
            "l": 1
          },
          {
            "a": "T1587.001",
            "c": 0.8999999761581421,
            "d": "Allocate virtual memory",
            "e": [
              "VirtualAlloc"
            ],
            "i": "micro-behaviors/mem/protect/modify::virtual-alloc",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE .reloc section presence",
            "e": [
              ".reloc"
            ],
            "i": "metadata/binary/section/names::reloc-section-presence",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Raise structured exception",
            "e": [
              "RaiseException"
            ],
            "i": "micro-behaviors/os/exception/raise::raise-exception",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Accesses ComSpec environment variable",
            "e": [
              "COMSPEC"
            ],
            "i": "micro-behaviors/os/env/vars::comspec-env-var",
            "l": 2
          },
          {
            "a": "T1134",
            "c": 0.949999988079071,
            "d": "Update process attribute list",
            "e": [
              "UpdateProcThreadAttribute"
            ],
            "i": "micro-behaviors/process/create/spawn::update-proc-thread-attribute",
            "l": 3
          },
          {
            "c": 0.8600000143051147,
            "d": "asInvoker manifest tag in resources",
            "e": [
              "\u003crequestedExecutionLevel level=\"asInvoker\" uiAccess=\"false\"\u003e"
            ],
            "i": "metadata/binary/resource::asinvoker-resource-manifest-flex",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Get system time as FILETIME",
            "e": [
              "GetSystemTimeAsFileTime"
            ],
            "i": "micro-behaviors/time/query::get-system-time-as-filetime",
            "l": 2
          },
          {
            "c": 0.8399999737739563,
            "d": "Read wide environment block",
            "e": [
              "GetEnvironmentStringsW"
            ],
            "i": "micro-behaviors/os/env/access::get-environment-strings-wide",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "ws2_32 ordinal 115 (WSAStartup)",
            "e": [
              "ORDINAL 115"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-32-ordinal-115",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Enter critical section",
            "e": [
              "EnterCriticalSection"
            ],
            "i": "micro-behaviors/process/sync/critical-section::critical-section-enter",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "WebClient.DownloadString method",
            "e": [
              "IEX (New-Object Net.Webclient).DownloadString('http://127.0.0.1:%u/'); %s",
              "IEX (New-Object Net.Webclient).DownloadString('http://127.0.0.1:%u/')"
            ],
            "i": "micro-behaviors/communications/http/client::downloadstring",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "Tiny writable data section",
            "e": [
              ".data (size: 9216)"
            ],
            "i": "metadata/binary/section/metrics::tiny-data-section",
            "l": 1
          },
          {
            "a": "T1574",
            "c": 0.8999999761581421,
            "d": "Disable WoW64 filesystem redirection",
            "e": [
              "Wow64DisableWow64FsRedirection"
            ],
            "i": "micro-behaviors/os/compat/wow64::wow64-disable-redirect",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE Rich header present (MSVC toolchain)",
            "e": [
              "pe.rich_header_present = 1.00"
            ],
            "i": "metadata/binary/resource::rich-header-present",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Free virtual memory",
            "e": [
              "VirtualFree"
            ],
            "i": "micro-behaviors/mem/protect/modify::virtual-free",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Unicode string locale mapping",
            "e": [
              "LCMapStringW"
            ],
            "i": "micro-behaviors/os/env/access::lcmap-string-w",
            "l": 2
          },
          {
            "c": 0.8199999928474426,
            "d": "Medium entropy rdata section",
            "e": [
              ".rdata (entropy: 6.60)"
            ],
            "i": "metadata/binary/section/metrics::medium-entropy-rdata-section",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Get process heap handle",
            "e": [
              "GetProcessHeap"
            ],
            "i": "micro-behaviors/mem/alloc/heap::get-process-heap",
            "l": 2
          },
          {
            "c": 0.75,
            "d": "Open process access token",
            "e": [
              "OpenProcessToken"
            ],
            "i": "micro-behaviors/os/privilege/token::open-process-token",
            "l": 2
          },
          {
            "a": "T1222.001",
            "c": 0.949999988079071,
            "d": "Extended memory protection modification",
            "e": [
              "VirtualProtectEx"
            ],
            "i": "micro-behaviors/mem/protect/modify::virtual-protect-ex",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "High number of imported symbols (\u003e80)",
            "e": [
              "binary.import_count = 210.00"
            ],
            "i": "metadata/binary/metrics::many-imports",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Get Unicode character type",
            "e": [
              "GetStringTypeW"
            ],
            "i": "micro-behaviors/os/env/access::get-string-type-w",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 25+ imports",
            "e": [
              "binary.import_count = 210.00"
            ],
            "i": "metadata/binary/metrics::many-imports-25",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Set security descriptor DACL",
            "e": [
              "SetSecurityDescriptorDacl"
            ],
            "i": "micro-behaviors/os/security/descriptor::set-security-descriptor-dacl",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 50+ imports",
            "e": [
              "binary.import_count = 210.00"
            ],
            "i": "metadata/binary/metrics::many-imports-50",
            "l": 1
          },
          {
            "c": 0.6600000262260437,
            "d": "Copy files (Windows API ANSI)",
            "e": [
              "CopyFileA"
            ],
            "i": "micro-behaviors/fs/file/copy::copyfile-a",
            "l": 3
          },
          {
            "a": "T1027",
            "c": 0.8199999928474426,
            "d": "Repeated padding marker string block",
            "e": [
              "…XPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX…",
              "\u003c/assembly\u003ePAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX…",
              "…XPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD",
              "…embly\u003ePAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX…"
            ],
            "i": "objectives/anti-static/obfuscation/binary-metrics::repeated-padding-marker",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.75,
            "d": "HTTP protocol version strings",
            "e": [
              "HTTP/1.1"
            ],
            "i": "micro-behaviors/communications/http/request::http-versions",
            "l": 1
          },
          {
            "c": 0.6600000262260437,
            "d": "Delete files (Windows API ANSI)",
            "e": [
              "DeleteFileA"
            ],
            "i": "micro-behaviors/fs/file/delete::deletefile-a",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has low average complexity",
            "e": [
              "binary.avg_complexity = 8.48"
            ],
            "i": "metadata/binary/metrics::avg-complexity-15-max",
            "l": 2
          },
          {
            "c": 0.6600000262260437,
            "d": "Create directories (Windows API ANSI)",
            "e": [
              "CreateDirectoryA"
            ],
            "i": "micro-behaviors/fs/directory/mkdir::create-directory-a",
            "l": 2
          },
          {
            "a": "T1071.004",
            "c": 0.8199999928474426,
            "d": "DNSAPI library reference",
            "e": [
              "DNSAPI.dll"
            ],
            "i": "micro-behaviors/communications/dns/lookup::dnsapi-dll",
            "l": 3,
            "m": "C0011"
          },
          {
            "c": 1.0,
            "d": "Binary has 100+ imports",
            "e": [
              "binary.import_count = 210.00"
            ],
            "i": "metadata/binary/metrics::many-imports-100",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Delete critical section",
            "e": [
              "DeleteCriticalSection"
            ],
            "i": "micro-behaviors/process/sync/critical-section::critical-section-delete",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Thread32Next API string",
            "e": [
              "Thread32Next"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::thread32-next-string",
            "l": 1
          },
          {
            "a": "T1587.001",
            "c": 0.8999999761581421,
            "d": "Allocate virtual memory in process",
            "e": [
              "VirtualAllocEx"
            ],
            "i": "micro-behaviors/mem/protect/modify::virtual-alloc-ex",
            "l": 2
          },
          {
            "a": "T1027.002",
            "c": 0.800000011920929,
            "d": "PEB access via FS segment (x86)",
            "e": [
              "64 a1 30 00 00 00"
            ],
            "i": "micro-behaviors/os/api-resolution/hash-based::peb-fs-access",
            "l": 2,
            "m": "F0004"
          },
          {
            "a": "T1110.001",
            "c": 0.20000000298023224,
            "d": "admin keyword",
            "e": [
              "admin"
            ],
            "i": "micro-behaviors/data/text/keywords/username::admin-keyword",
            "l": 2,
            "m": "B0028"
          },
          {
            "c": 0.949999988079071,
            "d": "Initialize WinInet session",
            "e": [
              "InternetOpenA"
            ],
            "i": "micro-behaviors/communications/http/get::internet-open",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Get file handle type",
            "e": [
              "GetFileType"
            ],
            "i": "micro-behaviors/fs/file/operations::get-file-type",
            "l": 2
          },
          {
            "a": "T1027.003",
            "c": 0.9900000095367432,
            "d": "PE checksum mismatch",
            "e": [
              "pe.checksum_mismatch = 1.00"
            ],
            "i": "objectives/anti-static/obfuscation/payload/container::pe-checksum-mismatch-png",
            "l": 1,
            "m": "F0001.006"
          },
          {
            "c": 0.8999999761581421,
            "d": "Get standard I/O handle",
            "e": [
              "GetStdHandle"
            ],
            "i": "micro-behaviors/fs/file/operations::get-std-handle",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "VirtualProtectEx/NtProtectVirtualMemory symbol",
            "e": [
              "VirtualProtectEx"
            ],
            "i": "objectives/evasion/fileless/memory::protect-memory-sym",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Get current process handle",
            "e": [
              "GetCurrentProcess"
            ],
            "i": "micro-behaviors/os/module/load::get-current-process",
            "l": 2
          },
          {
            "a": "T1055.001",
            "c": 0.949999988079071,
            "d": "CreateRemoteThread API reference",
            "e": [
              "CreateRemoteThread"
            ],
            "i": "micro-behaviors/process/inject/dll::create-remote-thread",
            "l": 3,
            "m": "F0003"
          },
          {
            "d": "Content-Type header string",
            "e": [
              "Content-Type: application/octet-stream",
              "HTTP/1.1 200 OK\r\nContent-Type: application/octet-stream\r\nContent-Length: %d"
            ],
            "i": "micro-behaviors/communications/http/request::content-type-header",
            "l": 1
          },
          {
            "a": "T1071",
            "c": 1.0,
            "d": "oleaut32 ordinal 15",
            "e": [
              "ORDINAL 15"
            ],
            "i": "objectives/command-and-control/backdoor/binary::oleaut-ordinal-15",
            "l": 1,
            "m": "B0025"
          },
          {
            "a": "T1082",
            "c": 0.8799999952316284,
            "d": "Query locale information",
            "e": [
              "GetLocaleInfoA"
            ],
            "i": "micro-behaviors/os/sysinfo/platform::get-locale-info",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "ws2_32 ordinal 22 (shutdown)",
            "e": [
              "ORDINAL 22"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-32-ordinal-22",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Get environment strings",
            "e": [
              "GetEnvironmentStringsW",
              "FreeEnvironmentStringsW",
              "GetEnvironmentStrings"
            ],
            "i": "micro-behaviors/os/env/access::get-environment-strings",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "Open HTTP request via WinInet",
            "e": [
              "HttpOpenRequestA"
            ],
            "i": "micro-behaviors/communications/http/get::http-open-request",
            "l": 3
          },
          {
            "c": 0.699999988079071,
            "d": "ws2_32 ordinal 19 (send)",
            "e": [
              "ORDINAL 19"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-32-ordinal-19",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has low average string entropy",
            "e": [
              "binary.avg_string_entropy = 3.15"
            ],
            "i": "metadata/binary/metrics::avg-string-entropy-4-max",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Get current thread ID",
            "e": [
              "GetCurrentThreadId"
            ],
            "i": "micro-behaviors/process/info/thread::get-current-thread-id",
            "l": 2
          },
          {
            "a": "T1106",
            "c": 0.949999988079071,
            "d": "Create process (ANSI)",
            "e": [
              "CreateProcessA"
            ],
            "i": "micro-behaviors/process/create/spawn::create-process-a",
            "l": 2
          },
          {
            "a": "T1083",
            "c": 0.8799999952316284,
            "d": "Enumerate logical drive letters",
            "e": [
              "GetLogicalDrives"
            ],
            "i": "micro-behaviors/fs/traversal/drives::get-logical-drives-text",
            "l": 3,
            "m": "E1083"
          },
          {
            "a": "T1222.001",
            "c": 0.949999988079071,
            "d": "Modify memory page protection",
            "e": [
              "VirtualProtect"
            ],
            "i": "micro-behaviors/mem/protect/modify::virtual-protect",
            "l": 2,
            "m": "C0021"
          },
          {
            "c": 0.7200000286102295,
            "d": "Short uppercase mutex token",
            "e": [
              "YYYYGGGG",
              "CCCCDDDD",
              "FFFFWWWW"
            ],
            "i": "micro-behaviors/process/sync/mutex::short-uppercase-token",
            "l": 1,
            "m": "C0042"
          },
          {
            "c": 0.8999999761581421,
            "d": "Thread-local storage allocation",
            "e": [
              "TlsAlloc"
            ],
            "i": "micro-behaviors/process/tls/fiber::tls-alloc",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "ws2_32 ordinal 16 (recv)",
            "e": [
              "ORDINAL 16"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-32-ordinal-16",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "PE has low overall entropy",
            "e": [
              "binary.overall_entropy = 5.37"
            ],
            "i": "metadata/binary/layout::low-overall-entropy",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Local memory allocation",
            "e": [
              "LocalAlloc"
            ],
            "i": "micro-behaviors/mem/alloc/heap::local-alloc",
            "l": 2
          },
          {
            "a": "T1082",
            "c": 0.8999999761581421,
            "d": "Query computer/host name",
            "e": [
              "GetComputerNameA"
            ],
            "i": "micro-behaviors/os/sysinfo/hostname::get-computer-name",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Thread-local storage assignment",
            "e": [
              "TlsSetValue"
            ],
            "i": "micro-behaviors/process/tls/fiber::tls-set-value",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Dominant text section ratio",
            "e": [
              "binary.largest_section_ratio = 0.72"
            ],
            "i": "well-known/malware/trojan/elex-technoinox::runner-dominant-text-ratio",
            "l": 1
          },
          {
            "a": "T1083",
            "c": 0.8999999761581421,
            "d": "Enumerate logical drive letters",
            "e": [
              "GetLogicalDrives"
            ],
            "i": "micro-behaviors/fs/traversal/drives::get-logical-drives",
            "l": 3,
            "m": "E1083"
          },
          {
            "c": 0.8999999761581421,
            "d": "PE resource section",
            "e": [
              ".rsrc"
            ],
            "i": "metadata/binary/section/names::pe-resource-section",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Heap memory deallocation",
            "e": [
              "HeapFree"
            ],
            "i": "micro-behaviors/mem/alloc/heap::heap-free",
            "l": 2
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "LoadLibraryA loader API string",
            "e": [
              "LoadLibraryA"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-loadlibrarya-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "c": 0.8999999761581421,
            "d": "Flush file buffer to disk",
            "e": [
              "FlushFileBuffers"
            ],
            "i": "micro-behaviors/fs/file/operations::flush-file-buffers",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Begin directory enumeration ANSI",
            "e": [
              "FindFirstFileA"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-first-file-a",
            "l": 2
          },
          {
            "a": "T1134",
            "c": 0.949999988079071,
            "d": "Initialize process attribute list",
            "e": [
              "InitializeProcThreadAttributeList"
            ],
            "i": "micro-behaviors/process/create/spawn::init-proc-thread-attribute-list",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Initialize critical section",
            "e": [
              "InitializeCriticalSectionAndSpinCount"
            ],
            "i": "micro-behaviors/process/sync/critical-section::critical-section-init",
            "l": 2
          },
          {
            "d": ".dll extension reference",
            "e": [
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll",
              ".dll"
            ],
            "i": "micro-behaviors/fs/path/extension::dll-dup",
            "l": 2
          },
          {
            "a": "T1055",
            "c": 0.699999988079071,
            "d": "Query virtual memory info (VirtualQuery)",
            "e": [
              "VirtualQuery"
            ],
            "i": "micro-behaviors/mem/query/info::virtualquery",
            "l": 2
          },
          {
            "c": 0.7799999713897705,
            "d": "Get module handle Unicode",
            "e": [
              "GetModuleHandleW"
            ],
            "i": "micro-behaviors/os/module/load::get-module-handle-wide",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.949999988079071,
            "d": "Open service control manager import",
            "e": [
              "OpenSCManagerA"
            ],
            "i": "micro-behaviors/os/service/control::open-sc-manager-import",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Set file position",
            "e": [
              "SetFilePointer"
            ],
            "i": "micro-behaviors/fs/file/operations::set-file-pointer",
            "l": 2
          },
          {
            "a": "T1559",
            "c": 0.8999999761581421,
            "d": "Peek at pipe data without reading",
            "e": [
              "PeekNamedPipe"
            ],
            "i": "micro-behaviors/communications/ipc/pipe::peek-named-pipe",
            "l": 3
          },
          {
            "c": 0.8500000238418579,
            "d": "Query file attributes or existence",
            "e": [
              "GetFileAttributesA"
            ],
            "i": "micro-behaviors/fs/path/check::get-file-attributes",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Directory enumeration (ANSI)",
            "e": [
              "FindNextFileA"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-next-file-a",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE mapped image under 768 KiB",
            "e": [
              "pe.size_of_image = 274432.00"
            ],
            "i": "metadata/binary/layout::image-under-768kb",
            "l": 1
          },
          {
            "a": "T1082",
            "c": 0.8999999761581421,
            "d": "Query Windows version info",
            "e": [
              "GetVersionExA"
            ],
            "i": "micro-behaviors/os/sysinfo/platform::get-version-ex",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Move or rename file",
            "e": [
              "MoveFileA"
            ],
            "i": "micro-behaviors/fs/file/move::move-file",
            "l": 2
          },
          {
            "c": 0.8600000143051147,
            "d": "VirtualProtect then VirtualAlloc strings",
            "e": [
              "VirtualProtectExU\u0004VirtualAlloc"
            ],
            "i": "micro-behaviors/mem/protect/modify::virtualprotect-virtualalloc-pair",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Get module handle ANSI",
            "e": [
              "GetModuleHandleA"
            ],
            "i": "micro-behaviors/os/module/load::get-module-handle-ansi",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "WinExec hidden-window flag immediate",
            "e": [
              "78 60 02 10",
              "28 61 02 10"
            ],
            "i": "micro-behaviors/process/create/flags::winexec-sw-hide-immediate",
            "l": 1
          },
          {
            "a": "T1071.001",
            "c": 0.8999999761581421,
            "d": "InternetCloseHandle API name",
            "e": [
              "InternetCloseHandle"
            ],
            "i": "micro-behaviors/communications/http/get::internet-close-handle-str",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Leave critical section",
            "e": [
              "LeaveCriticalSection"
            ],
            "i": "micro-behaviors/process/sync/critical-section::critical-section-leave",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.949999988079071,
            "d": "Read data from internet handle",
            "e": [
              "InternetReadFile"
            ],
            "i": "micro-behaviors/communications/http/get::internet-read-file",
            "l": 3,
            "m": "C0002"
          },
          {
            "a": "T1071.001",
            "c": 0.8600000143051147,
            "d": ".NET loopback HTTP prefix",
            "e": [
              "IEX (New-Object Net.Webclient).DownloadString('http://127.0.0.1:%u/'); %s",
              "IEX (New-Object Net.Webclient).DownloadString('http://127.0.0.1:%u/')"
            ],
            "i": "micro-behaviors/communications/http/server/managed::dotnet-loopback-prefix",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Get console output code page",
            "e": [
              "GetConsoleOutputCP"
            ],
            "i": "micro-behaviors/fs/file/operations::get-console-output-cp",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Initialize security descriptor",
            "e": [
              "InitializeSecurityDescriptor"
            ],
            "i": "micro-behaviors/os/security/descriptor::initialize-security-descriptor",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "ANSI console output",
            "e": [
              "WriteConsoleA"
            ],
            "i": "micro-behaviors/hardware/display/screen::write-console-a",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.9300000071525574,
            "d": "Open service import",
            "e": [
              "OpenServiceA"
            ],
            "i": "micro-behaviors/os/service/control::open-service-import",
            "l": 1
          },
          {
            "a": "T1134.001",
            "c": 0.7799999713897705,
            "d": "Shutdown privilege name string",
            "e": [
              "SeShutdownPrivilege"
            ],
            "i": "micro-behaviors/os/privilege/token::shutdown-privilege-name",
            "l": 3
          },
          {
            "a": "T1071.001",
            "c": 0.8999999761581421,
            "d": "HttpQueryInfo API name as string",
            "e": [
              "HttpQueryInfoA"
            ],
            "i": "micro-behaviors/communications/http/get::http-query-info-str",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "ImpersonateNamedPipeClient symbol",
            "e": [
              "ImpersonateNamedPipeClient"
            ],
            "i": "objectives/privilege-escalation/hijack-execution-flow/named-pipe::impersonate-named-pipe-client-symbol",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Binary has 30+ imports",
            "e": [
              "binary.import_count = 210.00"
            ],
            "i": "metadata/binary/metrics::many-imports-30",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Heap memory allocation",
            "e": [
              "HeapAlloc"
            ],
            "i": "micro-behaviors/mem/alloc/heap::heap-alloc",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Read current working directory",
            "e": [
              "GetCurrentDirectoryA",
              "GetCurrentDirectoryW"
            ],
            "i": "micro-behaviors/fs/traversal/drives::get-current-directory",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "GetModuleFileName API call",
            "e": [
              "GetModuleFileNameW",
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/process/info/current::get-module-filename",
            "l": 2
          },
          {
            "a": "T1027.007",
            "c": 0.699999988079071,
            "d": "PE header access via e_lfanew offset",
            "e": [
              "40",
              "46",
              "41",
              "48",
              "42"
            ],
            "i": "objectives/anti-static/obfuscation/imports::pe-header-walk",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "c": 0.8399999737739563,
            "d": "High basic block count in sparse binary",
            "e": [
              "binary.total_basic_blocks = 8410.00"
            ],
            "i": "metadata/binary/metrics::dense-basic-blocks",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Emotet API hashing ROR instruction",
            "e": [
              "c8",
              "c8",
              "c8",
              "c9",
              "ca",
              "ce",
              "cb",
              "cb",
              "ce",
              "cf",
              "ce",
              "c8",
              "c9",
              "ca",
              "cb",
              "cb"
            ],
            "i": "well-known/malware/trojan/emotet::emotet-api-hashing-ror",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "GetCurrentThread API call",
            "e": [
              "GetCurrentThread"
            ],
            "i": "micro-behaviors/process/info/current::get-current-thread",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Binary with very few exports (1-2)",
            "e": [
              "binary.export_count = 1.00"
            ],
            "i": "metadata/binary/metrics::minimal-exports",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.9300000071525574,
            "d": "Start service import",
            "e": [
              "StartServiceA"
            ],
            "i": "micro-behaviors/os/service/control::start-service-import",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Get system error code",
            "e": [
              "GetLastError"
            ],
            "i": "micro-behaviors/os/exception/error-handling::get-last-error",
            "l": 2
          },
          {
            "a": "T1053.005",
            "c": 0.8999999761581421,
            "d": "Task Scheduler builder methods",
            "e": [
              "Connect",
              "Connect",
              "Connect"
            ],
            "i": "objectives/persistence/login/scheduled-task::task-scheduler-builder-methods",
            "l": 1,
            "m": "F0012"
          },
          {
            "c": 0.800000011920929,
            "d": "Five section PE layout",
            "e": [
              "binary.section_count = 5.00"
            ],
            "i": "metadata/binary/section/metrics::five-section-pe",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Get module file path (ANSI)",
            "e": [
              "GetModuleFileNameA"
            ],
            "i": "micro-behaviors/os/module/load::get-module-filename-ansi",
            "l": 2
          },
          {
            "a": "T1559",
            "c": 0.8999999761581421,
            "d": "Create anonymous pipe",
            "e": [
              "CreatePipe"
            ],
            "i": "micro-behaviors/communications/ipc/pipe::create-pipe",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Runtime library unwind operation",
            "e": [
              "RtlUnwind"
            ],
            "i": "micro-behaviors/os/exception/error-handling::rtl-unwind",
            "l": 2
          },
          {
            "c": 0.8399999737739563,
            "d": "Invoke unhandled exception filter",
            "e": [
              "UnhandledExceptionFilter"
            ],
            "i": "micro-behaviors/os/exception/error-handling::unhandled-exception-filter-import",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "CorExitProcess CLR termination reference",
            "e": [
              "CorExitProcess"
            ],
            "i": "micro-behaviors/process/inject/runtime::corexitprocess-string",
            "l": 3
          },
          {
            "c": 0.699999988079071,
            "d": "Delay execution",
            "e": [
              "Sleep"
            ],
            "i": "micro-behaviors/time/timing/delay::sleep-dup",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "OpenProcess/NtOpenProcess symbol",
            "e": [
              "OpenProcess"
            ],
            "i": "objectives/evasion/fileless/memory::open-process-sym",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "File is a compiled binary",
            "e": [
              "binary.file_size = 206848.00"
            ],
            "i": "metadata/binary/framework::is-binary",
            "l": 1
          },
          {
            "a": "T1129",
            "c": 0.949999988079071,
            "d": "Create thread in current process",
            "e": [
              "CreateThread"
            ],
            "i": "micro-behaviors/process/thread/create::create-thread",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Check if running under WoW64",
            "e": [
              "IsWow64Process"
            ],
            "i": "micro-behaviors/os/compat/wow64::is-wow64-process",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "Case-mangled GetUserObjectInformation token",
            "e": [
              "GetUserObjectInform"
            ],
            "i": "well-known/malware/ransomware/stop_djvu::case-mangled-getuserobjectinformation",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Get console input/output mode",
            "e": [
              "GetConsoleMode"
            ],
            "i": "micro-behaviors/fs/file/operations::get-console-mode",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Suspicious combination of imported APIs",
            "e": [
              "pe.suspicious_import_combo = 1.00"
            ],
            "i": "metadata/binary/metrics/markers::suspicious-import-combo-marker",
            "l": 1
          },
          {
            "a": "T1112",
            "c": 0.8399999737739563,
            "d": "Open registry key ANSI",
            "e": [
              "RegOpenKeyExA"
            ],
            "i": "micro-behaviors/os/registry/manipulate::reg-open-key-ex-a",
            "l": 2
          },
          {
            "c": 0.8199999928474426,
            "d": "Query current process command line",
            "e": [
              "GetCommandLineA"
            ],
            "i": "micro-behaviors/process/info/commandline::get-command-line",
            "l": 2
          },
          {
            "a": "T1055.012",
            "c": 0.800000011920929,
            "d": "CreateProcess API string reference",
            "e": [
              "CreateProcessA",
              "CreateProcessWithLogonW",
              "CreateProcessWithTokenW",
              "CreateProcessAsUserA"
            ],
            "i": "objectives/evasion/process/injection/hollowing::create-process-string",
            "l": 1,
            "m": "E1055.012"
          },
          {
            "a": "T1059.001",
            "c": 0.8999999761581421,
            "d": "PowerShell launcher reference",
            "e": [
              "powershell"
            ],
            "i": "objectives/execution/interpreter/script/wsh::powershell-launcher",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Truncate file via SetEndOfFile",
            "e": [
              "SetEndOfFile"
            ],
            "i": "micro-behaviors/fs/file/truncate::set-end-of-file-win",
            "l": 2
          },
          {
            "a": "T1071",
            "c": 0.7799999713897705,
            "d": "Winsock library string marker",
            "e": [
              "WS2_32.dll"
            ],
            "i": "objectives/command-and-control/backdoor/binary::winsock-library-reference",
            "l": 1
          },
          {
            "c": 0.30000001192092896,
            "d": "token keyword",
            "e": [
              "token",
              "token",
              "token",
              "token",
              "token",
              "token",
              "token",
              "token"
            ],
            "i": "micro-behaviors/data/text/keywords::token",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "High-risk token privilege name",
            "e": [
              "SeDebugPrivilege",
              "SeTcbPrivilege",
              "SeAssignPrimaryTokenPrivilege"
            ],
            "i": "objectives/privilege-escalation/token-manipulation::dangerous-privilege-name",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Remote thread creation symbol",
            "e": [
              "CreateRemoteThread"
            ],
            "i": "objectives/evasion/fileless/memory::create-thread-sym",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Heap memory reallocation",
            "e": [
              "HeapReAlloc"
            ],
            "i": "micro-behaviors/mem/alloc/heap::heap-realloc",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Multiple embedded MZ headers",
            "e": [
              "4D 5A",
              "4D 5A",
              "4D 5A"
            ],
            "i": "metadata/binary/layout::multiple-pe-embedded-loose",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Read startup info via GetStartupInfoA",
            "e": [
              "GetStartupInfoA"
            ],
            "i": "micro-behaviors/os/sysinfo/process::get-startup-info-a",
            "l": 2
          },
          {
            "a": "T1562.001",
            "c": 0.8999999761581421,
            "d": "Task Manager process enumeration",
            "e": [
              "Process32Next"
            ],
            "i": "micro-behaviors/process/terminate/kill::taskmgr-process-enum",
            "l": 3,
            "m": "B0001"
          },
          {
            "a": "T1195.002",
            "c": 0.550000011920929,
            "d": "Plaintext exec command token",
            "e": [
              "exec"
            ],
            "i": "objectives/command-and-control/backdoor/binary::plaintext-exec-command-token",
            "l": 1,
            "m": "B0025"
          },
          {
            "c": 1.0,
            "d": "Binary is not position-independent (fixed load address)",
            "e": [
              "binary.is_pie = 0.00"
            ],
            "i": "metadata/hardening::no-pie",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Wait for process/object",
            "e": [
              "WaitForSingleObject"
            ],
            "i": "micro-behaviors/process/create/spawn::wait-for-single-object",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Thread-local storage deallocation",
            "e": [
              "TlsFree"
            ],
            "i": "micro-behaviors/process/tls/fiber::tls-free",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "Remove directory (ANSI)",
            "e": [
              "RemoveDirectoryA"
            ],
            "i": "micro-behaviors/fs/directory/rmdir::remove-directory-a",
            "l": 2
          },
          {
            "a": "T1027.010",
            "d": "Hardcoded standard base64 alphabet",
            "e": [
              "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"
            ],
            "i": "micro-behaviors/data/encode/base64::alphabet-standard",
            "l": 2,
            "m": "B0032.001"
          },
          {
            "a": "T1543.003",
            "c": 0.949999988079071,
            "d": "Create service import",
            "e": [
              "CreateServiceA"
            ],
            "i": "micro-behaviors/os/service/control::create-service-import",
            "l": 1
          },
          {
            "d": "windir environment variable",
            "e": [
              "@%windir%\\sysnative\\rundll32.exe",
              "@%windir%\\syswow64\\rundll32.exe"
            ],
            "i": "micro-behaviors/os/env/vars/system-info::windir-var",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Get tick count",
            "e": [
              "GetTickCount"
            ],
            "i": "micro-behaviors/time/query::get-tick-count",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.699999988079071,
            "d": "Code section dominates file layout",
            "e": [
              "binary.largest_section_ratio = 0.72"
            ],
            "i": "objectives/anti-static/obfuscation/string/anomaly::dominant-text-section",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 0.8600000143051147,
            "d": "Register unhandled exception filter",
            "e": [
              "SetUnhandledExceptionFilter"
            ],
            "i": "micro-behaviors/os/exception/error-handling::set-unhandled-exception-filter-import",
            "l": 2
          },
          {
            "c": 0.699999988079071,
            "d": "ws2_32 ordinal 4 (connect)",
            "e": [
              "ORDINAL 4"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-32-ordinal-4",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Read data from file handle",
            "e": [
              "ReadFile"
            ],
            "i": "micro-behaviors/fs/file/read::read-file",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "VirtualProtect symbol",
            "e": [
              "VirtualProtectEx",
              "VirtualProtect"
            ],
            "i": "objectives/anti-static/obfuscation/reflection/class::virtualprotect-sym",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Thread-local storage retrieval",
            "e": [
              "TlsGetValue"
            ],
            "i": "micro-behaviors/process/tls/fiber::tls-get-value",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Uses internet communication API imports",
            "e": [
              "HttpOpenRequestA",
              "InternetOpenA"
            ],
            "i": "micro-behaviors/communications/http::has-internet-communication-apis",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "PE standard runtime section",
            "e": [
              ".rdata",
              ".reloc"
            ],
            "i": "metadata/binary/section/names::pe-runtime-standard-section",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "ws2_32 ordinal 116 (WSACleanup)",
            "e": [
              "ORDINAL 116"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-32-ordinal-116",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Get current process ID",
            "e": [
              "GetCurrentProcessId"
            ],
            "i": "micro-behaviors/process/info/thread::get-current-process-id",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Windows file creation/open API",
            "e": [
              "CreateFileA"
            ],
            "i": "micro-behaviors/fs/file/open::file-create-win",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.8999999761581421,
            "d": "HttpSendRequest API name as string",
            "e": [
              "HttpSendRequestA"
            ],
            "i": "micro-behaviors/communications/http/get::http-send-request-str",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "Creates a new service (ANSI)",
            "e": [
              "CreateServiceA"
            ],
            "i": "micro-behaviors/os/service::create-service-a",
            "l": 3
          },
          {
            "c": 1.0,
            "d": "LoadLibrary symbol",
            "e": [
              "LoadLibraryA"
            ],
            "i": "objectives/anti-static/obfuscation/reflection/class::loadlibrary-sym",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Set standard I/O handle",
            "e": [
              "SetStdHandle"
            ],
            "i": "micro-behaviors/fs/file/operations::set-std-handle",
            "l": 2
          },
          {
            "c": 0.8500000238418579,
            "d": "Modify file creation/access/write times",
            "e": [
              "SetFileTime"
            ],
            "i": "micro-behaviors/fs/sync/fsync::set-file-time",
            "l": 3
          },
          {
            "c": 0.949999988079071,
            "d": "Unicode console output",
            "e": [
              "WriteConsoleW"
            ],
            "i": "micro-behaviors/hardware/display/screen::write-console-w",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Revert WoW64 filesystem redirection",
            "e": [
              "Wow64RevertWow64FsRedirection"
            ],
            "i": "micro-behaviors/os/compat/wow64::wow64-revert-redirect",
            "l": 2
          },
          {
            "a": "T1106",
            "c": 0.949999988079071,
            "d": "Open process handle",
            "e": [
              "OpenProcess"
            ],
            "i": "micro-behaviors/process/create/spawn::open-process",
            "l": 2
          },
          {
            "c": 1.0,
            "d": "Binary has 20+ imports",
            "e": [
              "binary.import_count = 210.00"
            ],
            "i": "metadata/binary/metrics::many-imports-20",
            "l": 1
          },
          {
            "a": "T1218.011",
            "c": 0.8999999761581421,
            "d": "Executes a DLL using rundll32.exe",
            "e": [
              "rundll32.exe",
              "rundll32.exe"
            ],
            "i": "micro-behaviors/process/create/shell::rundll32-exec",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Close directory enumeration handle",
            "e": [
              "FindClose"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-close",
            "l": 2
          },
          {
            "a": "T1027.007",
            "c": 0.8500000238418579,
            "d": "PEB Ldr access for module enumeration",
            "e": [
              "64 A1 30 00 00 00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::peb-ldr-access",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "c": 0.949999988079071,
            "d": "Process termination via TerminateProcess",
            "e": [
              "TerminateProcess"
            ],
            "i": "micro-behaviors/process/terminate/kill::terminate-process",
            "l": 2,
            "m": "B0033"
          },
          {
            "c": 0.8199999928474426,
            "d": "Elevated text section entropy",
            "e": [
              ".text (entropy: 6.64)"
            ],
            "i": "metadata/binary/section/metrics::elevated-text-entropy-section",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "PE standard code/data section",
            "e": [
              ".text",
              ".data"
            ],
            "i": "metadata/binary/section/names::pe-code-data-standard-section",
            "l": 1
          },
          {
            "c": 1.0,
            "d": "VirtualAllocEx/NtAllocateVirtualMemory symbol",
            "e": [
              "VirtualAllocEx"
            ],
            "i": "objectives/evasion/fileless/memory::alloc-memory-sym",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "ws2_32 ordinal 9 (htons)",
            "e": [
              "ORDINAL 9"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-32-ordinal-9",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "Send HTTP request via WinInet",
            "e": [
              "HttpSendRequestA"
            ],
            "i": "micro-behaviors/communications/http/get::http-send-request",
            "l": 3
          },
          {
            "c": 1.0,
            "d": "Binary has 50+ functions",
            "e": [
              "binary.function_count = 637.00"
            ],
            "i": "metadata/binary/metrics::many-functions-50",
            "l": 1
          },
          {
            "a": "T1027.007",
            "c": 0.800000011920929,
            "d": "ROR13 hash algorithm constant",
            "e": [
              "c8",
              "c8",
              "c8",
              "c9",
              "ca",
              "ce",
              "cb",
              "cb",
              "ce",
              "cf",
              "ce",
              "c8",
              "c9",
              "ca",
              "cb",
              "cb"
            ],
            "i": "objectives/anti-static/obfuscation/imports::ror13-hash-seed",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "a": "T1027",
            "c": 1.0,
            "d": "Allocate cross-process virtual memory (NT or Win32)",
            "e": [
              "VirtualAllocEx"
            ],
            "i": "objectives/anti-static/pack::nt-or-virtual-alloc-ex-import",
            "l": 1,
            "m": "B0032"
          },
          {
            "c": 1.0,
            "d": "Binary has 3+ functions",
            "e": [
              "binary.function_count = 637.00"
            ],
            "i": "metadata/binary/metrics::few-functions-3",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Convert time to local timezone",
            "e": [
              "SystemTimeToTzSpecificLocalTime"
            ],
            "i": "micro-behaviors/time/query::systemtime-tz-convert",
            "l": 2
          },
          {
            "a": "T1071.001",
            "d": "HTTP/1.x version string",
            "e": [
              "HTTP/1.1 200 OK\r\nContent-Type: application/octet-stream\r\nContent-Length: %d"
            ],
            "i": "micro-behaviors/communications/http/request::http-version",
            "l": 2,
            "m": "C0002"
          },
          {
            "a": "T1070.006",
            "c": 0.699999988079071,
            "d": "PE header compile timestamp predates 2025",
            "e": [
              "pe.timestamp = 1495488078.00"
            ],
            "i": "objectives/evasion/indicator-removal/timestamps::header-timestamp-pre-2025",
            "l": 1
          },
          {
            "a": "T1071.001",
            "c": 0.8999999761581421,
            "d": "InternetOpen API name as string",
            "e": [
              "InternetOpenA"
            ],
            "i": "micro-behaviors/communications/http/get::internet-open-str",
            "l": 1
          },
          {
            "c": 0.699999988079071,
            "d": "Get module file path",
            "e": [
              "GetModuleFileNameW"
            ],
            "i": "micro-behaviors/os/module/load::get-module-filename-dup",
            "l": 2
          },
          {
            "c": 0.800000011920929,
            "d": "Thread32First API string",
            "e": [
              "Thread32First"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::thread32-first-string",
            "l": 1
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "GetProcAddress loader API string",
            "e": [
              "GetProcAddress"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-getprocaddress-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "a": "T1055",
            "c": 0.949999988079071,
            "d": "SetThreadContext API reference",
            "e": [
              "SetThreadContext"
            ],
            "i": "micro-behaviors/process/inject/runtime::set-thread-context-dup",
            "l": 3
          },
          {
            "a": "T1543.003",
            "c": 0.8600000143051147,
            "d": "Send service control code",
            "e": [
              "ControlService"
            ],
            "i": "micro-behaviors/os/service/control::control-service",
            "l": 3
          },
          {
            "a": "T1033",
            "c": 0.8500000238418579,
            "d": "Allocate and initialize SID",
            "e": [
              "AllocateAndInitializeSid"
            ],
            "i": "micro-behaviors/os/privilege/check::allocate-initialize-sid",
            "l": 3
          },
          {
            "a": "T1543.003",
            "c": 0.8199999928474426,
            "d": "Query service runtime status",
            "e": [
              "QueryServiceStatusEx",
              "QueryServiceStatus"
            ],
            "i": "micro-behaviors/os/service/control::query-service-status",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "GetTokenInformation API",
            "e": [
              "GetTokenInformation"
            ],
            "i": "micro-behaviors/os/privilege/token::get-token-information",
            "l": 3
          },
          {
            "c": 0.6000000238418579,
            "d": "GetEnvironmentVariable method",
            "e": [
              "GetEnvironmentVariableA"
            ],
            "i": "metadata/package/config::get-env-var",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "ANSI GUI probe API cluster",
            "e": [
              "GetLastActivePopup",
              "GetActiveWindow",
              "MessageBoxA"
            ],
            "i": "well-known/malware/trojan/elex/test-loader::ansi-gui-probe-cluster",
            "l": 3
          },
          {
            "a": "T1055.001",
            "c": 0.9800000190734863,
            "d": "CreateRemoteThread API reference",
            "e": [
              "CreateRemoteThread"
            ],
            "i": "micro-behaviors/process/inject/runtime::create-remote-thread-dup",
            "l": 3,
            "m": "B0013"
          },
          {
            "c": 0.800000011920929,
            "d": "PE executable is unsigned",
            "i": "metadata/signed::unsigned-pe-executable",
            "l": 3
          },
          {
            "a": "T1543.003",
            "c": 0.8500000238418579,
            "d": "Start Windows service",
            "e": [
              "StartServiceA"
            ],
            "i": "micro-behaviors/os/service/control::start-service",
            "l": 3
          },
          {
            "a": "T1559",
            "c": 0.6499999761581421,
            "d": "ConnectNamedPipe API call",
            "e": [
              "ConnectNamedPipe"
            ],
            "i": "micro-behaviors/communications/ipc/named-pipe::connect-named-pipe",
            "l": 3
          },
          {
            "c": 0.75,
            "d": "Lookup privilege name to LUID",
            "e": [
              "LookupPrivilegeValueA"
            ],
            "i": "micro-behaviors/os/privilege/token::lookup-privilege-value",
            "l": 3
          },
          {
            "a": "T1027",
            "c": 0.8600000143051147,
            "d": "Long mixed-case identifiers cluster",
            "e": [
              "GetProcessWindowStation",
              "GetUserObjectInformationA",
              "EnvironmentDirectory",
              "SunMonTueWedThuFriSat",
              "JanFebMarAprMayJunJulAugSepOctNovDec",
              "GetCurrentProcessId",
              "GetEnvironmentVariableA",
              "DisconnectNamedPipe",
              "SetCurrentDirectoryA",
              "GetCurrentDirectoryW",
              "GetCurrentDirectoryA",
              "SystemTimeToTzSpecificLocalTime",
              "FileTimeToSystemTime",
              "DeleteProcThreadAttributeList",
              "UpdateProcThreadAttribute",
              "ProcessIdToSessionId"
            ],
            "i": "objectives/anti-static/obfuscation/string::long-mixedcase-identifiers",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1543.003",
            "c": 0.8500000238418579,
            "d": "Open service control manager",
            "e": [
              "OpenSCManagerA"
            ],
            "i": "micro-behaviors/os/service/control::open-sc-manager",
            "l": 3
          },
          {
            "c": 0.699999988079071,
            "d": "High function count over 200",
            "e": [
              "binary.function_count = 637.00"
            ],
            "i": "metadata/binary/metrics::high-function-count-200",
            "l": 2
          },
          {
            "a": "T1574.002",
            "c": 0.8999999761581421,
            "d": "Hidden LoadLibraryA string reference",
            "e": [
              "LoadLibraryA"
            ],
            "i": "micro-behaviors/dylib/load::load-library-a-string-no-import",
            "l": 1
          },
          {
            "c": 0.800000011920929,
            "d": "Enable/disable privileges in access token",
            "e": [
              "AdjustTokenPrivileges"
            ],
            "i": "micro-behaviors/os/privilege/token::adjust-token-privileges",
            "l": 3
          },
          {
            "a": "T1055.012",
            "c": 0.75,
            "d": "SetThreadContext call",
            "e": [
              "SetThreadContext"
            ],
            "i": "objectives/evasion/process/injection/hollowing::set-thread-context",
            "l": 1,
            "m": "E1055.012"
          },
          {
            "a": "T1055.012",
            "c": 0.699999988079071,
            "d": "WriteProcessMemory call",
            "e": [
              "WriteProcessMemory"
            ],
            "i": "objectives/evasion/process/injection/hollowing::write-process-memory-dup",
            "l": 1,
            "m": "E1055.012"
          },
          {
            "c": 0.8999999761581421,
            "d": "Resolve exports with GetProcAddress",
            "e": [
              "GetProcAddress"
            ],
            "i": "micro-behaviors/os/module/load::get-proc-address-import",
            "l": 2
          },
          {
            "a": "T1622",
            "c": 0.949999988079071,
            "d": "Check if debugger is attached",
            "e": [
              "IsDebuggerPresent"
            ],
            "i": "objectives/anti-analysis/debugger-detect/check::is-debugger-present",
            "l": 1,
            "m": "B0001"
          },
          {
            "a": "T1055",
            "c": 0.8799999952316284,
            "d": "VirtualAllocEx API name reference",
            "e": [
              "VirtualAllocEx"
            ],
            "i": "micro-behaviors/mem/protect/modify::virtual-alloc-ex-name",
            "l": 2
          },
          {
            "a": "T1055.012",
            "c": 0.6000000238418579,
            "d": "ResumeThread call",
            "e": [
              "ResumeThread"
            ],
            "i": "objectives/evasion/process/injection/hollowing::resume-thread",
            "l": 1,
            "m": "E1055.012"
          },
          {
            "a": "T1543.003",
            "c": 0.8500000238418579,
            "d": "Open existing service handle",
            "e": [
              "OpenServiceA"
            ],
            "i": "micro-behaviors/os/service/control::open-service",
            "l": 3
          },
          {
            "c": 0.949999988079071,
            "d": "PE checksum mismatch (modified binary)",
            "e": [
              "pe.checksum_mismatch = 1.00"
            ],
            "i": "metadata/binary/layout::pe-checksum-mismatch",
            "l": 3
          },
          {
            "c": 0.949999988079071,
            "d": "Signed PE checksum mismatch",
            "e": [
              "pe.checksum_mismatch = 1.00"
            ],
            "i": "metadata/binary/layout::signed-pe-checksum-mismatch",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Switch current working directory",
            "e": [
              "SetCurrentDirectoryA"
            ],
            "i": "micro-behaviors/fs/traversal/drives::set-current-directory",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "Tiny resource section (no version/icon)",
            "e": [
              ".rsrc (size: 512)"
            ],
            "i": "metadata/binary/resource::minimal-resources",
            "l": 2
          },
          {
            "a": "T1033",
            "c": 0.8999999761581421,
            "d": "Query current username",
            "e": [
              "GetUserNameA"
            ],
            "i": "micro-behaviors/os/sysinfo/hostname::get-user-name",
            "l": 3
          },
          {
            "a": "T1055.012",
            "c": 0.699999988079071,
            "d": "GetThreadContext call",
            "e": [
              "GetThreadContext"
            ],
            "i": "objectives/evasion/process/injection/hollowing::get-thread-context",
            "l": 1,
            "m": "E1055.012"
          },
          {
            "c": 0.6000000238418579,
            "d": "Beacon keyword (neutral context)",
            "e": [
              "beacon"
            ],
            "i": "micro-behaviors/data/text/keywords::beacon",
            "l": 1
          },
          {
            "a": "T1057",
            "c": 0.8999999761581421,
            "d": "Create process or module snapshot",
            "e": [
              "CreateToolhelp32Snapshot"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::create-toolhelp32-snapshot",
            "l": 3,
            "m": "E1057"
          },
          {
            "c": 0.8500000238418579,
            "d": "Repeated GetTickCount with small-constant comparisons",
            "e": [
              "88 61 02 10",
              "04 61 02 10",
              "88 61 02 10",
              "44 63 02 10",
              "1c 60 02 10",
              "88 61 02 10",
              "88 61 02 10",
              "88 61 02 10",
              "88 61 02 10",
              "88 61 02 10",
              "14 62 02 10",
              "88 61 02 10",
              "88 61 02 10",
              "88 61 02 10"
            ],
            "i": "objectives/anti-static/obfuscation/instruction/junk::gettickcount-junk-branches",
            "l": 1
          },
          {
            "c": 0.8999999761581421,
            "d": "Create private heap (HeapCreate)",
            "e": [
              "HeapCreate"
            ],
            "i": "micro-behaviors/mem/alloc/heap::heap-create",
            "l": 2
          },
          {
            "a": "T1559",
            "c": 0.699999988079071,
            "d": "CreateNamedPipe API call",
            "e": [
              "CreateNamedPipeA"
            ],
            "i": "micro-behaviors/communications/ipc/named-pipe::create-named-pipe",
            "l": 3
          },
          {
            "c": 1.0,
            "d": "Binary is not digitally signed",
            "e": [
              "binary.has_signature = 0.00"
            ],
            "i": "metadata/signed::unsigned",
            "l": 2
          },
          {
            "c": 0.75,
            "d": "Open thread access token",
            "e": [
              "OpenThreadToken"
            ],
            "i": "micro-behaviors/os/privilege/token::open-thread-token",
            "l": 2
          },
          {
            "a": "T1055",
            "c": 0.8999999761581421,
            "d": "SuspendThread API reference",
            "e": [
              "SuspendThread"
            ],
            "i": "micro-behaviors/process/inject/runtime::suspend-thread",
            "l": 3
          },
          {
            "a": "T1486",
            "c": 0.8999999761581421,
            "d": "Generate cryptographic random bytes",
            "e": [
              "CryptGenRandom"
            ],
            "i": "micro-behaviors/os/random/generator::crypt-gen-random",
            "l": 2,
            "m": "C0027"
          },
          {
            "a": "T1055",
            "c": 0.949999988079071,
            "d": "WriteProcessMemory API reference",
            "e": [
              "WriteProcessMemory"
            ],
            "i": "micro-behaviors/process/inject/runtime::write-process-memory-dup",
            "l": 3,
            "m": "C0032"
          },
          {
            "a": "T1055.001",
            "c": 0.949999988079071,
            "d": "Dynamic LoadLibraryA resolution for remote injection",
            "e": [
              "LoadLibraryA"
            ],
            "i": "micro-behaviors/process/inject/dll::load-library-a-remote-resolution",
            "l": 3,
            "m": "F0003"
          },
          {
            "c": 0.800000011920929,
            "d": "Resolve SID to account/group name",
            "e": [
              "LookupAccountSidA"
            ],
            "i": "micro-behaviors/os/group/lookup::lookup-account-sid",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "Create extended duplicate of access token",
            "e": [
              "DuplicateTokenEx"
            ],
            "i": "objectives/privilege-escalation/token-manipulation::duplicate-token",
            "l": 3
          },
          {
            "a": "T1543.003",
            "c": 0.8399999737739563,
            "d": "Delete installed service",
            "e": [
              "DeleteService"
            ],
            "i": "micro-behaviors/os/service/control::delete-service",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "Legitimate DLL name associated with module stomping",
            "e": [
              "mscoree.dll"
            ],
            "i": "objectives/evasion/process/injection::module-stomping-target",
            "l": 1
          },
          {
            "a": "T1005",
            "c": 0.8999999761581421,
            "d": "GetThreadContext API reference",
            "e": [
              "GetThreadContext"
            ],
            "i": "micro-behaviors/process/inject/runtime::get-thread-context-dup",
            "l": 3
          },
          {
            "c": 0.7799999713897705,
            "d": "Hardcoded loopback IPv4 address",
            "e": [
              "127.0.0.1"
            ],
            "i": "micro-behaviors/communications/ip::loopback-ipv4-binary",
            "l": 3
          },
          {
            "a": "T1055",
            "c": 0.8999999761581421,
            "d": "VirtualAlloc string import marker",
            "e": [
              "VirtualAlloc"
            ],
            "i": "objectives/evasion/process/injection/vb6::virtual-alloc-string",
            "l": 1,
            "m": "C0041"
          },
          {
            "c": 0.8999999761581421,
            "d": "CreateFile API string reference",
            "e": [
              "CreateFile"
            ],
            "i": "micro-behaviors/fs/file/open::createfile-api",
            "l": 2
          },
          {
            "a": "T1071.001",
            "c": 0.699999988079071,
            "d": "Hardcoded loopback IP (likely test C2)",
            "e": [
              "127.0.0.1",
              "127.0.0.1"
            ],
            "i": "objectives/command-and-control/channel/http-beacon::hardcoded-localhost-c2",
            "l": 3,
            "m": "B0030"
          },
          {
            "a": "T1543.003",
            "c": 0.8500000238418579,
            "d": "Create Windows service",
            "e": [
              "CreateServiceA"
            ],
            "i": "micro-behaviors/os/service/control::create-service",
            "l": 3
          },
          {
            "c": 0.7200000286102295,
            "d": "WinInet DLL import name",
            "e": [
              "WININET.dll"
            ],
            "i": "micro-behaviors/communications/http/get::wininet-dll-import-name",
            "l": 3
          },
          {
            "a": "T1027",
            "c": 0.8199999928474426,
            "d": "Packed loader largest section ratio above 0.65",
            "e": [
              "binary.largest_section_ratio = 0.72"
            ],
            "i": "objectives/anti-static/obfuscation/payload/section::packed-loader-largest-section-dominates",
            "l": 1,
            "m": "B0032"
          },
          {
            "a": "T1033",
            "c": 0.8500000238418579,
            "d": "Check token group membership",
            "e": [
              "CheckTokenMembership"
            ],
            "i": "micro-behaviors/os/privilege/check::check-token-membership",
            "l": 3
          },
          {
            "d": ".exe extension reference",
            "e": [
              ".exe",
              ".exe"
            ],
            "i": "micro-behaviors/fs/path/extension::exe-dup",
            "l": 2
          },
          {
            "a": "T1027.007",
            "c": 0.8600000143051147,
            "d": "PE API hashing indicator present",
            "e": [
              "pe.api_hashing_indicators = 1.00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::pe-api-hashing-indicator-single",
            "l": 1,
            "m": "B0032.014"
          },
          {
            "c": 0.699999988079071,
            "d": "WS2_32 Winsock DLL import",
            "e": [
              "WS2_32.dll"
            ],
            "i": "micro-behaviors/communications/socket/init::ws2-32-dll-marker",
            "l": 3
          },
          {
            "a": "T1134",
            "c": 0.8999999761581421,
            "d": "CreateProcessWithToken API reference",
            "e": [
              "CreateProcessWithTokenW"
            ],
            "i": "micro-behaviors/process/create/spawn::create-process-with-token",
            "l": 3
          },
          {
            "a": "T1620",
            "c": 0.8999999761581421,
            "d": "VirtualAlloc loader API string",
            "e": [
              "VirtualAlloc"
            ],
            "i": "objectives/command-and-control/dropper/execution/loader::dark-eye-virtualalloc-string",
            "l": 1,
            "m": "B0030"
          },
          {
            "c": 0.8999999761581421,
            "d": "Binary has many functions",
            "e": [
              "binary.function_count = 637.00"
            ],
            "i": "objectives/anti-static/pack/entropy::large-function-surface",
            "l": 1
          },
          {
            "a": "T1027",
            "c": 0.800000011920929,
            "d": "Few PE resource entries (no DIALOG/MENU/STRINGTABLE)",
            "e": [
              "pe.resource_count = 1.00"
            ],
            "i": "objectives/evasion/anti-av/heuristic::minimal-pe-resources",
            "l": 1
          },
          {
            "a": "T1134",
            "c": 1.0,
            "d": "CreateProcessAsUser API reference",
            "e": [
              "CreateProcessAsUserA"
            ],
            "i": "micro-behaviors/process/create/spawn::create-process-as-user",
            "l": 3
          },
          {
            "c": 0.800000011920929,
            "d": "Five or more PE sections",
            "e": [
              "binary.section_count = 5.00"
            ],
            "i": "objectives/anti-static/obfuscation/imports::five-plus-sections-pe",
            "l": 1
          },
          {
            "c": 0.949999988079071,
            "d": "links DNSAPI.dll (DnsFree, DnsQuery_A)",
            "e": [
              "DNSAPI.dll"
            ],
            "i": "metadata/dylib::dnsapi/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links IPHLPAPI.DLL (GetIfEntry, GetIpAddrTable)",
            "e": [
              "IPHLPAPI.DLL"
            ],
            "i": "metadata/dylib::iphlpapi/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links Secur32.dll (LsaCallAuthenticationPackage, LsaConnectUntrusted, LsaLookupAuthenticationPackage)",
            "e": [
              "Secur32.dll"
            ],
            "i": "metadata/dylib::secur32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links WS2_32.dll (ORDINAL 15, ORDINAL 4, ORDINAL 9, ORDINAL 23, ORDINAL 1, ... +18 more)",
            "e": [
              "WS2_32.dll"
            ],
            "i": "metadata/dylib::ws2_32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links KERNEL32.dll (MoveFileA, FindNextFileA, DeleteProcThreadAttributeList, HeapAlloc, UpdateProcThreadAttribute, ... +133 more)",
            "e": [
              "KERNEL32.dll"
            ],
            "i": "metadata/dylib::kernel32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links ADVAPI32.dll (GetUserNameA, CloseServiceHandle, OpenProcessToken, CreateProcessWithLogonW, DeleteService, ... +27 more)",
            "e": [
              "ADVAPI32.dll"
            ],
            "i": "metadata/dylib::advapi32/dll",
            "l": 2
          },
          {
            "c": 0.949999988079071,
            "d": "links WININET.dll (HttpQueryInfoA, InternetConnectA, InternetQueryDataAvailable, InternetReadFile, InternetSetOptionA, ... +5 more)",
            "e": [
              "WININET.dll"
            ],
            "i": "metadata/dylib::wininet/dll",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "WinInet request and response workflow",
            "e": [
              "InternetConnectA",
              "InternetReadFile",
              "HttpOpenRequestA",
              "InternetOpenA",
              "HttpSendRequestA"
            ],
            "i": "micro-behaviors/communications/http/get::wininet-http-flow",
            "l": 3
          },
          {
            "c": 0.8399999737739563,
            "d": "Cleanup Winsock library",
            "e": [
              "WS2_32.dll",
              "ORDINAL 116"
            ],
            "i": "micro-behaviors/communications/socket/init::winsock-cleanup-ordinal",
            "l": 2
          },
          {
            "a": "T1543.003",
            "c": 0.949999988079071,
            "d": "Windows service admin import cluster",
            "e": [
              "CreateServiceA",
              "StartServiceA",
              "OpenSCManagerA",
              "OpenServiceA"
            ],
            "i": "micro-behaviors/os/service/control::service-admin-import-cluster",
            "l": 3
          },
          {
            "c": 0.8399999737739563,
            "d": "Winsock shutdown import",
            "e": [
              "ORDINAL 22",
              "WS2_32.dll"
            ],
            "i": "micro-behaviors/communications/socket/init::shutdown-api-ordinal",
            "l": 2
          },
          {
            "c": 0.8600000143051147,
            "d": "Winsock receive import",
            "e": [
              "ORDINAL 16",
              "WS2_32.dll"
            ],
            "i": "micro-behaviors/communications/socket/init::recv-api-ordinal",
            "l": 2
          },
          {
            "c": 0.9599999785423279,
            "d": "Extended process startup attributes",
            "e": [
              "InitializeProcThreadAttributeList",
              "UpdateProcThreadAttribute"
            ],
            "i": "micro-behaviors/process/create/spawn::proc-thread-attribute-list",
            "l": 3
          },
          {
            "c": 0.949999988079071,
            "d": "Standard MSVC CRT linkage (rich header + many imports)",
            "e": [
              "binary.import_count = 210.00",
              "pe.rich_header_present = 1.00"
            ],
            "i": "objectives/evasion/process/injection::msvc-crt-full-linkage",
            "l": 1
          },
          {
            "a": "T1543.003",
            "c": 0.9200000166893005,
            "d": "Service stop or delete chain",
            "e": [
              "QueryServiceStatusEx",
              "OpenSCManagerA",
              "OpenServiceA",
              "DeleteService",
              "QueryServiceStatus",
              "ControlService"
            ],
            "i": "micro-behaviors/os/service/control::service-stop-control",
            "l": 3
          },
          {
            "a": "T1027",
            "c": 0.8999999761581421,
            "d": "WinInet APIs resolved dynamically",
            "e": [
              "InternetReadFile",
              "HttpOpenRequestA",
              "HttpSendRequestA",
              "InternetReadFile",
              "InternetConnectA",
              "HttpQueryInfoA",
              "InternetOpenA",
              "InternetCloseHandle"
            ],
            "i": "micro-behaviors/communications/http/get::wininet-dynamic-load",
            "l": 2
          },
          {
            "c": 0.8399999737739563,
            "d": "Network byte order conversion",
            "e": [
              "ORDINAL 9",
              "WS2_32.dll"
            ],
            "i": "micro-behaviors/communications/socket/init::htons-api-ordinal",
            "l": 2
          },
          {
            "c": 0.8600000143051147,
            "d": "Initialize Winsock library",
            "e": [
              "WS2_32.dll",
              "ORDINAL 115"
            ],
            "i": "micro-behaviors/communications/socket/init::winsock-startup-ordinal",
            "l": 3
          },
          {
            "c": 0.8799999952316284,
            "d": "Enumerate process environment block",
            "e": [
              "GetEnvironmentStringsW",
              "FreeEnvironmentStringsW"
            ],
            "i": "micro-behaviors/os/env/access::environment-block-enumeration",
            "l": 2
          },
          {
            "c": 0.8999999761581421,
            "d": "Toolhelp thread enumeration strings",
            "e": [
              "Thread32First",
              "Thread32Next"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::toolhelp-thread-enumeration-string",
            "l": 3
          },
          {
            "c": 0.8399999737739563,
            "d": "IPv4 string conversion import",
            "e": [
              "ORDINAL 11",
              "WS2_32.dll"
            ],
            "i": "micro-behaviors/communications/socket/init::inet-addr-api-ordinal",
            "l": 2
          },
          {
            "c": 0.9200000166893005,
            "d": "Dynamically resolve own modules and exports",
            "e": [
              "GetProcAddress",
              "GetModuleHandleA",
              "GetModuleHandleW"
            ],
            "i": "micro-behaviors/os/module/load::dynamic-self-resolution-imports",
            "l": 2
          },
          {
            "c": 0.8799999952316284,
            "d": "Winsock outbound connect import",
            "e": [
              "WS2_32.dll",
              "ORDINAL 4"
            ],
            "i": "micro-behaviors/communications/socket/init::connect-api-ordinal",
            "l": 3
          },
          {
            "c": 0.9200000166893005,
            "d": "Directory walker using Win32 find APIs",
            "e": [
              "FindClose",
              "FindNextFileA",
              "FindFirstFileA"
            ],
            "i": "micro-behaviors/fs/enumerate/directory::find-file-walker",
            "l": 2
          },
          {
            "a": "T1105",
            "c": 0.8999999761581421,
            "d": "WinInet download write and execute chain",
            "e": [
              "CreateProcessA",
              "InternetReadFile",
              "InternetOpenA",
              "DeleteFileA",
              "WriteFile",
              "GetLastError"
            ],
            "i": "objectives/command-and-control/dropper/delivery/download::wininet-download-write-exec",
            "l": 4
          },
          {
            "c": 0.8600000143051147,
            "d": "Winsock send import",
            "e": [
              "ORDINAL 19",
              "WS2_32.dll"
            ],
            "i": "micro-behaviors/communications/socket/init::send-api-ordinal",
            "l": 2
          },
          {
            "a": "T1027",
            "c": 0.8799999952316284,
            "d": "Timing API junk branches in minimal stub",
            "e": [
              "GetTickCount",
              "1c 60 02 10",
              "44 63 02 10",
              "04 61 02 10",
              "88 61 02 10",
              "14 62 02 10"
            ],
            "i": "objectives/anti-static/obfuscation/instruction/junk::timing-junk-code-stub",
            "l": 1
          },
          {
            "a": "T1559",
            "c": 0.8199999928474426,
            "d": "Named pipe server and client wait",
            "e": [
              "WaitNamedPipeA",
              "CreateNamedPipeA",
              "ConnectNamedPipe"
            ],
            "i": "micro-behaviors/communications/ipc/named-pipe::named-pipe-client-server",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Pipe creation with handle redirect",
            "e": [
              "PeekNamedPipe",
              "DuplicateHandle",
              "CreatePipe",
              "SetStdHandle"
            ],
            "i": "micro-behaviors/communications/ipc/pipe::pipe-io-redirect",
            "l": 3
          },
          {
            "c": 0.8799999952316284,
            "d": "Winsock socket creation import",
            "e": [
              "WS2_32.dll",
              "ORDINAL 23"
            ],
            "i": "micro-behaviors/communications/socket/init::socket-api-ordinal",
            "l": 3
          },
          {
            "c": 1.0,
            "d": "Windows memory manipulation (3 of 3)",
            "e": [
              "VirtualAllocEx",
              "CreateRemoteThread",
              "WriteProcessMemory"
            ],
            "i": "well-known/malware/rat/cobalt-strike::mem-functions-3",
            "l": 1
          },
          {
            "c": 0.9200000166893005,
            "d": "Dynamic Toolhelp enumeration suite",
            "e": [
              "Thread32First",
              "GetProcAddress",
              "Thread32Next"
            ],
            "i": "micro-behaviors/process/enumerate/snapshot::dynamic-toolhelp-enumerator",
            "l": 3
          },
          {
            "a": "T1070.004",
            "c": 0.8199999928474426,
            "d": "Resolve own path then delete file",
            "e": [
              "DeleteFileA",
              "GetModuleFileNameA",
              "DeleteFileA",
              "GetModuleFileNameW"
            ],
            "i": "objectives/evasion/self-delete/file::module-path-delete",
            "l": 1,
            "m": "F0007"
          },
          {
            "a": "T1083",
            "c": 0.8600000143051147,
            "d": "Drive context switching via cwd APIs",
            "e": [
              "SetCurrentDirectoryA",
              "GetLogicalDrives",
              "GetCurrentDirectoryA",
              "GetCurrentDirectoryW",
              "GetLogicalDrives"
            ],
            "i": "micro-behaviors/fs/traversal/drives::drive-context-switching",
            "l": 3
          },
          {
            "a": "T1059",
            "c": 0.8999999761581421,
            "d": "Pipe command capture with dynamic HTTP loading",
            "e": [
              "HttpOpenRequestA",
              "PeekNamedPipe",
              "HttpSendRequestA",
              "CreatePipe",
              "InternetConnectA",
              "InternetOpenA",
              "InternetCloseHandle",
              "SetStdHandle",
              "DuplicateHandle",
              "HttpQueryInfoA",
              "InternetReadFile",
              "InternetReadFile"
            ],
            "i": "objectives/command-and-control/backdoor/binary::pipe-command-capture-c2",
            "l": 2
          },
          {
            "a": "T1055",
            "c": 0.6600000262260437,
            "d": "Process injection via Windows API",
            "e": [
              "VirtualAllocEx",
              "WriteProcessMemory",
              "CreateRemoteThread"
            ],
            "i": "objectives/evasion/process/injection/memory::process-inject-api",
            "l": 3,
            "m": "B0033"
          },
          {
            "a": "T1134",
            "c": 0.8600000143051147,
            "d": "Token access and duplication cluster",
            "e": [
              "OpenThreadToken",
              "GetTokenInformation",
              "DuplicateTokenEx",
              "OpenProcessToken"
            ],
            "i": "objectives/privilege-escalation/token-manipulation::token-manipulation-cluster",
            "l": 3
          },
          {
            "a": "T1055",
            "c": 0.8999999761581421,
            "d": "Remote process memory manipulation",
            "e": [
              "VirtualProtectEx",
              "CreateRemoteThread",
              "WriteProcessMemory",
              "OpenProcess",
              "VirtualAllocEx"
            ],
            "i": "objectives/evasion/fileless/memory::remote-injection",
            "l": 3
          },
          {
            "a": "T1622",
            "c": 0.9300000071525574,
            "d": "Debugger check with teardown guards",
            "e": [
              "SetUnhandledExceptionFilter",
              "IsDebuggerPresent",
              "Sleep"
            ],
            "i": "objectives/anti-analysis/debugger-detect/check::debugger-check-with-guards",
            "l": 1,
            "m": "B0001"
          },
          {
            "a": "T1134.001",
            "c": 0.8799999952316284,
            "d": "Dynamic token privilege adjustment chain",
            "e": [
              "AdjustTokenPrivileges",
              "SeDebugPrivilege",
              "SeTcbPrivilege",
              "OpenProcessToken",
              "SeAssignPrimaryTokenPrivilege",
              "LookupPrivilegeValueA"
            ],
            "i": "objectives/privilege-escalation/token-manipulation::dynamic-token-privilege-chain",
            "l": 3
          },
          {
            "a": "T1559",
            "c": 0.800000011920929,
            "d": "Named pipe server creation",
            "e": [
              "ConnectNamedPipe",
              "CreateNamedPipeA"
            ],
            "i": "micro-behaviors/communications/ipc/named-pipe::named-pipe-server",
            "l": 3
          },
          {
            "a": "T1057",
            "c": 0.8999999761581421,
            "d": "ToolHelp snapshot enumeration with process access",
            "e": [
              "OpenProcess",
              "CreateToolhelp32Snapshot"
            ],
            "i": "objectives/discovery/process/targeting::toolhelp-enumeration-with-access",
            "l": 3,
            "m": "E1057"
          },
          {
            "a": "T1055.001",
            "c": 0.8999999761581421,
            "d": "DLL injection API chain with process enumeration",
            "e": [
              "WriteProcessMemory",
              "CreateRemoteThread",
              "CreateToolhelp32Snapshot",
              "VirtualAllocEx"
            ],
            "i": "objectives/evasion/process/injection/dll::game-process-dll-injection-chain",
            "l": 4,
            "m": "B0033"
          },
          {
            "a": "T1055.001",
            "c": 0.9399999976158142,
            "d": "DLL injection via remote LoadLibrary call",
            "e": [
              "WriteProcessMemory",
              "LoadLibraryA",
              "CreateRemoteThread",
              "VirtualAllocEx"
            ],
            "i": "objectives/evasion/process/injection/dll::remote-loadlibrary-injection",
            "l": 5,
            "m": "B0033"
          },
          {
            "c": 0.8999999761581421,
            "d": "Unsigned binary contains DLL name associated with module stomping",
            "e": [
              "binary.has_signature = 0.00",
              "mscoree.dll"
            ],
            "i": "objectives/evasion/process/injection::unsigned-module-stomping-target",
            "l": 1
          },
          {
            "a": "T1105",
            "c": 0.9200000166893005,
            "d": "WinInet downloader with in-memory staging",
            "e": [
              "ExitProcess",
              "VirtualAlloc",
              "InternetReadFile",
              "InternetOpenA",
              "Sleep"
            ],
            "i": "objectives/command-and-control/dropper/delivery/download-execute::wininet-memory-stager",
            "l": 4,
            "m": "E1105"
          },
          {
            "a": "T1055",
            "c": 0.9200000166893005,
            "d": "Cross-process injector references runtime DLL injection target",
            "e": [
              "SetThreadContext",
              "VirtualProtectEx",
              "CreateRemoteThread",
              "mscoree.dll",
              "WriteProcessMemory"
            ],
            "i": "objectives/evasion/process/injection::cross-process-injector-runtime-dll-target",
            "l": 3
          },
          {
            "a": "T1055.012",
            "c": 0.9399999976158142,
            "d": "Parent PID spoofing process attributes",
            "e": [
              "UpdateProcThreadAttribute",
              "InitializeProcThreadAttributeList",
              "CreateProcessA"
            ],
            "i": "objectives/evasion/process/injection/hollowing::ppid-spoofing-attributes",
            "l": 4,
            "m": "E1055.012"
          },
          {
            "a": "T1055",
            "c": 0.9200000166893005,
            "d": "Debug privilege with process injection",
            "e": [
              "CreateRemoteThread",
              "SeAssignPrimaryTokenPrivilege",
              "AdjustTokenPrivileges",
              "VirtualAllocEx",
              "SeDebugPrivilege",
              "WriteProcessMemory",
              "SeTcbPrivilege"
            ],
            "i": "objectives/privilege-escalation/process-injection::debug-privilege-injection",
            "l": 4,
            "m": "E1055"
          },
          {
            "c": 0.8999999761581421,
            "d": "Register and invoke exception filters",
            "e": [
              "SetUnhandledExceptionFilter",
              "UnhandledExceptionFilter"
            ],
            "i": "micro-behaviors/os/exception/error-handling::exception-filter-pair-imports",
            "l": 2
          },
          {
            "a": "T1055.012",
            "c": 0.9200000166893005,
            "d": "Process hollowing via alloc, write, context swap",
            "e": [
              "WriteProcessMemory",
              "CreateProcessA",
              "GetThreadContext",
              "VirtualAllocEx",
              "SetThreadContext",
              "ResumeThread"
            ],
            "i": "objectives/evasion/process/injection/hollowing::process-hollowing-alloc-write-context",
            "l": 2,
            "m": "E1055.012"
          },
          {
            "a": "T1134",
            "c": 0.8399999737739563,
            "d": "User-token process spawn chain",
            "e": [
              "CreateProcessWithTokenW",
              "CreateProcessAsUserA",
              "OpenProcessToken",
              "DuplicateTokenEx"
            ],
            "i": "objectives/privilege-escalation/token-manipulation::token-spawn-api-chain",
            "l": 3
          },
          {
            "a": "T1033",
            "c": 0.8999999761581421,
            "d": "Admin group SID membership check",
            "e": [
              "CheckTokenMembership",
              "AllocateAndInitializeSid"
            ],
            "i": "micro-behaviors/os/privilege/check::admin-sid-check",
            "l": 3
          },
          {
            "a": "T1622",
            "c": 0.949999988079071,
            "d": "Unsigned loader anti-analysis suite",
            "e": [
              "InitializeProcThreadAttributeList",
              "IsDebuggerPresent",
              "UpdateProcThreadAttribute",
              "CreateProcessA",
              "SetUnhandledExceptionFilter",
              "Sleep"
            ],
            "i": "objectives/anti-analysis/debugger-detect/check::unsigned-loader-anti-analysis-suite",
            "l": 4,
            "m": "B0001"
          },
          {
            "a": "T1134",
            "c": 0.8999999761581421,
            "d": "Token spawn with privilege manipulation",
            "e": [
              "LookupPrivilegeValueA",
              "OpenProcessToken",
              "SeTcbPrivilege",
              "AdjustTokenPrivileges",
              "CreateProcessWithTokenW",
              "CreateProcessAsUserA",
              "SeAssignPrimaryTokenPrivilege",
              "SeDebugPrivilege",
              "DuplicateTokenEx"
            ],
            "i": "objectives/privilege-escalation/token-manipulation::token-spawn-privilege-adjust",
            "l": 3
          },
          {
            "c": 0.8999999761581421,
            "d": "Encoded payload detected: xor",
            "e": [
              "193.37.212.20,/c/msdownload/update/other \u003cxor\u003e",
              "@/c/msdownload/update/others/2016/12/014 \u003cxor\u003e",
              "@%windir%\\sysnative\\rundll32.exe \u003cxor\u003e"
            ],
            "i": "metadata/encoded-payload/xor",
            "l": 3
          }
        ],
        "sha": "ff7cd21b958532ae93b7455fe6fb16d4e12da71a9d120fba35da8a1634ad4234",
        "path": "/data/samples/bad/datasets/pe-machine-learning-dataset/502370",
        "type": "pe"
      }
    ],
    "tv": "2a0fe"
  }
}